Exploring cyber risk reporting in South African banks
Loading...
Date
Authors
Supervisors
Journal Title
Journal ISSN
Volume Title
Publisher
North-West University (South Africa)
Record Identifier
Abstract
Using a qualitative document analysis method, this research explored a unique area with actual risk work, in cyber risk reporting by South African banks listed on the JSE. The study used publicly available integrated reports, risk management reports, and corporate governance reports
(collectively referred to as governance reports) from the top five JSE-listed banks, to address the research question: How can South African banks and regulators enhance cyber risk reporting to better inform investors? As a new research area, this question appeals to stakeholders of the banks and investors. Firstly, to address the research question, a literature review was conducted, analysing peer-reviewed academic literature, South African regulations, and SEC cyber risk reporting guidelines and regulations. This review informed the development of a thematic codebook containing themes and subthemes for cyber risk reporting information, useful for investor decision-making. The literature review highlighted gaps in South Africa's regulatory framework on cyber risk reporting. Secondly, the banks' governance reports were evaluated against these themes and subthemes to assess whether the information provided is beneficial for investor decision-making. The findings indicated that, while banks report some relevant cyber risk information, there are gaps in the completeness and comprehensiveness. As such, the study recommends that South Africa's regulators enhance regulatory requirements to mandate cyber risk incident reporting for investor decision-making and to provide more detailed guidance on information to be included in annual governance reports. It is also recommended that banks use these findings to evaluate and improve their reporting for greater transparency. Although this study has limitations, it offers valuable insights into the banking industry, regulators, and academics by providing guidance to the banks to improve their cyber risk reporting practices, suggesting improvements to the regulatory framework, and contributing to the body of knowledge on cyber risk reporting in a South African context.
Sustainable Development Goals
Description
Master of Commerce in Applied
Risk Management , North-West University, Vanderbijlpark Campus
