Industry Comparison
Select Language
Current language: English (2023)
You are viewing information about the following Industries:
-
Software & IT Services
The Software & Information Technology (IT) Services industry offers products and services globally to retail, business and government customers, and includes entities that develop and sell applications software, infrastructure software and middleware. The industry generally is competitive but with dominant players in some segments. Although relatively immature, the industry is characterised by high-growth entities that place a heavy emphasis on innovation and depend on human and intellectual capital. The industry also includes IT services entities delivering specialised IT functions, such as consulting and outsourced services. New industry business models include cloud computing, software as a service, virtualisation, machine-to-machine communication, big data analysis and machine learning. Additionally, brand value is important for entities in the industry to scale and achieve network effects, whereby wide adoption of a particular software product may result in self-perpetuating growth in sales. -
Telecommunication Services
Telecommunication Services industry entities provide a range of services from wireless and wireline telecommunications to cable and satellite services. The wireless services segment provides direct communication through radio-based cellular networks and operates and maintains the associated switching and transmission facilities. The wireline segment provides local and long-distance voice communication via the Public Switched Telephone Network. Wireline carriers also offer voice over internet protocol (VoIP) telephone, television and broadband internet services over an expanding network of fibre optic cables. Cable providers distribute television programming from cable networks to subscribers. They typically also provide consumers with video services, high-speed internet service and VoIP. Traditionally, these services are bundled into packages that charge subscribers a single payment. Satellite entities distribute TV programming through broadcasting satellites orbiting the earth or through ground stations. Entities serve customers primarily in their domestic markets, although some entities operate in more than one country.
Relevant Issues for both Industries (7 of 26)
Why are some issues greyed out?
The SASB Standards vary by industry based on the different sustainability-related risks and opportunities within an industry. The issues in grey were not identified during the standard-setting process as the most likely to be useful to investors, so they are not included in the Standard. Over time, as the ISSB continues to receive market feedback, some issues may be added or removed from the Standard. Each company determines which sustainability-related risks and opportunities are relevant to its business. The Standard is designed for the typical company in an industry, but individual companies may choose to report on different sustainability-related risks and opportunities based on their unique business model.-
Environment
- GHG Emissions
- Air Quality
-
Energy Management
The category addresses environmental impacts associated with energy consumption. It addresses the company’s management of energy in manufacturing and/or for provision of products and services derived from utility providers (grid energy) not owned or controlled by the company. More specifically, it includes management of energy efficiency and intensity, energy mix, as well as grid reliance. Upstream (e.g., suppliers) and downstream (e.g., product use) energy use is not included in the scope. - Water & Wastewater Management
- Waste & Hazardous Materials Management
- Ecological Impacts
-
Social Capital
- Human Rights & Community Relations
-
Customer Privacy
The category addresses management of risks related to the use of personally identifiable information (PII) and other customer or user data for secondary purposes including but not limited to marketing through affiliates and non-affiliates. The scope of the category includes social issues that may arise from a company’s approach to collecting data, obtaining consent (e.g., opt-in policies), managing user and customer expectations regarding how their data is used, and managing evolving regulation. It excludes social issues arising from cybersecurity risks, which are covered in a separate category. -
Data Security
The category addresses management of risks related to collection, retention, and use of sensitive, confidential, and/or proprietary customer or user data. It includes social issues that may arise from incidents such as data breaches in which personally identifiable information (PII) and other user or customer data may be exposed. It addresses a company’s strategy, policies, and practices related to IT infrastructure, staff training, record keeping, cooperation with law enforcement, and other mechanisms used to ensure security of customer or user data. - Access & Affordability
- Product Quality & Safety
- Customer Welfare
- Selling Practices & Product Labeling
-
Human Capital
- Labour Practices
- Employee Health & Safety
-
Employee Engagement, Diversity & Inclusion
The category addresses a company’s ability to ensure that its culture and hiring and promotion practices embrace the building of a diverse and inclusive workforce that reflects the makeup of local talent pools and its customer base. It addresses the issues of discriminatory practices on the bases of race, gender, ethnicity, religion, sexual orientation, and other factors.
-
Business Model and Innovation
- Product Design & Lifecycle Management
- Business Model Resilience
- Supply Chain Management
-
Materials Sourcing & Efficiency
The category addresses issues related to the resilience of materials supply chains to impacts of climate change and other external environmental and social factors. It captures the impacts of such external factors on operational activity of suppliers, which can further affect availability and pricing of key resources. It addresses a company’s ability to manage these risks through product design, manufacturing, and end-of-life management, such as by using of recycled and renewable materials, reducing the use of key materials (dematerialization), maximizing resource efficiency in manufacturing, and making R&D investments in substitute materials. Additionally, companies can manage these issues by screening, selection, monitoring, and engagement with suppliers to ensure their resilience to external risks. It does not address issues associated with environmental and social externalities created by operational activity of individual suppliers, which is covered in a separate category. - Physical Impacts of Climate Change
-
Leadership and Governance
- Business Ethics
-
Competitive Behaviour
The category covers social issues associated with existence of monopolies, which may include, but are not limited to, excessive prices, poor quality of service, and inefficiencies. It addresses a company’s management of legal and social expectation around monopolistic and anti-competitive practices, including issues related to bargaining power, collusion, price fixing or manipulation, and protection of patents and intellectual property (IP). - Management of the Legal & Regulatory Environment
- Critical Incident Risk Management
-
Systemic Risk Management
The category addresses the company’s contributions to or management of systemic risks resulting from large-scale weakening or collapse of systems upon which the economy and society depend. This includes financial systems, natural resource systems, and technological systems. It addresses the mechanisms a company has in place to reduce its contributions to systemic risks and to improve safeguards that may mitigate the impacts of systemic failure. For financial institutions, the category also captures the company’s ability to absorb shocks arising from financial and economic stress and meet stricter regulatory requirements related to the complexity and interconnectedness of companies in the industry.
Disclosure Topics
What is the relationship between General Issue Category and Disclosure Topics?
The General Issue Category is an industry-agnostic version of the Disclosure Topics that appear in each SASB Standard. Disclosure topics represent the industry-specific impacts of General Issue Categories. The industry-specific Disclosure Topics ensure each SASB Standard is tailored to the industry, while the General Issue Categories enable comparability across industries. For example, Health & Nutrition is a disclosure topic in the Non-Alcoholic Beverages industry, representing an industry-specific measure of the general issue of Customer Welfare. The issue of Customer Welfare, however, manifests as the Counterfeit Drugs disclosure topic in the Biotechnology & Pharmaceuticals industry.-
Access Standard
-
Energy Management
The category addresses environmental impacts associated with energy consumption. It addresses the company’s management of energy in manufacturing and/or for provision of products and services derived from utility providers (grid energy) not owned or controlled by the company. More specifically, it includes management of energy efficiency and intensity, energy mix, as well as grid reliance. Upstream (e.g., suppliers) and downstream (e.g., product use) energy use is not included in the scope.-
Environmental Footprint of Hardware Infrastructure
With the growth of cloud-based service offerings, entities in this industry own, operate or rent increasingly more data centres and other hardware. Thus, managing the energy and water use associated with IT hardware infrastructure is relevant to value creation. Data centres must be powered continuously, and disruptions to the energy supply can have a material effect on operations, depending on the magnitude and timing of the disruption. Entities face a trade-off between energy and water consumption because of data centre cooling needs. Cooling data centres with water instead of chillers improves energy efficiency, but this method may create dependence on significant local water resources. Data centre specification decisions are important for managing costs, obtaining a reliable supply of energy and water, and reducing reputational risks, particularly with the increasing global regulatory focus on climate change and the opportunities arising from energy efficiency and renewable energy innovations.
-
-
Customer Privacy
The category addresses management of risks related to the use of personally identifiable information (PII) and other customer or user data for secondary purposes including but not limited to marketing through affiliates and non-affiliates. The scope of the category includes social issues that may arise from a company’s approach to collecting data, obtaining consent (e.g., opt-in policies), managing user and customer expectations regarding how their data is used, and managing evolving regulation. It excludes social issues arising from cybersecurity risks, which are covered in a separate category.-
Data Privacy & Freedom of Expression
As Software & IT Services entities increasingly deliver products and services over the Internet and through mobile devices, they must carefully manage two separate and often conflicting priorities. First, entities use customer data to innovate and provide customers with new products and services to generate revenues. Second, entities have access to a wide range of customer data, such as personal, demographic, content and behavioural data creating associated privacy concerns. This dynamic may result in increased regulatory scrutiny in many countries. The delivery of cloud-based software and IT services also raises concerns about potential access to user data by governments that may use it to limit the citizens’ freedoms. Effective management in this area may reduce regulatory and reputational risks that may result in decreased revenues, reduced market share and increased regulatory actions involving potential fines and other legal costs.
-
-
Data Security
The category addresses management of risks related to collection, retention, and use of sensitive, confidential, and/or proprietary customer or user data. It includes social issues that may arise from incidents such as data breaches in which personally identifiable information (PII) and other user or customer data may be exposed. It addresses a company’s strategy, policies, and practices related to IT infrastructure, staff training, record keeping, cooperation with law enforcement, and other mechanisms used to ensure security of customer or user data.-
Data Security
Software & IT Services entities are targets of growing data security threats from cyberattacks, which puts their own data and their customers’ data at risk. Inadequate prevention, detection and remediation of data security threats may influence customer acquisition and retention and result in decreased market share and reduced demand for the entity’s products. In addition to reputational damage and increased customer turnover, data breaches also may result in increased expenses, commonly associated with remediation efforts such as identity protection offerings and employee training on data protection. Meanwhile, new and emerging data security standards and regulations may affect operating expenses through increased compliance costs. Additionally, entities in this industry may be well-positioned to capture revenue opportunities by providing secure software and services to meet the demand for ensuring data is kept secure.
-
-
Employee Engagement, Diversity & Inclusion
The category addresses a company’s ability to ensure that its culture and hiring and promotion practices embrace the building of a diverse and inclusive workforce that reflects the makeup of local talent pools and its customer base. It addresses the issues of discriminatory practices on the bases of race, gender, ethnicity, religion, sexual orientation, and other factors.-
Recruiting & Managing a Global, Diverse & Skilled Workforce
Employees are important contributors to value creation in the Software & IT Services industry. Entities commonly find recruiting qualified employees to fill these positions difficult. A shortage in technically skilled employees can create intense competition to acquire highly skilled employees globally, contributing to high employee turnover rates. Some entities contribute to relevant education and training programmes to expand the availability of domestic, skilled employees. Entities offer significant monetary and non-monetary benefits to improve employee engagement and therefore retention and productivity. Initiatives to improve employee engagement and work-life balance may influence the recruitment and retention of a diverse workforce. Since the industry is characterised by relatively low representation from women and minority groups, efforts to recruit and develop globally diverse talent pools may address the talent shortage and improve the value of entity offerings. Greater workforce diversity is important for innovation and helps entities understand the needs of a diverse and global customer base.
-
-
Materials Sourcing & Efficiency
The category addresses issues related to the resilience of materials supply chains to impacts of climate change and other external environmental and social factors. It captures the impacts of such external factors on operational activity of suppliers, which can further affect availability and pricing of key resources. It addresses a company’s ability to manage these risks through product design, manufacturing, and end-of-life management, such as by using of recycled and renewable materials, reducing the use of key materials (dematerialization), maximizing resource efficiency in manufacturing, and making R&D investments in substitute materials. Additionally, companies can manage these issues by screening, selection, monitoring, and engagement with suppliers to ensure their resilience to external risks. It does not address issues associated with environmental and social externalities created by operational activity of individual suppliers, which is covered in a separate category.None -
Competitive Behaviour
The category covers social issues associated with existence of monopolies, which may include, but are not limited to, excessive prices, poor quality of service, and inefficiencies. It addresses a company’s management of legal and social expectation around monopolistic and anti-competitive practices, including issues related to bargaining power, collusion, price fixing or manipulation, and protection of patents and intellectual property (IP).-
Intellectual Property Protection & Competitive Behaviour
Entities in the Software & IT Services industry spend a significant proportion of their revenues on IP protection, including acquiring patents and copyrights. Although IP protection is inherent to some entity business models and is an important driver of innovation, entities’ IP practices sometimes may be a contentious societal issue. Entities sometimes acquire patents and other IP protection to restrict competition and innovation, particularly if they are dominant market players. Because of software complexity, its abstract nature and increasing IP rights protection related to software, entities in the industry must navigate overlapping patent claims to operate. As a result, entities in the industry may find themselves constantly in litigation or subject to regulatory scrutiny either because of allegations of patent violations if they engage in unethical business practices, or are perceived as doing so, or because they engage in IP infringement litigation. Adverse legal or regulatory rulings related to antitrust and IP may expose entities in the industry to costly and lengthy litigations and potential monetary losses as a result. Such rulings also may affect an entity’s market share and pricing power if its patents or dominant position in important markets are challenged legally, with potentially significant effects on revenue. Therefore, entities that balance the protection of their IP and its use to spur innovation while ensuring their IP management and other business practices do not unfairly restrict competition, may reduce regulatory scrutiny and legal actions while protecting their market value.
-
-
Systemic Risk Management
The category addresses the company’s contributions to or management of systemic risks resulting from large-scale weakening or collapse of systems upon which the economy and society depend. This includes financial systems, natural resource systems, and technological systems. It addresses the mechanisms a company has in place to reduce its contributions to systemic risks and to improve safeguards that may mitigate the impacts of systemic failure. For financial institutions, the category also captures the company’s ability to absorb shocks arising from financial and economic stress and meet stricter regulatory requirements related to the complexity and interconnectedness of companies in the industry.-
Managing Systemic Risks from Technology Disruptions
With trends towards increased cloud computing and Software as a Service (SaaS), software and IT service providers must ensure they have robust infrastructure and policies in place to minimise disruptions to their services. Disruptions such as programming errors or server downtime may generate systemic risks, because computing and data storage functions move from individual entity servers in various industries to data centres of cloud-computing service providers. The risks are increased particularly if the affected customers are in sensitive sectors, such as financial institutions or utilities, which are considered critical national infrastructure. Entities’ investments in improving the reliability and quality of their IT infrastructure and services may attract and retain customers, thereby creating revenue and opportunities in new markets.
-
-
-
Access Standard
-
Energy Management
The category addresses environmental impacts associated with energy consumption. It addresses the company’s management of energy in manufacturing and/or for provision of products and services derived from utility providers (grid energy) not owned or controlled by the company. More specifically, it includes management of energy efficiency and intensity, energy mix, as well as grid reliance. Upstream (e.g., suppliers) and downstream (e.g., product use) energy use is not included in the scope.-
Environmental Footprint of Operations
Individual Telecommunication Services entities consume substantial amounts of energy. Depending on the source of energy and generation efficiency, electricity consumption by telecom network infrastructure can contribute significantly to environmental externalities, such as climate change, creating sustainability risks for the industry. Although network equipment and data centres are becoming more energy efficient, their overall energy consumption is increasing with the expansion in telecommunications infrastructure and data traffic. How Telecommunication Services entities manage their overall energy efficiency or intensity, reliance on different types of energy, and how they access alternative sources of energy may become increasingly material as the global regulatory focus on climate change increases, creating incentives for energy efficiency and renewable energy as well as pricing of greenhouse gas (GHG) emissions. Because energy expenditures may be significant in the industry, entities that improve operational energy efficiency may increase cost savings and profit margins.
-
-
Customer Privacy
The category addresses management of risks related to the use of personally identifiable information (PII) and other customer or user data for secondary purposes including but not limited to marketing through affiliates and non-affiliates. The scope of the category includes social issues that may arise from a company’s approach to collecting data, obtaining consent (e.g., opt-in policies), managing user and customer expectations regarding how their data is used, and managing evolving regulation. It excludes social issues arising from cybersecurity risks, which are covered in a separate category.-
Data Privacy
As customers increasingly pay attention to privacy issues associated with cell phone, internet and email services, Telecommunication Services entities must implement strong management practices and guidelines related to their use of customer data. Telecommunication Services entities use growing volumes of customer location, web browsing and demographic data to improve their services as well as generate revenue by selling such data to third parties. Growing public concern about privacy may result in increased regulatory scrutiny over the use, collection and sale of consumer data. These trends increase the importance of Telecommunication Services entities adopting and communicating policies about providing customer data to third parties transparently, including the amount and type of data provided and the nature of its use (for example, use for commercial purposes). Additionally, Telecommunication Services entities receive, and must determine whether to comply with, government requests for customer information. Entities in the industry that fail to manage data privacy may be susceptible to decreased revenues because of lost consumer confidence and churn, as well as to financial effects stemming from legal exposures.
-
-
Data Security
The category addresses management of risks related to collection, retention, and use of sensitive, confidential, and/or proprietary customer or user data. It includes social issues that may arise from incidents such as data breaches in which personally identifiable information (PII) and other user or customer data may be exposed. It addresses a company’s strategy, policies, and practices related to IT infrastructure, staff training, record keeping, cooperation with law enforcement, and other mechanisms used to ensure security of customer or user data.-
Data Security
The Telecommunication Services industry is particularly vulnerable to data security threats because entities manage an increasing volume of customer data, including personally identifiable information, as well as demographic, behavioural and location data. Inadequate prevention, detection and remediation of data security threats may influence customer acquisition and retention and result in decreased market share and lower demand for the entity’s products. In addition to reputational damage and increased customer turnover, data breaches also may result in increased expenses, commonly associated with remediation efforts such as identity protection offerings and employee training on data protection. As the providers of critical infrastructure, the ability of entities to combat cyber-attacks may affect reputation and brand value, with a long-term effect on market share and revenue growth potential. Therefore, entities that identify and manage data security risks in a timely manner may be in a better position to protect market share and brand value while also reducing risk exposure to cyber-attacks. Additionally, new and emerging data security standards and regulations may affect the operating expenses of entities through increased costs of compliance.
-
-
Employee Engagement, Diversity & Inclusion
The category addresses a company’s ability to ensure that its culture and hiring and promotion practices embrace the building of a diverse and inclusive workforce that reflects the makeup of local talent pools and its customer base. It addresses the issues of discriminatory practices on the bases of race, gender, ethnicity, religion, sexual orientation, and other factors.None -
Materials Sourcing & Efficiency
The category addresses issues related to the resilience of materials supply chains to impacts of climate change and other external environmental and social factors. It captures the impacts of such external factors on operational activity of suppliers, which can further affect availability and pricing of key resources. It addresses a company’s ability to manage these risks through product design, manufacturing, and end-of-life management, such as by using of recycled and renewable materials, reducing the use of key materials (dematerialization), maximizing resource efficiency in manufacturing, and making R&D investments in substitute materials. Additionally, companies can manage these issues by screening, selection, monitoring, and engagement with suppliers to ensure their resilience to external risks. It does not address issues associated with environmental and social externalities created by operational activity of individual suppliers, which is covered in a separate category.-
Product End-of-life Management
Because of the rapid obsolescence of communications devices, particularly mobile phones, they represent an increasing proportion of electronic waste (e-waste) going to landfills, driven in part by a low recycling rate. Telecommunication Services entities face growing regulatory risks related to this issue. Numerous jurisdictions have implemented e-waste recycling laws mandating that electronics retailers and manufacturers create a system for recycling, reuse or proper disposal of electronic devices. Although in their early days many of these laws covered a limited scope of products, recent laws extend to mobile devices, requiring entities to finance the collection, treatment, recycling or proper disposal of e-waste, as concerns around e-waste from communications devices increase. E-waste laws often require vendors or manufacturers to pay for waste recycling or product take-back and recycling programmes. Penalties or costs, because of such laws, together with potential revenues generated from refurbishing and re-selling products, increasingly are providing incentives for entities in the industry to manage end-of-life impacts. Many Telecommunication Services entities work in partnership with phone manufacturers to bundle telecom services and mobile devices, and therefore have a shared responsibility for end-of-life management of such devices. Their relationship with customers provides an opportunity for effective management of product recycling, reuse and disposal. Establishing take-back programmes to recover end-of-life materials for further reuse, recycling or remanufacturing may increase cost savings and develop a more resilient supply of manufacturing materials.
-
-
Competitive Behaviour
The category covers social issues associated with existence of monopolies, which may include, but are not limited to, excessive prices, poor quality of service, and inefficiencies. It addresses a company’s management of legal and social expectation around monopolistic and anti-competitive practices, including issues related to bargaining power, collusion, price fixing or manipulation, and protection of patents and intellectual property (IP).-
Competitive Behaviour & Open Internet
The Telecommunication Services industry contains classic examples of natural monopolies, where high capital costs allow them to offer the most efficient production. Given the concentrated nature of telecommunications, cable and satellite entities, they must manage their growth strategies within the parameters of a regulatory landscape designed to ensure competition. In addition to natural monopoly, many entities in this industry benefit from terminal access monopolies over the so-called ‘last-mile’ of their networks, given their contractual relationship with each subscriber and the barriers for subscribers to change service providers. The nature of this relationship is the basis of much of the discussion regarding an open internet, where all data on the internet is treated equally in terms of performance and access. The industry faces legislative and regulatory actions to ensure competition, which may limit the market share and growth potential of some larger players. Merger and acquisition activity by dominant market players has come under regulatory scrutiny. This has resulted in entities abandoning plans to consolidate, affecting their value. Strong reliance on market dominance also may be a source of risk if entities are vulnerable to legal challenges, increasing their risk profile and cost of capital.
-
-
Systemic Risk Management
The category addresses the company’s contributions to or management of systemic risks resulting from large-scale weakening or collapse of systems upon which the economy and society depend. This includes financial systems, natural resource systems, and technological systems. It addresses the mechanisms a company has in place to reduce its contributions to systemic risks and to improve safeguards that may mitigate the impacts of systemic failure. For financial institutions, the category also captures the company’s ability to absorb shocks arising from financial and economic stress and meet stricter regulatory requirements related to the complexity and interconnectedness of companies in the industry.-
Managing Systemic Risks from Technology Disruptions
Given the systemic importance of telecommunications networks, systemic or economy-wide disruption may result if the Telecommunication Services network infrastructure is unreliable and prone to business continuity risks. As the frequency of extreme weather events associated with climate change increases, Telecommunication Services entities may face growing physical threats to network infrastructure, with potentially significant social or systemic impacts. In the absence of resilient and reliable infrastructure, entities may lose revenue associated with service disruptions or face unplanned capital expenditures to repair damaged or compromised equipment. Entities that successfully manage business continuity risks, including identifying critical business operations, and that enhance resilience of the system may substantially reduce their risk exposure and decrease their cost of capital. While implementation of such measures may have upfront costs, entities may gain long-term benefits in terms of lower remediation expenses in cases of high-impact disruptions.
-
-
General Issue Category
Remove
Software & IT Services
Access Standard
Remove
Telecommunication Services
Access Standard
Energy Management
-
Environmental Footprint of Hardware Infrastructure
With the growth of cloud-based service offerings, entities in this industry own, operate or rent increasingly more data centres and other hardware. Thus, managing the energy and water use associated with IT hardware infrastructure is relevant to value creation. Data centres must be powered continuously, and disruptions to the energy supply can have a material effect on operations, depending on the magnitude and timing of the disruption. Entities face a trade-off between energy and water consumption because of data centre cooling needs. Cooling data centres with water instead of chillers improves energy efficiency, but this method may create dependence on significant local water resources. Data centre specification decisions are important for managing costs, obtaining a reliable supply of energy and water, and reducing reputational risks, particularly with the increasing global regulatory focus on climate change and the opportunities arising from energy efficiency and renewable energy innovations.
-
Environmental Footprint of Operations
Individual Telecommunication Services entities consume substantial amounts of energy. Depending on the source of energy and generation efficiency, electricity consumption by telecom network infrastructure can contribute significantly to environmental externalities, such as climate change, creating sustainability risks for the industry. Although network equipment and data centres are becoming more energy efficient, their overall energy consumption is increasing with the expansion in telecommunications infrastructure and data traffic. How Telecommunication Services entities manage their overall energy efficiency or intensity, reliance on different types of energy, and how they access alternative sources of energy may become increasingly material as the global regulatory focus on climate change increases, creating incentives for energy efficiency and renewable energy as well as pricing of greenhouse gas (GHG) emissions. Because energy expenditures may be significant in the industry, entities that improve operational energy efficiency may increase cost savings and profit margins.
Customer Privacy
-
Data Privacy & Freedom of Expression
As Software & IT Services entities increasingly deliver products and services over the Internet and through mobile devices, they must carefully manage two separate and often conflicting priorities. First, entities use customer data to innovate and provide customers with new products and services to generate revenues. Second, entities have access to a wide range of customer data, such as personal, demographic, content and behavioural data creating associated privacy concerns. This dynamic may result in increased regulatory scrutiny in many countries. The delivery of cloud-based software and IT services also raises concerns about potential access to user data by governments that may use it to limit the citizens’ freedoms. Effective management in this area may reduce regulatory and reputational risks that may result in decreased revenues, reduced market share and increased regulatory actions involving potential fines and other legal costs.
-
Data Privacy
As customers increasingly pay attention to privacy issues associated with cell phone, internet and email services, Telecommunication Services entities must implement strong management practices and guidelines related to their use of customer data. Telecommunication Services entities use growing volumes of customer location, web browsing and demographic data to improve their services as well as generate revenue by selling such data to third parties. Growing public concern about privacy may result in increased regulatory scrutiny over the use, collection and sale of consumer data. These trends increase the importance of Telecommunication Services entities adopting and communicating policies about providing customer data to third parties transparently, including the amount and type of data provided and the nature of its use (for example, use for commercial purposes). Additionally, Telecommunication Services entities receive, and must determine whether to comply with, government requests for customer information. Entities in the industry that fail to manage data privacy may be susceptible to decreased revenues because of lost consumer confidence and churn, as well as to financial effects stemming from legal exposures.
Data Security
-
Data Security
Software & IT Services entities are targets of growing data security threats from cyberattacks, which puts their own data and their customers’ data at risk. Inadequate prevention, detection and remediation of data security threats may influence customer acquisition and retention and result in decreased market share and reduced demand for the entity’s products. In addition to reputational damage and increased customer turnover, data breaches also may result in increased expenses, commonly associated with remediation efforts such as identity protection offerings and employee training on data protection. Meanwhile, new and emerging data security standards and regulations may affect operating expenses through increased compliance costs. Additionally, entities in this industry may be well-positioned to capture revenue opportunities by providing secure software and services to meet the demand for ensuring data is kept secure.
-
Data Security
The Telecommunication Services industry is particularly vulnerable to data security threats because entities manage an increasing volume of customer data, including personally identifiable information, as well as demographic, behavioural and location data. Inadequate prevention, detection and remediation of data security threats may influence customer acquisition and retention and result in decreased market share and lower demand for the entity’s products. In addition to reputational damage and increased customer turnover, data breaches also may result in increased expenses, commonly associated with remediation efforts such as identity protection offerings and employee training on data protection. As the providers of critical infrastructure, the ability of entities to combat cyber-attacks may affect reputation and brand value, with a long-term effect on market share and revenue growth potential. Therefore, entities that identify and manage data security risks in a timely manner may be in a better position to protect market share and brand value while also reducing risk exposure to cyber-attacks. Additionally, new and emerging data security standards and regulations may affect the operating expenses of entities through increased costs of compliance.
Employee Engagement, Diversity & Inclusion
-
Recruiting & Managing a Global, Diverse & Skilled Workforce
Employees are important contributors to value creation in the Software & IT Services industry. Entities commonly find recruiting qualified employees to fill these positions difficult. A shortage in technically skilled employees can create intense competition to acquire highly skilled employees globally, contributing to high employee turnover rates. Some entities contribute to relevant education and training programmes to expand the availability of domestic, skilled employees. Entities offer significant monetary and non-monetary benefits to improve employee engagement and therefore retention and productivity. Initiatives to improve employee engagement and work-life balance may influence the recruitment and retention of a diverse workforce. Since the industry is characterised by relatively low representation from women and minority groups, efforts to recruit and develop globally diverse talent pools may address the talent shortage and improve the value of entity offerings. Greater workforce diversity is important for innovation and helps entities understand the needs of a diverse and global customer base.
Materials Sourcing & Efficiency
-
Product End-of-life Management
Because of the rapid obsolescence of communications devices, particularly mobile phones, they represent an increasing proportion of electronic waste (e-waste) going to landfills, driven in part by a low recycling rate. Telecommunication Services entities face growing regulatory risks related to this issue. Numerous jurisdictions have implemented e-waste recycling laws mandating that electronics retailers and manufacturers create a system for recycling, reuse or proper disposal of electronic devices. Although in their early days many of these laws covered a limited scope of products, recent laws extend to mobile devices, requiring entities to finance the collection, treatment, recycling or proper disposal of e-waste, as concerns around e-waste from communications devices increase. E-waste laws often require vendors or manufacturers to pay for waste recycling or product take-back and recycling programmes. Penalties or costs, because of such laws, together with potential revenues generated from refurbishing and re-selling products, increasingly are providing incentives for entities in the industry to manage end-of-life impacts. Many Telecommunication Services entities work in partnership with phone manufacturers to bundle telecom services and mobile devices, and therefore have a shared responsibility for end-of-life management of such devices. Their relationship with customers provides an opportunity for effective management of product recycling, reuse and disposal. Establishing take-back programmes to recover end-of-life materials for further reuse, recycling or remanufacturing may increase cost savings and develop a more resilient supply of manufacturing materials.
Competitive Behaviour
-
Intellectual Property Protection & Competitive Behaviour
Entities in the Software & IT Services industry spend a significant proportion of their revenues on IP protection, including acquiring patents and copyrights. Although IP protection is inherent to some entity business models and is an important driver of innovation, entities’ IP practices sometimes may be a contentious societal issue. Entities sometimes acquire patents and other IP protection to restrict competition and innovation, particularly if they are dominant market players. Because of software complexity, its abstract nature and increasing IP rights protection related to software, entities in the industry must navigate overlapping patent claims to operate. As a result, entities in the industry may find themselves constantly in litigation or subject to regulatory scrutiny either because of allegations of patent violations if they engage in unethical business practices, or are perceived as doing so, or because they engage in IP infringement litigation. Adverse legal or regulatory rulings related to antitrust and IP may expose entities in the industry to costly and lengthy litigations and potential monetary losses as a result. Such rulings also may affect an entity’s market share and pricing power if its patents or dominant position in important markets are challenged legally, with potentially significant effects on revenue. Therefore, entities that balance the protection of their IP and its use to spur innovation while ensuring their IP management and other business practices do not unfairly restrict competition, may reduce regulatory scrutiny and legal actions while protecting their market value.
-
Competitive Behaviour & Open Internet
The Telecommunication Services industry contains classic examples of natural monopolies, where high capital costs allow them to offer the most efficient production. Given the concentrated nature of telecommunications, cable and satellite entities, they must manage their growth strategies within the parameters of a regulatory landscape designed to ensure competition. In addition to natural monopoly, many entities in this industry benefit from terminal access monopolies over the so-called ‘last-mile’ of their networks, given their contractual relationship with each subscriber and the barriers for subscribers to change service providers. The nature of this relationship is the basis of much of the discussion regarding an open internet, where all data on the internet is treated equally in terms of performance and access. The industry faces legislative and regulatory actions to ensure competition, which may limit the market share and growth potential of some larger players. Merger and acquisition activity by dominant market players has come under regulatory scrutiny. This has resulted in entities abandoning plans to consolidate, affecting their value. Strong reliance on market dominance also may be a source of risk if entities are vulnerable to legal challenges, increasing their risk profile and cost of capital.
Systemic Risk Management
-
Managing Systemic Risks from Technology Disruptions
With trends towards increased cloud computing and Software as a Service (SaaS), software and IT service providers must ensure they have robust infrastructure and policies in place to minimise disruptions to their services. Disruptions such as programming errors or server downtime may generate systemic risks, because computing and data storage functions move from individual entity servers in various industries to data centres of cloud-computing service providers. The risks are increased particularly if the affected customers are in sensitive sectors, such as financial institutions or utilities, which are considered critical national infrastructure. Entities’ investments in improving the reliability and quality of their IT infrastructure and services may attract and retain customers, thereby creating revenue and opportunities in new markets.
-
Managing Systemic Risks from Technology Disruptions
Given the systemic importance of telecommunications networks, systemic or economy-wide disruption may result if the Telecommunication Services network infrastructure is unreliable and prone to business continuity risks. As the frequency of extreme weather events associated with climate change increases, Telecommunication Services entities may face growing physical threats to network infrastructure, with potentially significant social or systemic impacts. In the absence of resilient and reliable infrastructure, entities may lose revenue associated with service disruptions or face unplanned capital expenditures to repair damaged or compromised equipment. Entities that successfully manage business continuity risks, including identifying critical business operations, and that enhance resilience of the system may substantially reduce their risk exposure and decrease their cost of capital. While implementation of such measures may have upfront costs, entities may gain long-term benefits in terms of lower remediation expenses in cases of high-impact disruptions.