It seems everyone is concerned about cybersecurity these days, and the investor community is no different. Shareholders are reading the headlines—ransomware attacks, data breaches, infrastructure disruptions—and they are wondering how these incidents could impact the companies that they invest in.
Shareholders are about to get a lot more information from companies in the months ahead. In July 2023, the U.S. Securities and Exchange Commission (SEC) adopted new cybersecurity disclosure requirements that are designed to provide shareholders with enhanced information to help them understand how companies are addressing cybersecurity risks.
In this new era of transparency and accountability, how can shareholders leverage cybersecurity information in their investment decisions and corporate engagement strategies? In Part II of our series on cybersecurity, we’ll discuss a few key issues for shareholders:
- Is cybersecurity a material financial risk?
- How should shareholders evaluate the cybersecurity of companies they invest in?
- What should shareholders expect from disclosures?
- What are important indicators that a company’s cybersecurity program is performing well… or not?
1. Cybersecurity can impact financial performance
First things first—is cybersecurity really a material issue for investors? The answer is a resounding “yes.”
Cybersecurity performance is a governance indicator that is a positive indicator of company performance and a negative indicator of downside risk. Research shows that poor cybersecurity can have a negative impact on share price. In recent years, various researchers have demonstrated that significant cybersecurity incidents can cause material declines in both share price and market share. These analyses are based on reviewing publicly disclosed breaches and tracking share price post-breach. Credit ratings services firm Moody’s frequently warns that cyber incidents can be credit negative for affected companies and sectors.
But cybersecurity should not just be viewed by shareholders as an investment risk. Research also demonstrates that ongoing, strong cybersecurity performance is also linked to higher valuations. Well-performing companies were demonstrated to actually outperform a benchmark index by approximately 1% to 2% with lower volatility. In certain sectors, such as U.S. Technology, well-rated companies outperform the benchmark by 7%.
In other words, cybersecurity represents both risk and opportunity for shareholders. It has never been more important for shareholders to understand how the companies that they invest in are approaching cyber risk management. Now that the new SEC regulation is in effect, what should they do?
2. What does the new SEC regulation require companies to disclose?
Shareholders can anticipate learning more from public companies about their cybersecurity programs and performance in the months ahead. The SEC’s cybersecurity regulation creates new obligations for public companies to report “material” cybersecurity incidents and require more detailed disclosure of cybersecurity risk management, expertise, and governance. Companies are required to disclose risks in their annual reports beginning on December 15, 2023.
The SEC’s cybersecurity regulation will require disclosure in three main areas:
- First, the SEC requires organizations to describe the company’s processes for assessment, identification, and management of material risks from cybersecurity threats in its Form 10-K.
- Second, organizations must describe the board’s oversight of risks from cybersecurity threats and management’s role in assessing and managing material risks from cybersecurity threats in its Form 10-K.
- Third, the SEC requires disclosure of any material cybersecurity incident in Form 8-K within four business days of determining that an event is material.
Many companies have, in practice, disclosed cybersecurity information (usually as a “risk factor”) in various SEC filings over the years. For example, in a 2022 analysis of Fortune 100 company disclosures, the EY Center for Board Matters found that 99% of companies referenced efforts to mitigate cybersecurity risk, such as the establishment of processes, procedures and systems; 66% referenced response readiness, such as planning, disaster recovery or business continuity considerations; and 88% disclosed that at least one board-level committee was charged with oversight of cybersecurity matters. In the months ahead, we can expect more specific information about management and board efforts from all publicly traded companies, not just the Fortune 100.