A cyber risk balance sheet can protect your organization. Here’s how

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Joshua Jaffe, Vice President Cyber Security, Dell Technologies & Nisha Almoula, Cybersecurity, Risk and Regulatory Senior Manager, PwC


  • Cyberattacks are on the rise but many organizations are ill-equipped to deal with threats.
  • A cyber risk balance sheet documents the cyber events that could have a financial impact on an organization.
  • A new report outlines how organizations can more effectively manage and understand the economics of cyber risk.

Every day, we read new headlines about cybercrime or hear reports of a new data breach, and all data indicates that the number of hackers is growing. When one considers the exponential growth of data and network-connected sensors and combines this with the power of AI, automation, augmented reality, implantable medical devices, and autonomous vehicles – it becomes immediately clear that this problem must be put on a different trajectory.

Yet, even with cyberattacks increasing in frequency and the damages growing in terrifying complexity, it remains a challenge for organizations to know how to best prepare for and mitigate against these attacks. The problem is that organizations find it hard to balance cyber risks against their actions. Often, cyber risks are underestimated or misunderstood by organizations.

Investments in cyber are viewed as a tradeoff against investments in product R&D, employee welfare or shareholder returns. The truth, however, is that all these investments should be considered holistically. To that end, the World Economic Forum, and its partners, in collaboration with the NACD, ISA, and PwC, have published Principles for Board Governance of Cyber Risk to enable organizations to better manage and understand how to navigate the invisible ledger of cyber risks that continue to grow. A key principle in this guidance is that boards of directors must “understand the economic drivers and impact of cyber risk.”

Global risks horizon: when will risks become a critical threat to the world? Credit: World Economic Forum Global Risk Report 2022.
Global risks horizon: when will risks become a critical threat to the world? Credit: World Economic Forum Global Risk Report 2022.

As board members’ understanding of the economics of cyber risk evolves, they will be empowered to drive risk-based decisions and lead organizations to combat cyber events. According to a 2022 PwC survey, 42.5% of global organizations have stated they have made significant progress in increasing their assessment of the board’s understanding of cyber matters.

How can a cyber risk balance sheet offer protection?

Developing a cyber risk balance sheet is one “power move” that leaders can make to immediately improve their cyber risk decision making. The simple shift in risk thinking and corporate behavior aligns cyber hygiene with the existing corporate risk management machinery in a way that creates a deeper understanding, incentivizes smart investments, and rewards good behavior. The cyber risk balance sheet power move does this by making the invisible ledger of cyber risks visible.

If you are a board member, encourage your cyber leaders to task their teams with creating and quantifying a cyber risk balance sheet that documents the cyber events that could have a material impact on the organization in financial terms. The key steps in developing a cyber risk balance sheet are as follows:

  • Define a cyber risk quantification framework customized to your organization’s risk profile. This can be developed leveraging Factor Analysis of Information Risk (FAIR), in conjunction with other industry guidelines such as NIST SP 800-53 and ISO 27005. FAIR leverages scenario modeling to support organizations in compiling various risk factors, identifying their correlation, and quantifying financial impact.
  • Identify key cyber threats relevant to your organization and evaluate the probability of the threat, critical assets, and the effectiveness of cyber controls in place to mitigate against these threats.
  • Consolidate a balance sheet that maps the probability of in scope cyber threats to cyber risks in financial terms and associated planned or existing cyber investments.

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. The centre is an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors.

Since its launch the centre has driven impact throughout the cybersecurity ecosystem:

Contact us for more information on how to get involved.

Once the balance sheet is complete, have periodic discussions and reviews where the financial cost of cyber risks serves as the framework to understanding and translating the inherent consequence of the bottom line. This ledger can be used to evaluate the efficacy of current security investments and demand that chief information security officers (CISO) explain their business case for new cyber investment in terms that show a positive ROI. For example, investment in a security control will cost $2.5 million over the next three years, but it buys down $7 million of cyber risk on the cyber risk balance sheet.

Key considerations when implementing a cyber risk balance sheet

  • Hold your teams accountable to outcomes and demand a return on capital in the form of real risk reduction.
  • Empower security leaders to challenge themselves to really get to know the business and create allies within the business units by helping them reduce the risk of a cyber catastrophe that may impact their bottom line.
  • Embrace questions challenging the calculations and recognize that this is fostering engagement from business functions to help advocate for security.
  • Encourage security leaders to validate the risk values by collaborating with the CFO or ERM teams to review and vet the aggregate risk entries and increase their investment in the outcomes.

Enhance collaboration across the CISO, chief technology officer (CTO), and chief information officer (CIO) functions by involving the CTO and CIO teams in providing feedback on the likelihood and impact analysis done for each cyber scenario to further iterate on the estimates and balance sheet data.

Once the balance sheet is developed, and there is agreement across the organization’s leaders on the numbers, the security team should continue to iterate on the sheet to incorporate additional scenarios and evaluate business cases for every investment in a cyber control. This framework will support the organization to demand better leverage from existing cyber investments as well as retire antiquated cyber capabilities that may have consumed valuable talent and capital past their usefulness.

Future-proofing your organization

This power moveworks within organizations due to its simplicity and instead of promoting fear, it invites an understanding through transparency of the existing cyber risk. It creates a framework for leaders to engage in the solution using a language they all understand – the language of business. According to a 2022 PwC survey, 76.5% of global organizations have stated they have made moderate to significant progress in increasing the number of business decisions that involved input from the enterprise security management team. Regardless of the industries and verticals in which an organization operates, all corporate officers take pride in the value they create and are cognizant of the threats to that value.

The cyber risk balance sheet promotes trust through transparency and a stronger partnership between security, technology, and revenue generating functions of the business by aligning the interests of the company with the people protecting it.

There are several risks businesses must combat and the risks in cyberspace are growing every day. But what is often true in the physical world is also true in cyberspace – knowledge brings power. The more boards know and understand about the cyber risks and economic impact to their businesses, the better they can manage them.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

This article is published in association with United Nations.

UN agencies step up Ebola response in eastern DR Congo

This article is published in association with United Nations. United Nations agencies have moved swiftly to support efforts to contain the latest Ebola outbreak in eastern Democratic Republic of the Congo (DRC), delivering emergency medical supplies, protective equipment and logistics support. As health authorities in both the DRC and Uganda respond to the deadly resurgence, the […]
© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Bahrain and US float Security Council resolution on the Strait of Hormuz

This article is published in association with United Nations. Bahrain and the United States have circulated a draft Security Council resolution calling for Iran to cease attacks in the Strait of Hormuz, their ambassadors outlined to journalists at UN Headquarters in New York on Thursday. The text is supported by Kuwait, Qatar, Saudi Arabia and the […]
© CDC An enhanced microscopic image shows the Hantavirus.

Hantavirus outbreak: Another passenger contracts disease

This article is published in association with United Nations. It’s been confirmed that another passenger from the cruise liner linked to the outbreak of hantavirus has contracted the disease, which has claimed the lives of three people on board and sparked an international alert coordinated by the UN World Health Organization (WHO). The individual, who is […]
This article is published in association with United Nations.

UN warns of worsening human rights crisis in Mali after deadly attacks

This article is published in association with United Nations. The human rights situation in Mali is rapidly deteriorating following coordinated attacks by armed groups across the country, with civilians killed, displaced and cut off from food and aid, UN rights office OHCHR said on Tuesday. The violence, which erupted on 25 and 26 April, saw large-scale […]
© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]

Comments

  1. Cybersecurity is one of the most important layers of protection that any business can benefit from. This is great insight to have!

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com