NY-DILIGENT
Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.
“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”
“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.
In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:
Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers
- The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
- Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.
Companies with specialized risk or audit committees have better cybersecurity performance
- The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
- Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.
Highly regulated industries outperform other industries in cybersecurity performance
- The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
- By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.
"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."
Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.
View the full report here.
Methodology
Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.
About Diligent
Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.
Follow Diligent on LinkedIn, X (Twitter) and Facebook.
About Bitsight
Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240326307541/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Ant International Deepens Participation in Project Ensemble as New Architecture Community Member18.11.2025 04:00:00 CET | Press release
Ant International has been a participant in the Ensemble Sandbox since 2024 Ant International today announced it has joined Project Ensemble’s Architecture Community to support the design and advancement of Hong Kong’s tokenisation ecosystem. As a Community member, it will be more involved in defining industry standards and supporting the development of Hong Kong’s tokenisation market, together with the Hong Kong Monetary Authority (HKMA) and leading peers. A fintech representative on the Community, Ant International will also contribute its technological and innovation capabilities in tokenisation to support broader industry adoption. This comes at a time when Project Ensemble reaches a new milestone with EnsembleTX, which will see it move from sandbox experiments to live market use within a pilot environment. Through EnsembleTX, Ant International will continue to broaden its partnerships with banks and other committee members, contributing to real-world use cases of tokenisation in r
Celltrion Announces European Commission Approval of Additional Line Extension for Omlyclo™ 300mg18.11.2025 03:51:00 CET | Press release
Omlyclo™ (omalizumab) is the first and only omalizumab biosimilar approved in EuropeOmlyclo™ 300 mg/2ml prefilled syringe (PFS) presentation is now approved in EU offering a simpler dosing schedule and improved patient adherence The European Commission (EC) has granted a line extension in the European Union (EU) for Celltrion’s Omlyclo™ (omalizumab), Europe’s first and only omalizumab biosimilar, for the 300 mg/2ml prefilled syringe (PFS).The European Commission (EC) approved Omlyclo™ 75 mg/0.5ml and 150mg/1ml solution for injection in pre-filled syringe in May 2024. Omlyclo™ is indicated for the treatment of patients with allergic asthma, chronic spontaneous urticaria (CSU) and chronic rhinosinusitis with nasal polyps (CRSwNP). “The additional strength of Omlyclo™ 300mg can significantly decrease the frequency of injections, and reduce injection burden and discomfort, without compromising efficacy and safety,” said Nam Lee, Vice President of Global Medical Affairs at Celltrion. “These
2026 Mitsui Chemicals Catalysis Science Awards18.11.2025 03:00:00 CET | Press release
Online applications are open until December 25, 2025 Mitsui Chemicals, Inc. has announced that online applications for the 2026 Mitsui Chemicals Catalysis Science Award have been open since September 1, 2025. The application period will run from September 1 to December 25, 2025. Aiming to contribute to the sustainable development of chemistry and the chemical industry, Mitsui Chemicals established the Mitsui Chemicals Catalysis Science Awards in 2004. The awards consist of the Catalysis Science Award and the Catalysis Science Award for Creative Work, which recognize outstanding achievements in the field of catalysis science. To date, the awards have been conferred on 33 researchers within Japan and overseas. Past recipients include individuals who have gone on to be highly acclaimed worldwide, receiving honors such as the Nobel Prize in Chemistry and other prestigious Japanese and international awards. We welcome applications from a wide range of R&D fields, including solid catalysts,
Access Advance Welcomes Xiaomi to HEVC Advance and VVC Advance Patent Pools as a Licensor and Licensee18.11.2025 02:00:00 CET | Press release
Access Advance LLC, an independent licensing administrator for leading video codec patent pools, today announced that Xiaomi has joined the HEVC Advance Patent Pool and the VVC Advance Patent Pool, as a Licensor and Licensee. "We are delighted to welcome Xiaomi to the Access Advance licensing community," said Peter Moller, CEO of Access Advance. "Xiaomi's participation in both our HEVC and VVC patent pools represents a significant milestone in the video codec licensing landscape. Their joining of the HEVC Advance Patent Pool, which provides them with access to tens of thousands of essential patents for the widely adopted H.265 standard, and their dual role as both a licensor and licensee in the VVC Advance Patent Pool, demonstrates their commitment to innovation and the recognition of the value of patent pools that balance the interest of patent owners and implementers. In addition, it highlights their support for Access Advance’s efforts to bring a one-pool solution to video codec lic
Venture Global Files FERC Application for Plaquemines Expansion Project18.11.2025 00:02:00 CET | Press release
Today, Venture Global, Inc. (NYSE: VG) filed with the Federal Energy Regulatory Commission (FERC) its application for the permitting and approval of the Plaquemines LNG brownfield expansion project. In addition, Venture Global has filed with the U.S. Department of Energy (DOE) for the export authorizations associated with this expansion. The Plaquemines Expansion was announced earlier this year with U.S. Secretary of Energy Chris Wright, U.S. Secretary of the Interior Doug Burgum, and Louisiana Governor Jeff Landry. Venture Global has since increased the expected output from this project by nearly 40% from the previously announced plans due to the continued optimization of our liquefaction trains and strong market demand. This bolt-on expansion will be built incrementally in three phases and consist of 32 modular liquefaction trains, adding in total over 30.0MTPA in peak production capacity. This will bring the total peak production capacity across the entire Plaquemines complex to ove
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
