Only 5% of FTSE 100 companies have a director with specialist technology or cyber security experience, despite the fact that 87% recognise cyber threats as a principal risk in their disclosure reporting, according to research by Deloitte
The firm conducted a survey of detailed reporting practices on cyber risk of all FTSE 100 companies, covering the annual report published most recently as of 30 September 2016.
Deloitte says its analysis found a clear majority (56 companies or 64%) that included cyber risk as a principal risk also mentioned that the risk has increased compared to the previous year; 30 companies (34%) did not mention any change in the risk and one company (in the financial services sector) reported that the risk has decreased for them, although without further explanation.
Of the type of cyber attacks disclosed as a threat, unauthorised access to systems ranked most common (19%), followed by hacking (13%) and malware (13%). Distributed denial of service (DDoS) attacks were only mentioned by five companies, despite Deloitte predictions that there could be ten million DDoS incidents in 2017.
Phill Everson, head of cyber risk services, Deloitte UK said: ‘The vast majority of FTSE 100 reports acknowledge the principal risk, but our analysis shows there were wide variations in the disclosure of cyber risk management and mitigation strategies.’
Deloitte said 11% of the reports mentioned the creation of a new role or body to take overall accountability for cyber risk, demonstrating the increased focus on cyber risk in organisations. However, there is also a growing expectation for board involvement in cyber oversight, as evidenced by the 10% of companies that delivered cyber related training to their board.
Everson said: ‘With the pervasive nature of technology and the focus on cyber risk it is alarming that only one in twenty boards disclose that they currently have board members with specialist technology or cyber background and only a handful more disclose that they have advisors to the board with this experience. This is not sustainable, but also reinforces the importance of disclosing such information to investors.’
More than half of companies mentioned cyber contingency, crisis management or disaster recovery plans in their annual report. Of these, however, only 58% disclosed that these plans had been simulated in test scenarios over the year.
Everson said: ‘Testing is vital, as the nature of cyber attacks is developing rapidly, and organisations need to understand their resilience and adapt their defences.’
The research shows the most commonly disclosed potential impacts of cyber breaches were business disruption (68%), reputational damage (58%), and data loss (45%).
Everson said: ‘Clearly, the more frequently and stringently mitigation plans are tested, the more resilient and responsive the company. Interestingly, very few reports identified employee action as one of their cyber security threats. Company employees are, knowingly or unintentionally, the most common cause of a cyber breach.’
Deloitte's cyber reporting survey is available here.