ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The social and environmental importance of cyber-security

Tim Wallen at Logpoint explains why cyber-security is central to ESG reforms 

 

ESG (Environmental, Social and Governance) is advantageous in allowing organisations to demonstrate that they take their social and environmental responsibilities seriously. Annual reports detail the measures taken and acknowledge the risks posed to people and the environment, allowing parties such as insurers and investors to assess the risks accordingly.

 

But cyber-security per se is not part of those efforts. This seems surprising when you consider that it’s directly responsible for safeguarding people’s data, ensuring systems remain operational and that the business can fulfil its remit to its shareholders and the wider economy. 

 

For the investment community, this has been cause for alarm. Last year, Lombard Odier investment managers looked into the cyber-security risks within portfolio companies and determined that a fifth were running outdated software. This resulted in the asset manager demanding ESG processes be applied far more widely to protect its fund and a push for those companies to improve their cyber-hygiene through regular patching.

 

It revealed both how absent cyber-security has been from the assessment of companies but also that investors and other third parties both want and need this element of risk to be assessed and divulged. Now it seems regulators are catching up.

 

Changes in ESG regs

In the US, the Securities and Exchange Commission (SEC) passed a ruling in July that requires organisations to annually disclose information on their cyber-security risk management, strategy and governance.

 

In addition to disclosure reporting which is due four business days after an incident, businesses will now need to detail their processes for mitigating the incident as well as any risk as a consequence of the breach and previous incidents, including the board of directors oversight of risks and handling by senior management.

 

It’s a similar story in Europe, where organisations operating within the European Union (EU) or doing business with organisations based there will be required to file a standardised ESG report under the Corporate Sustainability Reporting Directive.

 

The mandatory directive brings almost 50,000 businesses within scope, including SMEs, who will need to report for the financial year ending in 2025, while non-EU companies with branches or subsidiaries within the EU with net turnover in excess of 150m euros will need to comply from January 2029. (Deloitte provides a great summary of the implications of CSRD for US companies).

 

Disclosure requirements are either mandatory or material, with the latter adhering to the principal of ‘double materiality’. This is the impact the business has on the environment, economy and society but also vice versa i.e. how its own operations are impacted by fluctuations in macro trends.

 

From a cyber-security perspective, in addition to European Sustainability Reporting Standard (ESRS) 2 covering General Disclosure, cyber-security plays to all of the social standards i.e. ESRS S1-S4 (own workforce, workers in the value chain, affected communities, consumers and end users) and governance standard ESRS G1 on Business Conduct. The intended audience for the reports extends beyond financial markets to other stakeholders and once again directors have duties under CSRD including establishing and overseeing due diligence processes.  

 

Ethical decision making

These are welcome developments that will bring some much needed transparency and help align ESG with other ethical frameworks such as the  United Nations Sustainable Development Goals (SDGs).

 

Its principles include goals to address poverty, inequality, climate change, environmental degradation, peace and justice. These, too, are applicable in a cyber-security context. Building resilient infrastructure under SDG 9, for example, could be interpreted as the need to protect critical national infrastructure. Building effective, accountable and inclusive institutions, with public access to information under SDG 16 could be read as the effective implementation of data protection regulations.

 

Consequently, ethical investors are now looking at organisations and even cyber-security vendors that seek to implement these principles.

 

So, why is cyber-security now finally being brought into the ESG fold? Firstly, there’s an awareness that a cyber-attack can be hugely detrimental to the business but just as important is how that risk is managed. Cyber-insurance providers and investors want the assurance that those processes are in place and ESG ratings agencies are now taking into account cyber-security when risk scoring businesses for this very reason.

 

If threat detection and incident response processes are in place and the incident is handled well this can limit the impact and enable the business to swiftly recover, protecting share price.

 

Worsening geopolitical tensions have also led to an increase in nation state sponsored or organised criminal gang (OCG) attacks while advances in technology have slashed the cost of orchestrating attacks.

 

At the same time, a growing skills shortage is threatening to undermine corporate security efforts, so there is a real need for regulation to step in and elevate risk assessment. It’s no exaggeration to say that resilience is no longer just in the interests of the business or its clients but also the nation/s within which it operates.

 

Finally, demand is growing from the wider community that organisations step up and protect data, assets and systems and be accountable should they fail to do so. The fallout from a breach is not localised. It can affect the wider ecosystem and even entire supply chains. Nor is the cost purely a financial one, with wider implications for society and the individuals impacted.

 

So it stands to reason that cyber-security processes must now be documented, the question is how to do so in a way that does not jeopardise defences?

 

Going forward, organisations will need to look at how they can meet the demands of the regulations in the jurisdictions they operate in, assign responsibility and ensure their annual reporting is both retrospective and outlines plans for the future.

 

Streamlining existing cyber-security defence systems will be a must to reduce complexity but also to provide a clear line of sight over threat detection, response and reporting functions. It will require a massive change in mindset but can also help organisations become leaner in their incident response and be seen to be more proactive as evidenced in their annual reports.  

 


 

Tim Wallen is Regional Director for the UK, US and Emerging at Logpoint

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543