Cybersecurity Risks in Digitized Capital Markets: A Comparative Regulatory Analysis of Operational Resilience, Disclosure, and Market Integrity

Authors

Akomolehin Francis Olugbenga

Department of Finance, College of Management & Social Science Afe Babalola University, Ado - Ekiti Ekiti (Nigeria)

Article Information

DOI: 10.51244/IJRSI.2026.1307000252

Subject Category: FINANCE

Volume/Issue: 13/7 | Page No: 3493-3510

Publication Timeline

Submitted: 2026-07-28

Accepted: 2026-08-03

Published: 2026-08-10

Abstract

The digitization of capital markets has increased efficiency, connectivity, and innovation, but it has also transformed cybersecurity from an institution-specific technical concern into a systemic threat to market integrity and financial stability. This study evaluates the adequacy and coherence of cybersecurity regulation in digitized capital markets. It employs qualitative policy analysis, doctrinal review, and comparative analysis of the United States Securities and Exchange Commission framework, the European Union’s Digital Operational Resilience Act, and IOSCO/CPMI-IOSCO standards. Regulatory documents and scholarly evidence covering 2020–2026 are assessed through directed content analysis and a comparative matrix spanning governance, incident reporting, disclosure, resilience testing, third-party risk, business continuity, enforcement, and systemic resilience. The findings reveal partial regulatory convergence but persistent structural fragmentation. The United States prioritizes disclosure and investor protection; the European Union adopts a broader operational-resilience model; and international standards emphasize financial-market infrastructures, coordination, and systemic stability. Major deficiencies include weak integration between disclosure and resilience requirements, uneven oversight of critical technology providers, inconsistent incident definitions and reporting timelines, limited cross-border enforcement, and inadequate treatment of contagion and market outages. The study proposes a multilayered regulatory model that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing. Such integration is essential for protecting investors, preserving market continuity, and containing systemic cyber risk.

Keywords

Cybersecurity risk; Digitized capital markets; Operational resilience; Regulatory governance

Downloads

References

1. Amani, F., Magnan, M., & Moldovan, R. (2025). Cybersecurity risks and incidents disclosure: A literature review. Accounting Perspectives, 24(3), 605–667. https://doi.org/10.1111/1911-3838.12411 [Google Scholar] [Crossref]

2. Buttigieg, C. P., & Brunelli Zimmermann, B. (2024). The digital operational resilience act: Challenges and reflections on the adequacy of Europe’s supervisory architecture. ERA Forum, 25, 11–28. https://doi.org/10.1007/s12027-024-00793-w [Google Scholar] [Crossref]

3. Chen, X., Hilary, G., & Tian, X. (2025). Mandatory data breach disclosure and insider trading. Journal of Business Finance & Accounting, 52(5–6), 2091–2110. https://doi.org/10.1111/jbfa.12842 [Google Scholar] [Crossref]

4. European Insurance and Occupational Pensions Authority. (2026). Digital operational resilience act (DORA). https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en [Google Scholar] [Crossref]

5. European Securities and Markets Authority. (2026). Digital operational resilience act (DORA). https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora [Google Scholar] [Crossref]

6. European Union. (2022). Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. Official Journal of the European Union, L 333, 1–79. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng [Google Scholar] [Crossref]

7. Gao, L., & Calderon, T. G. (2025). Cybersecurity risk governance and corporate cybersecurity risk disclosures. Journal of Accounting and Public Policy, 54, 107376. https://doi.org/10.1016/j.jaccpubpol.2025.107376 [Google Scholar] [Crossref]

8. Huang, J., & Murthy, U. (2024). The impact of cybersecurity risk management strategy disclosure on investors’ judgments and decisions. International Journal of Accounting Information Systems, 54, 100696. https://doi.org/10.1016/j.accinf.2024.100696 [Google Scholar] [Crossref]

9. International Organization of Securities Commissions. (2024). Market outages (Final Report No. FR04/2024). https://www.iosco.org/library/pubdocs/pdf/IOSCOPD767.pdf [Google Scholar] [Crossref]

10. International Organization of Securities Commissions. (2025). Annual report 2024. https://www.iosco.org/annual_reports/2024/pdf/annualReport2024.pdf [Google Scholar] [Crossref]

11. Kotidis, A., & Schreft, S. L. (2025). The propagation of cyberattacks through the financial system. The Journal of Finance, 80(6), 3313–3358. [Google Scholar] [Crossref]

12. Tan, W., Guo, B., & Zhang, Q. (2025). Cybersecurity governance and corporate market value: Perspectives from investor trust and supply chain trust. Pacific-Basin Finance Journal, 90, 102646. https://doi.org/10.1016/j.pacfin.2024.102646 [Google Scholar] [Crossref]

13. U.S. Securities and Exchange Commission. (2023a). Cybersecurity risk management, strategy, governance, and incident disclosure (Release No. 33-11216). https://www.sec.gov/files/rules/final/2023/33-11216.pdf [Google Scholar] [Crossref]

14. U.S. Securities and Exchange Commission. (2023b, July 26). SEC adopts rules on cybersecurity risk management, strategy, governance, and incident disclosure. https://www.sec.gov/newsroom/press-releases/2023-139 [Google Scholar] [Crossref]

15. Zhang, Q., & Wong, J. B. (2025). Cybersecurity risks and stock liquidity. International Journal of Managerial Finance, 21(3), 841–861. https://doi.org/10.1108/IJMF-05-2024-0253 [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles