Company valuations drop after a data breach – what happens next might surprise you…

impact of data breach on company valutaion

…Or how to add 5% to your company’s value for a tiny investment

The most comprehensive study yet conducted revealed company valuations (share prices) fall in the wake of a data breach. Amazingly, some then bounce back higher than before while others never recover. Read on to learn the fundamental difference between the two groups and how you can make sure your business is in the former…

The study: ‘The Impact of data breaches on reputation and share value’

We can all imagine the impact a data breach might have on the reputation and value on a business, but where’s the data? Well, it’s right here [‘The impact of data breaches on reputation and share value’ ].

Published in 2017 and still the definitive work on this subject, the Ponemon Institute looked at the impact on share prices of 113 publicly traded UK companies that had experienced a data breach involving the loss of customer or consumer data.

For the analysis they tracked a hypothetical portfolio of the 113 companies for the 30 days prior to and the 90 days after their data breaches were disclosed. The results are fascinating…

Data breach and valuation – the results you might have expected

The key takeout, hardly unsurprisingly, was that, on average, the companies suffered a significant decline in their stock market valuation immediately following the disclosure of their data breach. 

  • Specifically, the average fall in share price (or market valuation) in the immediate wake of their disclosures was 5%.
  • Thereafter, the price recovered and, on average, after 45 days returned to the pre-disclosure levels. 

This chart from the report shows the average performance:

impact of data breach on valuation

Chart from the Ponemon Institute report ‘The impact of data breaches on reputation and share value’ 

What the chart doesn’t show but the report offers insight into was the cost and disruption experienced in those businesses during that post-breach period, but that’s another story for another day.

In terms of market valuation, the bottom line so far is that a data breach, once disclosed, causes a significant drop in market valuation but, over an average of six to seven weeks, the valuation does return to pre-breach disclosure levels.

Probably no great surprises so far, but what came next when the Ponemon Institute dug deeper into the nature of the businesses that had been breached was fascinating…

Data breach and valuation – the unexpected twist

Whilst you might imagine how a company reacts to a data breach would have a big impact on the reaction of customers and markets – it does – the Ponemon Institute investigate what the companies who suffered the data breaches had done before their incidents.

Using a proprietary methodology, they assessed what they call the ‘security posture’ of the 113 businesses before they suffered their data breaches. In effect, they measured them on a series of criteria to evaluate how seriously they took cyber security. These measures include financial investment in cyber security training and technology, the presence of appropriate policies, evidence of external audit and vulnerability testing, board level responsibility and so on.

The 113 companies in the study were then divided into two groups depending on whether, overall, they were deemed to have had a ‘high security posture’ – ie they took cyber security seriously (57 of the 113) – or a ‘low security posture’ – i.e they didn’t take security seriously (56 of the 113) – before their breach.

The chart of the impact of the data breach on share price was then redrawn for each of these groups, as shown below:

Impact of data breach on valuation

Chart from the Ponemon Institute report ‘The impact of data breaches on reputation and share value’ 

The top line represents the ‘high security posture’ companies and the bottom line the ‘low security posture’ companies.

There are three very significant takeouts:

  1. The companies in the ‘low security posture’ group suffered a more significant drop in valuation in the immediate aftermath of their data breach than those in the ‘high security posture’ group. This extra drop was on average 4% more
  2. For the duration of the study, looking as far as 90 days after the breaches had been disclosed, the gap never closed and actually widened to an average of about 5%
  3. While the ‘low security posture’ companies never regained their original share valuations, on average, the ‘high security posture’ companies ended up with higher valuations than they had pre-breach disclosure. 

Huh? Say that again?

Let’s just run through that again.

The findings show that companies who failed to take cyber security seriously before suffering a data breach had a significant drop in valuation when they experienced a breach and their valuation never recovered to pre-breach levels. That’s probably not that surprising in itself.

But for companies that took cyber security seriously before they experienced a breach, not only did their valuations drop less, they recovered fully relatively quickly and ended up higher than they were before the breach was disclosed

That’s crazy, right? Well, maybe it isn’t…

Why these findings actually make perfect sense

I’d suggest that on reflection these findings are a lot less surprising than you might think at first glance. 

  • A company that took cyber security seriously before they experienced a data breach is much more likely to be able to get its operations back on track quickly. Preparation is everything and the actual impact of the breach is likely to be far less disruptive to their business
  • Likewise they likely were able to communicate with customers and stakeholders far more effectively if they had prepared for the worst in advance and had in place, for example, a rehearsed incident response plan. 
  • Data breaches have to be disclosed and that shines a light on company practices. When customers and stakeholders get to understand why a breach happened and whether good practice had been followed, they will judge the organisation accordingly. Customers are far less forgiving of businesses that lose their data when it looks like they didn’t even try to protect it than those who can demonstrate all the steps they had in place 
  • The world has grown up and understands that data breaches happen. Even with the best precautions, if enough resources are targeted at a business, it’s going to be a case of when, not if. What matters now is showing you have done all you reasonably could 

So whether you look at valuation from the perspective of the actual business or by the way it is perceived, a good security posture wins both ways. You are in a better place to respond and you will be seen to have done the right thing. 

How to add 5% to your company value

There are numerous reasons why a business should take cyber security seriously. But ignoring all of the others, adding 5% to the value of your business for a relatively small investment would be a pretty compelling business case in its own right, wouldn’t it?

Well, the conclusion of this study is clear: on average, a business that adopts good cyber security practices will boost its value by 5% over one that doesn’t if (when) they suffer a data breach.

How do you actually do it? Obviously that’s going to be different for everyone, but the key is to get started and make it a priority. That’s the first step. And how much will it cost? Probably a lot less than you think and certainly far, far less than the 5% of your company’s value that it will add. 

Here are some pointers:

  1. Make cyber security a board-level issue (See SME boards and cyber risk)
  2. Understand where you are – get an independent audit then develop a roadmap appropriate to your situation and measure progress (see Cyber Security Audit)
  3. Ensure your staff are aware and conditioned to spot threats (see Staff Awareness Training)
  4. Get accredited: eg. Cyber Essentials, Cyber Essentials Plus, ISO 27001 (see Cyber Essentials and Cyber Essentials Plus or ISO 27001 Certification)
  5. Ensure you have visibility of your environment (See SOC and SIEM monitoring solutions)
  6. Run independent penetration tests (simulated attacks) to find vulnerabilities (see Penetration Testing)
  7. Create and rehearse an incident response plan (including communications) (see When the s**t hits the fan)

For more guidance on your journey to a high cyber security posture, contact the team at Securious for a free consultation

So if we do the right thing, should we welcome a data breach?

Absolutely not. 

  • Suffering a data breach is a horrendous experience, no matter how well you are prepared. 
  • Suffering a data breach means that valuable, personal information, perhaps of your staff and customers, is likely to be revealed online with potentially devastating consequences for them. 
  • Suffering a data breach makes you more likely to be a target in the future 

The way to interpret this report is that, by doing the right things now, the long term impact on your business of a data breach will be far, far less severe than if you ignore them. Never, ever wish a data breach on your business. 

Final thoughts – adding 5% value to your business the easy way

Ok, cyber security isn’t easy. 

And it probably doesn’t seem as exciting as a new sales drive, marketing campaign or explainer video. 

But taking meaningful steps to show you take it seriously – to build that ‘high cyber security posture’ that makes all the difference should you experience a data breach – is not difficult and it is not expensive. 

Most importantly, it requires a recognition of good cyber security as a core priority throughout the business and action to demonstrate progress.

If you’re ready to take the next step and start adding value to your company, the team at Securious is ready to guide you on your journey and support you all the way. Fill in the form below, send us an email to info@securious.co.uk or call 01392 247 110.