Companies With Advanced Cybersecurity Performance Deliver Nearly Four Times’ Higher Shareholder Return Than Their Peers, According to Diligent and Bitsight
26.3.2024 14:00:00 EET | Business Wire | Press release
Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.
“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”
“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.
In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:
Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers
- The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
- Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.
Companies with specialized risk or audit committees have better cybersecurity performance
- The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
- Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.
Highly regulated industries outperform other industries in cybersecurity performance
- The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
- By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.
"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."
Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.
View the full report here.
Methodology
Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.
About Diligent
Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.
Follow Diligent on LinkedIn, X (Twitter) and Facebook.
About Bitsight
Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240326307541/en/
Contact information
Julia Hanbury
Senior Communications Manager, Diligent
Jhanbury@diligent.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Enry’s Island Unveils “Enry’s Island Adventures”: Venture Capital Becomes a Videogame and Launches the “Strap” Movement on Kickstarter3.4.2026 10:47:00 EEST | Press release
Enry’s Island SpA (WBAG: EIOS), the world’s first publicly traded Venture Builder, today announced the upcoming Kickstarter launch of Enry’s Island Adventures (EIA), developed by its New York-based portfolio company, Enry’s Island Adventures LLC. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260402548535/en/ The game is designed to make venture capital accessible to new generations, transforming startup creation into an engaging and social gaming experience. After three years of R&D, EIA introduces a "bleisure" model (business + leisure): players learn to launch and manage startups through gameplay that includes real business KPIs, a customizable and evolving personal island, synchronous and asynchronous multiplayer modes, social events, and community-driven seasonal missions. The “VC revolution”: teaching and democratizing through play "I agree with Elon Musk that the best way to teach is through a video game, and this is
SES Announces Results of the Annual General Meeting2.4.2026 17:49:00 EEST | Press release
SES (the “Company”) held the Annual General Meeting (“AGM”) of Shareholders today in Betzdorf, Luxembourg. Following the recommendations made by the Board of Directors of SES, the shareholders have voted in favor of all resolutions, including the Company’s 2025 annual accounts and the proposed annual dividend of EUR 0.50 per A-share (EUR 0.20 per B-share). The total dividend amount comprises the interim dividend of EUR 0.25 per A-share (EUR 0.10 per B-share), which has already been paid to shareholders on October 16, 2025. The final dividend of EUR 0.25 per A-share (EUR 0.10 per B-share) will be paid to shareholders on April 16, 2026. “I would like to sincerely thank our shareholders for their active engagement, visionary support and continued confidence in SES’ strategy,” said Adel Al-Saleh, CEO of SES. “The outcomes of today’s AGM underscore our shared commitment to a bold multi-orbit approach, with Medium Earth Orbit as the strategic backbone of a dynamically evolving global interco
Forrester: Three Years Into GenAI, Enterprises Are Still Chasing Its True Transformative Value2.4.2026 17:00:00 EEST | Press release
According to Forrester’s (Nasdaq: FORR) latest report, Accelerate Your AI Voyage, most enterprises are struggling to turn growing AI adoption and investment into measurable business impact. One of the key factors holding businesses back is low artificial intelligence quotient (AIQ) — Forrester’s measure of AI aptitude — with many employees lacking a clear understanding of how to use AI. Other barriers include an overemphasis on productivity-focused use cases, difficulty measuring impact, and siloed adoption within individual functions. While these challenges can leave firms frozen in doubt or indecision, the wait-and-see approach to AI adoption is no longer viable. To unlock AI’s full potential, organizations need to focus on four key areas: Define the business outcomes and success metrics for what they want AI to achieve; identify specific use cases for AI deployment aligned to those business outcomes; establish a structured runway to plan, test, and strategically time the deployment
Andersen Consulting Adds Multiplica2.4.2026 16:30:00 EEST | Press release
Andersen Consulting enters into a Collaboration Agreement with Multiplica, a digital consulting firm that helps organizations design, build, and scale impactful digital experiences. Founded in Spain with a presence in Latin America and the U.S., Multiplica focuses on user research and discovery, customer experience research, digital strategy, data modeling and analysis, report automation and data visualization, conversion rate optimization, product design, and user experience design. The firm helps organizations accelerate digital transformation by building digital capabilities, teams, and assets that advance expertise across digital products, consulting, and talent development. Multiplica enables clients to forecast emerging trends in digital experience and transform their businesses through enhanced digital channels and customer engagement. “Collaborating with Andersen Consulting represents an exciting opportunity to extend our reach and impact,” said David Boronat, CEO of Multiplica
Brightfin Unifies Brand Following Proven Optics Merger, Delivering a New Standard for Technology Cost Optimization2.4.2026 16:00:00 EEST | Press release
Brightfin today announced that, following its merger with Proven Optics, the combined company will operate under a single brand: Brightfin. The unified company brings together deep expertise in Technology Expense Management (TEM) and IT Financial Management (ITFM) to help organizations better understand, manage, and reduce total technology spend. Technology spending will exceed $6 Trillion this year, and for most organizations, it remains one of the least understood. CIOs can tell you what they’re spending. Far fewer can tell you whether it’s working. “Over the past several months, we’ve brought these two businesses together around a shared purpose: help enterprise businesses better understand and optimize their technology spend,” said Joel Martins, CEO of Brightfin. “What we are seeing now is a shift. Visibility alone isn’t enough. Teams need to be able to act, tied to real financial outcomes. See Clearly. Spend Better. That is our north star, and that is what our platform is built to
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
