Cybersecurity Risks in Digitized Capital Markets: A Comparative Regulatory Analysis of Operational Resilience, Disclosure, and Market Integrity
Abstract
The digitization of capital markets has increased efficiency, connectivity, and innovation, but it has also transformed cybersecurity from an institution-specific technical concern into a systemic threat to market integrity and financial stability. This study evaluates the adequacy and coherence of cybersecurity regulation in digitized capital markets. It employs qualitative policy analysis, doctrinal review, and comparative analysis of the United States Securities and Exchange Commission framework, the European Union’s Digital Operational Resilience Act, and IOSCO/CPMI-IOSCO standards. Regulatory documents and scholarly evidence covering 2020–2026 are assessed through directed content analysis and a comparative matrix spanning governance, incident reporting, disclosure, resilience testing, third-party risk, business continuity, enforcement, and systemic resilience. The findings reveal partial regulatory convergence but persistent structural fragmentation. The United States prioritizes disclosure and investor protection; the European Union adopts a broader operational-resilience model; and international standards emphasize financial-market infrastructures, coordination, and systemic stability. Major deficiencies include weak integration between disclosure and resilience requirements, uneven oversight of critical technology providers, inconsistent incident definitions and reporting timelines, limited cross-border enforcement, and inadequate treatment of contagion and market outages. The study proposes a multilayered regulatory model that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing. Such integration is essential for protecting investors, preserving market continuity, and containing systemic cyber risk.