6 principles to unite business in the fight against cybercrime

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Friso van der Oord, Senior Vice President, Content, NACD & Larry Clinton, President and Chief Executive Officer, Internet Security Alliance (ISA) & Joe Nocera, Cyber and Privacy Innovation Institute Leader, PwC & Daniel Dobrygowski, Head of Governance and Trust, World Economic Forum


• The COVID-19 pandemic has opened more opportunities for cyberattacks.

• Not enough board members understand the threat to their business.

• The World Economic Forum, PwC, NACD and ISA are partnering to define key principles of good cybersecurity governance .

In 2020, malevolent actors took advantage of the pandemic. The rush to digital-first arrangements at work and in schools, the urgency of vaccine research and increased cloud adoption opened opportunities for criminals to mount more profitable ransomware, phishing and other attacks. In order to effectively move forward into a future where digital connectivity supports most business functions, leaders will need to build their company strategy around cyber-risks.

The surge in cybersecurity attacks in 2020 has made boards and CEOs more acutely aware of the risks of inadequately secure technology. Indeed, in the World Economic Forum’s COVID-19 Risks Outlook, increases in cyberattacks were among the top three most worrisome risks to leaders around the world. As long as businesses pursue digital growth strategies, cybersecurity is a perennial concern; cybercriminals never sleep – and neither can board or corporate chiefs.

Today, few board members fully understand the risks to their organization’s cybersecurity, according to the recent PwC Annual Corporate Directors Survey. While 66% of board directors believe a cyber breach reflects negatively on themselves personally, and 82% believe expertise in cyber-risk is important to the board, very few board members claim to understand their company’s level of exposure to such threats.

Cybersecurity ranks highly among modern business risks
Cybersecurity ranks highly among modern business risks Image: World Economic Forum

Ignorance is not bliss. This inability to effectively assess cyber-risk throughout the enterprise may turn out to be the most dangerous weakness of all — one that malicious actors can exploit to the fullest extent – and which is not easily addressed. What exactly is the board’s role in addressing such risks, and how should they oversee their corporate teams’ efforts to manage them better?

Principles and questions

The first step in resolving the board’s role in overseeing cyber-risk is to establish the principles to guide directors’ behaviours and choices. When leading businesses adapt common principles into practices, the practices can, in turn, become widely accepted standards that the business community expects. The ripple effect can be transformative.

Drawing on our experience and knowledge of what works and what has truly made a difference, the World Economic Forum (the Forum), National Association of Corporate Directors (NACD), Internet Security Alliance (ISA), and PwC, in consultation with partner organizations and experts, have joined forces to offer the following set of consensus principles for organizational leaders’ and board members’ use. Ask these questions about your current practices to help you turn each principle into actions that can improve governance of cyber-risks.

The principles are the result of years of consultation with board members, security practitioners, academics and government entities from around the world. As such, they aim to constitute a de facto standard of practice for corporate boards seeking to fulfill their fiduciary role in overseeing cyber-risk.

In-depth handbooks that adapt these principles and provide real-world examples from our partners will be available as part of the full publication.

1. Cybersecurity is a strategic business enabler

Cybersecurity is more than just an IT issue

Strong, effective cybersecurity adds value to the business. Controlling cyber-risk means coordinating and collaborating with business units throughout the enterprise, including the CEO and the board. This ensures the entire enterprise, not just the IT department, is addressing cyber-risk. Further, organizations must instill a culture of cybersecurity by modelling good cyber decision-making:

• Are all executives – the entire C-suite – required to consider the cybersecurity implications of their activities?

• Has your organization discussed how to use cybersecurity as a market differentiator and business driver?

2. Align cyber-risk management with business needs

Boards should understand and assess how cyber-risks are effectively managed to pursue business objectives

By focusing on how cyber-risks impact their business and how to deal with them (by accepting, transferring, avoiding, or mitigating them), organizations can build a security profile that meets the needs of the business. Strategic leadership means ensuring that cyber-risk management conforms to business objectives with every decision, in mergers and acquisitions, digitizing the business, innovation and all other areas.

• Who is the “owner” of cyber-risk in your organization? The business or the security function?

• Are all business units required to report on key cyber-risks and response strategies?

• Is cyber-risk considered in all significant business decisions, such as launching a new product or publishing an app?

3. Understand the economic impact of cyber-risk

Enterprise decision-making requires analysis of the economic impact of cybersecurity choices

For effective business decisions, organizational risk assessments should weigh the costs of cybersecurity against strategic objectives, regulatory and statutory requirements, business outcomes, and the costs associated managing that risk. More than half (55%) of 3,249 business and tech/security executives lack confidence that cyber spending is aligned to the most significant risks, according to PwC’s Global Digital Trust Insights 2021.

Executives remain unconvinced that cybersecurity budgets are currently well-deployed
Executives remain unconvinced that cybersecurity budgets are currently well-deployed Image: PwC

• Does your organization apply a consistent framework for calculating the economic impact and likelihood of cybersecurity events?

• Do business decisions consider the costs of compromise on cybersecurity?

• Has your organization set its cyber-risk appetite in the context of the company’s realistic vulnerabilities and strategic goals?

4. Ensure organizational design supports cybersecurity

Organizational structure should support security and strategic goals

Organizations should design an internal governance structure that addresses cybersecurity throughout the enterprise. Clearly define who’s accountable for critical actions and design cybersecurity practices into how the business operates and makes decisions.

• When was the last time you reviewed your organizational structure to ensure that the cybersecurity function is adequately represented throughout the business?

• Which officer has authority and accountability for coordinating cyber-risk strategy throughout the organization? Are they in a senior enough position?

5. Incorporate cybersecurity expertise into board governance

Boards need diverse sources of cybersecurity expertise

In 2020, 28% of S&P 500 companies reported that a member of the board of directors was a cybersecurity expert, up from 23% in 2019 and 7% in 2013. To provide proper oversight of the enterprise’s cybersecurity program, the board needs to understand common risks, challenges, and failures. To educate themselves, directors may consult industry and other guidance, board peers and third parties, and internal resources.

• Does your board have the right relationships inside and outside the organization to build their security knowledge?

• How many, if any, board members have cyber expertise?

• How often do you get input from third-party experts and assessors, who report to the board, to ensure effective oversight of management?

6. Foster systemic resilience and collaboration

Boards can take the lead in improving the cyber-resilience of industries and sectors

It takes a virtual village to fight cybercrime. Recent events have taught us that even the best cybersecurity-focused companies can be compromised by a sophisticated actor. Knowing that it is a matter of when, not if, attackers will be successful, it is important to be ready to respond and limit the damage of any attack. Security breaches may affect an entire sector and working with peers and even competitors can be crucial for systemic, industry-wide resilience. Stress-testing resilience plans is one of the lasting lessons from the pandemic. Risk leaders in the US say that in 2021, stress-testing will become more frequent and commonplace, both internally and externally. Boards can set the tone at the top for how inter-organizational relationships should look and set the expectation of management for cyber-risk collaboration.

Frequent stress-testing will be necessary to ensure the cyber-resilience of different business sectors
Frequent stress-testing will be necessary to ensure the cyber-resilience of different business sectors Image: PwC

• How well do you collaborate with peers, including other board members, to raise the baseline cybersecurity of the industry as a whole?

• Does your organization interact with its public-sector counterparties to understand the resilience issues facing the industry?

What is the World Economic Forum doing on cybersecurity

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. We are an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors. We bridge the gap between cybersecurity experts and decision makers at the highest levels to reinforce the importance of cybersecurity as a key strategic priority. World Economic Forum | Centre for Cybersecurity

Our community has three key priorities:

Strengthening Global Cooperation – to increase global cooperation between public and private stakeholders to foster a collective response to cybercrime and address key security challenges posed by barriers to cooperation.

Understanding Future Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies, and accelerate forward-looking solutions.

Building Cyber Resilience – to develop and amplify scalable solutions to accelerate the adoption of best practices and increase cyber resilience.

Initiatives include building a partnership to address the global cyber enforcement gap through improving the efficiency and effectiveness of public-private collaboration in cybercrime investigations; equipping business decision makers and cybersecurity leaders with the tools necessary to govern cyber risks, protect business assets and investments from the impact of cyber-attacks; and enhancing cyber resilience across key industry sectors such as electricity, aviation and oil & gas. We also promote mission aligned initiatives championed by our partner organizations.

The Forum is also a signatory of the Paris Call for Trust and Security in Cyberspace which aims to ensure digital peace and security which encourages signatories to protect individuals and infrastructure, to protect intellectual property, to cooperate in defense, and refrain from doing harm.

For more information, please contact us.

Equipped with the right strategy, one that understands the centrality of cyber-risk to doing business in the 21st century, boards will be able to be more effective leaders in the future. By following these principles, the NACD, ISA and the Forum agree that boards will begin the journey that leads to more cyber-resilient and innovative companies.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNICEF/Oleksii Fili Children's toys are covered in snow outside a residential building in Kyiv during prolonged winter power and heating outages.

World News in Brief: Syria ceasefire welcomed, ‘Olympic truce’, Ukraine’s freezing children

This article is published in association with United Nations. The UN Commission of Inquiry on Syria has welcomed a ceasefire agreement between the Syrian Government and the mainly-Kurdish Syrian Democratic Forces (SDF), urging all parties to seize the moment to protect civilians and prevent further violations in the country’s northeast.  “We welcome efforts to bring stability […]

This article was exclusively written for The European Sting by Mr. Frank Shao is a Tanzanian medical student. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Access to Healthcare: is it too much to ask?

This article was exclusively written for The European Sting by Mr. Khalil Al Bilani is a 5th-year medical student at Saint George’s University of Beirut. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect […]

UN Photo/Manuel Elías Ramiz Alakbarov (on screen), Deputy Special Coordinator for the Middle East Peace Process, briefs the Security Council meeting on the situation in the Middle East.

Potential turning point for Gaza as peace plan enters second phase: UN envoy

This article is published in association with United Nations. The start of a second phase of a stabilisation plan for Gaza offers a potential turning point for the war-ravaged enclave, a senior UN official told the Security Council on Wednesday. Ramiz Alakbarov warned that risks of violence escalating again remain high, while the situation in the […]

This article is published in association with United Nations.

Gaza ceasefire improves aid access, but children still face deadly conditions

The fragile ceasefire in the Gaza Strip is making a difference to the lives of over a million children, and improving overall access to food – but more aid still needs to enter.  That’s the assessment of two senior officials from the UN Children’s Fund (UNICEF) and the World Food Programme (WFP), speaking on Monday to journalists in New York following a […]

A new blow for UNRWA as headquarters in East Jerusalem ‘set on fire’

© UNRWA Destruction at UNRWA headquarters in East Jerusalem after Israeli authorities sent in bulldozers on 20 January. This article is published in association with United Nations. The head of embattled UN relief agency for Palestinians, UNRWA, has condemned reports that its headquarters in East Jerusalem have been set alight deliberately. It comes after Israeli authorities […]

© UNHCR/Yevheniia Kozun This cinema in Saltivka, Kharkiv, was hit during an earlier strike (file Jan 2026).

‘Cycle of attacks must end’: Lead UN official in Ukraine

This article is published in association with United Nations. The senior UN official in Ukraine, Matthias Schmale, has issued a condemnation of the massive overnight Russian drone and missile strike on several major Ukrainian cities, killing and injuring civilians, and knocking out energy infrastructure amid sub-zero temperatures. The attacks on some of Ukraine’s most important population […]

WHO/P. Virot The flag of the UN World Health Organization (WHO) flies at its headquarters in Geneva, Switzerland.

US withdrawal from WHO ‘risks global safety’, agency says in detailed rebuttal

This article is published in association with United Nations. The World Health Organization (WHO) has issued a detailed statement regretting the United States decision to leave the UN agency, and declaring that it will leave both the US and the world less safe as a result. The statement, released on Saturday, also includes a rebuttal of […]

© UNOCHA/Ximena Borrazas Kateryna and her two children warm up at a heating point and use rhe available electricity to charge their devices.

Keeping people warm amid hostilities and harsh winter weather in Ukraine

This article is published in association with United Nations. As people in war-torn Ukraine face the coldest winter in more than a decade, authorities and humanitarians are working to help them stay warm, particularly the most vulnerable residents.  Russian forces continue to attack Ukraine’s energy grid, leaving families without electricity and heating as temperatures plummet to -20° Celsius.  Since 2022, the Government has established so-called “Invincibility Points” – located in tents or public […]

UN News A UN emergency shelter set up amid the ruins of Gaza.

Gaza: War crimes probe pledges to continue work for justice and accountability

This article is published in association with United Nations. As President Trump launched the international Board of Peace plan for Gaza on Thursday, top independent rights experts tasked by the UN Human Rights Council with investigating grave abuses linked to the Hamas-Israel war pledged to continue their work seeking justice and accountability for all. “The Board […]

© WFP/Maxime Le Lijour Children wait for a hot meal at a kitchen in Khan Younis, Gaza, supported by the World Food Programme.

Cold kills another infant in Gaza as West Bank displacement intensifies

This article is published in association with United Nations. Another child in the Gaza Strip has died from hypothermia as winter weather continues to whip the enclave, the UN said on Wednesday, citing information from the health authorities.  The baby girl – just three months old – was found frozen to death on Tuesday morning at her home in […]

Critical medicines: EU measures to boost competitiveness and tackle shortages 

Critical medicines: EU measures to boost competitiveness and tackle shortages 

This article is brought to you in association with the European Parliament. On Tuesday, Parliament adopted proposals to enhance the availability and supply of essential medicines in the EU. The report, adopted with 503 votes in favour, 57 against and 108 abstentions, aims to ensure a high level of public health protection for EU citizens by […]

Europe Was Warned: Why the Next Pandemic Could Be  Worse 

This article was exclusively written for The European Sting by one of our passionate readers, Dr Taimoor Ahmed Shumail , MD | Dr Ahmed Bilal , MD , Vice  President Global Health and Diplomacy Wing – Pakistan International Medical Students  Association. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position […]

UN News Many Palestinian families are living in poorly equipped shelters that are highly vulnerable to flooding, leaving people inevitably exposed to harsh, stormy weather..

Gaza humanitarian crisis ‘far from being over,’ UN aid coordination office warns

This article is published in association with United Nations. Three months into the ceasefire in the Gaza Strip, the UN and partners have delivered tonnes of assistance items and carried out critical repairs, but this is only a temporary “Band-Aid” solution, a veteran aid worker has warned. “The humanitarian situation and crisis in Gaza is far […]

This article is published in association with European Investment Bank.

Will AI kickstart a new age of nuclear power?

This article is published in association with United Nations. The rapidly expanding use of artificial intelligence worldwide is putting electrical grids under huge pressure and many believe that, to meet that need without contributing to the climate crisis, a full-scale expansion of nuclear energy is essential. The global demand for electricity is growing at a vertiginous […]

UN Photo/Loey Felipe Martha Ama Akyaa Pobee, Assistant Secretary-General for Political Affairs briefs the Security Council meeting on the situation in Iran.

Iran: UN urges ‘maximum restraint’ to avert more death, wider escalation

This article is published in association with United Nations. As nationwide protests in Iran appear to ease after nearly three weeks of unrest and bloodshed, a senior UN official called on Thursday for action to prevent further escalation.  Assistant Secretary-General Martha Pobee briefed an emergency meeting of the Security Council in New York called by the […]

UNRWA UNRWA Headquarters in East Jerusalem

East Jerusalem: Forced shutdown of UN clinic signals escalating disregard for international law

This article is published in association with United Nations. The temporary closure of a UN-run health centre in East Jerusalem is the latest phase in “a pattern of deliberate disregard” for international law, the head of the UN agency that assists Palestine refugees, UNRWA, said on Wednesday.  Israeli forces stormed the UNRWA-operated health centre on Monday and ordered it […]

Unsplash

Iran: ‘The killing of peaceful demonstrators must stop,’ UN rights chief says

This article is published in association with United Nations.  As anti-government demonstrations continue across Iran, the UN human rights chief said on Tuesday that he was horrified at the mounting violence directed by security forces against protestors, with reports of hundreds killed and thousands arrested.  Volker Türk urged the authorities to immediately halt all forms of violence and repression against peaceful […]

© UNHCR/Yevheniia Kozun The bombing of residential buildings in Saltivka, Kharkiv, has left many Ukrainians without power.

Ukraine: Deadly Russian strikes push civilians deeper into winter crisis

This article is published in association with United Nations. Ukraine has entered the new year under intensifying and deadly Russian attacks which have crippled energy systems and left millions without heating, electricity or water amid freezing temperatures, senior UN officials told the Security Council on Monday. Under-Secretary-General for Political Affairs Rosemary DiCarlo told ambassadors the start […]

UN Photo/Eskinder Debebe UN Secretary-General António Guterres. (file photo)

UN chief ‘shocked’ by reports of excessive force against protesters in Iran

This article is published in association with United Nations. The UN Secretary-General is shocked by reports of violence and excessive use of force by Iranian authorities against protesters across the country, urging restraint and the immediate restoration of communications as unrest enters its third week. “All Iranians must be able to express their grievances peacefully and […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading