Cyber security: An integral ESG component

Cyber security: An integral ESG component

By Jason Grimbeek, CEO, Iron Spear

As the financial and economic landscape continues to evolve and shift post-pandemic, CPA professionals are playing a vital role in helping businesses across all sectors address the emerging environmental, social, and governance (ESG) risks, challenges, and opportunities. Cyber security and data security are fast becoming key considerations in the ESG framework. CPAs are uniquely positioned to transition into the emerging role of strategic ESG advisors by helping businesses navigate complex ESG issues, manage new cyber risks, and build long-term resilience.

Institutional investors, business partners, and shareholders are demanding increased transparency in how companies manage their ESG practices and risks to ensure that they align with their values. Organizations are facing growing pressure to demonstrate that their cyber security program is in place and operating before being allowed to connect to business partners. Poor supply chain management techniques are coming under scrutiny as potential investment risks. The recent SolarWinds and MoveIT software breaches impacted data integrity and claimed multiple victims, including government organizations and private sector companies globally.

ESG principles

The three ESG principles are:

  1. Environmental: Measures a company’s stewardship of natural resources and resiliency against climate change to prevent business process interruptions. Cyber attacks on critical infrastructure can lead to environmental damage.
  2. Social: Examines how a company manages the relationships of its internal and external stakeholders, employees, clients, suppliers, and within their communities to avoid the disruption of essential services. The compromise of customer data increases the risk of personal information being exposed to identity theft and fraud, leading to the erosion of trust.
  3. Governance: Deals with the organization’s leadership, ethical conduct, oversight, audit, and internal controls to help manage risk across the business spectrum. Failure of corporate governance can potentially expose CEOs, CISOs, and boards of directors to lawsuits and fines.

The lack of proper ESG principles can impact an organization’s:

  • Reputation
  • Investment prospects
  • Mergers and acquisitions
  • Supply chain management
  • Employee well-being

According to Bloomberg Media’s Sustainable Future Study, current estimates predict a 15-20% continued growth in ESG investments, especially in the EU. 71% of business leaders believe, “Eventually no investment decisions will be made without considering ESG.”

Cyber governance roadmap

There are several ways that financial professionals can incorporate ESG principles into their work:

  1. Know who is accountable: Engage top leadership in business planning, financial decision-making, and reporting. Boards need to be knowledgeable in the oversight of ESG-related matters.
  2. Measure and manage cyber risk: A good cyber risk program will translate technical risks into business risks and can be measured.
  3. Develop and manage a cyber program: A cyber program provides a proactive and systematic approach to managing an organization’s cyber risks and digital assets.
  4. Be prepared with cyber insurance: Transfer any potential cyber risk to a third-party insurer where possible.

Business leaders need to remain prepared for emerging economic developments, changing business regulations, long-term market risks, and evolving stakeholder expectations. CPAs can play a unique and vital role in enabling a more secure, equitable, and sustainable future that requires challenging the usual way of conducting business.

Why cyber should be a part of your ESG strategy

By implementing a cyber program and addressing cyber risks within the ESG framework, CPAs can help organizations safeguard their operations and reputation while fulfilling their wider social and environmental obligations.

Want to learn more?
Uncover the importance of cybersecurity in your organization’s future ESG strategy and unlock your organization’s potential! Secure your spot now for Iron Spear’s workshop, Cyber Security: An Integral Component of ESG, in Calgary and Edmonton on Friday, November 24, from 8:30 a.m. to noon, a key part of EVOLVE 2023. Don’t miss the opportunity to shape your tomorrow!

This supplied content is provided by Iron Spear, a leader in cyber governance.



Discover more from Digital Dividends

Subscribe now to keep reading and get access to the full archive.

Continue reading