Beyond Binary Disclosure: Anchored LLM Assessment of 10-K Cybersecurity Disclosure Quality and Market Reactions

Authors

  • Winston Cai Department of Information Systems and Operations Management, George Mason Unviersity, Fairfax, VA
  • Sherry Chen Department of Information Systems and Operations Management, George Mason Unviersity, Fairfax, VA
  • Ishaan Tharian Joshy Department of Information Systems and Operations Management, George Mason Unviersity, Fairfax, VA
  • Riddhima Singh Department of Information Systems and Operations Management, George Mason Unviersity, Fairfax, VA
  • Si Xie Department of Information Systems and Operations Management, George Mason Unviersity, Fairfax, VA

DOI:

https://doi.org/10.13021/jssr2026.5722

Abstract

Cybersecurity incidents can trigger negative market reactions as investors anticipate potential earnings declines or operational disruptions resulting from cyberattacks. Prior research has examined the relationship between these cybersecurity incidents, market reactions measured by cumulative abnormal returns (CARs), and subsequent cybersecurity disclosure behavior. However, previous methods analyze these disclosures with simplistic measures such as binary indicators, keyword searches, and disclosure length. It remains unclear whether the observed relationship between breach-related market reactions and the quality of subsequent 10-K disclosures changes when a more detailed method for analyzing cybersecurity disclosures is used. Recent financial and accounting research also signals the emerging use of LLMs to analyze these disclosures, motivating the use of these technologies. This study used OpenAI’s GPT-5.6 Luna to grade the same 8 cybersecurity disclosure factors over an anchored LLM rubric with subscores of 0-4 for each factor. A traditional, binary rubric was also evaluated by the LLM. Both the traditional and anchored disclosure scores were regressed against the breach-related CARs and previous-year Fama-French risk controls. The study found that firms experiencing more negative CARs following cybersecurity breaches tend to provide higher-quality 10-K disclosures, as measured by our LLM-anchored rubric score. The corresponding relationship for the traditional unweighted scoring index holds no significance. These findings suggest that anchored LLM scoring may offer a new approach for identifying economically relevant variation in disclosure quality relative to traditional indexes.

Published

2026-09-24

Issue

Section

Costello College of Business: Department of Information Systems and Operations Management