japanja
Working to fortify digital assets to beat cybercrime

Working to fortify digital assets to beat cybercrime

22-10-2021 | インサイト

Attitudes to improving data security have improved as cybercrime becomes a multi-trillion dollar threat, a Robeco engagement program has found.

  • Peter van der Werf
    Peter
    van der Werf
    Engagement Specialist
  • Carolina Vergroesen
    Carolina
    Vergroesen
    Active Ownership Analyst

Speed read

  • Three-year engagement to improve cybersecurity at nine companies
  • Most have a clear strategy but are reluctant to advertise weaknesses
  • Ongoing skills gap means companies should nurture cyber skills internally

The Active Ownership team has just completed a three-year engagement program with nine companies, reaching a successful conclusion with seven of them. They were chosen because they operate using sensitive customer data in the payments, telecoms and household products sectors.

Most now have a clear strategy focused on improving their cybersecurity following a number of high-profile data breaches for some. However, most were reluctant to provide full transparency on their weaknesses, partly to avoid exposing any risk management gaps to criminals or competitors.

Cybercrime has become a global business on a par with the drugs industry, the costs of which have risen from about USD 500 billion in 2017 to an estimated USD 6 trillion in 2020. Since virtually all companies have digital operations in some form, their need to fortify and protect their digital assets has never been greater.

“As digitalization expands far beyond the tech realm, so do the associated cyber threats,” says Active Ownership Analyst Carolina Vergroesen. “Cybercrime can include anything from small, local security incidents with minor consequences, to cyberattacks which can disturb significant parts of the global economy.”

“Lax cybersecurity practices represent a clear and obvious threat to company business models. While these risks have become distinct in recent years, less clarity exists on the steps taken by companies to mitigate such risks.”

最新の「インサイト」を読む
最新の「インサイト」を読む
配信登録

Five topics for engagement

The engagement theme focused on five topics: governance and oversight; policy and procedure; risk management and controls; transparency and disclosure; and privacy by design. Originally, eleven companies were picked in 2018, but one was dropped after it was divested due to poor financial performance, and another was taken over.

“Most of the companies in our engagement peer group acknowledged the risks related to cybersecurity, but their approaches to this risk differed vastly,” says Vergroesen. “Whereas some considered it a top priority and an essential part of their license to operate, others saw it as merely one of many business risks. This variety resulted in clearly different success rates between companies and in relation to various objectives.”

“For the governance and oversight objective, nearly 80% of all companies had a clear strategy and governance hierarchy in place for managing cybersecurity. However, several transparency topics proved more challenging as most companies preferred to keep their cards close to their chest.”

Circumventing barriers

“This is understandable given that hackers can more easily circumvent barriers if they know exactly which security systems are in place. However, this hesitancy to provide information affected our success rate for our policy and procedure and transparency and disclosure objectives in particular, where engagement was successfully closed with only five of the nine companies.”

The team saw more openness from companies regarding the risk management and controls objective. “Although companies hesitated to disclose their particular responses to cyber threats, they were more open to discussing the sensitivity and integrity of their security controls,” says Vergroesen.

“Several have dedicated teams that regularly test their company’s defenses in order to identify possible gaps in their current practices. We found this especially encouraging as the threat landscape is continuously changing, and companies should be prepared to adapt their security accordingly and respond quickly to with emerging threats.”

Privacy as a priority

Data breaches involving personally identifiable information (PII) are particularly harmful for both the customers affected and the company’s reputation and legal liability. Overall, engagement with six of the nine companies was successfully closed for the privacy by design objective.

“Companies need to be clear to their customers what type of data is collected and for what purpose, and be informed in case of accidental breaches,” says Vergroesen.

“Although most companies had some form of privacy policy in place, the quality of these policies varied substantially. Whereas some were global and very detailed, others were local and only met legal requirements rather than being truly informative for clients.”

Legislation is helping

Meanwhile, cybersecurity legislation is becoming globalized, greatly boosted in 2018 with the introduction of the EU’s General Data Protection Regulation (GDPR). This toughened guidelines for what is expected when collecting information for commercial use within the EU and has already been used against companies failing to comply with it. Later this year the California Privacy Rights Act (CPRA) in the US is expected to have a similar impact on companies as GDPR has had in the EU.

“We are encouraged to see that nearly 80% of countries worldwide have cybersecurity legislation in place,” says Vergroesen. “Continued expansion of this legislation is crucial in ensuring clear standards for companies to adhere to.”

“Although several of the companies under engagement went far beyond legal requirements, many cyber strategies were directly linked to specific legislation.”

Skills shortage

But one flipside of the increased attention to cybersecurity is that it has created greater demand for IT specialists, and subsequently a skills gap. A report by the Information Systems Security Association shows that this gap between the demand for and supply of qualified technicians persisted for the fifth consecutive year in 2021.

“As cyber standards are raised globally, companies will have to vie for talent to hire the people who can work in this field,” says Vergroesen. “We believe companies should therefore focus on the development of cyber skills within their organizations, as simply acquiring outside talent might prove to be a difficult challenge.”

Further cybersecurity work

As the specific engagement program has ended, the team will now focus on the issue where it is an indirect consequence of digitalization across the spectrum.

“Although this engagement has come to a close, we continue to see the importance of cybersecurity across virtually all industries,” says Vergroesen.

“Specifically, our engagement themes on the digitalization of health care and the social impact of artificial intelligence continue to focus on companies’ diligent implementation of cybersecurity and data privacy practices. There is much work yet to be done; like technology itself it is always moving on.”

重要事項

当資料は情報提供を目的として、Robeco Institutional Asset Management B.V.が作成した英文資料、もしくはその英文資料をロベコ・ジャパン株式会社が翻訳したものです。資料中の個別の金融商品の売買の勧誘や推奨等を目的とするものではありません。記載された情報は十分信頼できるものであると考えておりますが、その正確性、完全性を保証するものではありません。意見や見通しはあくまで作成日における弊社の判断に基づくものであり、今後予告なしに変更されることがあります。運用状況、市場動向、意見等は、過去の一時点あるいは過去の一定期間についてのものであり、過去の実績は将来の運用成果を保証または示唆するものではありません。また、記載された投資方針・戦略等は全ての投資家の皆様に適合するとは限りません。当資料は法律、税務、会計面での助言の提供を意図するものではありません。

ご契約に際しては、必要に応じ専門家にご相談の上、最終的なご判断はお客様ご自身でなさるようお願い致します。

運用を行う資産の評価額は、組入有価証券等の価格、金融市場の相場や金利等の変動、及び組入有価証券の発行体の財務状況による信用力等の影響を受けて変動します。また、外貨建資産に投資する場合は為替変動の影響も受けます。運用によって生じた損益は、全て投資家の皆様に帰属します。したがって投資元本や一定の運用成果が保証されているものではなく、投資元本を上回る損失を被ることがあります。弊社が行う金融商品取引業に係る手数料または報酬は、締結される契約の種類や契約資産額により異なるため、当資料において記載せず別途ご提示させて頂く場合があります。具体的な手数料または報酬の金額・計算方法につきましては弊社担当者へお問合せください。

当資料及び記載されている情報、商品に関する権利は弊社に帰属します。したがって、弊社の書面による同意なくしてその全部もしくは一部を複製またはその他の方法で配布することはご遠慮ください。

商号等: ロベコ・ジャパン株式会社  金融商品取引業者 関東財務局長(金商)第2780号

加入協会: 一般社団法人 日本投資顧問業協会