NY-DILIGENT
Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.
“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”
“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.
In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:
Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers
- The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
- Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.
Companies with specialized risk or audit committees have better cybersecurity performance
- The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
- Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.
Highly regulated industries outperform other industries in cybersecurity performance
- The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
- By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.
"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."
Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.
View the full report here.
Methodology
Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.
About Diligent
Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.
Follow Diligent on LinkedIn, X (Twitter) and Facebook.
About Bitsight
Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240326307541/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Reply Achieves the AWS Advertising and Marketing Technology Competency Thanks to the Contribution of the Data Reply and Storm Reply Teams16.9.2025 10:40:00 CEST | Press release
Reply [EXM, STAR: REY] has achieved the AWS Advertising and Marketing Technology Competency, the official recognition from Amazon Web Services certifying advanced technical and project expertise in the design and delivery of advertising and marketing solutions on AWS. This milestone was made possible thanks to the joint contribution of Storm Reply and Data Reply, both part of the Reply Group, with solid expertise in implementing cloud-native and data-driven solutions on the AWS platform. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250916374888/en/ With this certification, Reply’s companies specialized in AWS services further consolidate their role as trusted technology partners for organizations looking to evolve their marketing and communication strategies through the advanced use of AWS cloud and AI technologies. The AWS Advertising and Marketing Technology Competency validates the ability of AWS Partners to deliver hig
PayPay Is Now Accepted in South Korea via Ant International’s Alipay+16.9.2025 10:26:00 CEST | Press release
Connecting 70 million PayPay users to over 2 million South Korean merchants A milestone in PayPay’s overseas expansion Starting from late September 2025, Japan's leading cashless payment service PayPay will be accepted at over 2 million merchants across South Korea through Alipay+, a global wallet gateway service operated by Ant International. This will allow its 70 million registered users to make seamless payments during their visit, wherever the Alipay+ logo is displayed. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250915612411/en/ Starting from late September 2025, Japanese travellers will be able to use PayPay to make payments in South Korea at stores displaying the Alipay+ logo. PayPay will show users the payment amount in Korean won and its yen equivalent in real time. This marks a new chapter in PayPay’s overseas expansion. From K-beauty stores and convenience chains to local eateries and cultural hotspots, from m
Talent shortages and AI pressures drive shifting dynamics in global technology leadership, According to Expereo16.9.2025 10:00:00 CEST | Press release
Skills gaps in networking, cybersecurity, and AI are delaying growth and forcing businesses to rethink leadership, training, and investment strategies Global businesses are facing mounting challenges in their growth ambitions due to persistent skills shortages in critical technology areas. As AI becomes more deeply embedded in business strategy, organisations are struggling to find or retain talent in key domains such as networking (39%), cybersecurity (40%), and Data/AI/automation (33%). The findings come from an IDC InfoBrief commissioned by Expereo, titled “Enterprise Horizons 2025: Technology Leaders Priorities: Achieving Digital Agility.” The report reveals that 39% of organisations are struggling to find or retain networking talent, while 33% report similar challenges in data, AI, and automation - figures that remain consistent with 2024 findings. These shortages are not only slowing down AI adoption but also reshaping leadership dynamics and workforce strategies across enterpris
Infobip Achieves GSMA Open Gateway Certifications for Network APIs16.9.2025 10:00:00 CEST | Press release
New credentials strengthen Infobip's role in the global telco ecosystem Global communications platform Infobiphas received two new Network API certifications from the GSMA, as part of the CAMARA project. The SIM Swap and Number Verification certifications demonstrate Infobip's commitment to advancing global standards for Network APIs through the GSMA Open Gateway initiative. The certifications mark a significant milestone for Infobip and its telco partners worldwide. The certifications validate Infobip's expertise and support mobile network operators (MNOs) in achieving their own certifications as part of GSMA's global standardization efforts. Viktorija Radman, Telecom Growth & Strategy Director at Infobip, said:"Achieving GSMA certifications for SIM Swap and Number Verification demonstrates our commitment to building secure, scalable solutions for operators worldwide. As a CPaaS enabler, Infobip is dedicated to helping telcos embrace new global standards and bring the benefits of Netw
Groundbreaking New Sensor Transforms How Europe Tracks Pollution, Smoke and Cloud From Space16.9.2025 09:00:00 CEST | Press release
The first images from the Multi-Viewing, Multi-Channel, Multi-Polarisation Imager, presented at the 2025 EUMETSAT Conference, reveal the brand-new instrument’s exceptional ability to monitor the Earth’s atmosphere from multiple perspectives, to support improved forecasts and air pollution and climate monitoring. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250915322837/en/ 3MI’s very first image, captured between 10:59 and 11:03 CEST on 28 August 2025, confirmed the instrument is already performing well as it delivers its preliminary data streams. The left panel shows a standard view using natural light, highlighting clouds and land surfaces. The right panel, based on polarised light measurements, reveals much finer detail of the atmosphere’s composition – such as subtle cloud structures over Italy and wildfire smoke on the right edge of the image, over Greece. When sunlight interacts with particles in the air, like drople
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom