Cyber threats are increasingly identified as a critical business risk in company reporting according to analysis for Deloitte’s annual survey of a sample of 100 UK listed companies
The firm says more than half of all companies surveyed identified cyber as a ‘principal risk to the business’. The number disclosing board involvement in cyber-related risks was greatest for the FTSE 100 companies sampled, at 79%. This fell to 59% in FTSE 250 companies and just 12% outside the FTSE 350.
Recent high profile breaches and the reputational damage such events can bring is behind the trend, Deloitte says, though board interaction in these discussions was varied.
According to its annual reports insights 2016, a third of FTSE companies are disclosing in their annual report how they are creating financial value for stakeholders other than shareholders, including employees, governments and local communities.
In total, around half (49%) of annual reports this year also included a cross reference to where further corporate responsibility information could be found outside the report, compared to the 34% who did so in 2015.
Looking ahead, Veronica Poole, Deloitte’s UK head of corporate reporting, predicts Brexit and climate change are expected to join the list of ‘principal risks’ for many in FY16, bearing in mind the recent recommendations of the Financial Reporting Council (FRC) and the work of the Financial Stability Board’s task force on climate-related financial disclosures.
Poole also pointed out that companies have been slow to react to regulators’ requests to see progressively more entity-specific qualitative and quantitative information on the anticipated impact of new IFRSs that are not yet effective. The Deloitte survey found that only 3% gave detailed explanations of significant impacts foreseen on adoption of IFRS 15.