The Sarbanes-Oxley legislation is a mandate that is bringing new attention to IT security as a critical part of the risk management framework for the dual purposes of certifying internal controls and attesting to the accuracy of information. Regulatory compliance, security audits and mandatory information disclosure about internal weaknesses can be very costly from a budget standpoint because internal resources need to be allocated away from critical functions such as innovation and product development into increased investments in technologies that facilitate compliance. We propose a theoretical framework towards analyzing the economic impact of government mandated information disclosure and internal audits on flrms’ investments in IT security, the optimal levels of industry wide production and the extent of market competition. Our analysis reveals that mandatory investments in regulatory compliance may have several unintended consequences such as reduction in optimal production quantities, decrease in the extent of market competition and an overall reduction in social welfare due to distortions in IT security and internal control investments. In particular, our results highlight that smaller sized flrms are more severely afiected than larger flrms and this process may lead to a severe long term impact on the operations of both capital as well as product markets. Our results are in accordance with recent anecdotal and empirical evidence.