Empirical Researcher & Data Scientist
Doctoral Candidate (ABD), Business Administration — Business Analytics
University of South Alabama · Mitchell College of Business
Timothy D. Spivey is a doctoral candidate in Business Administration with a Business Analytics emphasis at the University of South Alabama, where his dissertation examines what mandatory breach disclosure timing actually does — to markets, to organizations, and to boards.
The question is not whether disclosure matters. It is whether mandating when a firm discloses produces the benefit regulators assumed it would. Across three empirical channels, his work finds real costs and little of the intended benefit. The empirical backbone is a natural experiment built on the FCC's 2007 mandatory disclosure rule (47 CFR § 64.2011), applied to 1,054 breach events from 2006 to 2025.
Outside the dissertation, he supervises management information systems at Mediacom Communications and teaches entrepreneurship and small business accounting as an adjunct at Pensacola State College. Nearly twenty years of telecom operations sits underneath the research: he has built the reporting pipelines, sat in the escalation calls, and watched compliance decisions get made under real pressure. That is why the empirical questions he chases are the ones practitioners recognize.
He holds an MBA in Business Analytics from the University of West Florida and a BAS in Organizational Administration from Pensacola State College — where he now teaches.
What happens when regulation meets reality — mandatory disclosure, cybersecurity governance, and the ethical use of data, measured empirically.
How mandatory disclosure timing affects equity valuations and how investors price breach risk. Does forcing faster disclosure protect markets, or does it amplify volatility?
The operational friction of disclosure: how mandates strain organizational capacity, extend remediation timelines, and leave information asymmetries standing even after the report is filed.
Board-level response and decision-making under disclosure pressure. How compliance requirements reshape governance structures without necessarily improving security outcomes.
Algorithmic bias in hiring systems and the over-education paradox, framed through social exchange theory and organizational justice theory.
What actually causes privacy problems inside enterprise analytical pipelines, and where governance breaks down.
Reproducible research infrastructure: 1,054 breach events across nineteen years, normalized from inconsistent public sources into a Python and Snowflake pipeline matched to market data.
Practitioner research on security culture and IT governance.
Editorial review service and professional memberships.
International peer-reviewed journal, Q1 in Business, Management and Accounting; indexed in Scopus, EconBiz, EconLit, and RePEc.
International peer-reviewed journal covering strategic management, business development, and organizational growth.
Information Systems Audit and Control Association — professional association for IT audit, governance, and security.
Business and professional writing courses taught across Northwest Florida institutions, alongside doctoral study.
Academic history, complete publication list, applied work, and service record.
Research collaboration, speaking, teaching, or consulting — reach out.