6 principles to unite business in the fight against cybercrime

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Friso van der Oord, Senior Vice President, Content, NACD & Larry Clinton, President and Chief Executive Officer, Internet Security Alliance (ISA) & Joe Nocera, Cyber and Privacy Innovation Institute Leader, PwC & Daniel Dobrygowski, Head of Governance and Trust, World Economic Forum


• The COVID-19 pandemic has opened more opportunities for cyberattacks.

• Not enough board members understand the threat to their business.

• The World Economic Forum, PwC, NACD and ISA are partnering to define key principles of good cybersecurity governance .

In 2020, malevolent actors took advantage of the pandemic. The rush to digital-first arrangements at work and in schools, the urgency of vaccine research and increased cloud adoption opened opportunities for criminals to mount more profitable ransomware, phishing and other attacks. In order to effectively move forward into a future where digital connectivity supports most business functions, leaders will need to build their company strategy around cyber-risks.

The surge in cybersecurity attacks in 2020 has made boards and CEOs more acutely aware of the risks of inadequately secure technology. Indeed, in the World Economic Forum’s COVID-19 Risks Outlook, increases in cyberattacks were among the top three most worrisome risks to leaders around the world. As long as businesses pursue digital growth strategies, cybersecurity is a perennial concern; cybercriminals never sleep – and neither can board or corporate chiefs.

Today, few board members fully understand the risks to their organization’s cybersecurity, according to the recent PwC Annual Corporate Directors Survey. While 66% of board directors believe a cyber breach reflects negatively on themselves personally, and 82% believe expertise in cyber-risk is important to the board, very few board members claim to understand their company’s level of exposure to such threats.

Cybersecurity ranks highly among modern business risks
Cybersecurity ranks highly among modern business risks Image: World Economic Forum

Ignorance is not bliss. This inability to effectively assess cyber-risk throughout the enterprise may turn out to be the most dangerous weakness of all — one that malicious actors can exploit to the fullest extent – and which is not easily addressed. What exactly is the board’s role in addressing such risks, and how should they oversee their corporate teams’ efforts to manage them better?

Principles and questions

The first step in resolving the board’s role in overseeing cyber-risk is to establish the principles to guide directors’ behaviours and choices. When leading businesses adapt common principles into practices, the practices can, in turn, become widely accepted standards that the business community expects. The ripple effect can be transformative.

Drawing on our experience and knowledge of what works and what has truly made a difference, the World Economic Forum (the Forum), National Association of Corporate Directors (NACD), Internet Security Alliance (ISA), and PwC, in consultation with partner organizations and experts, have joined forces to offer the following set of consensus principles for organizational leaders’ and board members’ use. Ask these questions about your current practices to help you turn each principle into actions that can improve governance of cyber-risks.

The principles are the result of years of consultation with board members, security practitioners, academics and government entities from around the world. As such, they aim to constitute a de facto standard of practice for corporate boards seeking to fulfill their fiduciary role in overseeing cyber-risk.

In-depth handbooks that adapt these principles and provide real-world examples from our partners will be available as part of the full publication.

1. Cybersecurity is a strategic business enabler

Cybersecurity is more than just an IT issue

Strong, effective cybersecurity adds value to the business. Controlling cyber-risk means coordinating and collaborating with business units throughout the enterprise, including the CEO and the board. This ensures the entire enterprise, not just the IT department, is addressing cyber-risk. Further, organizations must instill a culture of cybersecurity by modelling good cyber decision-making:

• Are all executives – the entire C-suite – required to consider the cybersecurity implications of their activities?

• Has your organization discussed how to use cybersecurity as a market differentiator and business driver?

2. Align cyber-risk management with business needs

Boards should understand and assess how cyber-risks are effectively managed to pursue business objectives

By focusing on how cyber-risks impact their business and how to deal with them (by accepting, transferring, avoiding, or mitigating them), organizations can build a security profile that meets the needs of the business. Strategic leadership means ensuring that cyber-risk management conforms to business objectives with every decision, in mergers and acquisitions, digitizing the business, innovation and all other areas.

• Who is the “owner” of cyber-risk in your organization? The business or the security function?

• Are all business units required to report on key cyber-risks and response strategies?

• Is cyber-risk considered in all significant business decisions, such as launching a new product or publishing an app?

3. Understand the economic impact of cyber-risk

Enterprise decision-making requires analysis of the economic impact of cybersecurity choices

For effective business decisions, organizational risk assessments should weigh the costs of cybersecurity against strategic objectives, regulatory and statutory requirements, business outcomes, and the costs associated managing that risk. More than half (55%) of 3,249 business and tech/security executives lack confidence that cyber spending is aligned to the most significant risks, according to PwC’s Global Digital Trust Insights 2021.

Executives remain unconvinced that cybersecurity budgets are currently well-deployed
Executives remain unconvinced that cybersecurity budgets are currently well-deployed Image: PwC

• Does your organization apply a consistent framework for calculating the economic impact and likelihood of cybersecurity events?

• Do business decisions consider the costs of compromise on cybersecurity?

• Has your organization set its cyber-risk appetite in the context of the company’s realistic vulnerabilities and strategic goals?

4. Ensure organizational design supports cybersecurity

Organizational structure should support security and strategic goals

Organizations should design an internal governance structure that addresses cybersecurity throughout the enterprise. Clearly define who’s accountable for critical actions and design cybersecurity practices into how the business operates and makes decisions.

• When was the last time you reviewed your organizational structure to ensure that the cybersecurity function is adequately represented throughout the business?

• Which officer has authority and accountability for coordinating cyber-risk strategy throughout the organization? Are they in a senior enough position?

5. Incorporate cybersecurity expertise into board governance

Boards need diverse sources of cybersecurity expertise

In 2020, 28% of S&P 500 companies reported that a member of the board of directors was a cybersecurity expert, up from 23% in 2019 and 7% in 2013. To provide proper oversight of the enterprise’s cybersecurity program, the board needs to understand common risks, challenges, and failures. To educate themselves, directors may consult industry and other guidance, board peers and third parties, and internal resources.

• Does your board have the right relationships inside and outside the organization to build their security knowledge?

• How many, if any, board members have cyber expertise?

• How often do you get input from third-party experts and assessors, who report to the board, to ensure effective oversight of management?

6. Foster systemic resilience and collaboration

Boards can take the lead in improving the cyber-resilience of industries and sectors

It takes a virtual village to fight cybercrime. Recent events have taught us that even the best cybersecurity-focused companies can be compromised by a sophisticated actor. Knowing that it is a matter of when, not if, attackers will be successful, it is important to be ready to respond and limit the damage of any attack. Security breaches may affect an entire sector and working with peers and even competitors can be crucial for systemic, industry-wide resilience. Stress-testing resilience plans is one of the lasting lessons from the pandemic. Risk leaders in the US say that in 2021, stress-testing will become more frequent and commonplace, both internally and externally. Boards can set the tone at the top for how inter-organizational relationships should look and set the expectation of management for cyber-risk collaboration.

Frequent stress-testing will be necessary to ensure the cyber-resilience of different business sectors
Frequent stress-testing will be necessary to ensure the cyber-resilience of different business sectors Image: PwC

• How well do you collaborate with peers, including other board members, to raise the baseline cybersecurity of the industry as a whole?

• Does your organization interact with its public-sector counterparties to understand the resilience issues facing the industry?

What is the World Economic Forum doing on cybersecurity

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. We are an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors. We bridge the gap between cybersecurity experts and decision makers at the highest levels to reinforce the importance of cybersecurity as a key strategic priority. World Economic Forum | Centre for Cybersecurity

Our community has three key priorities:

Strengthening Global Cooperation – to increase global cooperation between public and private stakeholders to foster a collective response to cybercrime and address key security challenges posed by barriers to cooperation.

Understanding Future Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies, and accelerate forward-looking solutions.

Building Cyber Resilience – to develop and amplify scalable solutions to accelerate the adoption of best practices and increase cyber resilience.

Initiatives include building a partnership to address the global cyber enforcement gap through improving the efficiency and effectiveness of public-private collaboration in cybercrime investigations; equipping business decision makers and cybersecurity leaders with the tools necessary to govern cyber risks, protect business assets and investments from the impact of cyber-attacks; and enhancing cyber resilience across key industry sectors such as electricity, aviation and oil & gas. We also promote mission aligned initiatives championed by our partner organizations.

The Forum is also a signatory of the Paris Call for Trust and Security in Cyberspace which aims to ensure digital peace and security which encourages signatories to protect individuals and infrastructure, to protect intellectual property, to cooperate in defense, and refrain from doing harm.

For more information, please contact us.

Equipped with the right strategy, one that understands the centrality of cyber-risk to doing business in the 21st century, boards will be able to be more effective leaders in the future. By following these principles, the NACD, ISA and the Forum agree that boards will begin the journey that leads to more cyber-resilient and innovative companies.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Bahrain and US float Security Council resolution on the Strait of Hormuz

This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
© CDC An enhanced microscopic image shows the Hantavirus.

Hantavirus outbreak: Another passenger contracts disease

This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
This article is published in association with United Nations.

UN warns of worsening human rights crisis in Mali after deadly attacks

This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]
© ADB/Ariel Javellana Women farmers in India sell wheat grain and buy fertilizer with the proceeds.

Middle East crisis puts aid, food, fuel further out of reach for millions already struggling – UN agencies

This article is published in association with United Nations. As the Middle East crisis continues the humanitarian fallout is worsening, with aid route disruptions and food and fuel price hikes wrecking the lives and the rights of the most vulnerable people worldwide, UN agencies warned on Friday. Heightened insecurity and instability around key Gulf routes, including […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com