Companies with advanced cyber security performance create 372% higher shareholder returns compared to their peers with basic cyber security performance, according to a new report from Diligent and Bitsight. The report also reveals that companies with either a specialized risk committee or audit committee achieve better cyber security performance compared to those with neither, and that only 5% of companies have cyber security experts on their boards.
These findings show that cyber security is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on. With increased pressure from regulators for organizations to demonstrate how they oversee cyber security, now is the time for boards and leaders to build their competency around cyber risk.
Dottie Schindlinger, Executive Director of the Diligent Institute
In the report, Cybersecurity, Audit and the Board, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Findings include:
Companies with measurably stronger cyber security performance deliver higher financial performance than their peers
- The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
- Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.
Companies with specialized risk or audit committees have better cyber security performance
- The median cyber security rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
- Having a cyber security expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cyber security experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cyber security experts on the general board, but not on either committee attain a security rating of 580.
Cyber security is no longer about simply mitigating risk, it’s now a key indicator of financial performance. Companies must treat cyber security as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards.
Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board
Methodology
Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cyber security ratings based on externally observable measurements of an organization’s security posture.






