It seems that almost every day now we read in the media about another cyber attack, and there has certainly been no shortage of firms that have experienced sizeable attacks recently, which include Target, Home Depot, JPMorgan Chase, and eBay. The attack against Sony at the end of 2014 reminds us that these attacks are not only limited to financial institutions or large retailers. Sony lost several of its unreleased motion pictures, information about its employees and third parties, as well as sensitive and embarrassing e-mail communications. Rather, companies in all industries are at risk of such attacks, and it is therefore no surprise that many firms and their boards of directors now recognize that cyber security is one of their top risks.
Investors must also realize that cyber security is a risk they should consider within their due diligence and research activities. But what can they do to better understand whether the firms they are invested in, or are considering investing in, are vulnerable to such attacks?
Below are five key questions that investors may wish to consider.
1. What is included in the firm’s disclosure about cyber security risk?
It is common for most firms to disclose information about key risks they face and to provide an overview of programs in place to mitigate these risks. If cyber security is considered a key risk for the firm, there should be a commensurate level of disclosure about the risk exposure, as well as the firm’s cyber security risk management program.
As many firms are currently undertaking significant enhancements to their cyber security programs, security budgets have been significantly increased to support this. Investors may also wish to review the amount of disclosure regarding the firm’s cyber security budget.
2. What are the specific cyber threats and attack scenarios that could cause damage to the firm?
A cyber security risk assessment should identify cyber threats and attack scenarios that could cause damage to the institution. For example, if the firm holds a large volume of personal and private customer information (e.g., credit or debit card information, social insurance numbers, health records, etc.), it should identify data loss and fraud as a key risk and ensure that an effective data loss prevention strategy has been established to both detect and prevent the loss of this information.
3. How does the firm evaluate the effectiveness of its cyber security practices?
Many firms are currently looking to assess the effectiveness of their cyber security practices against sound industry standards and practices. One of the more commonly referenced security frameworks is that produced by the National Institute of Standards and Technology in the United States. The Office of the Superintendent of Financial Institutions, Canada’s regulator and supervisor of federally regulated financial institutions, released another security framework that is relevant. Both frameworks offer practices that should be considered as part of a sound cyber security risk management program.
4. Who are the firm’s key service providers, and what oversight exists to ensure their preparedness?
Many firms outsource business activities, functions, and processes to meet the challenges of technological innovation, increased specialization, cost control, and heightened competition. However, outsourcing can increase a firm’s dependence on third parties, which may increase its risk profile. Outsourcing certain activities, such as hosting and managing information technology infrastructure, may entail additional requirements for effective cyber security controls. Firms may also be exposed to cyber security risk through arrangements with suppliers, which often have access to, or control of, sensitive information.
Firms should monitor all material outsourcing and supplier arrangements to ensure that the service is being delivered in the manner expected and is consistent with their own cyber security standards. This monitoring may take the form of regular meetings with the service provider, receipt and review of regular reports (e.g., internal audit reports, performance metrics, etc.), and periodic reviews or audits of the controls within the service provider.
5. To what extent is the firm using insurance as a mitigating factor?
Cyber insurance policies can offer additional mitigation against cyber attacks. While such protection should not be a firm’s only form of cyber security, insurance protection against cyber attacks may offset some or most of the costs of a potential catastrophic impact. Investors may wish to inquire whether the firm is considering such cyber security protection and the degree to which the firm’s existing insurance coverage applies to data loss or fraudulent activity.
While cyberspace offers tremendous value and opportunity to firms, it also presents new risks. Firms in all industries, both large and small, should be aware of these risks and take appropriate actions to protect their internal operations, customers, investors, and other relevant stakeholders.
Similarly, investors should consider cyber security as a key investment risk and should consider including the questions above as part of their due diligence and research activities.