Business Wire

NY-DILIGENT

Share
Companies With Advanced Cybersecurity Performance Deliver Nearly Four Times’ Higher Shareholder Return Than Their Peers, According to Diligent and Bitsight

Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.

“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”

“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.

In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:

Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers

  • The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
  • Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.

Companies with specialized risk or audit committees have better cybersecurity performance

  • The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
  • Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.

Highly regulated industries outperform other industries in cybersecurity performance

  • The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
  • By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.

"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."

Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.

View the full report here.

Methodology

Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.

About Diligent

Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.

Follow Diligent on LinkedIn, X (Twitter) and Facebook.

About Bitsight

Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240326307541/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Ant International Partners with Google’s Universal Commerce Protocol to Expand AI Capabilities12.1.2026 02:15:00 CET | Press release

Ant International, a leading global payment, digitisation, and financial technology provider, is collaborating on the launch of Google’s Universal Commerce Protocol (UCP), a new open standard for agentic commerce that works across the entire shopping journey — from discovery and buying to post-purchase support. UCP establishes a common language for agents and systems to operate together across consumer surfaces, businesses, and payment providers to enable commerce. So instead of requiring unique connections for every individual agent, UCP enables all agents to interact easily. UCP is built to work across verticals and is compatible with existing industry protocols like Agent2Agent (A2A), Agent Payments Protocol (AP2), and Model Context Protocol (MCP). “For agentic commerce to scale, it’s critical for the industry to align on a common set of standards. We are proud to have Ant International endorse the Universal Commerce Protocol as the foundation for that future,” said Ashish Gupta, VP

Torq Secures $140M Series D at $1.2B Valuation to Lead the AI SOC and Agentic AI Era11.1.2026 17:59:00 CET | Press release

Fueled by Massive Customer Adoption of AI Agents, Torq Scales the World’s First True AI SOC Platform and Accelerates Expansion into the U.S. Federal Market Torq, the established Agentic AI security operations pioneer, today announced it has closed a massive $140 million Series D funding round, propelling its valuation to $1.2 billion and total funding to $332M. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260112510774/en/ Led by Merlin Ventures—a leading cybersecurity fund renowned for its deep access to the U.S. commercial and Public Sector markets—with participation from all existing investors, including Evolution Equity Partners, Notable Capital, Bessemer Venture Partners, Insight Ventures Partners, and Greenfield Partners, this capital injection is a definitive investment in the future of security. Torq is driving the industry’s critical shift: the complete transformation of the Security Operations Center (SOC) through

Andersen udvider sine kompetencer med tilføjelsen af Scimitar9.1.2026 21:44:00 CET | Pressemeddelelse

Andersen Consulting har indgået en samarbejdsaftale med Scimitar, der er et firma med fokus på at accelerere innovation i biovidenskabsbranchen. Scimitar, der har hovedkvarter i USA, et førende konsulenthus inden for strategieksekvering for biovidenskabsbranchen. Virksomheden er specialiseret i design af driftsmodeller, digital transformation og organisatorisk forandring. Scimitar samarbejder med medicinal- og biotech-virksomheder om at accelerere innovation, styrke den driftsmæssige eksekvering og sikre compliance gennem hele produkters livscyklus. Deres praktiske og samarbejdsorienterede tilgang sikrer løsninger, der ikke blot er formålstjenlige, men også skalerbare. "Virksomheder inden for biovidenskabsbranchen befinder sig i en tid med hurtige videnskabelige fremskridt, stigende regulatorisk kompleksitet og et voksende behov for operationel agilitet, samtidig med at de holdes op mod de højeste standarder for patientsikkerhed og dataintegritet," udtaler Ramy Khalil, CEO i Scimitar.

Biocytogen and Acepodia Expand Collaboration Through Option-based Evaluation Framework for First-in-Class Bispecific and Dual-Payload ADCs (BsAD2C)9.1.2026 13:00:00 CET | Press release

Expanded collaboration builds on Acepodia and Biocytogen’s recent co-development efforts to evaluate selected bispecific antibody and dual-payload ADC programs Biocytogen Pharmaceuticals (Beijing) Co., Ltd. (Biocytogen, SSE: 688796; HKEX: 02315) and Acepodia (6976:TT), today announced that the companies have entered into an option and license agreement designed to enable the structured evaluation of bispecific antibody-drug conjugate (BsADC) programs to further advance the development of dual-payload bispecific antibody-drug conjugates (BsAD2Cs). The agreement grants Acepodia an option to obtain an exclusive worldwide license from Biocytogen for two BsADC programs. Under the terms of the agreement, Biocytogen is eligible to receive an upfront option fee and, upon Acepodia’s exercise of the option, additional payments including option exercise fees, development, regulatory, and commercial milestone payments, as well as royalties on future product sales. The financial terms of the agreem

Blockstream Capital Partners Announces Strategic Acquisition of Derivatives Trading Team from Numeus Group, Leveraging Strategic Partnership with Komainu9.1.2026 11:08:00 CET | Press release

Blockstream Capital Partners (“BCP”) today announced that it has entered into a strategic agreement to acquire a division within Numeus Group’s digital asset trading and investment business. The transaction includes the absorption of select Bitcoin focused trading strategies with a focus on yield generation as well as a ten person derivatives trading team led by Chief Investment Officer Deepak Gulati, a specialist in volatility and derivatives markets. Deepak Gulati, appointed Co-Chief Investment Officer of Blockstream Capital Management alongside Rodrigo Rodriguez, previously served as Global Head of Proprietary Trading at JPMorgan, before founding Argentiere Capital, a multibillion-dollar volatility-focused hedge fund. With a thesis that derivatives would drive Bitcoin and digital asset market maturity, he co-founded Numeus Group in 2021 to develop institutional-grade trading, risk management and market-structure capabilities. Komainu, an existing BCP strategic investment, has played

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye