Investors grapple with cyber risk

Fund managers understand that cybersecurity is one of the biggest threats to banks. They don’t yet have the tools to properly assess it. But if the data drought were to end, cyber-strategies could become an integral part of their investment decisions

IN ADDITION


The chief executive of one of Europe’s biggest retail banks, one that has invested heavily in its digital platforms, is outlining what he perceives as the biggest risks to his business. He’s mentioned political risk and conduct risk. Then he pauses, takes a deep breath and tells Euromoney: “But the biggest risk of all is probably a cyberattack.”

So, we suggest, this must now be a regular source of discussion in your regular meetings with investors. “No,” he fires back immediately. “I can’t recall a single institution who has ever asked me about our cybersecurity policies.”

There is a clear disconnect here. The 1,200 risk experts in more than 50 countries that contribute to Allianz’s annual Risk Barometer rank cybersecurity as the third greatest threat facing companies, ahead of natural disasters. It is also ranked as the top future peril. In a report sponsored by Herjavec Group, the global annual cost of cybercrime was predicted to rise from $400 billion in 2015 to $6 trillion by 2021. That is equivalent to the combined GDP of France and Germany. 

The problem for fund managers trying to factor cyber-risks into their investment decisions is that the threat from cyberattacks is relatively new: there is not a lot of history to study and the risk is not readily quantifiable. 

heart5

Asset managers like data. It is what they understand and how they make investment decisions. Currently it is sparse in cyber; companies do not generally say if they have been attacked, and that makes the measuring, modelling and hedging of cyber-risk based on past performance all but impossible. 

Fund managers are well aware of its importance, however. In 2015, UK fund manager Legal & General Investment Management (LGIM) called for compulsory cyber audits to be introduced to ensure companies can protect themselves from attack. LGIM said it wanted companies to identify and monitor information assets as a strategic issue; document the management of the risk through an audit; and make sure awareness of cyber-risk was embedded in the culture of the company.

“Cybersecurity is a significant risk to our investee companies,” said David Patt, then senior analyst for corporate governance and public policy at LGIM. “It is incumbent on us to discuss how company boards are managing cybersecurity and their digital infrastructure throughout the corporate year. We are concerned that many responses we receive to this major corporate risk are insufficient. Boards need to be more aware of their operational environment and emerging threats to their business. Simply put, it can affect a company’s value.”

Tesco-R-780px
The most prominent case in UK banking of a cyberattack was in 2016. Tesco Bank repaid £2.5 million of losses to around 9,000 customers 

More recently, a group of 53 institutional investors, representing $12 trillion in assets under management, have banded together under the auspices of the UN’s Principles for Responsible Investment (PRI) to tackle the issue. It is the biggest task the PRI has undertaken. 

Vaishnavi Ravishankar, coordinator of the project at the PRI, says: “It is still in its early stages. There are 60 companies being targeted in the consumer, healthcare and financial sectors. We decided to focus on these sectors because they have different types of sensitivities and approaches. The financial sector is obviously the biggest target for cybercriminals.”

Ravishankar sums up succinctly the current state of how cybersecurity is perceived and managed. For fund management companies, it is typically delegated to the environmental, social and governance (ESG) team. The two big credit ratings agencies, Moody’s and Standard & Poor’s, point to their bank analysts when approached about this topic. 

This does not belittle the efforts of those analysts. Cybersecurity is a risk that needs to be assessed somewhere, but it shows that for many it is still hard to define. The focus on banks makes sense. Most cybercriminals want money. In 2016, according to a report by IBM, banks were attacked 65% more than any other sector, resulting in 200 million records being breached. Giles Edwards, senior director, financial services ratings at S&P in London, says it is a big risk. However, it has not so far led to any direct ratings actions. 

He notes that banks have proved remarkably resilient, so far at least. “To date, the issues we have seen have been short-lived and have not led to an obvious competitive disadvantage or more deep-seated concerns. We have privileged access as a credit rating agency and it is obvious our ratings matter to banks. But it is far easier to assess the things we are used to assessing, such as balance-sheet strength. It is still far from easy to say whether bank A is better than bank B at cybersecurity,” says Edwards. 

The rating agencies treat cybersecurity both as a continuing risk and discrete event. Effie Tsotsani, analyst at Moody’s Investors Service, says: “Our fundamental credit analysis incorporates numerous stress-testing scenarios, and a cyberevent could be the trigger for those stress scenarios. 

“During the credit assessment, we also place particular emphasis on risk governance and cyber readiness, along with any track record of control failures. Ratings may also include additional factors such as information technology and infrastructure risks, which are more difficult to quantify and have a meaningful effect in differentiating credit quality only in some cases but not all.” 

At what cost?

The biggest immediate costs of cybercrime are typically theft or business interruption. AP Moller-Maersk, the global shipping company, and Merck, the US pharmaceutical firm, both pointed to the NotPetya attack last June for missing earnings estimates. 

Merck blamed NotPetya for losing $375 million in the third quarter, including $280 million in sales from not being able to supply a vaccine to the US Centers for Disease Control and Prevention. Maersk blamed the cyberattack for between $250 million and $300 million in lost sales. 

There are other generally less harmful costs such as investigation, patching systems and customer notification. But the longer-term effect of data loss on reputation and customer trust are harder to quantify. Yahoo’s data loss in 2013 caused Verizon to cut the price of its acquisition by $350 million, but because Yahoo effectively ceased to exist, how customers would have reacted is unknowable. 

While it is too early to make any meaningful comment on how Facebook might be affected by the Cambridge Analytica scandal, the former’s share price was down 19% at one point after it emerged that the latter had used data on 50 million users to target voters in the US presidential election in 2016. Some high-profile users have chosen to close their accounts, but that does not mean the rest of world will fall out of love with photographing their supper or being liked.

“There’s no such thing as mastering this and saying: ‘We’ve got it cracked’. That would be naive and foolhardy in the extreme.” – Andy Mason, Aberdeen Standard Investments

Litigation expenses and regulatory fines could make the losses at Maersk and Merck seem unimportant. Rosa van den Beemt, head of ESG analysis at Canadian socially responsible investment specialist NEI Investment, draws a chilling parallel: “A business with a consumer focus holding a significant amount of data that is then compromised seems to me to be in a similar situation to an energy company that has an oil spill. We know how damaging that can be, and it is only a matter of time that we see the cost in a cyberattack.”

Deepwater Horizon is estimated to have cost up to $20 billion. There has been nothing comparable, yet, in the cyberworld. At S&P, Edwards does not rule out a cyberattack causing a credit event, although he is quick to add it is not something he is predicting. 

“There could be an event which led to significant short-term loss and serious long-term reputational damage,” he says. “That is certainly a possibility. But the context is important too. If it was an industry-wide, systemic issue, then customers might be forgiving and governments may have to step in.” 

The most prominent case in UK banking of a cyberattack was in 2016. Tesco Bank repaid £2.5 million of losses to around 9,000 customers. But it is a small business in terms of UK bank market share. But a big loss at an individual big bank would likely have catastrophic consequences for that institution far beyond immediate losses or future compensation claims. Banks, fundamentally, must maintain their reputation as safe custodians of their customers’ money. Lose that and they lose their entire business. 

Valuable engagement

For now, the best data is what can be got from companies directly through engagement. And, despite what European bank chief executives say, some investors are trying to start a conversation. Felipe Gordillo, senior ESG analyst at BNP Paribas Asset Management, which has €569 billion in AuM, sees cybersecurity in two spheres: governance and social. For good governance, he wants to see board-level responsibility and clear plans of action in the event of an attack. The social aspect reflects how customers may react to data loss. 

“When we first started looking at this there was a lack of transparency, so it was difficult to assess,” says Gordillo. “Two years ago, the typical reaction of companies was to say: ‘We are planning, we are dealing with it, but we don’t want to disclose information as hackers will use the information against us’. Now the conversation has moved on and it is a board-level issue and there is much greater transparency about dealing with the cybersecurity challenge.” 

That engagement is important because the threat is always evolving. At Aberdeen Standard Investments, Europe’s largest active manager with $807 billion in AuM, analyst Andy Mason, straddles ESG and banks. 

“There is no such thing as mastering this and saying: ‘We’ve got it cracked’,” he says. “That would be naive and foolhardy in the extreme to boast about. So, what you want to see is processes, board involvement, investment and engagement. We want as much information as we can get. Through initiatives such as the PRI and simply by being asked, companies are slowly getting more comfortable about disclosing this information.” 

That engagement is yielding valuable insights for asset managers. Mason thinks an in-depth analysis of cyber security can reveal much about corporate culture more broadly. “I think of this in terms of operating expenditure and capital expenditure,” he says. “Anyone can buy a flash bit of kit with capex and say: ‘We’ve got this problem solved’, which is never true. But if the operating expenses are being constantly driven down, and many companies see this as badge of honour, the chances are vulnerabilities are being introduced via the back door. WannaCry came from not updating Windows.” 

It is this sort of granular analysis that fund managers hope will allow them to identify cyber-risks to their portfolios. ESG is not a woolly, nice to have add-on for most active asset managers. It is integral to differentiating active management from passive and indexed investing, which through exchange-traded funds and institutional indexing are stealing the majority of fund flows. 

Merck-R-780px
Merck blamed the NoPetya attack for losses totalling $375 million in the third quarter of 2017 

Sébastien Thévoux-Chabuel is head of ESG at Comgest, an independent Paris-based manager running $34 billion in high conviction equities. He does not care whether cyber-risk is regarded as an ESG factor or not. “It is a risk, a material investment risk, and by examining and understanding risk you become a better fund manager,” he says. “Cybersecurity is fascinating because it reveals so much about how a company is managed. If we can be at the forefront of this, I believe it does make a difference to portfolios.”

David Sneyd, senior associate, governance and sustainable investment at BMO Global Asset Management (EMEA), explains: “This is not simply about sudden massive profit warnings, like Maersk or Merck, but the slow erosion of competitiveness and market share through reputational damage.”

In May, the General Data Protection Regulation (GDPR) becomes law throughout the European Union. A company that loses customer data can be fined up to 4% of its global revenues, or €20 million, whichever is higher. GDPR is getting fund managers and analysts excited because it will offer disclosure – regular and uniform data on cyberattacks. Most believe that this will reveal companies are under constant threat. For analysts like Thévoux-Chabuel and Aberdeen’s Mason, it is a move along the road to providing the sort of data they want and are used to interpreting.

“Incorporating cyber-risk in our credit analysis consistently and transparently across all sectors and regions can be challenging,” says Moody’s Tsotsani. “The introduction of the GDPR will enable a more uniform comparison amongst European entities due to consistent reporting and disclosure of related risks to the authorities. Furthermore, we expect the strengthening regulatory standards to be a key driver for improving risk governance.”

Thévoux-Chabuel believes the fact that GDPR will force companies to show their hands, will mark a watershed in disclosure: “I still have to sign NDAs [non-disclosure agreements] in approximately 20% of cases. I think companies worry they are revealing dirty secrets. That won’t be the case when GDPR comes. It will normalize disclosure and everyone will see that, in fact, they do not face unique or more terrifying threats.” 

“If any CEO told me they were 100% confident that their cybersecurity could defeat any threat, I would laugh” – Sébastien Thévoux-Chabuel, Comgest

GDPR has also put a number on cyber-risk that investors can see is material. As Henk Grootveld, head of the trends investing equity team at Robeco, says: “People used to think that even if investors were worried about cyber-risk, they couldn’t measure it – especially that reputational risk element. But GDPR has changed that – at least insofar as it has put a number on part of the potential cost. It is a wake-up call for investors – the fine of 4% of global turnover is material in their eyes and it is a risk you face that they now take into account even if you do not think you will ever be hit with that 4% fine.”

Data and engagement seem to be the big prizes asset managers are seeking at the moment, which will allow them to get deeper knowledge of the materiality of threats. Aberdeen’s Mason can also see a time when intense technical work will also be applied in this sphere.

“I’m a banks analyst with an ESG role as well, so I’d like to think I do a very good job assessing these risks with the information currently available,” he says. “But I’m not an expert programmer, so I take a view on best practice and governance. I don’t know the intricacies of the latest first line of defence. But I suspect that fund managers will evolve those skills as well as it becomes ever more apparent how important this issue is.”

In the absence of those skills, at least one investor spoken to by Euromoney has hired its own ethical hacker to help it understand the issues and to investigate investee companies. Others go in almost the opposite direction and treat cybersecurity as a governance issue. Without detailed cyber-disclosure, they simply use the company’s existing governance record as a proxy: if your overall governance is poor, they assume your cybersecurity is too. 

The classic example is Tesco. A raft of financial irregularities, senior members of the finance team in court, outcry over the treatment of suppliers, problems of Payment Card Industry Data Security Standard compliance in its online shopping website and then the Tesco Bank hack. 

Know thine enemy

However, it is true that a deeper technical knowledge and understanding could become critical. It is not just criminals after material gain that are exploiting cyber vulnerabilities. ‘Hacktivists’ such as LulzSec have targeted governments, companies and media organizations that they disapprove of. But the biggest emerging threat is state-sponsored cyberattacks.

China, Iran, North Korea and Russia are among the states known to be engaged in so called asymmetric warfare on the internet. Some experts believe North Korea is using cyberwarfare not just for political purposes but as a profit centre, designed to bring foreign currency into the country. The Shadow Brokers group, which last year released a gigabyte of data on the US National Security Agency’s weaponized ‘exploits’ (hacking tools) targeting the Windows operating system, is widely believed to be a proxy for the Russian intelligence services. 

Stephen Bonner, a partner in Deloitte’s cyber-risk services team, argues that the involvement of states in cyberattacks dramatically changes the nature and severity of the threat: “Organized crime is akin to a parasite. It doesn’t want to kill its host. It wants to continue to feed off it. A state might want to cause real harm to a company to make a political point. They may pose an existential threat.”

It is a chilling thought. But probably not one people will take seriously until it happens. And even if you had 100% certainty such an outcome was inevitable, how could you manage the risk that a company you have invested in would not be the victim? 

It is an unanswerable question because geopolitical events are generally unpredictable. Is a manufacturer of cluster bombs a more likely target than a bank rigidly upholding financial sanctions or a utility supplying electricity to an important city? Even if you knew the answer to the first question, it is clear investors are also only beginning to get to grips with what good, rather than bad, cybersecurity looks like.

“Organized crime is akin to a parasite. It doesn’t want to kill its host. It wants to continue to feed off it.” – Stephen Bonner, Deloitte

For now, they are on an information hunt, hoping that it can be regularized into the sort of data they are used to dealing with. “I think the traffic in information is both ways,” says Deloitte’s Bonner. “We’ve moved from a world where the question was how do you stop these attacks to how do you manage and respond to them when it happens? Because it will happen and I’m sure GDPR will reveal this. It is about detection, management and recovery. Those are legitimate questions for investors to ask, and good for companies too, because it forces them to think how robust their answers are.” 

For the time being, just as the credit rating agencies are not upgrading or downgrading banks on the basis of cybersecurity, it is not an active driver of portfolio decision making. At some firms, ESG analysts can put in place hard bars on stocks, particularly for retail funds with particular ethical criteria or segregated mandates for religious bodies, for example. 

That is true at NEI. But van den Beemt says this still does not apply to cybersecurity. “Obviously, most investment processes are driven by both quantitative and qualitative inputs, but with this issue we are still dealing with the highly qualitative,” she says. “That is slowly changing. But we would not exclude a company from any portfolio on our assessment of the robustness or otherwise of their cybersecurity. We are still at the development stage of understanding what these issues are.” 

For other fund managers, such as Paris-based Comgest, ESG is more of an advisory function. Given the lack of hard data, bottom-up qualitative work may still be the best way forward for investors looking for an information edge. Cybersecurity concerns may not be driving stock selection, but for some it is becoming integral to fundamental analysis. 

It is also keeping better-informed fund managers awake at night. “Frankly, if any CEO told me they were 100% confident that their cybersecurity could defeat any threat, I would laugh,” says Comgest’s Thévoux-Chabuel. “I can definitely see scenarios in which a cyberattack financially cripples a company. In some ways, I am surprised it hasn’t happened yet. At this point you cannot base a decision on whether to invest or not on cybersecurity and whether you think it is good, bad or indifferent. It’s a piece of the puzzle, but a piece that didn’t exist a few years ago.”

 

Short sellers sniff opportunity

It sounds like a plot dreamt up by a thriller writer. In 2016, a US short-selling hedge fund and research fi rm, Muddy Waters, sent out a note that claimed that the pacemakers of St Jude Medical were vulnerable to cyberattack. The incendiary nature of the report and the (literally) existential nature of the alleged threat saw the group’s stock price fall by 10.4% on the day the allegation was made.

The claims and counter claims are now subject to legal proceedings in the US. But outlandish and macabre as it sounds, medical devices such as pacemakers and insulin pumps have emerged as a matter of mainstream concern for cybersecurity researchers.

The US Food and Drug Administration, the regulator, spoke at Def Con, the annual hackers’ conference in Las Vegas in August 2017. It urged medical devices companies to take cyberthreats seriously and work with so-called ‘white-hat’ hackers to better manage vulnerabilities. An insulin pump, for example, could deliver a fatal dose or a pacemaker could be switched off. Many devices are currently connected to the internet without any form of encryption.

This is not a theoretical threat dreamt up to sell books or line the pockets of short sellers by causing sharp share-price movements. As well as seriously disrupting the UK’s National Health Service, last year’s WannaCry ransomware attack temporarily disabled some radiology equipment made by Bayer.

Most investors are not even close to making perceived cyber vulnerability or strength a reason to invest or not. Short selling based on this assessment is even further down the agenda. But the legal battle between Muddy Waters and St Jude Medical shows how publicly pointing to cyber vulnerability can move share prices and make short sellers a handsome, if perhaps ethically questionable, profit.