This article originally appeared on the NACD BoardTalk blog. Reprinted with permission.
“What we’ve got here is failure to communicate.” I’m reminded of this line—famously uttered by the prison guard to Paul Newman’s character in Cool Hand Luke—when I think about the disconnect between companies and their investors on cybersecurity, which is one of the critical risk issues of our time.
In recent years, investors have identified cybersecurity as one of their critical areas of concern. A 2021 RBC Global Asset Management survey identified cybersecurity as the second-highest ranked governance issue for investors. More recently, a 2022 report from Fidelity affirms the investor’s perspective on the importance of cybersecurity: “we believe cybersecurity is material to all industries and sectors.”
Investors are worried about cybersecurity—and for good reason. Cybersecurity is a critical risk that can materially impact a company’s long-term value and sustainability. And with ransomware incidents growing significantly year over year, changes in cyber insurance coverage and costs, and expanding digitalization that introduces new risks for companies, things are only going to get more challenging.
Yet despite growing concerns and the criticality of the issue, the dialogue between companies and investors still feels closed. When asked by Forrester Consulting about communicating cybersecurity metrics to stakeholders, security decision-makers ranked investors last on a list of audiences who receive accurate measurements of their companies’ security performance. Many investors feel that they are not getting critical information they need from companies to make informed decisions. Inconsistency in the frequency and substance of companies’ disclosures related to cyber risk, investment, policy, readiness, and incidents are contributing to significant uncertainty and concern within the investment community that their investments are at risk.