NY-DILIGENT
Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.
“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”
“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.
In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:
Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers
- The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
- Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.
Companies with specialized risk or audit committees have better cybersecurity performance
- The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
- Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.
Highly regulated industries outperform other industries in cybersecurity performance
- The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
- By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.
"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."
Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.
View the full report here.
Methodology
Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.
About Diligent
Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.
Follow Diligent on LinkedIn, X (Twitter) and Facebook.
About Bitsight
Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240326307541/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
OMRON Releases the “Medium-Term Roadmap SF 2nd Stage”8.11.2025 07:00:00 CET | Press release
OMRON (TOKYO: 6645) has announced its “Medium-Term Roadmap Shaping the Future 2nd Stage (“SF 2nd Stage”),” covering from FY2026 to FY2030, on November 7, 2025 (JST). This Roadmap presents the Group’s vision and growth strategies through 2030, which are disclosed on our corporate website. Overview of the “Medium-Term Roadmap SF 2nd Stage” Since April 2024, OMRON has been implementing a Structural Reform Program “NEXT 2025” aimed at rebuilding our foundation for profitability and growth. With the completion of this Program in September 2025, we have shifted into a growth phase and formulated a new Roadmap looking ahead to 2030. This Roadmap identifies Business Portfolio Restructuring as a core strategy. We have defined Thirteen Focus Businesses to drive the Group’s future growth. By accelerating our selection and concentration efforts, we aim to build a “distinctive” business portfolio that maximizes overall Group growth. Furthermore, to maximize the growth potential of our Focus Busines
26th UN Tourism General Assembly kicks off in Riyadh7.11.2025 22:13:00 CET | Press release
UN Tourism marks 50 years of global cooperation as leaders from across the industry gather to shape the future of tourism. His Excellency Ahmed Al Khateeb, Minister of Tourism – “The Kingdom will play an integral part in ensuring one of the world’s most powerful generators of jobs and GDP grows in harmony with the Sustainable Development Goals.” UN Tourism Secretary-General ZurabPololikashvili – “The UN Tourism General Assembly brings together tourism leaders from across the world to set the agenda and build a more innovative and inclusive sector. From Riyadh, we will set the agenda for tourism for the years ahead.” The 26th session of the UN Tourism General Assembly opened today in Riyadh, marking a historic first for the Gulf Cooperation Council (GCC) region and the largest Assembly since UN Tourism was founded 50 years ago. Around 160 delegations from member states including ministers, senior officials, and leaders from across industry and civil society are coming together to celebr
Xsolla Partners With Deloitte Turkiye and Lorien Accelerator as Category Sponsor for Gaming Awards at Fast 50 Türkiye 2025 Program7.11.2025 19:11:00 CET | Press release
Celebrating Turkey’s Gaming Industry with High-Impact Sponsorship and Industry Panel Xsolla, a leading global video game commerce company that helps developers launch, grow, and monetize their games, is proud to announce its sponsorship of the Gaming Awards segment at the Deloitte Technology Fast 50 Türkiye 2025 Program, organized in collaboration with Lorien Accelerator. The event will take place on December 10, 2025, and will recognize Turkey’s top high-growth companies across various industries, with a special focus on the dynamic gaming sector. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251107671030/en/ Graphic: Xsolla As the Gaming Awards category sponsor, Xsolla will receive significant brand exposure through prominent logo placements across all event materials, including digital platforms, official event signage, and other promotional materials. In addition to this visibility, Xsolla’s participation includes an ex
Takeda Presents New Data Showing Mezagitamab (TAK-079) Sustained Effect on Kidney Function 18 Months After Treatment in Primary IgA Nephropathy7.11.2025 17:00:00 CET | Press release
− Phase 1b, Open-Label Study Follow Up Shows Stable Kidney Function (eGFR) in Patients Treated with Investigational Mezagitamab Through Week 96 – 18 Months After Last Dose1− Rapid Reductions in Proteinuria and Serum Gd-IgA1 Levels Were Sustained Through Week 961− No Serious Adverse Events or Opportunistic Infections Were Observed Through Week 961− Takeda Initiated Pivotal Phase 3 Clinical Trials Evaluating Mezagitamab in Primary IgA Nephropathy and Immune Thrombocytopenia with Patient Enrollment Ongoing Takeda (TSE:4502/NYSE:TAK) today announced new interim data from the Phase 1b, open-label, proof-of-concept study of subcutaneous mezagitamab (TAK-079), an anti-CD38 monoclonal antibody with disease-modifying potential, in primary immunoglobulin A (IgA) nephropathy. Data from the study showed that kidney function (eGFR) remained stable in patients with IgA nephropathy through Week 96 – up to 18 months after the last mezagitamab dose.1 The results were presented at the American Society o
Oremus Corporate Services Expands into Europe with Launch in Finland7.11.2025 16:23:00 CET | Press release
CEO, Lalit Ananth Chawla, to Attend Slush 2025 in Helsinki Oremus Corporate Services Private Limited, a multinational Finance and Accounting Advisory firm having its offices in the USA, India and the UK, has announced the extension of its services to Finland, marking the company’s foray into the European market. With over two decades of expertise in accounting, payroll, tax compliance, and advisory services, Oremus has earned trust as a technology-driven finance partner serving clients across geographies. Oremus is an ISAE 3402, ISO 27001, GDPR & DPDP Compliant Company, adhering to International Quality and Security Standards. “Finland isn’t just a new market for us — it’s the gateway to meaningful, growth-driven partnerships across Europe”. said Lalit Ananth Chawla, CEO of Oremus. Having established a strong reputation for delivering reliable Accounting and Advisory solutions to scale-ups and growing businesses, we seek to collaborate with like-minded firms and investors to build a tr
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
