Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
What is City Talk? City Talk allows marketers to connect directly with our audience by publishing content on citypm.eu
Tuesday 25 May 2021 10:12 am

Investment professionals must beware of the cyber risks in portfolios

By: Rhodri Preece

Add as a preferred source on Google
Large scale cyber-attacks impact is becoming an increasingly important consideration for investment professionals.

Internet security blog posts are usually more at home on the inside pages of IT trade publications than on the front pages of international newspapers. The one published by Microsoft Corporate Vice President Tom Burt on 2 March, about the emergence of “state-sponsored threat actor” Hafnium, was a notable exception.

A new threat had emerged, targeting Microsoft exchange server software. It wasn’t long before the phones of helpdesks worldwide started to ring, and IT managers’ social media feeds lit up. The hackers had attempted to penetrate much deeper than usual into the systems of their intended victims, in order to lurk undetected for a long period of time. The attack may have compromised as many as 20,000 organisations.

Large scale cyber-attacks of this kind are becoming more common and quantifiable. Their impact is becoming an increasingly important consideration for investment professionals who need to engage with corporations to understand the risks and protect their portfolios against adverse scenarios.

To illustrate what is at stake, a new publication by the CFA Institute Research Foundation on cyberwarfare and cybercrime cited a study examining the average revenue growth of companies affected by severe IT security breaches, and compared those results to industry peers not affected by cybercrime. The research covered some 432 companies and 460 unique events over a six-year period.

It found that in the two years after a severe security breach, corporate revenues first declined by about 10 percent on average and then recovered slowly. After two years, revenues had only recovered to the same level they were at when the security breach happened. By contrast, companies that did not suffer a security breach saw revenue growth of almost 20 percent over the same period.

Click here for the full book

What does this mean for investors?

The impact of a major security breach is not just reflected in a company’s earnings but also in its share price. Indeed, corporations that have suffered a severe breach could see share prices drop by 10 percent or more over six months and remain depressed for a long time.

With such potentially enduring consequences, it is no surprise that companies are stepping up data protection efforts.

That task is, however, becoming much more difficult as the pandemic has forced millions of people to work from home. This has increased the vulnerability of corporate data – especially from phishing attacks directed at employees.

These attacks have become so widespread that many analysts are comparing the coronavirus pandemic with an emerging “cyber pandemic”— with at-home employees playing the role of trojans.

Read more

Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

The CFA Institute Research Foundation publication – Data, the Oil of the 21st Century – reveals the risks faced by corporations by the growing number of cyber threats emerging from both nation-states as well as criminal groups.

Author Joachim Klement warns that investors need to assess their potential exposure to such attacks which are already costing the average bank – with banks being the preferred targets of cybercrime – some $18.4 million-a-year (about £12.3m) based on 2018 data. Model estimates for the global banking system range from $97 billion (about £68.5bn) to $351 billion (about £247.6bn) per year in potential losses — easily capable of triggering a financial crisis.

Action needs to be taken

The recent Microsoft attack attracted global attention. It was, however, the eighth time in 12 months that the company had publicly revealed an attack by so-called nation-state groups targeting critical institutions. Victims ranged from health organisations fighting COVID-19, to political campaigns involved in the 2020 US elections.

Such attacks have encouraged a major push at state level to bolster cyber defences. For example, in March 2021, the UK government launched a new National Cyber Force – the result of cooperation between the Ministry of Defence and Government Communications Headquarters (GCHQ) – to disrupt and destroy communications systems of those posing a national security threat.

The financial industry should now engage to protect itself, and its clients, from emerging threats which – as the latest Microsoft hack highlights – are becoming more and more damaging. 

Industry leaders may flinch at the required outlay of capital to upgrade cyber defences, at a time when there is a pressing need to conserve cash. But in order to prevent business disruption, information loss and revenue loss, the investment is critical.

To this end, the former US State Department official Richard Clarke may have some prescient insight. “If you spend more on coffee than on IT security, you will be hacked. What’s more, you deserve to be hacked.”


If this article has sparked your interest, click here for the full book.


Image credit: ©Getty Images / filadendron

Read more

The Debate: Should CEOs be held personally accountable for cyberattacks?

Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Jobs and Money
  • Markets & Economics
  • News

Categories

  • Business
  • Economics
  • Money
  • Tech

Related Topics

  • Books
  • Cybercrime
  • Data protection
  • Data science

Trending Articles

  • Top Burnham adviser calls for capital gains and inheritance tax hikes

  • A meeting with the breakfast king of Mayfair

  • As it happened: Stocks jump on defence and metals boost; Oil on track to shed a fifth on US-Iran peace hopes

  • Housebuilding giants hit with £4.5bn lawsuit for allegedly overcharging buyers

  • Clarkson’s Farm and why businesses must stop blaming the weather

More from City PM

  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • ‘Act now’: AI models capable of attacks on governments months away, Five Eyes warn

    Tech
    GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.
  • Professional services firms the ‘flavour of the month’ for cyberattacks

    Prof Services
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Level Access Now Available in the Microsoft Marketplace

    Business Wire
  • ICON selects Microsoft as a preferred technology partner to power AI-enabled clinical development

    Business Wire
  • Jaguar Land Rover eyes cost-cutting and wealthy buyers in cyber attack recovery

    Retail
    JLR logo prominently displayed in an automotive business setting, highlighting the companys brand presence and identity
  • City law firm Shoosmiths launches Microsoft-led AI tool for junior lawyers

    Legal
    Burges Salmon partners with legal tech startup Wexler to enhance AI-driven litigation support for UK lawyers

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy