Cybersecurity: an environmental, social and governance issue.

Estimated reading time: 3 minutes

Summary

As cyberattacks increase, society is realizing that cybersecurity is much more related to ESG (Environmental, Social and Governance) issues than previously thought.

As the risks become more evident and the The number of attacks is becoming more frequent.It has become clear that responsibility cannot simply be delegated to the state and the insurance company.

It is necessary for companies and organizations to be aware of their share of responsibility for the data they process, making use of the following measures from now on. good ESG practices to seek a higher level of security, because as we have noticed, cyber security It is also a matter of responsibility and good governance.

O World Economic Forum The World Economic Forum recently published an article that highlights how often... Cybersecurity is treated as a matter solely for regulatory bodies.However, it should, in reality, be a joint effort.

The World Economic Forum warns of risks and calls for attention to ESG (Environmental, Social, and Governance) issues.

According to the published report, three issues stand out: cyber attacks and the risks they pose to society as a whole, the need for companies and organizations to also take responsibility for cybersecurity management and security. as part of their strategy rather than relying on other factors, and ultimately as the creation of a A standard framework can help organizations measure and manage risks.

From this, we can list 3 reasons why good practices are necessary. ESG should be properly included in the strategy of all companies.

  • Cyber ​​risk represents a threat to a company's assets.

It is estimated that intangible assets represent, on average, 90% of an organization's assets. having even tripled in the index Standard and Poor's 500 (S&P 500) over the last 35 years, a fact that is largely due to the accelerated migration towards the digitalization of assets during the pandemic.

Os Data are now considered the most decisive intangible assets in a company's value.Because as companies grow, their intangible value also grows, increasing the impact that a security breach would have on the company if it were to occur.

O cyber crime It is designed to increase, because as a company's intangible assets increase, so do the profits for criminals.

Cybersecurity needs to be thought of in a broader sense, because it's not so much about racing against time to protect every computer within a company, but rather about creating a strategy that minimizes losses should such an intrusion occur.

There are assets without which a company cannot operate: these should be the focus.

  • Cyber ​​risk represents a risk to society.

As digital transactions These technologies were hastily adopted by companies to increase consumer convenience. And this type of transaction is everywhere: from essential public services to consumer goods.

The problem is that this computerization has increased the risks.

In 2021 alone, there were record numbers of identity thefts, representing a 23% increase compared to the previous record.

However, this has a much greater effect on people, as breaches of systems give criminals the ability to access institutional data, affecting the quality of service to the community.

An example of this harmful potential was the attack on the US pipeline operator Colonial Pipeline, which resulted in the interruption of fuel supplies to the southeastern United States in May.

  • Insurance cannot reduce risk.

We all know that implementing governance to promote cybersecurity is laborious. However, delegating responsibility solely to insurance companies does not reduce the risk, because as the courts have ruled in favor of the victimized companies, insurers have tightened their grip and reduced the scope of coverage under their policies.

The fact is that it is It's essential to have insurance.However, it serves as a support, since insurance cannot be seen as a substitute for good governance in a company.

A well-established standard framework can help companies and regulators understand and measure risks, and better yet, it can help to... incorporate these risks into the ESG strategy, Because government regulations alone cannot realistically manage all businesses, since each one has its own unique business model.

A standardized framework for conducting these risk analyses could be the solution for more efficient governance. aligned with ESG parameters, which, when applied correctly, can only generate positive consequences for companies.

About the Author

Meet the author of this article.

  • We are a Privacy and Personal Data Protection Management, GRC, and ESG solution provider. We help companies build responsible businesses.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also