Data Breaches: A growing concern for Listed Companies
- Damien and Ami Arthur

- Jan 24, 2023
- 3 min read
Data Breaches: A Growing Concern for Listed Companies
In today's digital age, data breaches have become a major concern for businesses of all sizes. However, for listed companies, the consequences of a data breach can be particularly severe. Not only do they risk damaging their reputation and losing the trust of their customers, but they also face potential legal and financial repercussions.
According to a recent study, 56% of data breaches are related to the theft of trade secrets. This highlights the importance of protecting proprietary information and sensitive data. Additionally, with the rise of remote working, companies are facing increased costs in protecting their networks and systems. It's estimated that companies spend on average $1 million more to protect against security breaches caused by remote work.
One of the biggest challenges for listed companies is the growing sophistication of cybercriminals. Hackers are constantly developing new techniques to gain access to sensitive information, such as using malware or social engineering tactics. Ransomware and malware attacks have also increased in recent years, with the cost of ransomware being exponential. A 25GB malware can shut down a company's operations in 24 hours.
Another concerning statistic is the average time to realize a breach. On average, it takes 207 days to detect a breach and a further 70 days to contain it. This highlights the importance of having incident response plans in place and regularly reviewing and testing them.
One of the most important steps that listed companies can take is to invest in cybersecurity. This includes implementing firewalls, encrypting data, and regularly updating software and systems. Companies should also conduct regular security audits to identify vulnerabilities and address them promptly. Additionally, companies should have incident response plans in place to quickly contain and mitigate the effects of a data breach.
Another key step is to ensure compliance with relevant laws and regulations. For example, listed companies in the US are subject to the Data Privacy laws and protection of personal information. In the EU the Data protection Acts and laws have wide reaching affect and include GDPR to protect natural persons, which requires them to maintain accurate audits and implement internal controls. Failure to comply with these regulations can result in significant fines and penalties. Companies also have legal obligations and notification requirements that require legal counsel familiar with cybersecurity laws when a breach happens.
In addition, listed companies should have a crisis communication plan in place to address the public and media in the event of a data breach. This should include steps to notify affected individuals and provide them with information on how to protect themselves. Companies should also be transparent about the cause of the breach and the steps they are taking to prevent it from happening again.
In conclusion, data breaches are a growing concern for listed companies, particularly with the increasing risk of trade secret theft, the added costs of remote working, and the increasing sophistication of cybercriminals. To mitigate the risk and minimize the potential damage, companies must invest in cybersecurity, comply with relevant laws and regulations, and have a crisis communication plan in place. By taking proactive steps to protect their data and respond to a breach, listed companies can minimize the impact on their reputation and financial performance. There are various steps that should be taken but the key point is to communicate and have relevant stakeholders and departments talk to each other to maintain a resilient cyber security policy. Policy to be affective needs to be implemented, maintained and reviewed regularly.


Comments