Get real on cybersecurity
Skip to main content
pilogo-NEW
Subscribe
  • Subscribe
  • My Account
  • login
  • NEWS
    • Asset owners and the coronavirus
    • Alternatives
    • Consultants
    • Coronavirus
    • Defined Contribution
    • ESG
    • Frontlines
    • Hedge Funds
    • Investing / Portfolio Strategies
    • Money Management
    • Pension Funds
    • People Moves
    • Private Equity
    • Real Estate
    • Searches & Hires News
    • SECURE Act
    • Special Reports
    • WorldPensionSummit
    • Ron Schmitz
      Pandemic drives faster transition for Virginia to private markets
      Mubadala Investment Co. logo
      Mubadala draws on portfolio in coronavirus fight
      T.J. Carlson
      Texas Muni reduces downside risk during pandemic, finding opportunities now
      Scott Davis
      ‘Triage plan’ at Indiana system helped stem losses
    • Varagon Capital fills new business development role
      Fitch Group in deal to acquire CreditSights
      Credit managers’ outlook still gloomy but brightening – survey
      Digital Colony picks head of Europe capital formation
    • Will Martindale
      Cardano Group chooses group head of sustainability
      Meketa hires first chief marketing officer
      Nick Horsfall
      Redington names managing directors for investment consulting team
      Marsh & McLennan Agency sets sights on Compass Financial
    • New York State Common challenges Tyson’s dual-share stock structure
      Credit managers’ outlook still gloomy but brightening – survey
      Investors call for action on COVID-19-induced humanitarian crisis at sea
      U.S. jobs worker restaurant
      Job market slipped in December as virus surge hindered activity
    • Ascensus, Empower acquire Truist record-keeping business
      PCS Retirement acquires Alliance Benefit Group-Rocky Mountain
      Shawn O'Brien
      Annuities coming to target-date funds, but not right away
      David Ireland
      Sponsors returning to questions about in-plan annuities
    • New law requires MassPRIM to increase diversity of managers, consultants
      Impact investors getting savvier, more efficient – report
      SSGA alum named head of ESG at Mirova
      Aegon moves to cut carbon from workplace DC business
    • Galina Churkina
      Building research earns honor from Aquila Capital
      Blackstone holiday video
      Blackstone would like to show you how things are done around the office
      MacArthur Foundation invests in women’s safe housing fund
      Bill Harmon
      Voya offers fee break for minority-owned firms
    • The Sun Hung Kai Properties Ltd. logo is displayed on the Sun Hung Kai Centre building in Hong Kong on Sept. 13, 2018
      SHK spins out East Point Asset Management
      Man holding a business card with Hedge Fund written on it
      Hedge funds chalk up decade’s best returns in 2020 – HFR
      New hedge fund launches surpass liquidations in third quarter
      Michael Hintz
      CQS deal with spinoff team falls apart
    • New York State Common challenges Tyson’s dual-share stock structure
      A sign on the exterior of a Northern Trust Corp. branch in Chicago on July 13, 2017
      Northern Trust to cut 500 jobs
      Wells Fargo targets $8 billion in cuts
      Maine Public Employees boosts target to alternative credit
    • A sign on the exterior of a Northern Trust Corp. branch in Chicago on July 13, 2017
      Northern Trust to cut 500 jobs
      Wells Fargo targets $8 billion in cuts
      A sign at a China Telecom Corp. store in Shanghai on Jan. 6, 2021
      Managers make further divestments from sanctioned Chinese firms
      The Chinese flag flies in front of the Liaison Office of the Central People's Government in Hong Kong on May 22, 2020
      Standard Life Aberdeen JV to open mainland China pension insurance company
    • Maine Public Employees boosts target to alternative credit
      Los Angeles City Deferred Comp narrows list to 2 in manager search
      Connecticut pension fund CIO resigns
      Arizona State Retirement looking for CIO
    • Sharmila Chatterjee Kassam
      AIF Institute hires former Texas ERS deputy CIO as executive director
      Varagon Capital fills new business development role
      SSGA alum named head of ESG at Mirova
      Capital Group hires BlackRock executive to launch ETF unit
    • Pension funds continue private equity investing spree
      Big jump in private equity AUM expected over next 5 years
      Thoma Bravo takes in $22.8 billion for 3 funds
      Jason Thomas
      Data, technology become new prized possessions
    • Ivanhoe Cambridge Inc. signage is displayed outside the company's office near Bay Street in Toronto on Aug. 29, 2011
      Ivanhoe Cambridge, PAG announce joint venture for Japan logistics investments
      Residential buildings in Hong Kong on Feb. 20, 2020
      KKR closes first Asia-Pacific real estate fund at $1.7 billion
      CPPIB in deal with Greystar to develop U.S. housing
      Global real estate investments to hit $79 billion in 2021 – survey
    • Retirement cartoon
      Hopes rising for retirement readiness in 2021
      Neal and Brady
      Retirement security could be only issue both sides accept
      Shawn O'Brien
      Annuities coming to target-date funds, but not right away
      David Ireland
      Sponsors returning to questions about in-plan annuities
    • Outlook 2021
      The top 10 stories of 2020
      The best places to work in money management
      Investment consultants
    • U.S. still a key market for investors
      Collected coverage of P&I's 2020 WorldPensionSummit
      Pedestrians pass a large advertisement on the Arndale Center shopping mall reading 'Act now to avoid a local lockdown' in Manchester, England
      COVID-19 puts new opportunities and risks on the agenda - WPS panelists
      Screens display stock price information over the trading floor of the NYSE Euronext exchange in Paris
      Private assets will continue to grow in portfolios – WPS panelists
  • Data
    • Research Center
    • Searches & Hires Database
    • Searches & Hires News
    • RFPs
    • Charts / Infographics
    • Sponsored Research
    • Trackers
    • Q2 2020 searches and hires overview report
      Q2 2020 money manager M&A activity summary
      Q2 2020 legal overview report
      Q1 2020 searches and hires overview report
    • San Jose Federated commits $11 million to real estate fund
      Essex Pension Fund on the lookout for private debt manager
      Lexington Contributory wants large-cap equity manager
      Fort Lauderdale fund scouting for large-cap manager
    • San Jose Federated commits $11 million to real estate fund
      Essex Pension Fund on the lookout for private debt manager
      Lexington Contributory wants large-cap equity manager
      Fort Lauderdale fund scouting for large-cap manager
    • International Small Cap Manager Services
      Financial Expertise
      Passive Index Manager Services
      Emerging Markets Equity Investment Management Services
    • U.S. fixed-income returns post another positive year
      Nasdaq delivers an impressive year
      U.S. dollar's recent decline continues
      Hedge funds warming up to financial sector, remain long U.S. equities
    • Institutional Investors: Shared Expectations, Divergent Paths
      Global Investor Study 2016
      Workplace Financial Wellness
    • U.S. Endowment Returns Tracker
      Pension Fund Returns Tracker
      Earnings Tracker
      Corporate Pension Contribution Tracker
  • Insights
    • Opinion
    • White Papers
    • Industry Voices
    • Letters to the Editor
    • Partner Content
    • Publisher's Update
    • Retirement cartoon
      Hopes rising for retirement readiness in 2021
      view gallery
      25 photos
      Cartoons depict a year like no other
      view gallery
      25 photos
      2020 in editorial Cartoons
      Consultants cartoon
      Seeking an investment consultant? Caveat emptor
    • Climate change and emerging markets after Covid-19
      An Asset Owner's Guide to Multi-Manager Portfolio Management
      Research for Institutional Money Management
      The Future of the U.S. Dollar - Dominant currency or one of many?
    • Michael McNally
      Commentary: New ‘investment-plus’ test poses risks to private equity investors
      Adam Waterous
      Commentary: Institutions urged to act now on opportunities created by current global oil disruption
      Ron Lagnado
      Commentary: Straw man critiques don’t hold up in face of real world success
      Robert Raben
      Commentary: What the asset management industry must do to bolster diversity
    • Writer using a typewriter
      OCIO industry needs to adopt GIPS
      Writer or journalist workplace. stock illustration
      Even as it assails China, Trump administration emulates it
      Skeptical of Main Street support for proxy adviser proposal
      Focus on manager diversity pushes asset owners’ to walk the talk
    • Sponsored Content By iShares
      ETFs are becoming a cornerstone of insurance equity portfolios
      Sponsored Content By Aberdeen Standard Investments
      Taking a passive approach to the hedge-fund universe
      Sponsored Content By World Gold Council
      Gold: the most effective commodity investment
      Sponsored Content By iShares
      For institutional investors, ETFs can make meeting liquidity needs easier
    • Help us help you by supporting quality journalism
      You Must Believe in Spring
      Everything Must Change
      Tomatoes & Investments
  • Multimedia
    • Videos
    • Webinars
    • Polls
    • Slideshows
    • Charts / Infographics
    • watch video
      1:24
      U.S. stocks were 2020’s comeback kid
      watch video
      1:23
      Outlook 2021
      watch video
      1:52
      Buy gold's pullback?
      Coronavirus and the S&P 500: 2020
    • Getting Back to Normal: How to Creatively Manage Fixed Income Portfolios in a Rising Rate Environment
      What might a Biden DOL and SEC mean for retirement plans?
      Staying on target with target-date funds
      The Institutionalization of Retail Part Two: A Webinar Series from P&I Content Solutions and Chestnut Advisory Group
    • POLL: Retirement issues in 2021
      POLL: Money managers' priority in Asia-Pacific region
      POLL: Retirement issues in the presidential election
      POLL: The S&P 500 in the third quarter
    • view gallery
      9 photos
      Coronavirus and the markets
      view gallery
      22 photos
      The 1,000 largest retirement funds: 2020
      view gallery
      10 photos
      Outlook 2020
      view gallery
      10 photos
      2019 as seen through the eyes of Roger
    • Graphic: U.S. stocks were 2020's comeback kid
      U.S. fixed-income returns post another positive year
      By the Numbers
  • Events
    • Conferences
    • Webinars
    • Defined Contribution Spring Virtual Series
      DC Investment Lineup Virtual Series
      ESG Investing Virtual Series
      Private Markets Virtual Series
    • Getting Back to Normal: How to Creatively Manage Fixed Income Portfolios in a Rising Rate Environment
      What might a Biden DOL and SEC mean for retirement plans?
      Staying on target with target-date funds
      The Institutionalization of Retail Part Two: A Webinar Series from P&I Content Solutions and Chestnut Advisory Group
  • Careers
  • Research Center
MENU
Breadcrumb
  1. Home
  2. MONEY MANAGEMENT
January 23, 2017 12:00 AM

Get real on cybersecurity

  • Tweet
  • Share
  • Share
  • Email
  • More
    Reprints Print
    Roger Schillerstrom

    Cybersecurity represents a high-profile risk management challenge that corporations must address at the level of board of directors as a top priority. Minimizing cybersecurity risks is a critical fiduciary duty for directors as well as asset owners and other institutional investors.

    The apparent Russian hacking to undermine the U.S. presidential election process should have raised the profile of cyberthreats to all significant companies and institutions, and should drive more attention to the exposure. At the very least, one director on every board must have cybersecurity expertise.

    Cyberthreats expose investors to risks. For example, Verizon Communications Inc.'s proposed acquisition of Yahoo Inc.'s operating business is still at risk of termination over “security incidents disclosed” by Yahoo last month and in September, according to a Jan. 9 Yahoo filing with the Securities and Exchange Commission.

    The vulnerability of even an Internet-savvy company such as Yahoo shows the challenge of protecting against cyber risks and responding to cyberattacks.

    While most large companies and institutions, those most likely to be attacked by cyber criminals or vandals, have built protections against such attacks, without someone knowledgeable on their boards they cannot know if the companies' efforts are sufficient and keeping pace with the sophistication of the attackers.

    Only 52 companies in the S&P 500 stock index have at least one director identified with cybersecurity expertise, according to data from ISS Analytics. The companies include Arthur J. Gallagher & Co., Boeing Co., Bank of America Corp., Bank of New York Mellon Corp., Chevron Corp., General Motors Co., Raytheon Co., State Street Corp. and Wells Fargo & Co. In all, there are 55 directors whose companies disclose them as having cyber competency.

    Of the S&P 500 companies, the list amounts to about 1% of the 5,534 directors on boards of the companies.

    Shareholders must do more to raise the profile of the issue at the board level by seeking board expertise, and through more disclosure initiatives. But shareholders have not generally so far embraced the issue in terms of proxy proposals.

    In 2014, 2015 and 2016, only seven proposals were filed that called for a report on board oversight of privacy and data security. Four were withdrawn, and three came to a shareholder vote, all at American Express Co., with votes ranging from 78% to 78.8% to reject the proposal.

    As a yardstick for gauging shareholder interest, the small number of proxy proposals indicates that cybersecurity hasn't been a priority. The lack of shareholder concern likely helps explain the inattention at the board level.

    Even so, far more corporations must embrace cybersecurity at the board level as a basis for building a management infrastructure that can oversee corporate efforts to identify, prevent, and respond to cyberattacks. Corporations, with or without board-level expertise, must explain to shareholders how they manage the issue, and they must provide enough disclosure so shareholders can evaluate the cybersecurity approach.

    Some boards leave it to audit committees to take on oversight of cybersecurity, but Mary Jo White, SEC chairwoman who announced in November she would step down at the end of the Obama administration, warned about the audit committee taking on an additional responsibility, thus diluting its core focus on financial concerns.

    Beyond the competitive, financial and reputational pressures to minimize cyber risk, regulations are coming that will push corporations to strengthen cybersecurity.

    The Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corp. on Oct. 1 jointly proposed rule-making to enhance cyber risk management standards at larger, interconnected financial service companies under their regulatory oversight.

    In a comment submitted on the proposal, Reginald P. Best, president and chief product officer, Lumeta Corp., which provides cyber situational awareness analytics tools and services to seven of the largest financial services companies, said: “In our experience, covered entities have limited tools or processes to authoritatively evaluate their situational awareness. There is a false sense of security that organizations have that they know and understand what is happening on their networks.”

    The proposal would require financial institutions that come under the oversight “to establish and maintain a corporate governance structure that implements the cyber risk management program on an enterprise-wide basis.”

    SEC guidelines require companies to disclose material cybersecurity risks. But these guidelines, dating to 2011, need updating to stay up with cyber risks.

    In 2015, a bill called the Cybersecurity Disclosure Act of 2015 was introduced in the Senate seeking to encourage “transparency in the oversight of cybersecurity risks.” It would require companies to disclose whether any director has cybersecurity expertise or, if not, why this expertise on the board is not necessary. The legislation was directed at enhancing disclosure to better inform shareholders and encourage companies to act, rather than requiring any such cyber expertise on boards.

    The bill, which never made it out of committee, could be revived in the new Congress, considering the firestorm over the Russian hacking that heightened attention to cyber risk. Boards must keep pace with technology innovation and cyber risks.

    PricewaterhouseCoopers in a 2016 report recommended companies develop a set of cybermetrics to assess risks and develop a framework for managing vulnerabilities. That is a good idea to begin to measure effectiveness because what gets measured gets managed.

    Corporations have to demonstrate that they are adding board cyber competency, and disclose such moves to show shareholders they are doing so. Like corporations, asset owners and other institutional investors have a fiduciary duty to minimize unrewarded risk exposures and must embrace cybersecurity as a priority, and encourage companies they invest in, or that provide them with services, to do likewise.

    Related Articles
    G-7 countries establish elements to target cybersecurity in global finance indu…
    Plans face threats to crucial data
    Plans ask about cybersecurity insurance — but not for them
    SEC sets marketwide risks, money market funds and cybersecurity as top examinat…
    New York financial firms will have to implement cybersecurity programs
    S&P warns institutions on cybersecurity
    Cybersecurity breaches cost companies billions in value; financial companies hi…
    Reducing cyberrisk exposure from outside service partners
    Lack of guidance putting institutions at end of line
    Still more victims in cyber wars
    Express Scripts clashes with DiNapoli over cyberrisk disclosure
    Recommended for You
    Northern Trust to cut 500 jobs
    Northern Trust to cut 500 jobs
    Wells Fargo targets $8 billion in cuts
    Wells Fargo targets $8 billion in cuts
    Managers make further divestments from sanctioned Chinese firms
    Managers make further divestments from sanctioned Chinese firms
    Research for Institutional Money Management
    Sponsored Content: Research for Institutional Money Management
    sponsored
    Events
     
     
    Sponsored
    White Papers
    Climate change and emerging markets after Covid-19
    An Asset Owner's Guide to Multi-Manager Portfolio Management
    Research for Institutional Money Management
    Bond ETFs show maturity during Covid market mayhem
    Global gold-backed ETFs: A popular gateway to the gold market
    The Future of the U.S. Dollar - Dominant currency or one of many?
    View More
    Sponsored Content
    Partner Content
    The Industrialization of ESG Investment
    For institutional investors, ETFs can make meeting liquidity needs easier
    Gold: the most effective commodity investment
    2021 Investment Outlook | Investing Beyond the Pandemic: A Reset for Portfolios
    Ten ways retirement plan professionals add value to plan sponsors
    Gold: an efficient hedge
    View More
    E-MAIL NEWSLETTERS

    Sign up and get the best of News delivered straight to your email inbox, free of charge. Choose your news – we will deliver.

    Subscribe Today

    Get access to the news, research and analysis of events affecting the retirement and institutional money management businesses from a worldwide network of reporters and editors.

    Subscribe
    Connect With Us
    • RSS
    • Twitter
    • Facebook
    • LinkedIn

    Our Mission

    To consistently deliver news, research and analysis to the executives who manage the flow of funds in the institutional investment market.

    pilogo-NEW
    About Us

    Main Office
    685 Third Avenue
    Tenth Floor
    New York, NY 10017-4036

    Chicago Office
    150 N. Michigan Ave.
    Chicago, IL 60601

    Contact Us

    Careers at Crain

    About Pensions & Investments

     

    Advertising
    • Media Kit
    • P&I Content Solutions
    • P&I Careers | Post a Job
    • Reprints & Permissions
    Resources
    • Subscribe
    • Newsletters
    • FAQ
    • P&I Research Center
    • Site map
    • Staff Directory
    Legal
    • Privacy Policy
    • Terms and Conditions
    • Privacy Request
    Pensions & Investments
    Copyright © 1996-2021. Crain Communications, Inc. All Rights Reserved.
    • NEWS
      • Asset owners and the coronavirus
      • Alternatives
      • Consultants
      • Coronavirus
      • Defined Contribution
      • ESG
      • Frontlines
      • Hedge Funds
      • Investing / Portfolio Strategies
      • Money Management
      • Pension Funds
      • People Moves
      • Private Equity
      • Real Estate
      • Searches & Hires News
      • SECURE Act
      • Special Reports
      • WorldPensionSummit
    • Data
      • Research Center
      • Searches & Hires Database
      • Searches & Hires News
      • RFPs
      • Charts / Infographics
      • Sponsored Research
      • Trackers
    • Insights
      • Opinion
      • White Papers
      • Industry Voices
      • Letters to the Editor
      • Partner Content
      • Publisher's Update
    • Multimedia
      • Videos
      • Webinars
      • Polls
      • Slideshows
      • Charts / Infographics
    • Events
      • Conferences
      • Webinars
    • Careers
    • Research Center