{"id":19778,"date":"2022-08-08T09:01:07","date_gmt":"2022-08-08T17:01:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/08\/08\/news-13511\/"},"modified":"2022-08-08T09:01:07","modified_gmt":"2022-08-08T17:01:07","slug":"news-13511","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/08\/08\/news-13511\/","title":{"rendered":"IT security: An opportunity to raise corporate governance scores"},"content":{"rendered":"<p><strong>Credit to Author: Christine Barrett| Date: Mon, 08 Aug 2022 16:00:00 +0000<\/strong><\/p>\n<h2>What is a corporate governance score?<\/h2>\n<p>Corporate governance scoring is increasingly important to boards of directors, executive leadership, and the investment community.&nbsp;If we want to enlist the support of a stakeholder, we have to talk about the things that are important to them.&nbsp;Sales revenue is important to sellers.&nbsp;Data breach risk gets the attention of the chief information security officer (CISO).&nbsp;Governance scores often affect executive compensation and the way an analyst rates a company\u2019s stock.&nbsp;They are important to the board.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n<p>If the IT security team communicates in terms of improving a corporate governance score, it will get their attention.&nbsp;Boards have a lot of demands on their attention as they prioritize the many risks and opportunities they need to navigate.&nbsp;Moving the needle on a benchmark they already care about helps them prioritize IT security.&nbsp;<\/p>\n<p>Corporate governance benchmarks, such as the Institutional Shareholder Services (ISS) ESG Governance QualityScore, are a focus area for boards, management, and investment analysts.<sup>1<\/sup> This is a language that they speak. If we want to advocate with these stakeholders, framing our IT security investments and actions in terms of an increased QualityScore is an effective way to do this.<\/p>\n<p>Leaders in the corporate governance space have recognized the part that IT security plays in corporate governance and have included this in their scoring methodology. Cybersecurity is identified as a focus area in Principles of Corporate Governance for the board risk oversight and management strategic planning responsibilities,<sup>2<\/sup> as well as an evolving governance challenge in the Harvard Law School Forum on corporate governance.<sup>3<\/sup> Security, particularly concerning data breaches, is identified by the Corporate Finance Institute as one of the principles of corporate governance.<sup>4<\/sup><\/p>\n<p>We\u2019ll identify the specific ways that IT security governance can impact a company\u2019s ISS Governance QualityScore, potentially driving analyst recognition, shareholder value, and executive compensation. This can help inform the board as they consider relative priorities and investments in IT security.<\/p>\n<p>While the discussion is applicable to all geographies and segments, the scoring example we\u2019ll use is for a United States-based company in the Standard and Poor\u2019s (S&amp;P) 500 index.<\/p>\n<h2>How corporate governance scores are calculated<\/h2>\n<p>The ISS ESG Governance QualityScore is a data-driven scoring and screening solution designed to help institutional investors monitor portfolio company governance. The ISS Governance QualityScore global coverage is applied to approximately 7,000 companies, including those represented in S&amp;P 500, STOXX 600, Russell 3000, Nikkei 400, and others around the world.<\/p>\n<p>The companies\u2019 annual meeting notes, regulatory filings, and other public-facing information are reviewed quarterly and in real-time for some events to update the QualityScore.<\/p>\n<p>The methodology is made available on the ISS website.<sup>5<\/sup><\/p>\n<p>To improve the organization\u2019s QualityScore and map the impact of IT security investments and activities, it is important to understand the factors (questions) and how a score is calculated.<\/p>\n<p>The topics scored include:<\/p>\n<ul>\n<li>Board structure.<\/li>\n<li>Compensation.<\/li>\n<li>Shareholder rights.<\/li>\n<li>Audit and risk oversight.<\/li>\n<\/ul>\n<p><em>The audit and risk oversight section is where the IT security-related factors are located. We\u2019ll focus our discussion on how to map and raise these factors.<\/em><\/p>\n<p>A raw score based on the factors is calculated and ranked relative to companies in the same index or region to promote an \u201capples to apples\u201d comparison, with a number from 1 to 10 assigned to each category. Figure 1 shows an example of a raw score and category score for each category for a United States-based company in the S&amp;P 500.<\/p>\n<div style=\"height:77px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-table aligncenter\">\n<table>\n<thead>\n<tr>\n<th class=\"has-text-align-center\" data-align=\"center\">Category<\/th>\n<th class=\"has-text-align-center\" data-align=\"center\">Category Raw Score<\/th>\n<th class=\"has-text-align-center\" data-align=\"center\">Category Score<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Board Structure<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">25.0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">7<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Compensation<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">19.5<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">10<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Shareholder Rights<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">28.0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">5<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Audit &amp; Risk Oversight<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">56.5<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">4<\/td>\n<\/tr>\n<\/tbody>\n<tfoot>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\"><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>Overall Raw Score<\/strong><\/td>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>Governance QualityScore<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Total<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">129.0<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">8<\/td>\n<\/tr>\n<\/tfoot>\n<\/table>\n<\/figure>\n<p><em>Table 1. Score methodology example for S&amp;P 500 United States-based company<\/em>.<\/p>\n<div style=\"height:79px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-table is-style-regular\">\n<table class=\"has-white-background-color has-background\">\n<thead>\n<tr>\n<th class=\"has-text-align-center\" data-align=\"center\">Rating Category<\/th>\n<th class=\"has-text-align-center\" data-align=\"center\">Questions Scored<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Board Structure<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">51<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Audit and Risk Oversight<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">21<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Shareholder Rights<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">32<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Compensation<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">37<\/td>\n<\/tr>\n<\/tbody>\n<tfoot>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\">Total<\/td>\n<td class=\"has-text-align-center\" data-align=\"center\">141<\/td>\n<\/tr>\n<\/tfoot>\n<\/table>\n<\/figure>\n<p><em>Table 2. Questions scored in each category for a United States-based company<\/em>.<\/p>\n<p>For the United States, there are 141 factors scored. Twenty-one are for the Audit and Risk Oversight category. Of these, 11 are related to information security. Thus, more than half of this category\u2019s raw score that will be scaled to create the 1 to 10 QualityScore for the Audit and Risk Oversight category is related to IT security.<\/p>\n<p>The definition of IT security-related questions differs from what an IT security and compliance professional will have encountered from working with the ISO, the NIST, or similar security standards. We\u2019ll look at this next.<\/p>\n<h2>IT security conversation with the board and executives through the corporate governance lens<\/h2>\n<p>The factors used for the governance score are different from what we\u2019d encounter in an IT audit. They don\u2019t cover the fulsome controls and defense in depth that we\u2019d expect as IT security professionals. Some are likely part of key performance indicators (KPIs) already tracked, such as those relating to awareness and training, financials, and breaches.<\/p>\n<p>When a strategic plan or business case for an investment is presented to leadership, it can be mapped to the QualityScore factors. An improvement in the governance score can be forecasted.<\/p>\n<p>An example is provided below for the implementation of <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/compliance\/advanced-audit?msclkid=da646dc1b60611eca60670457b2f42eb&amp;view=o365-worldwide\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Purview Audit (Premium)<\/a>. This tool is a part of Microsoft 365, is easily deployed, and has no user impact or change management requirements. In the event of a <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/01\/06\/privacy-breaches-using-microsoft-365-advanced-audit-and-advanced-ediscovery-to-minimize-impact\/\">credentials compromise<\/a>, it provides forensic information to understand if there was a breach of sensitive information, what documents may have been accessed by the bad actor, and provides retention of audit data for long periods of time.<\/p>\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th>QuestionID<\/th>\n<th>Question<\/th>\n<th>Mapping for Microsoft Purview Audit (Premium)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>402<\/td>\n<td>Does the company disclose an approach to identifying and mitigating information security risks?<\/td>\n<td>Audit (Premium) allows a company to identify the information accessed by a bad actor if an account is compromised. It provides forensic information to understand the consequences of a breach and remediate appropriately. This is part of risk mitigation.<\/td>\n<\/tr>\n<tr>\n<td>406<\/td>\n<td>What are the net expenses incurred from information security breaches over the last three years relative to total revenue?<\/td>\n<td>Audit (Premium) makes information available that can differentiate a breach that has no impact from one that has a massive impact on the company, its partners, and its customers. Without this information, the company may incur massive costs for breach notification and mitigation that would not be necessary if the breach could be properly scoped.<\/td>\n<\/tr>\n<tr>\n<td>407<\/td>\n<td>Has the company experienced an information security breach in the last three years?<\/td>\n<td>Audit (Premium) can differentiate between account compromise that has no impact and may not be reportable as opposed to a breach requiring large-scale reporting and remediation. Reporting information security compromises correctly, including knowing what is and is not a breach is a focus of Audit (Premium).<\/td>\n<\/tr>\n<tr>\n<td>408<\/td>\n<td>What are the net expenses incurred from information security breach penalties and settlements over the last three years relative to total revenue?<\/td>\n<td>The expenses and penalties incurred due to an information security breach will vary greatly depending on the scope and impact of the breach. Expenses and penalties can be reduced as a result of the forensic information Audit (Premium) makes available.<\/td>\n<\/tr>\n<tr>\n<td>409<\/td>\n<td>Has the company entered into an information security risk insurance policy?<\/td>\n<td>Insurers require underwriting to issue security risk insurance policies. Underwriting depends on the company\u2019s IT security program, controls, and governance. Audit (Premium) is an important part of the security program, providing uniquely valuable forensic information.<\/td>\n<\/tr>\n<tr>\n<td>412<\/td>\n<td>How long ago did the most recent information security breach occur (in months)?<\/td>\n<td>Audit (Premium) can differentiate between account compromise that has no impact and may not be reportable as opposed to a breach requiring large-scale reporting and remediation. It can enable a forensic investigation that scopes a breach in terms of time and the timing of bad actor activities in this period.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><em>Table 3. Example Mapping of Microsoft Purview Audit (Premium) to ISS Governance QualityScore<\/em>.<\/p>\n<p>Alignment with the Governance QualityScore goes beyond the support of security solutions and investments.<\/p>\n<p>Some of what the company may already have in place, like security training, standards-based audit, metrics, and reporting is part of the scoring. Communicating this so that it is reflected in the governance score increases the company\u2019s return on investment and leadership\u2019s awareness of the contributions of the security team.<\/p>\n<p>The score will be boosted by having senior leadership regularly brief the board on information security matters.<\/p>\n<p>Adding a board member with security experience will also boost the score. These will give the security function the attention and investment that it needs from leadership to increase the company\u2019s security posture.<\/p>\n<h2>Conclusion<\/h2>\n<p>Showing how a company\u2019s Governance QualityScore benefits from their investment in security demonstrates additional return on investment and wins support for the security program from a range of stakeholders. Stakeholders that may not recognize the value of IT security controls and processes or understand IT security risk may recognize the financial and brand value of an increased governance score.<\/p>\n<p>As time goes on, the expectations for IT security to be part of corporate governance will increase. The focus on the breach will likely be broadened to a more holistic perspective. Additional factors will be considered and the impact of IT security on the overall scoring will increase.<\/p>\n<p>Consider demonstrating how an IT security investment or activity will raise your company\u2019s governance score along with other aspects of the business case and risk management when presenting to leadership to make a fulsome case for action.<\/p>\n<p>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n<p><em>This document is provided \u201cas-is.\u201d Information and views expressed in this document, including URL and other Internet website references, may change without notice. You bear the risk of using it. This document is not intended to communicate legal advice or a legal or regulatory compliance opinion. Each customer\u2019s situation is unique, and legal and regulatory compliance should be assessed in consultation with their legal counsel.<\/em><\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n<p><sup>1<\/sup><a href=\"https:\/\/www.issgovernance.com\/esg\/?msclkid=64306e1cb45111ec802b66f3a9f5753b\" target=\"_blank\" rel=\"noreferrer noopener\">Institutional Shareholder Services<\/a> ESG Governance QualityScore, ISS. March 31, 2022.<\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/corpgov.law.harvard.edu\/2016\/09\/08\/principles-of-corporate-governance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Principles of Corporate Governance<\/a>, Harvard Law School Forum on Corporate Governance. September 8, 2016.<\/p>\n<p><sup>3<\/sup><a href=\"https:\/\/corpgov.law.harvard.edu\/2020\/03\/15\/cybersecurity-an-evolving-governance-challenge\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cybersecurity: An Evolving Governance Challenge<\/a>, Harvard Law School Forum on Corporate Governance. March 15, 2020.<\/p>\n<p><sup>4<\/sup><a href=\"https:\/\/corporatefinanceinstitute.com\/resources\/knowledge\/other\/corporate-governance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Corporate Governance<\/a>, Corporate Finance Institute. May 8, 2022.<\/p>\n<p><sup>5<\/sup><a href=\"https:\/\/www.issgovernance.com\/esg\/ratings\/governance-qualityscore\/?msclkid=7049f441b5fb11ecae79277bc68a0c9d\" target=\"_blank\" rel=\"noreferrer noopener\">Governance QualityScore<\/a>, ISS. <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/08\/08\/it-security-an-opportunity-to-raise-corporate-governance-scores\/\">IT security: An opportunity to raise corporate governance scores<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/08\/08\/it-security-an-opportunity-to-raise-corporate-governance-scores\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christine Barrett| Date: Mon, 08 Aug 2022 16:00:00 +0000<\/strong><\/p>\n<p>Corporate Governance scoring is increasingly important to boards of directors, executive leadership, and the investment community. Governance frameworks now incorporate aspects of IT security. Communicating the security message in ways that impact a company\u2019s governance score is important to getting attention and investment from corporate leadership. This post examines a leading governance framework from Institutional Shareholder Services, Governance QualityScore, and the specifics of how IT security can increase a company\u2019s score. <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/08\/08\/it-security-an-opportunity-to-raise-corporate-governance-scores\/\">IT security: An opportunity to raise corporate governance scores<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[12534,4500,22073],"class_list":["post-19778","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-compliance","tag-cybersecurity","tag-data-governance"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19778"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19778\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19778"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}