• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Current price of oil as of June 15, 2026

2

Current price of silver as of Monday, June 15, 2026

3

Meet Gwynne Shotwell, the engineer-turned-COO who runs SpaceX in platform heels and is now worth over $2 billion

1

Current price of oil as of June 15, 2026

2

Current price of silver as of Monday, June 15, 2026

3

Meet Gwynne Shotwell, the engineer-turned-COO who runs SpaceX in platform heels and is now worth over $2 billion
CommentaryCybersecurity

Does Facebook Have a Cyberattack Plan? If So, We Need to See It

By
Bugra M. Gezer
Bugra M. Gezer
and
Shiva Rajgopal
Shiva Rajgopal
Down Arrow Button Icon
By
Bugra M. Gezer
Bugra M. Gezer
and
Shiva Rajgopal
Shiva Rajgopal
Down Arrow Button Icon
October 4, 2018, 1:49 PM ET
Add Fortune on Google for similar content.

Last week, a cyberattack on Facebook compromised the accounts of 50 million users—one of the most significant cybersecurity lapses in the company’s history. As a result, Facebook’s stock fell by over 5% in three days.

How do investors assess the cash flow implications of such an attack? They look at what companies disclose about these threats, which is next to nothing.

When you look at Facebook’s latest 10-K (a report summarizing a company’s financial condition), for example, the word “cyber-attack” appears only four times, and almost all of the disclosures related to Facebook’s vulnerability and readiness for such an attack are boilerplate and uninformative.

While the Securities and Exchange Commission earlier this year issued guidance “to assist public companies in preparing disclosures about cybersecurity risks and incidents,” we believe these guidelines do not go far enough. The SEC should require public companies to disclose the following data points:

  • Company policy on cybersecurity and the implementation of that policy. Commentary on the company’s general approach toward cybersecurity would provide insights into the riskiness of the company, based on what it tells us and what it chooses to stay silent about.
  • Information technology (IT) infrastructure. It is imperative to ask a company to clearly disclose the nature of its IT infrastructure. For example, is the infrastructure located on the company’s premises, or is it outsourced? And what is the dollar budget devoted to that infrastructure? The budget, as compared to the total revenue of a business, will give investors a sense for whether the firm under-invests in such infrastructure. We recommend disclosure on both hardware and software spending for the business, including data on personnel and training, and specific disclosure of the cybersecurity budget. If any material portion of the IT infrastructure is outsourced, the company should disclose the vendors and provide an outline of the services provided by such vendors. The idea is to be able to create comparable ratios in industries to identify companies that under-invest in this area. Disclosure on cybersecurity training is especially important, because 90% of cyberattacks exploit preventable human mistakes.
  • The daily value of business interruption. If an automotive company produces 120,000 cars per year and the revenue per car is $10,000, the daily revenue lost by a cyberattack to its factory that relies heavily in robotics would be around $3.3 million. Skeptics might wonder whether revealing this would represent an open invitation to hackers to go after a company. We counter-argue that hackers are already aware of high-value targets. Better disclosures about, at least, the ranges of daily value of business interruption would reduce investors’ estimation risk associated with evaluating the cash flow loss from an attack.
  • Continuity planning. A continuity plan identifies all of the critical information an organization needs to continue operating during an unplanned event, such as a cyberattack or natural disaster. The plan then identifies systems and processes that must be sustained and details how the company plans to keep these going.

What stops companies from being more forthcoming about their exposure to cyber risk? One answer, of course, is the fear of litigation. We propose that the SEC follow the precedent set in this regard by the Year 2000 (Y2K) Information and Readiness Disclosure Act, which read, in part, as follows:

“In enacting this legislation, Congress found that (i) the Year 2000 computer problem, if not effectively addressed, could severely adversely affect the Nation’s economy and critical infrastructure, and (ii) concern about liability arising from disclosure and exchange of Year 2000 information is impeding the ability of both government and the private sector to address the Year 2000 problem. The Act’s purpose is to create a safe harbor for the disclosure and exchange of Year 2000 information by (i) limiting liability in civil actions for such disclosure and exchange of information, and (ii) creating a temporary and narrowly tailored exemption from federal and state antitrust laws for such disclosure and exchange of information.”

Simply replacing references to the Year 2000 problem with cyberattacks would encourage companies to more willingly share information with investors about cyber exposure so that systemic risk could be detected and addressed in a timely manner.

For instance, Amazon Web Services (AWS) is clearly a systemic risk. But we currently have no idea how many public (and private companies) are hooked into AWS, and what the cumulative dollar value of business interruption for companies reliant on AWS might be. A vulnerable API from a relatively small startup company on AWS has the potential to bring down electronic commerce in a large part of our economy.

Voluntary disclosure about cyber exposure is clearly not working. It is time for the SEC to step in and mandate dollar disclosures related to cyber risk exposure. Our financial security depends on it.

Bugra M. Gezer is the founder and CEO of Cyber Rate. Shiva Rajgopal is the Kester and Byrnes professor at Columbia Business School, and a Chazen senior scholar at the Jerome A. Chazen Institute for Global Business.

About the Authors
By Bugra M. Gezer
See full bioRight Arrow Button Icon
By Shiva Rajgopal
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

cj
CommentaryIBM
IBM’s $17 million DOJ settlement makes the case for civility
By Carolynn JohnsonJune 16, 2026
3 hours ago
Vietnam has bold plans for its economic future. It will need U.S. tech, capital, and speed to make them happen
CommentaryVietnam
Vietnam has bold plans for its economic future. It will need U.S. tech, capital, and speed to make them happen
By Brian McFeeters and Vu Tu ThanhJune 14, 2026
2 days ago
ivan
CommentaryMidwest
The Sun Belt boom is over. Midwest real-estate investors say ‘I told you so’
By Ivan BarrattJune 14, 2026
2 days ago
t
CommentaryTariffs
A quartz countertop tariff could double your kitchen renovation cost — and kill 13 jobs for every one it creates
By Steve SwedbergJune 14, 2026
2 days ago
nexstar
CommentaryAntitrust
Nexstar CEO: big tech swallowed local newspapers. Local TV could be next
By Perry A. SookJune 14, 2026
2 days ago
ravi
CommentaryWeather and forecasting
I spent 8 years flood-proofing a city. Capital markets are running out of time to take El Niño seriously
By Ravi S. BhallaJune 13, 2026
3 days ago

Most Popular

Current price of oil as of June 15, 2026
Personal Finance
Current price of oil as of June 15, 2026
By Joseph HostetlerJune 15, 2026
1 day ago
Current price of silver as of Monday, June 15, 2026
Personal Finance
Current price of silver as of Monday, June 15, 2026
By Joseph HostetlerJune 15, 2026
1 day ago
Meet Gwynne Shotwell, the engineer-turned-COO who runs SpaceX in platform heels and is now worth over $2 billion
Startups & Venture
Meet Gwynne Shotwell, the engineer-turned-COO who runs SpaceX in platform heels and is now worth over $2 billion
By Eva RoytburgJune 15, 2026
1 day ago
Hundreds of Stanford students walked out of their grad ceremony to protest Google CEO’s commencement speech. It wasn’t all about AI
Big Tech
Hundreds of Stanford students walked out of their grad ceremony to protest Google CEO’s commencement speech. It wasn’t all about AI
By Tristan BoveJune 15, 2026
21 hours ago
Boomers actually do hold most of the wealth and power. So why do they call it 'whiny' to point that out?
Economy
Boomers actually do hold most of the wealth and power. So why do they call it 'whiny' to point that out?
By Nick LichtenbergJune 14, 2026
2 days ago
Team USA star Ricardo Pepi grew up in a trailer in El Paso—and his parents pawned their car title to fuel his soccer dream. Now, he’s in the World Cup
Success
Team USA star Ricardo Pepi grew up in a trailer in El Paso—and his parents pawned their car title to fuel his soccer dream. Now, he’s in the World Cup
By Preston ForeJune 15, 2026
22 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.