# Too easy to steal: blame management, not hackers, when cyber events lead to losses.
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-01-30
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Understanding the Importance of Cyber Risk Governance
Meta Description: Discover why cyber risk governance matters more than the latest technology in protecting companies from financial fallout. Learn the crucial steps to safeguard
URL: https://financedigest.com/easy-steal-blame-management-not-hackers-cyber-events-lead-losseshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/too-easy-to-steal-blame-management-not-hackers-when-cyber-events-lead-to-losses-1736839179433-compressed.jpg)

_By **Ryan Dodd**, Founder and CEO of_ [_Cyberhedge_](http://www.cyberhedge.com/)

Consider this; in 2018 over a [billion people were affected by data breaches](https://www.computerweekly.com/news/252455311/Data-breaches-affected-more-than-a-billion-people-in-2018). Similarly, just a few days into 2019 and major organisations suffering data breaches were hitting headlines. From [Singapore Airlines](https://www.zdnet.com/article/singapore-airlines-data-breach-affects-284-accounts-exposes-travel-details/) to the [German Parliament](https://www.itnews.com.au/news/german-politicians-hit-by-massive-data-breach-517500), these most recent breaches continue to show that no sector is immune from cyber risk, which is undoubtedly one of the greatest risks facing companies today.

When such cyber incidents occur, headlines tend to focus on the technical how’s and why’s of the breaches themselves, rather than the long-term financial fallout. Despite much improved education on cyber threats, there is still a startling lack of understanding on how the day to day management of cyber hygiene affects an organisation’s long-term value.

**For [cyber risk](https://www.financedigest.com/automated-cyber-risk-quantification-saving-the-insurance-industry.html "Automated Cyber Risk Quantification: Saving the Insurance Industry"), governance matters more than deploying the latest technology.**

![Ryan Dodd](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/ryan-1736839179421-compressed.jpg)

Ryan Dodd

Considering the research showing that the value of corporations’ assets is increasingly digital, the lack of emphasis onon-going cyber risk assessment—as a starting point for proper cyber management– should be considered unconscionable by businesses leaders,regulators and investors.

For example, few established companies would consider taking on a new supplier or partner without undertaking a thorough audit of its financial stability and credit rating—it is often a legal or compliance requirement considered basic “best practice”. Very few, however, will undertake the same audit of a partner or [acquisition target’s IT controls and cyber](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") management practices.

Despite most serious breaches in recent years have been the result of a [third party’s](https://www.financedigest.com/why-a-replacement-to-third-party-cookies-is-key-to-post-pandemic-recovery.html "Why a replacement to third party cookies is key to post-pandemic recovery") network vulnerabilities, there is an argument that cyber audit is still a new service and not all companies have on-boarded this new technology. However, considering the size of digital assets’ value at risk, [corporate leadership’s](https://www.financedigest.com/corporate-leadership-understanding-your-own-bias.html "Corporate Leadership: Understanding Your Own Bias") negligence at not managing this risk is swiftly punished by the market losses and firings.

If we look at the well-publicised [2018 Marriott hotels breach](https://www.bbc.co.uk/news/technology-46401890),this was the result of the challenge of  managing cyber risks in highly complex legacy IT systems due to its acquisition of Starwood, part of the USD $13.6 billion takeover in 2016.

These risks could and should have been identified by Marriott pre-acquisition.In fact, they probably were aware but there was no [way a threat of a cyber](https://www.financedigest.com/the-best-ways-to-protect-your-business-from-cyber-threats-in-2021.html "The best ways to protect your business from cyber threats in 2021") breach was going to stop the momentum of a mega-deal, especially considering a weak regulatory and oversight environment for cyber.

Now however, instead of increased profits post-merger, Marriott is [facing several shareholder](https://www.financedigest.com/just-eat-takeaway-faces-shareholder-backlash-over-dealmaking.html "Just Eat Takeaway faces shareholder backlash over dealmaking") lawsuits and is undergoing a rebranding exercise starting with their loyalty programs.

The more important issue is that even a company of Marriott’s size doesn’t have the cyber [risk management](https://www.financedigest.com/risk-management-redefined-navigating-post-covid-disruption.html "Risk Management redefined: navigating post-COVID disruption") procedures in place to adequately understand where all the unlocked doors and open windows are on an IT network that spans multiple properties around the globe.

Marriott is certainly not alone in this challenge. Most [major global](https://www.financedigest.com/how-to-best-protect-assets-following-major-global-shifts.html "How to Best Protect Assets Following Major Global Shifts") companies, especially a corporation built via multiple acquisitions does not have the capability of pinpointing what part of its network specifically is at risk and how much money that risk represents. Think about that. There is no way we would find that acceptable for a physical [safety issue or critical infrastructure like electricity](https://www.financedigest.com/demand-for-electrical-safety-insulating-gloves-is-strong-in-the-power-utility-industry-unveils-fact-mr.html "Demand for Electrical Safety Insulating Gloves Is Strong In The Power Utility Industry Unveils Fact.MR"), gas, transport or water. Yet with cyber, lack of [managing the valuable assets](https://www.financedigest.com/exclusive-allianz-in-talks-with-banks-for-china-asset-management-venture-sources.html "Exclusive-Allianz in talks with banks for China asset management venture -sources") at risk is the norm, not the exception.

**Companies are undervaluing their most important asset**

With cyber risk impacting every aspect of modern organisations, it is high time that shareholders, investors and advisors treat cyber risk as a macro risk as essential as financial and [commercial](https://www.financedigest.com/the-benefits-of-using-a-commercial-finance-broker.html "The Benefits of Using a Commercial Finance Broker") risks.

When a new [risk emerges](https://www.financedigest.com/emerging-risks-is-our-insurance-system-able-to-cope.html "Emerging risks: is our Insurance system able to cope?") it always takes time to understand, measure and discuss it in familiar terms, and cyber risk is no exception. While organisations are accustomed to talking about financial and commercial risk, for now discussion of [cyber risk is often fixated on the attack](https://www.financedigest.com/lloyds-of-london-investigates-possible-cyber-attack.html "Lloyd’s of London investigates possible cyber attack") itself; what kind of malware was used, what defences were breached, how many files were stolen, and so on.

Similarly, the financial fall out is usually only expressed in terms of the immediate [operational](https://www.financedigest.com/finance-operations-efficiency-7-ways-to-slick-up-your-department.html "Finance operations efficiency – 7 ways to slick up your department"), legal and regulatory costs in the wake of a breach.

However, given that most [business’ primary revenue](https://www.financedigest.com/covid-19-is-impacting-the-high-speed-steel-market-size-business-revenue-forecast-leading-competitors-and-growth-trends-2031.html "COVID-19 Is Impacting The High Speed Steel Market | Size, Business Revenue Forecast, Leading Competitors And Growth Trends 2031") lies within its IT and data infrastructure, focusing on fines as the primary financial concern of a breach is a highly unsophisticated approach.

But is that also true in the case of Marriott, a hotel chain with [real estate](https://www.financedigest.com/the-professionals-at-real-estate-funding-solutions-helping-you-find-success-with-commercial-real-estate-loans.html "The Professionals At Real Estate Funding Solutions Helping You Find Success With Commercial Real Estate Loans") assets spread around the world? Yes. It is perhaps surprising that a major driver of Marriott’s [future](https://www.financedigest.com/microbial-rennet-market-overview-2022-2029-top-manufacturers-cagr-value-future-scope-revenue-growth-rate-and-forecast.html "Microbial Rennet Market Overview 2022-2029 (Top Manufacturers, CAGR Value, Future Scope, Revenue, Growth Rate and Forecast)") value as a hotel chain is less based on its property values, but rather in its proprietary technology applied to loyalty programs, franchise operating agreements, booking systems and other technology designed to drive efficiency and monetise data. [Consider Air](https://www.financedigest.com/europes-wizz-air-considering-a-saudi-operating-license.html "Europe’s Wizz Air considering a Saudi operating license") BnB, the second most valuable hotel chain in the world, that derives none of its value from owning property. The ability to govern and protect digital systems has become the [key revenue driver](https://www.financedigest.com/publishers-and-brands-view-commerce-content-as-a-key-revenue-driver.html "Publishers and Brands View Commerce Content as a Key Revenue Driver") of most organisations.

**A basic issue of governance and** [management quality](https://www.financedigest.com/healthcare-quality-management-market-is-expected-to-register-highest-cagr-of-12-during-the-forecast-period-2021-to-2031.html "Healthcare Quality Management Market Is Expected To Register Highest CAGR Of 12% During The Forecast Period 2021 to 2031")

What happens when a company fails to understand its level of cyber risk, and what are the value benefits of a [widening of standard risk](https://www.financedigest.com/high-inflation-recession-risk-widen-ecb-dilemma.html "High inflation, recession risk widen ECB dilemma") assessments? We know that the stock markets reward companies that exhibit higher quality of management over time, so companies that are seen as correctly and proactively [managing risk of their digital assets](https://www.financedigest.com/guide-to-choosing-a-digital-asset-management-system.html "Guide to Choosing a Digital Asset Management System") can expect to see their value increase in the future.

Indeed, in the last decade alone, digital companies (e.g. Google, Netflix, Amazon, etc.) have replaced oil, finance and [manufacturing companies as the top](https://www.financedigest.com/uks-top-manufacturing-body-slashes-forecasts-for-2023.html "UK’s top manufacturing body slashes forecasts for 2023") 10 most valuable companies in the world.

Contrast the digital assets winners with a sampling of the losers – the unfortunate companies that must publicly disclose significant [breaches due](https://www.financedigest.com/amazons-twitch-hit-by-data-breach-due-to-configuration-error.html "Amazon’s Twitch hit by data breach due to configuration error") to regulations (TalkTalk, Maersk and Equifax).

These companies suffer tens to hundreds of millions of dollars in financial losses. But this is only part of the value picture.The wider scene sees these companies [lose far more in shareholder value](https://www.financedigest.com/back-to-basics-for-cost-control-as-the-usual-levers-lose-value.html "Back to basics for cost control as the usual levers lose value") relative to peers. For example, Maersk disclosed a financial [loss of approximately USD $300 million stemming](https://www.financedigest.com/yen-stems-losses-after-report-of-boj-rate-check-hints-on-intervention.html "Yen stems losses after report of BOJ rate check, hints on intervention") from its breach, yet the relative shareholder value loss 6 months on was close to USD $7 billion, and it can take six-to-nine months to recoup the market losses relative to peers.

Rather than waiting for the market to force a change, it is in the interests of all well [managed companies and their shareholders to proactively change](https://www.financedigest.com/uk-at-forefront-of-fx-management-change.html "UK at Forefront of FX Management Change") the approach to cyber risk. It must now be apriority to put cyber in the same category as other macro risks such as finance, health, safety and [asset protection](https://www.financedigest.com/top-tips-for-protecting-your-assets-in-2020.html "asset protection").

Crucially, this means demanding two things that are required with other risks: an on-going independent audit or [stress test](https://www.financedigest.com/stress-test-backs-extending-lifespan-of-two-german-nuclear-plants-sources.html "Stress test backs extending lifespan of two German nuclear plants: sources") of network security controls, and translation of the identified cyber risks into financial terms.

**Choose between hollow promises or independent assessment**

The CFO demands this from other divisions of the business and cyber should be no different. A [prospective business](https://www.financedigest.com/metal-cans-and-glass-jars-market-demand-from-food-industry-to-grant-sustainable-business-prospects.html "Metal Cans and Glass Jars Market – Demand from Food Industry to Grant Sustainable Business Prospects ") partner or regulator would never settle for an internal memo about health and safety saying “everything is fine”, and the same is now true for cyber. Likewise, organisations must ensure that any prospective suppliers, partners, and other third parties have undergone thorough independent audits in the same manner as they would for other financial risks.

Independent cyber risk audits will also improve C-suite and [board level](https://www.financedigest.com/electronic-board-level-underfill-and-encapsulation-material-market-to-expand-at-a-cagr-of-5-5-by-during-the-forecast-period-of-2020-2030.html "Electronic Board Level Underfill And Encapsulation Material Market to expand at a CAGR of 5.5% by during the forecast period of 2020-2030") decision-making if they are presented in commercial terms, like all other risks. Rather than fixating on specific technical details, cyber audits should use financial metrics, such as value-at-risk, as they would for any other macro risk. There should be an emphasis on the active benefits of good security such as improved productivity, stock value, and [insurance premiums](https://www.financedigest.com/no-exam-term-life-insurance-premiums-explained.html "No-Exam Term Life Insurance Premiums Explained"). This should be an integral part of all major decisions. In short, merging the rapidly [evolving](https://www.financedigest.com/the-evolving-world-of-work-what-next-for-employers.html "The Evolving World Of Work – What Next For Employers?") world of cybersecurity with the well understood world of finance will help companies better manage this growing macro risk.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

