IT auditing in assurance of financial statement: what characterizes Cybersecurity data breach disclosure by Brazilian filers of NYSE?
Joshua Onome Imoniana, Washington Lopes da Silva, Vilma Geni Slomski, Valmor Slomski · Procedia Computer Science · 2025
This study explores the characteristics of data breach disclosure (DBD) by the Brazilian NYSE filings for the period of 2018 through 2024. The study collated the narratives of the secondary data of 6 companies purposefully, disclosing their financial statements as filers. The study emphasizes Information quality spurred by staggered adoption of DBD laws. For Brazilian filers (of F-20) a key factor in determining whether to disclose a data breach is whether it is meaningful to influence an investor’s decision. This further depends on factors like the size of the breach, the sensitivity of the data, and potential financial impacts. Results show that estimation in respect of materiality impact sounds vague with the rules provided by SEC. No yardstick as to determining the extension of impacts of cybersecurity breach. Brazilian companies are yielding to the SEC rules upon complying with DBD by narrating the incidents and presenting the apparent impacts. Most of the companies disclosed non-impact while responding to incidents timely. Findings also show breach of integrity of customers’ financial data, leading to potential losses and reputational damage, nevertheless, this is not readily measured. This study offers an exhaustive debate on cybersecurity and challenges posed to accounting and assurance. The study imparts valuable insights to regulators and suggestions for the academia and the policy makers.