This policy brief is based on Journal of Corporate Finance Volume 98. The views expressed are those of the authors and not necessarily those of the institutions the authors are affiliated with.
Abstract
As cyber threats have become a growing concern for firms and financial markets alike, understanding how they affect borrowing costs is increasingly important. We find that lenders adjust loan pricing when a firm’s cyber risk rises, mainly by responding to changes within the same firm over time. Borrowing costs increase modestly, especially for commercial bank loans, while the effect is weaker when non bank lenders are involved. We also find that cyber insurance does not mitigate this pricing effect. Notably, cyber risk is priced only when lenders themselves are attentive to cybersecurity issues, underscoring the importance of risk awareness for the recognition and pricing of the risk.
The SEC’s disclosure guidance of October 2011 states that “registrants should review, on an ongoing basis, the adequacy of their disclosure relating to cybersecurity risk and cyber incidents” (U.S. Securities and Exchange Commission, 2011). Accordingly, an increasing share of firms in the US explicitly discuss cybersecurity risk in their annual filings. In Choi, Degryse and Smedts (2026), we study whether lenders are pricing the disclosed cybersecurity risks. To measure firms’ exposure to cybersecurity risk, we rely on the data of Florackis et al. (2023), which are based on textual analysis of cybersecurity-related disclosures in the “Item 1A. Risk Factors” section of firms’ 10-K filings.1 Figure 1 illustrates the increasing number of U.S. firms discussing cybersecurity risk in their disclosures.
Figure 1. Cybersecurity risk over time of U.S. Firms

Figure 2 further shows that cybersecurity risk is not confined to a small set of industries. While sectors with direct consumer interaction and extensive digital activity, such as passenger transportation, retail, and business and educational services, tend to face higher cybersecurity risk, median cybersecurity risk levels are broadly similar across industries. At the same time, there is substantial variation within industries, indicating that cyber risk is widespread.
Figure 2. Distribution of cybersecurity risk by two-digit SIC industry
Using US syndicated loan data from Thomson Reuters’ LPC DealScan2 over the period 2012-2018, covering 5,957 loans to 1,714 unique borrowers, we find that lenders do incorporate cybersecurity risk into loan pricing, but in a nuanced way. Rather than responding to differences across firms, lenders primarily react to changes in a borrower’s cybersecurity risk over time. When a firm’s cyber risk increases with one standard deviation, loan spreads rise by approximately 4 to 13 basis points.
In contrast, lenders do not appear to price persistent cross-sectional differences between firms, such as those between technological leaders and laggards. Rather than relying on broad comparisons across borrowers, they focus on firm-specific changes in risk. This pattern suggests that cybersecurity risk is highly idiosyncratic and cannot be understood as an industry-wide characteristic. As a result, simple cross-sectional analyses that abstract from firm-level dynamics are unlikely to capture cybersecurity risk accurately.
We also find important differences across lender types. Commercial banks adjust loan pricing more strongly in response to cybersecurity risk, while the presence of non-bank lenders attenuates this effect. The underlying mechanism remains an open question. One plausible explanation is that commercial banks operate under tighter regulatory requirements, leading them to adopt a more cautious approach to (emerging) risks. Non-bank lenders, by contrast, may exhibit greater risk tolerance and may be more accustomed to lending to riskier borrowers.
Firms may purchase cyber insurance to protect themselves against losses from cyber incidents.3 Our results show that firms are more likely to hold cyber insurance when they are riskier than their peers within the same industry. This pattern is consistent with adverse selection, particularly in an environment characterized by severe information asymmetries around cybersecurity risk. At the same time, firms do not appear more likely to purchase insurance when their own cybersecurity risk increases over time. This may help explain why lenders primarily price cybersecurity risk in response to within-firm changes. If insurance coverage does not evolve with a firm’s risk profile, lenders may place greater weight on such firm-specific worsening trends when assessing and pricing residual risk.
We further find that holding cyber insurance does not reduce loan spreads. Several factors may account for this result. First, insurance typically covers only a limited share of the direct losses associated with a cyber incident. Coverage may also be denied, in whole or in part, when losses fall outside policy terms or when the insured fails to meet agreed minimum standards. Second, insurance does not appear to reduce the likelihood of future breach events. If anything, our results suggest that riskier firms are more likely to hold cyber insurance. Third, insurance may give rise to moral hazard by weakening incentives to invest in stronger cyber security practices. Taken together, these findings suggest that cyber insurance neither materially lowers the probability of a breach nor fully shields firms from the financial consequences of cyber incidents. As a result, lenders do not appear to view insurance as a sufficient mitigant when pricing cybersecurity risk.
A related question is whether lenders own awareness of cybersecurity risk matters to incorporate borrowers’ cybersecurity risk into loan pricing. Using data from from Jamilov et al. (2021), we capture lenders’ discussions regarding their own cybersecurity risk and insurance policy, thereby measuring their level of awareness on cybersecurity risk and internal risk management policy. As lenders become more conscious of this source of vulnerability, they may also become more likely to recognize and price similar risks among their borrowers.
Our findings show that borrowers’ cybersecurity risk is priced only when loans are arranged by lenders that explicitly discuss their own cybersecurity risk. This pricing effect is even stronger when lenders also discuss their cyber insurance policies. This suggests that lender awareness is a necessary condition for cybersecurity risk to be reflected in loan pricing at all. We also find that the intensity of these discussions matters. Lenders that engage more extensively with cybersecurity issues, as measured by the frequency of cybersecurity-related keywords in conference calls, charge higher loan spreads to riskier borrowers. Finally, awareness shapes not only pricing but also risk exposure. As lenders become more attentive to their own cybersecurity risk, they reduce their share in loans involving cyber-riskier borrowers.
Cyber risk is widespread across firms, difficult to capture through simple industry comparisons, and highly dependent on firm-specific developments. Our findings highlight the importance of lender awareness in determining whether and how cybersecurity risk is reflected in loan pricing. This points to an important role for policy in helping financial institutions identify, assess and incorporate cyber risk into lending decisions. Supervisory guidance, stress tests, and targeted risk assessment exercises could support lenders in developing a more systematic understanding of cyber-related vulnerabilities, thereby promoting more consistent pricing and exposure decisions.
These insights are likely to extend beyond cybersecurity. Other emerging risks, such as biodiversity or climate-related transition risks, share similar features: they are difficult to measure, evolve rapidly, and are often poorly captured by traditional risk models. Strengthening the capacity of financial institutions to recognize, assess, and price such risks will therefore be critical for safeguarding financial stability more broadly.
At the same time, our findings reveal two potential weaknesses in how cybersecurity risk is absorbed by credit markets. First, the participation of non-bank lenders appears to weaken the pricing of cybersecurity risk by commercial banks, suggesting that risk discipline may erode as lending shifts toward less regulated segments of the financial system. Second, cyber insurance does not appear to reduce the premium lenders attach to cyber risk, possibly reflecting severe information asymmetries and the limited protection insurance offers against cyber-related losses. Taken together, these findings suggest that effective policy should not only enhance risk awareness, but also address the institutional settings in which cybersecurity risk is priced, particularly differences in lender incentives and the pronounced information frictions surrounding cyber risk.
Choi, B. M., Degryse, H., & Smedts, K. (2026). Do lenders price firms’ cybersecurity risk?. Journal of Corporate Finance, 102958.
Florackis, C., Louca, C., Michaely, R., & Weber, M. (2023). Cybersecurity risk. The Review of Financial Studies, 36(1), 351-407.
Jamilov, R., Rey, H., & Tahoun, A. (2021). The anatomy of cyber risk (No. w28906). National Bureau of Economic Research.
It calculates the similarity between a firm’s current disclosure and pre-breach disclosures (t-1) of firms that have experienced significant data breaches. The underlying assumption of this measure is that firms with similar levels of cybersecurity risk use similar language to describe their risk exposure and management strategies. Thus, a higher score is associated with higher risk. More details in Florackis et al. (2023).
It provides comprehensive data on syndicated loans including loan amounts, maturity, interest rates, lender information and additional loan-specific information such as collateral and covenants. The data is estimated to encompass up to 75% of the total value of all outstanding commercial loans in the U.S. after 1995.
A firm is classified as having cyber insurance if insurance-related topics appear at least once in any quarterly earnings call during a given year. We use the data from Jamilov et al. (2021), which identify insurance-related topics occurring within 50 words of cybersecurity-related terms in firms’ quarterly earnings call transcripts. In our loan-level sample, 28% have cybersecurity insurance coverage.