Friday, June 12, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Cyberlaw Data Security Security Bloggers Network Threats & Breaches 

Home » Cybersecurity » Cyberlaw » Why Cybersecurity Needs to be a Part of Your ESG

SBN

Why Cybersecurity Needs to be a Part of Your ESG

by Nik Hewitt on August 9, 2022

What is an ESG?

Environmental, social, and corporate governance (ESG) documentation is a way to visualize and evaluate how an organization is working for the betterment of social goals and how that organization is responding to the cry for greener, more aware, and more responsible, sustainable investing. The ESG looks at how the organization responds to the community and our environment, and how they embrace the call for a more health-conscious workplace.

An integral part of modern accountability is cybersecurity. Organizations can’t rely on cyber insurance to dig them out of an inevitable problem but must (be seen to) be proactively protecting and securing their users, staff, and supply chain data. Cybersecurity, and regional compliance, are for the betterment of social goals – and as such, they should now be included in any company ESG.

The call for business transparency

According to Deloitte, 65% of survey respondents say they want to buy from purpose-driven brands and services that advocate sustainability. Customers are looking towards the likes of ethical banking, and ESG reporting has become a requirement by investors, directors, and other stakeholders in financial services and fintech companies – where software and applications are being created to automate and improve the financial trading and transactions for organizations and their consumers.

The same is true of government agencies, energy, and public utility companies, as there is a greater call to be more transparent about their ESG efforts as the topic of renewable energy, ethics, community support, data protection, and public safety have become common news headlines in the last decade. When ransomware attacks on oil pipelines and malicious attacks on water pumping stations hit the news, customers and investors become quickly aware of the need for organizations to take responsibility for the protection of their potential cyber vulnerabilities.

Sectors such as technology and retail, especially online retail, are taking notice. 50% of C-level executives who work in the fashion and textile industry say consumer demand has moved their business to source more sustainable materials, and to create more ethical products. Shareholders are aware that consumers are more attracted to brands with sustainable practices and products.

People are also justifiably shy of sharing their data, and naturally protective of their personal information. A company that can wear its security credentials with pride, as part of their public or private ESG, is far easier to trust and eminently more socially responsible than one that does not.

A growing number of customers want to spend their money with businesses that are part of their community, are inclusive, and fight gender and racial bias in the workplace. Businesses need to offer a green alternative, be shown to genuinely care about their customers, and guarantee the confidentiality and integrity of their personal data. Investors want to invest in organizations that champion social justice, commit to regional data standards, and produce safe and sympathetic products while still maintaining a competitive price. These are the businesses that will stand out in the marketplace of the future.

Environmental, social, and corporate governance through cybersecurity

“A lack of data protection is a threat to society.” I’ve read this sentence to myself several times, thinking at first this might be overly dramatic and untrue. It is, I believe, a fact. In a world where government leaders are calling on businesses of all sizes to protect their most valuable asset – data – not doing so is ignoring best practices and skirting around social responsibilities.

Any data breach can have a significant impact on people, organizations, partners, investors, the supply chain, and communities. The knock-on effect of a data breach or cybersecurity incident has the potential to impact a large number of people. Not protecting organizational data to the best of a business’s ability, in the modern age, is considered careless – even litigious. A cybersecurity breach can also impact an individual’s well-being. Mentally, physically, and financially, impacting their personal reputation. Non-inclusion of (at least) the very basics of a business data protection policy in an ESG is now an obvious omission.

News sites regularly document attacks by bad actors targeting healthcare institutions, such as the WannaCry ransomware attack, which jeopardized patient care when it targeted Britain’s National Health Service (NHS). Such media documented and mainstream attacks are making the general public more aware of the rising threat landscape. As a result, there is a clear demand for transparency around organizational use and the protection of confidential data. Trust between an organization and its customers, employees, and third parties, is more important than ever.

ESG cybersecurity best practices

As a part of an organization’s ESG, it will be the cybersecurity team leader’s responsibility to document current practices and to address issues of concern with solid and quantifiable security solutions. The days of enterprises simply declaring “We have cybersecurity insurance” are over. Where applicable, organizations might consider addressing additions to the following aspects of their data management plan.

Stating regulatory compliance with regional requirements (e.g., GDPR, CCPA, POPI, Australia’s Privacy Act, PIPEDA, or GLBA) shows a willingness to meet best practices and is a publicly expected set of standards. Mentioning compliance in an organization’s ESG is a common business practice that offers reassurance that they are managing sensitive data responsibly and in line with state and government regulations.

If organizations provide general awareness training for staff, such as against phishing attacks or for best security practices, this is something worth documenting. Making staff familiar with the dangers of clicking on untrusted links, opening unsolicited emails, and interacting online are fundamental components of cybersecurity awareness. Over two-thirds of organizations train employees in cybersecurity best practices, and showing a proactive approach to employee education and accountability is an essential part of business readiness.

While it’s not essential to provide specifics, for obvious security reasons, if an organization is able to say that they are protecting data from malicious or accidental damage and can quickly restore data in the event of damage or loss through having a disaster recovery plan in place already, this is worthy of mentioning. Being cognizant of ransomware practices and the basics of how the organization is actively mitigating against them is information that an organization should be proud to announce in its ESG documentation.

Organizations need to be seen to be preventing employees from becoming insider threats by considering the restriction of access rights for users, accounts, and activity to only those resources needed to conduct legitimate activities. Having Data User Behaviour Analytics in place can also be a convincing part of any public data security documentation. Any data breach can come from within, often unintentionally, and a motivated security-first approach to this is worthy of illustration.

Show how you are protecting your customers’ data by creating a list of your current threat protection assets and how they support others. Document how, without going into too much detail, the organization is securing a user’s personal information, guaranteeing safe transactions, and preventing the likes of account takeover. If you utilize a WAF to prevent web attacks, or real-time attack detection and prevention from your application runtime environment to protect against nefarious supply chain code, mention them here. If you can say that your API endpoints are protected (as they are published) and shield your applications and users from zero-day exploitation, this is a strong testimony of responsible cybersecurity practices. The ability to detail that a business has control over third-party JavaScript code – preventing client-side attacks, reducing the chance of supply chain fraud, and mitigating data breaches – shows that an organization genuinely cares about its social responsibilities and that its ESG is more than just a box-ticking exercise.

Organizational standouts

An organization should consider how they responsibly respond to the new threat landscape. What difference will your cybersecurity posture make to the end user, your staff, to your investors and shareholders, and to those who engage with your business?

Ask what else you do that helps you stand out from your competitors. Do you conduct red team exercises? Do you have a forward-thinking security team training program? Can you, perhaps, showcase individual team experts or cybersecurity champions? How have you invested your budget for the betterment of all concerned?

As an extra element, how are you considering the environment in your day-to-day data practices? Do you use solar power or a green energy supplier? Are you carbon offsetting servers, using sustainable cloud services (like AWS), or do you recycle outdated computer equipment? While these may not be directly related to day-to-day cybersecurity, they still make great support content for any ESG.

For most organizations, showcasing environmental, social, and corporate governance (ESG) is now standard, and supporting the organization’s marketing function with ongoing documentation for stakeholder-facing evidence and credentials is something the CISOs of the future will have to embrace.

The post Why Cybersecurity Needs to be a Part of Your ESG appeared first on Blog.

*** This is a Security Bloggers Network syndicated blog from Blog authored by Nik Hewitt. Read the original post at: https://www.imperva.com/blog/why-cybersecurity-needs-to-be-a-part-of-your-esg/

August 9, 2022August 9, 2022 Nik Hewitt account takeover, CISOs, cyber insurance, Data Security, Digest, ESG Documentation, insider threats, Ransomware
  • ← GoNoGo Checks Kubernetes Add-ons Before an Upgrade
  • A Compilation of Publicly Accessible URLs Found on Cyber Jihad Forums – Part Six – An OSINT Analysis →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
The Cost of Exposure: Managing the Operational Risks of Executive Security Incidents
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

1 week ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

2 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

2 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

4 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Ex-IBM Exec Accuses Big Blue and AT&T of Covering Up Foreign Data Breaches
Google Patches 429 Chrome Vulnerabilities in Major Browser Update
Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
ShinyHunters Secret to Success: Breaking the Trust Barrier
8 Self-Evolving Skills Hermes Agent Writes on Its Own
8 Claude Code Alternatives Compared (2026)
9 Open-Source AI Coding Agents Worth Self-Hosting
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
ServiceNow Breach Explained: API Exposure, Risks & Security

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Incident Response Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Vulnerabilities 

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances

June 11, 2026 Jeffrey Burt | Yesterday 0
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
AI and ML in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Zero-Trust 

Zscaler Launches Industry-First Zero Trust Security for Agentic AI

June 10, 2026 Jon Swartz | 2 days ago 0
Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Vulnerabilities 

Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours

June 9, 2026 Jeffrey Burt | 3 days ago 0

Security Humor

Randall Munroe’s XKCD 'Husband and Wife'

Randall Munroe’s XKCD ‘Husband and Wife’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
7 Must-Read eBooks for Security Professionals
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.