Prepare for the SASB Fundamentals of Sustainability Accounting Level II Test. Study with multiple choice questions, gaining hints and explanations. Enhance your sustainability reporting skills and ace your exam!

Multiple Choice

Which company reported zero data breaches involving customers' personal identifiable information (PII)?

Interpreting PII breach disclosures and what they say about cybersecurity and data governance. If a company reports zero data breaches involving customers’ personal identifiable information, it means there were no such incidents recorded during the reporting period. This suggests strong data protection controls in place—things like robust access controls, encryption, comprehensive incident monitoring, and a responsive incident management process—as well as effective governance over data handling and third-party/vendor risk management. In SASB disclosures, findings about data security and privacy are meant to reveal how well a company protects customer information and manages cyber risk, so a zero-breach statement highlights a lower incident risk profile relative to peers. Therefore, the correct choice is the company whose report states that there were no PII breach incidents, indicating robust protection and risk management for customer data.

Interpreting PII breach disclosures and what they say about cybersecurity and data governance. If a company reports zero data breaches involving customers’ personal identifiable information, it means there were no such incidents recorded during the reporting period. This suggests strong data protection controls in place—things like robust access controls, encryption, comprehensive incident monitoring, and a responsive incident management process—as well as effective governance over data handling and third-party/vendor risk management. In SASB disclosures, findings about data security and privacy are meant to reveal how well a company protects customer information and manages cyber risk, so a zero-breach statement highlights a lower incident risk profile relative to peers. Therefore, the correct choice is the company whose report states that there were no PII breach incidents, indicating robust protection and risk management for customer data.