This blog was written by Pallavi Sharma and originally appeared on glasslewis.com and be read here. It has been republished with permission.
Cybersecurity continues to pose a significant risk to public companies and their investors.
Companies are under attack from malicious actors. From ransomware to security breaches targeting critical infrastructure, cyber risk continues to escalate. The FBI reported $43 billion has been stolen over the last five years from companies through impersonation of executive emails. Attacks targeting critical infrastructure appear to be increasing and the financial loss could be tremendous; according to a recent Moody’s analysis, $22 trillion of Moody’s-scored debt is associated with sectors having High or Very High cyber risk exposure. High-profile cybersecurity attacks continue to dominate the news cycle, and public companies like Uber, Activision, and others have all experienced public cybersecurity incidents in recent months.
The business impact of these incidents can no longer be ignored. Costs to businesses and investors can include: remediation and litigation costs (including regulatory action); increased cyber protection costs and insurance premiums; reputational damage; lost revenue; and damage to the stock-price and long-term shareholder value.
Investors have become deeply concerned about cybersecurity and how security incidents can impact their investments. Warren Buffett has called cybersecurity the “number one problem with mankind.” In the RBC Global Asset Management Responsible Investment Survey, investors ranked cybersecurity as the number one most concerning environmental, social, and governance (ESG) issue. The Securities and Exchange Commission has turned its attention to the issue as well, with proposed rules on cybersecurity risk management and oversight.