Investors need to consider cyber preparedness in their investment decisions, writes Kondi Nkosi, country head of Schroders South Africa.
Today, 100% of companies rely on the internet to operate, compared to the one-in-four 10 years ago, according to a study from Accenture. Add to this greater connectivity the increased volume of data being handled by companies and the shift to remote working brought about by Covid-19, and it’s not hard to see why cybercrime represents a significant risk for organisations.
Cybercrime in the headlines
There has been a spate of recent high-profile cyberattacks in which significant companies have been held to ransom. Across the globe, giants such as Colonial Pipeline, the largest fuel pipeline in the United States (US); JBS, the world’s biggest meat processing company, and even Ireland’s National Health Service have all been victims of cyber-attacks.
Locally, there have been a number of cyber breaches across the country, with victims that include key bodies such as the Department of Justice (DOJ) and the South African National Space Agency (Sansa). The DOJ reported that all of its information systems were encrypted, and subsequently internal employees and members of the public were unable to access important data.
These are just a few examples of recent ransomware attacks; a type of cyberattack that involves locking the user out of their own files or systems and demanding a ransom in return for access. In Colonial Pipeline’s case, the ransom was $4.4 million, while JBS was forced to pay the equivalent of $11-million.
Other examples include the foreign exchange company Travelex, which was held to a $6-million ransom in early 2020; the attack on British Airways in 2018 (which resulted in a $26-million fine for the company because it was found not to have sufficient security measures in place) and the 2016 hack into the central bank of Bangladesh’s systems, where criminals made off with $81-million.
Many attacks don’t make the headlines. On a global basis, it’s reported that more than 30-billion data records were stolen in 2020. This is more than in the prior 15 years put together. In the US alone, the FBI received a record nearly 800 000 cybercrime complaints in 2020, a 69% increase on 2019’s total complaints, with reported losses at more than $4,1-billion. In Europe, cyberattacks increased by 75% over 2020 compared to 2019.
Cybercrime prevention: spending surge
The cost of cybercrime globally is expected to hit $6-trillion annually in 2021, and $10,5-trillion by 2025, according to Cybersecurity Ventures, a cyber research company. Cybercrime costs include damage and loss of data, money, productivity, intellectual property, business interruption, the restoration of hacked data and systems and reputational damage.
As a result, spending on protection mechanisms has sky-rocketed. Global spending on cybersecurity products and services is expected to increase at a compound annual growth rate (CAGR) of 7,7% to 14,5% between 2020 and 2026. CAGR indicates the growth rate over multiple periods, taking into account the effects of compounding.
What does cybercrime look like?
Cybercrime can take various forms and is becoming increasingly sophisticated. Most involve a user unwittingly clicking on dangerous links or opening harmful attachments that install malicious software (known as malware), enable the disclosure of confidential information and prevent legitimate users from accessing to necessary systems and data
Weak spots of cybercrime vulnerability
Email is the most common way attackers infiltrate a company’s systems and data. Employees therefore represent the biggest weakness, with the main cause of cybersecurity failures reportedly being human error. This could be an employee failing to install security updates in time, not using a strong enough password to protect sensitive data or falling prey to phishing emails.
On a global basis, 43% of firms view employee naivety about cybersecurity as their most significant organisational weakness, according to the 2021 State of Email Security Report issued by the cybersecurity provider Mimecast. This percentage is notably higher in some countries: in the UK, the Netherlands, South Africa and the United Arab Emirates 50% or more participants view employees’ lack of cyber knowledge as a major threat to their companies’ security, according to its survey.
Rob Hyde, Schroders’ chief information security officer and head of enterprise technology, says: “Training our employees is our best defence against cyberattacks. While we have high-security products to provide protection, ensuring our employees are educated as to how to spot a suspicious email or link is key to our ability to effectively guard our systems and data.
“Corporations have four key adversaries that we try to protect ourselves from. The ‘malicious outsider’ is someone external to the organisation that tries to penetrate our defences to access sensitive or proprietary information. The ‘malicious insider’ is similar but is an employee that we’ve trusted with access to such information. The ‘accidental insider’ is an employee who has unwittingly become part of an attempted attack by clicking on a harmful link or opening a harmful email. We also have the ‘supplier’, which refers to the risk we take on when engaging the services of third-party providers.
“We have measures in place to guard against all four of these and are constantly improving our protection as attackers are becoming increasingly sophisticated in how they try to penetrate our defences. The advent of cryptocurrencies, for example, is creating a means for attackers to profit from their actions in ways that the traditional financial services system would make very difficult,” he says.
Cybercrime can have a considerable impact on financial companies
Any firm that uses the internet is a potential target for cybercriminals and a cyberattack can have a significant impact on a company, whether that’s financially or operationally.
There is also the reputational damage associated with having security defence breaches. On average, it takes two years for a business’s reputation to recover after a data breach is revealed, according to research by HSBC. Meanwhile share prices of companies affected tend to underperform by 15.6% in the following three years.
The finance sector tends to be the worst affected: it experienced the greatest decline in stock prices, of -16,7% on average against the NASDAQ, in comparison to the technology sector, which averaged -2,9%.
Assessing a company’s cyber preparedness
A company’s cyber preparedness should be a crucial consideration in an investor’s investment decision. It is a business risk that investors can’t afford to ignore, according to Samuel Thomas, a sustainable investment analyst at Schroders.
“We use our proprietary ESG tool, Context, to help us measure how well a company is managing cyber risk. This involves assessing whether companies have a cyber security certification and ranking companies on how well they protect their customers’ data.
He says the organisation gains further insights through direct company engagement, focusing on how well a company can answer the questions such as:
* Is there responsibility for cyber security and data privacy at the board and management level?
* How is the company’s technical expertise organised?
* What training and monitoring of employees and suppliers is in place?
* To what extent does the company work with external cyber security specialists?
Fund managers Katherine Davidson and Charles Somers use this approach to assess the cyber preparedness of the companies they invest in.
Davidson says: “Ideally, we’d like to see more cyber security and data privacy expertise at the board and management level of the companies we invest in. Typically, this would include a chief information security officer or data protection officer in charge of cyber matters.”
Research by accounting firms Deloitte and Grant Thornton finds only 8% of FTSE 100 boards had a chief information security officer (CISO) in 2018. Meanwhile more than one-third of FTSE 350 companies that reported technology and cyber security as a key business risk in 2019 did not have directors with relevant expertise on their boards. In the oil and gas, consumer goods and financial sectors, this figure was 50% or more.
“We also want to see adequate protective systems and controls in place, rigorous and systematic testing of these systems and controls, and regular updates of security software,” says Somers.
“It’s important to us too that there’s appropriate training of employees and suppliers and that the security team use external specialists to keep up-to-date with industry trends and best practice.”