
According to a new survey, cyberbreaches cost British businesses up to £374mn in losses during 2021.
The national survey, conducted by governance company Diligent, of 450 senior finance and risk professionals in UK-listed businesses indicates that the reported losses were mainly due to cyberbreaches caused by staff having to work from home.
The survey also shows that the lack of strategies associated with Environmental, Social, and Governance (ESG), and complex regulatory landscape are chief concerns for businesses.
An example of some of the results from the survey below give an indication of the challenges UK risk professionals view their organisations as having to face in 2022:
Cyberbreaches and risks from working from home
- 64% of surveyed companies claim they have been victims of a cyber attack or data breach in the last 18 months.
- 82% of those who reported a breach stated that it was the result of tech issues or behaviour related to working from home.
- 75% claim their organisation lost money/revenue − totalling £374m − as a result of a breach.
Concerns ESG is just a box-ticking exercise
- 40% of risk professionals see the ESG strategy currently in place at their organisations as a box-ticking exercise, rather than a strategy designed to have a real impact.
- 56% claim their companies’ ESG strategies don’t support their wider GRC goals.
- Some say there is a clear lack of ownership in regards to setting and leading ESG goals, with 42% arguing responsibility lies with GRC/risk teams, 40% saying the investor relations team, and 375 with the communications department.
Top risks in 2022
- 85% of companies are worried about abiding by changing regulatory requirements in 2022.
- There are multiple concerns with geopolitics with 32% concerned about tension within international politics being the macro risk, followed by inflation at 31% and shareholder activism−30%.
- There are also concerns regarding workforce turnover, with the top operational risk for businesses being human capital (21%).
The survey obtained responses from 450 chief risk officers, heads of risk, chief financial officers, finance directors, chief information security officers and chief information officers based in the UK in November 2021.
“UK PLCs fielded an incredible number of challenges over the last 18 months, and our research shows that leaders are wary of evolving risks moving into 2022,” said Dan Zitting, Chief Product and Strategy Officer of Diligent.
“From cyber-attacks to ESG and regulatory compliance, businesses need to better understand and incorporate risk into their long-term planning to ensure a sustainable future.
“Technology will play a crucial role by painting a complete picture of risk and enabling decision-makers to monitor and mitigate risk quickly and efficiently. This builds resiliency into organizations and drives confidence among stakeholders.”









