Business Wire

NY-DILIGENT

26.3.2024 12:01:25 CET | Business Wire | Press release

Share
Companies With Advanced Cybersecurity Performance Deliver Nearly Four Times’ Higher Shareholder Return Than Their Peers, According to Diligent and Bitsight

Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.

“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”

“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.

In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:

Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers

  • The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
  • Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.

Companies with specialized risk or audit committees have better cybersecurity performance

  • The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
  • Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.

Highly regulated industries outperform other industries in cybersecurity performance

  • The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
  • By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.

"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."

Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.

View the full report here.

Methodology

Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.

About Diligent

Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.

Follow Diligent on LinkedIn, X (Twitter) and Facebook.

About Bitsight

Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240326307541/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Vena To Acquire Acterys, Creating a New Category of Enterprise Performance Management: Orchestrated Planning3.2.2026 17:00:00 CET | Press release

The acquisition unites finance foresight and IT innovation in the first Microsoft-native Orchestrated Planning environment, helping enterprises plan better and achieve more by turning strategy into aligned execution in real time. Vena, the only complete FP&A platform powered by agentic AI and purpose-built to amplify the Microsoft technology ecosystem, today announced it has entered into a definitive agreement to acquire Managility Pty Ltd, operating as Acterys (“Acterys”), the industry’s leading Power BI–based operational planning and app development platform, subject to customary closing conditions and regulatory approval. This acquisition unlocks a category-defining way for enterprises to combine planning, analytics, and application development within the Microsoft tools they already trust to run their business. By combining Vena’s Excel-native financial planning and analysis (FP&A) capabilities with Acterys’ proprietary Power BI write-back engine and unified analytics within Micros

Volante Technologies named a Leader in Gartner® Magic Quadrant™ for Banking Payment Hub Platforms3.2.2026 16:15:00 CET | Press release

Volante believes its solutions provide complete always-on payment processing support for banks and financial institutions across all tiers Volante Technologies, the global leader in Payments as a Service (PaaS), today announced its recognition as a Leader in the 2026 Gartner® Magic Quadrant™ for Banking Payment Hub Platforms, which evaluates vendors based on Ability to Execute and Completeness of Vision. In Volante’s view, Gartner positioned them as a Leader based on their capacity to support enterprise-scale payment processing in banks and financial institutions across multiple regions, deployment models, and operational environments. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260203149834/en/ This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. As the highest positioned provider in Ability to Execute, Volante believes its AI-pow

Toptal Ranked #1 Most Reliable Professional Services Company in America by Newsweek3.2.2026 16:00:00 CET | Press release

Toptal, the world’s largest fully remote workforce, has been ranked the #1 most reliable professional services company in America on the America’s Most Reliable Companies 2026 list by Newsweek and Statista. The list ranks top US companies based on trust, dependability, and consistent performance in their industry. In Newsweek’s ranking of 300 companies across all industries, Toptal took 10th place, right behind Bank of America and Oracle, which tied for 9th. As the most reliable professional services organization in America, Toptal, which ranked 11th in absolute rankings across all companies, placed well ahead of companies like Accenture (33), Deloitte (39), and Cognizant (66). The America’s Most Reliable Companies 2026 ranking is based on an independent survey of more than 80,000 evaluations submitted by 2,400 business decision-makers at America’s largest companies, including Apple, Dropbox, Johnson & Johnson, and UPS, making this recognition an especially meaningful indicator of prod

HTEC Research Reveals the Real AI Scaling Challenge: It’s Not the Technology3.2.2026 15:46:00 CET | Press release

Global executive survey finds AI momentum is real—but leadership alignment, capability gaps, and ROI clarity are slowing enterprise impact AI has moved from ambition to action. Every organization is deploying it. Yet for most enterprises, the real challenge is only just beginning. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260203951136/en/ HTEC, a global AI‑first provider of software and hardware design and engineering services, released Executive Summary: A Cross‑Industry View of the State of AI in 2025, a global research report capturing how senior executives are navigating the next phase of AI transformation—and why scaling value remains elusive. Today, HTEC, a global AI‑first provider of software and hardware design and engineering services, released Executive Summary: A Cross‑Industry View of the State of AI in 2025, a global research report that captures how senior executives are navigating the next phase of AI tra

Yubico Reveals 265% ROI and 99.99% Reduction in Risk of Exposure to Addressable Breach Risk Costs According to Total Economic Impact Study3.2.2026 15:00:00 CET | Press release

Effectiveness of Yubico’s technology: $5.3 million Net Present Value and $7.3 million in total benefits over three years, driven by 80% faster authentication and reduced help desk burden Yubico (NASDAQ STOCKHOLM: YUBICO), a modern cybersecurity company and creator of the most secure passkeys, today announced the results of a commissioned Total Economic Impact™ (TEI) of Yubico YubiKeys study conducted by Forrester Consulting. The study, comprised of interviews with global enterprises with over 5,000 employees, found that a composite organization based on interviewed customers achieved a 265% return on investment (ROI) and a net present value (NPV) of $5.3 million over three years by replacing traditional multi-factor authentication (MFA) and one-time passwords (OTPs) with phishing-resistant YubiKeys. In an era of high-quality deepfakes and generative AI-driven extortion, the study shows a critical shift in cybersecurity: traditional MFA is no longer sufficient to stop modern MFA-bypass

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye