Business Wire

Companies With Advanced Cybersecurity Performance Deliver Nearly Four Times’ Higher Shareholder Return Than Their Peers, According to Diligent and Bitsight

Share

Companies with advanced cybersecurity performance create 372% higher shareholder return compared to their peers with basic cybersecurity performance, according to a new report from Diligent and Bitsight. The report also reveals that highly regulated industries, such as healthcare and financial services, have the highest cybersecurity ratings, and companies with either a specialized risk committee or audit committee achieve better cybersecurity performance compared to those with neither, with ratings of 710 and 650 respectively.

“These findings show that cybersecurity is not just an IT problem — it is an enterprise risk that has material impact on a company’s near-term performance and long-term health, and one that management and the board needs to be up to speed on,” said Dottie Schindlinger, Executive Director of the Diligent Institute. “With increased pressure from regulators for organizations to demonstrate how they oversee cybersecurity, now is the time for boards and leaders to build their competency around cyber risk.”

“Cybersecurity is no longer about simply mitigating risk, it's now a key indicator of financial performance. Companies must treat cybersecurity as a cornerstone of their business strategy, guided by clear, ambitious benchmarks, and backed by the full support of their boards," added Dr. Homaira Akbari, CEO of AKnowledge Partners, Board of Director member for Banco Santander and Landstar System and member of Bitsight’s Advisory Board.

In the “Cybersecurity, Audit and the Board” report, Diligent and Bitsight analyzed more than 4,000 mid to large-cap companies in public indices globally. Additional findings include:

Companies with measurably stronger cybersecurity performance deliver higher financial performance than their peers

  • The average total shareholder return (TSR) for companies with advanced security performance ratings over a five-year and three-year period was 71% and 67%, respectively, while companies in the basic performance range delivered 37% and 14% TSR over the same time frames.
  • Companies with a higher number of independent directors are more likely to have advanced security ratings. About 76% of directors on the boards of these companies with advanced security ratings are independent, compared to 66% in the basic security performance category.

Companies with specialized risk or audit committees have better cybersecurity performance

  • The median cybersecurity rating for companies with specialized risk committees is 730, compared to 720 for companies with just audit committees, indicating there is not a significant difference in the ability of the audit committee to oversee cyber risk compared to a specialized risk committee.
  • Having a cybersecurity expert on the general board is not enough – those experts need to be directly involved with cyber oversight. Companies with cybersecurity experts on either audit or specialized risk committees achieve an average security performance rating of 700, whereas companies with cybersecurity experts on the general board, but not on either committee attain a security rating of 580.

Highly regulated industries outperform other industries in cybersecurity performance

  • The healthcare sector had the highest average security ratings overall at 730. Of the companies with advanced security performance ratings, 33% came from the financial services sector, with an average rating of 720.
  • By comparison, 24% of companies with basic security performance ratings came from the industrials sector, and the sector with the lowest overall performance rating was the communications sector, at 630.

"The research shows that market leading companies that prioritize cyber risk management outperform their peers,” said Derek Vadala, Chief Risk Officer, Bitsight. “This cannot be achieved without a strong understanding of cybersecurity performance and clear benchmarks shared across the executive team and board. The role of the CISO has shifted. Cyber risk is a key component of business performance."

Learn more about how to get certified to oversee cyber risk here. For more information on how Diligent and Bitsight partner to give directors access to market-leading cyber risk data and insights, visit here.

View the full report here.

Methodology

Analyses consists of 4,149 mid to large-cap companies in public indices across Australia, Canada, France, Germany, Japan, the United Kingdom, and the United States. Diligent correlated each company’s cyber oversight structure with their corresponding security performance data, obtained from Bitsight. The correlation method involved averaging the ratings within each category to identify discernible patterns. Bitsight creates cybersecurity ratings based on externally observable measurements of an organization’s security posture. View a full report methodology here.

About Diligent

Diligent is the leading GRC SaaS company, empowering more than 1 million users and 700,000 board members and leaders to make better decisions, faster. The Diligent One Platform helps organizations connect their entire GRC practice — including governance, risk, compliance, audit and ESG — to bring clarity to complex risk, stay ahead of regulatory changes and deliver impactful insights, in one consolidated view. Learn more at diligent.com.

Follow Diligent on LinkedIn, X (Twitter) and Facebook.

About Bitsight

Bitsight is a global cyber risk management leader transforming how organizations manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss. Built on over a decade of market-leading innovation, Bitsight’s integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance and data analysis. For more information, visit bitsight.com or connect with us on LinkedIn.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Julia Hanbury
Senior Communications Manager, Diligent
Jhanbury@diligent.com

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Catch the Best Prime Day Offers on Smart Home Must-Haves: EZVIZ Rolls Out Jaw-Dropping Deals on Tried-and-True Cameras and Entryway Innovations for Everyday Peace of Mind8.7.2025 12:30:00 EEST | Press release

This Prime Day, EZVIZ, an internationally trusted name in smart home security, introduces a handpicked selection of exclusive offers that protect homes from the very first point of contact. For households that value safety around the home and especially at the very threshold, this is a moment to invest in home security that is as advanced as it is effortless. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250702338311/en/ From 8 to 11 July, homeowners can seize the window on EZVIZ Prime Day deals on Amazon UK, featuring EZVIZ’s best-loved smart cameras, expertly bundled packages, and a complete range of entry products. These limited-time savings offer a rare opportunity to elevate home protection, no matter for a bustling city apartment or a sprawling family residence. Here are some top-rated deals: CP3 Pro Video Doorbell with solar panel – now £49.98, was £79.99 An intelligent welcome with built-in protection. Powered by an

CapVest and Parquest Agree Terms on IPN’s Acquisition of Sopral8.7.2025 11:00:00 EEST | Press release

Inspired Pet Nutrition (“IPN”), the fast-growing pet food company controlled by CapVest Partners LLP (“CapVest”), and Parquest, a leading investment firm, have agreed terms on the acquisition of Sopral, a prominent branded pet food platform serving the European market, with manufacturing operations based in France. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250708134461/en/ Sopral products The transaction is subject to customary regulatory approvals and closing conditions. Financial terms have not been disclosed. Based in Pléchâtel, Brittany, France, Sopral is a leading manufacturer of branded premium dry petfood with a comprehensive range of high-quality nutritional solutions, including Pro-Nutrition Prestige, Pure Life and Protect brands. Sopral has a strong footprint and reputation in France and a fast growing online and international market presence in over 50 countries around the world. Employing over 130 people, th

Thales Reinforces its Leadership in eSIM and IoT Connectivity with a ‘Ready to Use’ Certified Solution8.7.2025 09:00:00 EEST | Press release

With over 5.8 billion IoT cellular connections expected globally by 2030 (GSMA Intelligence), businesses and industries face growing pressure to deploy connected devices at scale — securely and efficiently. The SGP.32 IoT specification has been designed specifically to meet the unique needs of IoT devices by simplifying remote connectivity activation while maintaining high levels of trust. And more specifically, the GSMA eSA certification ensures that the eSIM product (hardware, firmware, OS, and cryptographic libraries) complies with strict security and functional requirements, recognised across the global mobile ecosystem. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250707594164/en/ Thales reinforces its leadership in eSIM and IoT connectivity with a ‘ready to use’ certified solution. SGP.32 is a new standard that allows connected devices—like smartwatches, trackers, or medical sensors—to download and activate a mobile

Tigo Energy Adds Solar-Plus-Storage Portfolio in Czech Republic to Build on MLPE Success8.7.2025 07:00:00 EEST | Press release

Tigo Energy, Inc. (NASDAQ: TYGO) (“Tigo” or “Company”), a leading provider of intelligent solar and energy software solutions, today announced that the Company’s entire portfolio of three-phase Tigo EI Inverters has successfully passed the certification tests for compliance with the PPDS P4 requirements in the Czech Republic. Compliance with PPDS P4, formally known as Distribution System Operation Rules, Annex 4, is a prerequisite for grid connection of solar inverters in the Czech Republic, validating the compatibility with the technical conditions defined by the European Commission and adopted by local utility companies. In the wake of the proliferation of rapid shutdown requirements across Europe, with installers in the Czech Republic deploying nearly 107MW of Tigo MLPE in 2024, Tigo products have been deployed by thousands of Czech installers in the past decade. As an established brand trusted in the Czech solar installer community, the release of the Tigo EI Residential system cap

Invivoscribe Expands Flow Cytometry Services to Accelerate CAR-T Immunotherapy Development and Regulatory Readiness with the Initiation of CERo Therapeutics Phase 1 Clinical Trial8.7.2025 07:00:00 EEST | Press release

Invivoscribe Inc., a global leader in precision diagnostics and measurable residual disease (MRD) testing, is proud to support CERo Therapeutics Holdings, Inc., an innovative immunotherapy company seeking to advance the next generation of engineered T cell therapeutics that employ phagocytic mechanisms. Through this collaboration, LabPMM (Invivoscribe’s global reference laboratories) have customized their multiparametric flow cytometry (MFC) services and implemented their sensitive MFC AML MRD assay to supportCERo’s clinical trial of its lead compound, CER-1236. The trial targets Acute Myeloid Leukemia (AML) in patients who are relapsed/refractory, in remission with MRD, or newly diagnosed with TP53-mutated MDS/AML. AML is an aggressive blood cancer characterized by the rapid accumulation of abnormal myeloid cells in the bone marrow and blood, disrupting normal hematopoiesis.1 Treating AML is especially complex due to its genetic heterogeneity and the high risk of relapse. CAR-T (chime

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye