Skip to content

10 August, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

  • Comment
      • View all
    • create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

      growth

      Governance Guide: How boards drive growth

      The strategic role of the board is changing rapidly, in line with a shifting world....

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC Annual Review of Audit Quality 2026

      This Financial Reporting Council report uses findings from its supervisory activities to assess audit quality...

      Governance Guide: How Boards Drive Growth

      This Board Agenda Governance Guide investigates how directors can evolve to drive performance and growth...

      Organizational Transformation in the Age of AI

      This World Economic Forum paper looks at how organisations must re-architect their workflows and operating...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

The true cost of cyber breaches

by Katherine Blackler

Cyber-security and data breaches have been making headlines following high-profile incidents at TalkTalk and Vodafone, but cyber-attacks can jeopardise the security of any company.

Photo: Shutterstock

Favorite
Photo: Shutterstock
Photo: Shutterstock

In October 2015 three young men allegedly changed the game for TalkTalk by hacking its firewall and stealing customer information, the third attack on the telecommunications company this year.

In its half-year results report, the company estimated the short-to-medium-term charge of putting things right following the hack would be ÂŁ35m.

Commentators from The Telegraph newspaper even suggest that the hack could leave TalkTalk vulnerable to a takeover.

Soon after the attack on TalkTalk, Vodafone admitted in November that almost 2,000 customer accounts were accessed using information acquired from a third party.

The company admitted customers’ names, mobile numbers, bank sort codes and the last four digits of their bank accounts could have been taken, The Guardian reports.

Unlike the cyber-attack on TalkTalk the week before, Vodafone claims its own systems were “not compromised or breached in any way”. Instead, it says customers’ account names and passwords were obtained through an “external” source. How the details came to be held by a third party is not known but it serves to highlight that companies need to consider it is not only their own IT systems that could leave them vulnerable.

Cyber-attacks may have been especially prevalent recently, but it is not a new problem.

At least 13 other big brands have been hit by cyber-security breaches. The National Crime Agency is investigating claims that account details for Halifax, O2, EE, Sky and BT Sport customers are also being sold by hackers along with passwords and user names for major retailers including Amazon, Uber, Ticketmaster and Ocado.

Cyber-attacks may have been especially prevalent recently, but it is not a new problem. In 2011 hackers accessed Sony’s PlayStation network, putting the payment details of more than 70 million customers at risk. The service was closed for several weeks, even though it has since emerged that no data was actually stolen.

Business are vulnerable

The attack on TalkTalk should be a “wake-up call” for British business, senior government officials have told the Financial Times, and warned that many other companies storing millions of customers’ details had weak digital security standards.

Many other large British businesses were equally exposed to such attacks, they warned, emphasising that the breach was not the work of a sophisticated state act or terror group.

Baroness Harding, chief executive of TalkTalk, said that the company could have done more on cyber-protection, but that “no system is free from vulnerabilities”.

John Stewart, CSO of Cisco, says that a data breach is not a unique experience: “You’re eventually going to be hit. It’s not worth the effort of thinking you won’t be hit. It’s no longer a relevant conversation.”

“You’re eventually going to be hit. It’s not worth the effort of thinking you won’t be…”

–John Stewart, Cisco

Google and IT security company McAfee estimates that there are 2,000 cyber-attacks every day around the world, costing the global economy about £300bn a year, while the Institute of Directors says only “serious breaches” make the headlines, but attacks on British businesses “happen constantly”.

The costs

So what are the potential costs should something go wrong?

For TalkTalk, that cost was estimated at £35m. However, shares fell sharply when details of the incident were disclosed, suggesting that the potential cost to reputation could be much higher.

Deloitte’s 2014 global survey on reputation risk found that security (physical or cyber) was one of the three key drivers of reputational risk among the 300 executives it sampled.

A report from Alva has analysed the issue of data breaches and their impact on company reputation, using more than 12 months’ worth of data for TalkTalk, Sony, Barclays, RSA, LV= and Carphone Warehouse.

It found that data breaches can result in some of the most impactful downturns in sentiment for an organisation. Two of the four largest declines in TalkTalk’s sentiment score have all resulted from data breach concerns, making it a genuine reputational risk.

It also found that data breaches can produce tenacious negativity. TalkTalk’s sentiment trend did not return to its pre-February 2015 breach starting point until early May, and negative data breach content only subsided in June following TalkTalk’s announcement that it would change the way in which it processed credit and debit payments to reduce the risk of a future breach.

There is a tangible ramping-up of the impact on reputation of the data breaches over the three highlighted cyber-security attacks.

This is in part due to differences in the scale of the breaches, but Alva also notes that there is the additional element of an incremental reduction in stakeholder trust when a company is repeatedly exposed to the same risk.

Tipping point

Repeated negative issues can reach a tipping point, beyond which the company loses the opportunity to mitigate risk, and damage limitation is the best available outcome.

Different stakeholders reacted to the breaches at TalkTalk with different levels of criticism and through different actions.

For customers, this manifested itself in an increase in active criticism of the organisation and the proactive discussion of switching providers.

TalkTalk’s Alva Social Media Advocacy score has plummeted since the incident, with a significant increase in switching behaviour expressed online suggesting future retention and new business concerns.

It is not just major consumer brands that are at risk. Any company that holds a record of client, company or employee details could find themselves a target.

For investors, the drop in TalkTalk’s share price is indicative of concern over the company’s customer base, its ability to prevent a future recurrence and its exposure to regulatory pressures.

For regulators and politicians the number of people affected necessitates a firm stance against the company, with lengthy reviews or probes potentially fuelling future coverage of the breach and thereby extending the lifecycle of the issue.

According to Alva a general rule of thumb when assessing the extent of reputational risk is to assess the number of stakeholders affected; the more that are impacted, the longer and more damaging the risk.

Prevention

TalkTalk insists that it had adequate defences in place, which it regularly reviewed. This is the third time that hackers have managed to breach TalkTalk’s cyber-security to steal client data in a year, suggesting that defences were struggling to cope.

It is not just major consumer brands that are at risk. Any company that holds a record of client, company or employee details could find themselves a target.

There are several routes that non-executives concerned about cyber-security at the companies they represent can take. Non-executives should review systems in place and ask:

  1. Are operating systems updated and regularly patched?
  2. Does the company have a firewall and software in place that opposes viruses, spyware and phishing attacks?
  3. Are there any wireless networks? Are they encrypted?
  4. Is company software restricted? Has anyone set up administrative rights so that nothing can be installed on computers without authorisation?
  5. Is there filtering in place that controls access to data?
  6. Is access to the web completely open? Restricting access to sites with internet filters can prevent employees and hackers from uploading data to storage clouds.
  7. Do the company computers have USB ports? Removing or disabling USB ports can help stop malicious data being uploaded or downloaded.
  8. Are there strict password policies in place?
  9. Are drives, folders and files containing sensitive information encrypted?
  10. Have you considered hiring professionals to assess your vulnerability?
  11. Insurance can be a useful tool: do you have adequate cyber-insurance cover? Who would pay the bill should the worse happen?

Non-executives need to consider what their company’s cyber-security vulnerabilities are, and make sure that some or all of these routes are under consideration or already in place.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Cyber criminals chase ransomware insurance money
    April 18, 2023
    ransomware insurance

    Specialist ransomware criminals are investigating victims’ insurance capacity—sometimes by blatantly asking companies outright.

  • Technology, cyber risk and ESG top list of business leaders' concerns
    June 8, 2022
    Digital code on skycrapers

    Mazars survey reveals 82% of executives plan to increase investment in IT systems, while 75% plan to boost spending on sustainability.

  • Are cyber disclosure demands too high?
    August 15, 2022
    cyber disclosure

    Organisations increasingly struggle with cybersecurity as they balance fear of reputational damage against cyber disclosure requirements.

  • Cyber security reporting falls short
    August 4, 2022
    cyber security

    UK companies are struggling to provide focused disclosures as cyber attacks continue to increase, says the FRC.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy