Cybersecurity: from Cost Center to Strategic Investment

Once seen as a cost center, cybersecurity is increasingly understood as a business driver and strategic investment.  Both external and internal forces are at work. The pace and audaciousness of cybercrime, increasingly brazen intellectual property theft (which IBM estimates cost business $4.35 million per breach), and the actions of a few nations have much to do with the changes now underway.

It’s not simply the quantity, but also the quality of cyberattacks and the effect on the bottom line that has made cyber liability emerge as a critical concern for executives. And when it comes to dealing with risk, cybersecurity insurance can’t do it alone. There are now evolving sets of best practices that executives must engage with.

In the wake of a series of high profile breaches, shareholder lawsuits have become more commonplace as parties seek to recover for losses following cyber attacks. These lawsuits very often are smartly keyed into attacks that were either reasonably foreseeable or, once known to leadership, mismanaged. 

Consider that just in the last six months alone we learned that SolarWinds has agreed to pay $26 million to settle a shareholder lawsuit following the massive breach they, and their clients, suffered in 2020. Coming fast on the heels of that settlement, Solarwinds is also expecting to be hit with an enforcement action by the Securities and Exchange Commission (“SEC”). 

Attacks against critical infrastructure have become a feature of today’s news and national cybersecurity strategies are taking such attacks into account. In the United States, cybercrime against critical infrastructure is now judged a threat to national security. Organizations are on the hook to improve their cybersecurity posture, with mandates coming in fast. 

Just last March, the SEC announced proposed rules on cybersecurity risk management, strategy, governance, and incident disclosure. The rules are meant to address concerns of increasingly significant cybersecurity hazards for public companies. 

Among the key elements, the proposed rules would require public companies to disclose material cybersecurity risks and incidents. The SEC stated that “materiality” for purposes of the proposed rules would be consistent with applicable case law and precedents. Further, publicly traded companies would be required to report cybersecurity incidents on Form 8-K within four days of determining that the incident is material.

With these rapid changes top of mind for executives and boards, cybersecurity should be embedded into everything that we do and organizations will be challenged to plan and prepare, regularly reporting and continuously monitoring risks. Are you ready?

PUBLISHED BY

Sean Costigan

28 Mar. 2023

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
DMARC

400,000 DMARC boost after Microsoft’s high-volume sender update

Jack Lilley

Microsoft’s decision to join Google and Yahoo in enforcing stricter rules for high-volume senders has triggered an immediate response across the internet. In the last 30 days alone, 406,042 new domains have deployed Domain‑based Message Authentication, Reporting & Conformance (DMARC), pushing the global total to 10.9 million. While not all domains will be exclusive Outlook users,…

Read more
DMARC

Red Sift partners with Gradian to strengthen email security through OnDMARC

Jack Lilley

Today Red Sift launches a new partnership with Gradian, a leading data protection provider, to offer its award-winning applications, including Red Sift OnDMARC, to new and existing customers. Established through Red Sift’s relationship with UK distributor E92plus, the two companies look to strengthen defences against phishing and Business Email Compromise (BEC) attacks. Allowing organisations…

Read more
Cybersecurity

DMARCbis: What are the changes and how to be ready

Jack Lilley

Executive Summary: DMARCbis, also known as DMARC 2.0, is the forthcoming update to the DMARC email authentication protocol, designed to address limitations and ambiguities in the original standard, with an expectation to be finalized and published in 2025. The update introduces clearer guidelines, a new method for determining organizational domains, and streamlined record management.…

Read more
Certificates

TLS certificates are changing: What you need to know

Jack Lilley

Executive summary: TLS certificates are about to get significantly shorter-lived. Starting 15 March 2026, newly issued public-trust certificates will max out at 200 days—and just three years later, that lifespan drops to 47 days. Backed by Google, Apple, and Mozilla, this shift aims to make the web safer through fresher data, faster failover, and…

Read more