cyber risk

Two-thirds of FTSE 100 firms say cyber risk is increasing

Published: 19:23, March 15, 2017

A survey of FTSE 100 firms finds that over two-thirds (64 percent) of the United Kingdom’s top listed companies recognize that cyber risk is increasing year on year.

The survey, conducted by Deloitte, is the first ever to focus on cyber risk and draws on information given in company annual reports.

It focuses on what companies say in their annual reports about cyber risk, paying particular attention to whether they identify it as a principal risk, how they categorize it, and describe its effects.

cyber risk
The area of cyber risk most often mentioned by FTSE 100 companies as a principal risk was cyber crime or cyber attack. Image: pixabay 1979478

Four areas of cyber risk

In a report about the findings, Deloitte say they found companies mostly mentioned four main areas of cyber risk: cyber crime (or cyber attack), IT systems failure (not necessarily in connection with cyber crime), protection of data and “sensitive” information, and data theft.

The results show that 87 percent of FTSE 100 companies picked one or more these four areas of cyber risk as a principal risk in the information they disclosed in their annual reports.

The area of cyber risk most often mentioned as a principal risk was cyber crime or cyber attack (mentioned by 72 percent of FTSE 100 companies), closely followed by IT systems failure (71 percent).

Protection of data and sensitive information – for instance to comply with data protection regulations – is a principal risk by 59 percent of the FTSE 100.

Only 33 percent of companies identified data theft or misappropriation (including theft of intellectual property or IP) as a principal risk in their annual reports, but Deloitte suggest some companies might categorize this as cyber crime.

‘Employees are one of the biggest threats to cyber security’

In a discussion on the nature of threats to cyber security, the report notes that:

“A company’s own employees remain one of the biggest threats to cyber security, intentional or otherwise, but very few companies publicly acknowledge this fact.”

The survey finds AstraZeneca is one of the few companies to allude to this risk. In their 2015 annual report, the British-Swedish biopharma mentions that their increasingly complex systems are potentially vulnerable to security breaches from “attacks by malicious third parties, or from intentional or inadvertent actions by our employees or vendors.”

GlaxoSmithKline’s (GSK’s) 2015 annual report also mentions that some employees have been indicted for theft of GSK research information. The report defines the area of risk, its potential impact, and notes that as far as the company can discern, the breach has not damaged R&D activity or ongoing business. GSK also outline the steps and procedures they follow to mitigate such breaches.

Deloitte say they would like to see more UK companies acknowledging employee actions – “inadvertent or otherwise” – as a source of cyber risk and reporting on how they are dealing with it.

Companies need to acknowledge and report on cyber security issues

William Touche, Vice‑Chairman of Deloitte UK and head of the company’s centre for corporate governance, says the growing threat to cyber security “comes at a time when there is also increasing focus from investors and regulators on how organizations manage risk.”

In a recent letter to audit committees and finance directors, the UK Financial Reporting Council wrote they would encourage companies to look at a broad range of factors when considering the main risks facing their business, and give the example of “cyber security.”

Touche says they conclude from their survey that companies should think carefully if they have not identified cyber as a principal risk. Cyber breaches can do a lot of damage – incurring not only the cost of repair but also loss of reputation. He remarks:

“The better disclosures are company specific, year specific and provide sufficient detail to give meaningful information to investors and other stakeholders.”

Video – What is Cyber Security?

Cyber security (also: cybersecurity) involves protecting an organization’s computer systems, sensitive data, and other IT components from cyber attacks and hackers. The word cyber, which can be either a prefix or adjective, refers to anything characteristic of or related to computers, virtual reality, and other IT phenomena.

Catharine Paddock PhD Avatar

Other News

Global wealth hit a record, but much of the gain was on paper, MGI says

Sep 29, 2026

Progress closes $400 million Domo deal to add AI data platform

Sep 29, 2026

SOCAR and Comstock set a $1.65 billion framework for Haynesville gas investment

Sep 28, 2026

HCLSoftware plans Robotiq.ai deal to connect AI agents with older business systems

Sep 28, 2026

ONS research says payroll records could sharpen the UK labor market picture

Sep 28, 2026

Select Water agrees $700 million deal for Pilot Water’s oilfield network

Sep 27, 2026

US firms are pulling back investment in China, Federal Reserve analysis finds

Sep 26, 2026

NetApp plans PEAK:AIO acquisition to scale storage for larger AI clusters

Sep 26, 2026

Bank AI use was linked to a smaller share of small-business lending, Fed study finds

Sep 26, 2026

Iridium shareholders approve Rocket Lab takeover: what still has to happen

Sep 25, 2026

Akamai’s 11.6 billion dollar Anthropic deal ties cloud revenue to a 5.5 billion dollar buildout

Sep 25, 2026

Bentley completes 350 million pound Crewe investment as it unveils its first electric vehicle

Sep 25, 2026

Falling birth rates did not reduce total output in historical data, NBER study finds

Sep 25, 2026

Cheaper renewable power does not solve the capital problem for poorer countries

Sep 25, 2026

Facial payments may feel novel, but money worries can curb repeat use

Sep 24, 2026

Precision farming cuts water use while raising crop yields, study finds

Sep 24, 2026

EU allocates €505m to Lebanon for recovery, reforms and basic services

Sep 23, 2026

Alcoa raises $2.6bn in notes to fund South32 aluminium-assets deal

Sep 23, 2026

UK workplace health plan targets preventable exits from employment

Sep 23, 2026

IMF says Sri Lanka’s recovery is holding, but the next review is still unresolved

Sep 23, 2026