This study aims to examine how organizations communicate security compliance in mandatory data breach announcements. It investigates how compliance-related dimensions – internal/external investigations, internal compliance, legal enforcement, and customer protection – are embedded in publicly disclosed breach communications. By shifting attention from the market consequences of breach announcements to their informational content and structure, the study advances understanding of compliance as a central and explicitly communicated component of post-breach disclosure.
The authors use a large-scale text-mining approach using Latent Dirichlet Allocation (LDA) topic modeling to analyze 292 publicly disclosed data breach announcements filed between 2015 and 2022. After preprocessing the documents with natural language processing techniques, the authors applied an LDA MALLET model to identify latent thematic structures. Topic coherence scores guided the selection of the optimal number of topics, which were consolidated into six higher-level thematic categories through iterative interpretation.
The analysis identified 13 latent topic groups consolidated into six thematic categories: incident description, incident content, investigation activities, internal compliance, legal and regulatory enforcement and customer protection and remediation. Four dimensions – internal/external investigation, internal compliance, legal enforcement, and customer protection – emerged as central to security compliance. The findings show that compliance is structurally embedded in breach disclosures and communicated as evidence of accountability, governance maturity and regulatory alignment, rather than treated as a peripheral condition of breach management.
This study introduces a content-centric perspective to data breach research by analyzing the textual structure of data breach announcements rather than focusing solely on market reactions. It conceptualizes security compliance as a multidimensional, communicative construct that integrates governance, regulation, investigation, and remediation. By combining topic modeling with security governance theory, the study provides novel theoretical insights and practical guidance for organizations, regulators and policymakers regarding data breach disclosure practices.
