The government may want the UK to be a âglobal tech superpowerâ, but it seems the countryâs companies struggle to disclose their cyber security measures to meet investor needs.
A report from the countryâs governance watchdog says many disclosures from companies are âboilerplateâ and âoverly staticâ.
Experts point to a number of reasons why this may be happening, but watchdogs and government ministers appear concerned. Mark Babington, executive director of regulatory standards at the Financial Reporting Council (FRC), says: âEvery company is now digital, so providing useful, relevant and focused disclosure on digital security is critical.â
Meanwhile, digital minister Matt Warman underscores the ÂŁ2.6bn government has ploughed into the national cyber security strategy. But he adds: âBusinesses can do more to bolster their online defences and improve transparency and reporting around cyber security.â
The warnings come at a time when there is heightened concernâdriven in part by fears of Russian cyber attacksâwith high-profile security breaches making the news on a regular basis.
Under attack
This month the UK governmentâs cyber breaches survey estimated that 39% of businesses have identified a cyber attack in the last 12 months, though there may be under-reporting, especially from companies with less âmatureâ cyber security set-ups. A little more than four out of five of those assaults are classified as âphishingâ attacks, while around a fifth report more sophisticated incursions, such as denial-of-service, malware or ransomware attacks.
Only 54% of businesses have moved over the last year to identify cyber security risks, down on the 64% in 2020. A mere 19% of businesses are reported to have a formal âincident response planâ. And this despite the fact that surveys show executives place cyber security among their top priorities.
There is wider parliamentary concern about security. MPs on the House of Commons Digital, Culture, Media and Sport Committee have been taking evidence on security in new technology in advance of a report expected later this year. The conclusions will make for an interesting read.
But it is the geopolitical landscape that is causing increased anxieties. Britainâs support for Ukraine has intensified, as has anticipation of institutions and organisations here becoming targets for Russian cyber aggression.
At the beginning of July, the National Cyber Security Centre (NCSC) issued a statement warning companies of an âextended period of heightened threatâ . Paul Maddinson, NCSCâs director for national resilience, said it was ânow clear that weâre in this for the long haul and itâs vital that organisations support their staff through this demanding period of heightened cyber threatâ.
Company disclosures give stakeholders an idea of whether corporate leaders are doing enough to combat cyber risk, especially from data breaches.
The FRC says corporate reporting teams and audit committees need to up their game in a number of areas. They need to detail how cyber is âimportant to the companyâs current and future business model, strategy and environmentâ. They also need to describe the âgovernance structures, culture and processesâ used to support cyber security and identify their digital and cyber security risks faced now and in the future.
Lastly, companies should report on attacks. In short, they should âhighlight the impact of internal and external events and the actions and activities that respond to theseâ.
Cyber house rules
Ask the experts and there is broad agreement that not all companies are at the same point, either in their cyber security measures or their reporting.
According to Dr Ali Al-Sherbaz, a professor and cyber security expert at the University of Gloucestershire, companies have two problems to overcome in the current climateâfinding the right people and providing the right training and information. Companies should also be sharing more data. âMany companies are struggling with growing cybersecurity demands,â he says.
Others caution against rushing to conclude that disappointing disclosures means falling short on the daily cyber security battle.
âI donât think you can imply a correlation between poor reporting being linked to poor performance and a reluctance to open up about whatâs going on,â says Sam De Silva, a technology lawyer and partner at the law firm CMS. âReporting (especially accurate reporting) takes time and effort, so companies may be focusing on other thingsâsuch as the âdoingâ.â
Annual reporting is not the only disclosure responsibility. Other regulators demand reports too, not least the Information Commissionerâs Office (ICO).
Al-Sherbaz points out reporting responsibilities can be immense. âCoveredâ incidents need to be reported to the ICO, meaning some firms may be faced with compiling information on as many as 100,000 incidents in a single day. âThis means automated reporting is the only solution,â he says. âManaging this is a constant challenge for industry.â
Competing pressures
That said, pressure to report to shareholders and stakeholders is likely to only increase. And executives are only too aware of the effects that security can have on the perception of their companies, according to Andrew Kakabadse, professor of governance and leadership at Henley Business School. Reputation and share prices are all on the line in the event of a cyber breach.
âUnder these circumstances, what is likely to be disclosed is questionable, as share price is largely determined by soft factors such as trust and reputation, rather than tangible issues like products and services,â Kakabadse says.
âTop executives are treading a very fine line between disclosure and safeguarding the organisation through minimal reporting of cyber threats. This will increasingly threaten [to bring] legal repercussions for senior executives.â
Managers may have other concerns, too. Pressure may be growing for more transparency, but many executives may be weighing that against security, says De Silva.
âDepending on the contents of the disclosures, it could be argued that an organisation providing information about its cyber security practices (particularly if they are not adequate) could open the organisation up to nefarious actors.â
Cyber threats are here to stay and the balancing act between regulatory demands, reputations, share price and security concerns will continue. This will be an enduring question not only for company leaders, but for rule makers too.



