Article navigation
Purpose

This study aims to examine how organizations communicate security compliance in mandatory data breach announcements. It investigates how compliance-related dimensions – internal/external investigations, internal compliance, legal enforcement, and customer protection – are embedded in publicly disclosed breach communications. By shifting attention from the market consequences of breach announcements to their informational content and structure, the study advances understanding of compliance as a central and explicitly communicated component of post-breach disclosure.

Design/methodology/approach

The authors use a large-scale text-mining approach using Latent Dirichlet Allocation (LDA) topic modeling to analyze 292 publicly disclosed data breach announcements filed between 2015 and 2022. After preprocessing the documents with natural language processing techniques, the authors applied an LDA MALLET model to identify latent thematic structures. Topic coherence scores guided the selection of the optimal number of topics, which were consolidated into six higher-level thematic categories through iterative interpretation.

Findings

The analysis identified 13 latent topic groups consolidated into six thematic categories: incident description, incident content, investigation activities, internal compliance, legal and regulatory enforcement and customer protection and remediation. Four dimensions – internal/external investigation, internal compliance, legal enforcement, and customer protection – emerged as central to security compliance. The findings show that compliance is structurally embedded in breach disclosures and communicated as evidence of accountability, governance maturity and regulatory alignment, rather than treated as a peripheral condition of breach management.

Originality/value

This study introduces a content-centric perspective to data breach research by analyzing the textual structure of data breach announcements rather than focusing solely on market reactions. It conceptualizes security compliance as a multidimensional, communicative construct that integrates governance, regulation, investigation, and remediation. By combining topic modeling with security governance theory, the study provides novel theoretical insights and practical guidance for organizations, regulators and policymakers regarding data breach disclosure practices.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$41.00
Rental

or Create an Account

Close Modal
Close Modal