4 ways to incorporate cyber resilience in your business

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Joe Nocera, Cyber and Privacy Innovation Institute Leader, PwC US


  • Cybersecurity is a major concern for all organizations and collaboration is key to effectively tackle this threat.
  • A report on Cyber Governance by the World Economic Forum, PwC, the National Association of Corporate Directors, and the Internet Security Alliance looks at how board directors can manage cyber risks.
  • Here we explore how companies can accomplish cyber resilience through collaboration.

One goal, one team.

Effective cybersecurity has become a shared responsibility that demands teamwork and an unwavering commitment to internal and external collaboration.

Today, threat actors are targeting organizations and entire industries with increasingly effective cyberattacks. Cybersecurity failure has become a leading threat, according to the World Economic Forum’s Global Risk Report 2022. Businesses agree: 70% of board directors view cybersecurity as a strategic enterprise risk, according to a survey conducted by the National Association of Corporate Directors (NACD).

The ascendant trajectory of cybercrime shows no sign of decline.In fact, 60%of executives forecast that cybercrime will continue to surge in 2022. In particular, respondents expect more attacks on cloud services, ransomware intrusions, and compromises of critical infrastructure. Threat actors are also exploiting dangerous new software vulnerabilities such as the Log4j flaw, which can enable them to remotely execute code on systems and networks. There is also growing unease that geopolitical conflict will likely result in further cyberattacks on critical infrastructure.

In a report published by the World Economic Forum, PwC, the NACD, and the Internet Security Alliance (ISA), we identified six principles that can support board directors in governing cyber-risks:

  • Cybersecurity is a strategic business enabler
  • Understand the economic drivers and impact of cyber-risk
  • Align cyber-risk management with business needs
  • Ensure organizational design supports cybersecurity
  • Incorporate cybersecurity expertise into board governance
  • Encourage systemic resilience and collaboration

In this article, we dive into the sixth principle: encourage systemic resilience and collaboration. Systemic risks require systemic resilience. This requires a decisive dedication to collective effort — and a great deal of individual resilience.

The good news? There are “power moves” you can incorporate to start building resilience in your organization.

Become a cybersecurity team player

Effective cybersecurity comes from the top. The CEO, board, and other senior leaders should champion a cybersecurity culture that fosters collaboration across the company, the industry and with public and private stakeholders.

Creating a culture of security will require everyone’s involvement — the board, C-suite, chief information security officers (CISOs), line of business leaders, and individual employees. You will also need to partner with supply chains, contractors, and other third parties.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. The centre is an independent and impartial platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors.

Since its launch, the centre has driven impact throughout the cybersecurity ecosystem:

Contact us for more information on how to get involved.

Given the complexity and stealth of today’s cyber threats, it is likely that boards will need a bit of cybersecurity tutoring. CISOs may need to step in to help senior executives understand threats, potential business impacts and the specific role each executive can play in keeping the company secure.

Awareness doesn’t stop at the C-suite, however. Cybersecurity education should cascade down to every employee and include training, upskilling, and career advancement opportunities.

Educating the board has become urgent thanks to new regulations requiring cyber disclosures. In the US, for example, the Securities and Exchange Commission (SEC) has proposed rules for disclosing material cyber incidents and practices in cyber governance, strategy, and risk management.

The rules may require public companies to disclose details of the board of directors’ oversight of cybersecurity risk and cybersecurity expertise – if any. Disclosures include the processes by which the board is informed about cybersecurity risks and the frequency of its discussions on this topic. A new law requires entities in critical infrastructures to report significant cyber breaches to the Cybersecurity and Infrastructure Security Agency (CISA).

How to make the move
  • Allocate more time to security discussions in board or subcommittee meetings
  • Provide training for board members to become more cyber-savvy
  • Use business language to frame discussions of cyberthreats
  • Create plans for effective collaboration
  • Confirm performance measures for cybersecurity are aligned for all business executives and not just the CISO

Conduct tabletop exercises and update Business Impact Analysis (BIA)

Security training for employees is essential. But resilience calls for more.

Tabletop exercises, which use simulated attacks to illustrate threat response and decision-making processes, can be an effective way for board members to practice the decision-making required in a cyber crisis. Tabletop exercises can prepare business leaders to confidently — and quickly — take appropriate action when real threats are detected. They can illuminate gaps or weaknesses in current response plans.

Similarly, a business impact analysis (BIA) can help organizations develop more targeted and effective strategies for incident response and business continuity. BIAs prioritize business systems, processes, and interdependencies to focus defence, response, and recovery strategies on the issues that matter most to the business.

How to make the move
  • Revisit and update the company’s BIA annually or whenever a major business change occurs
  • Leverage the BIA to inform Cyber Resiliency Planning
  • Conduct tabletop exercises throughout the year at different levels of the organization (technical, business, C-suite and boards) using different threat scenarios
  • Consider including critical third parties like outside counsel and law enforcement in some tabletops

Build relationships with info-sharing groups, law enforcement, and government agencies

If cybercriminals share information on attack techniques and tools — and they do — then why shouldn’t you? Sharing intelligence about cyber threats and responses may be critical to staying ahead of cybercriminals. Companies cannot, single handedly, defend themselves against attacks by powerful hackers.

Critical infrastructure providers, for example, require proactive cooperation and collaboration among governments, cybersecurity groups, industry peers, and organizations to combat geopolitical and nation-state threats.

The practice of cyber-related information-sharing is growing around the world. Today, 84% of global organizations say they participate in public-private information-sharing. Organizations fostering such a culture include the World Economic Forum Centre for Cybersecurity, Interpol, the US CISA, the UK National Cyber Security Centre, and the Open Data Center, where there is global collaboration of over 1,500 governments and organizations.

You should build robust relationships with local, national and global government and law enforcement agencies to promote intelligence sharing. In addition, companies can build ties with nonprofit cybersecurity organizations such as Information Sharing and Analysis Centers (ISACs), some of which offer 24/7 threat warnings, incident reporting capabilities, and networking opportunities.

Sharing requires trust. Organizations are often reluctant to disclose incidents and responses to industry peers and government entities. To create a collective consciousness of cybersecurity, attitudes must change. While private-public collaboration is commonplace — 45% of organizations do so — there is often a reluctance to divulge breached information. That mindset must change.

How to make the move
  • Use all available resources, including government agencies, to identify potential threats
  • Participate in collaborative groups such as the European Union Agency for Network and Information Security (ENISA), Information Systems Security Association (ISSA International), the Cloud Security Alliance, the Internet Security Alliance, and WiCyS Women in Cybersecurity
  • Join information-sharing groups such as the Information Security Forum, the Anti-Phishing Working Group, and ISACs
  • Critical infrastructure providers can join organizations such as the European Programme for Critical Infrastructure protection, the Task Force on Critical Infrastructure Protection, and the DHS Cyber Information Sharing and Collaboration Program (CISCP)
  • Proactively build relationships with law enforcement and government agencies prior to a breach occurring

Discover

How is the World Economic Forum contributing to a more efficient, resilient, inclusive and equitable financial system?

The World Economic Forum’s Platform for Shaping the Future of Financial and Monetary Systems brings together leaders from the banking sector, the insurance industry and fintechs with regulators and governments to work on five areas: Sustainable Finance and Investments; Technology and Innovation; Risk and Resilience; Leadership and Governance; China’s Financial Transformation.

  • The Forum’s Living, Learning and Earning Longer initiative is building multi-generational workforces and giving older workers greater opportunities to work. By collaborating through a unique digital platform that employers can use to find case studies, statistics and research on the advantages of a multi-generational workforce, this could raise GDP per capita by 19% over the next three decades.
  • Illicit proceeds from criminal activity are estimated to account for 2%-5% of global GDP (about $2 trillion). Our Global Coalition to Fight Financial Crime brings together over 100 organizations to raise awareness of how financial laws are violated. Working with financial and non-financial sectors, the coalition recognizes and promotes the importance of emerging technologies and drives change by helping financial institutions.
  • Experts from Zurich Insurance predict that by 2030 cybersecurity costs will reach $1.2 trillion. We have brought together a group of fintechs, financial institutions and regulators to strengthen cybersecurity in financial services. The Cybersecurity Consortium works to ensure global regulatory requirements are synchronized and the security of the financial services supply chain is enhanced.
  • For the private sector to drive progress towards achieving the UN Sustainable Development Goals, a common system of non-financial measurement is essential. To promote alignment among existing ESG frameworks, the Forum worked with partners to draw on existing frameworks and identified a set of universal disclosures – the Stakeholder Capitalism Metrics. During 2021, the Forum announced that over 50 companies have started to incorporate these ESG reporting metrics in their annual reports and sustainability reports.
  • The Forum has developed knowledge products to advise stakeholders on technology-driven systemic risks and the continued need for innovation. By exploring the relationship between increased technology adoption in financial services and systemic risk, the research examines how businesses can act to address identified risks, including the role that technology itself can play in mitigation approaches.

Contact us for more information on how to get involved.

Collaborate on collective cybersecurity

In today’s hyper-connected digital world, cybersecurity is no longer the responsibility of a singular organization or single executive.

Cybersecurity is the ultimate team sport and it is crucial for businesses, industries, and governments to unite to defend against global threat actors.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© World Vision Smoke rises in Beit Mery, close to the Lebanese capital, Beirut, following an airstrike.

Middle East war’s ‘spiral of conflict’ drives mounting civilian toll

This article is published in association with United Nations. The widening war in the Middle East and its growing impact on civilians came under scrutiny at the UN in Geneva on Monday, as independent experts briefing the Human Rights Council warned of escalating violence following the onset of Israeli and US strikes on Iran and counterstrikes […]
© Mousawat A mother and child displaced by the conflict in Lebanon receiving care at a clinic.

Middle East war: Women in Lebanon forced to give birth on roadside

This article is published in association with United Nations. As the UN Secretary-General touched down in Beirut on Friday in solidarity with the people of Lebanon, UN agencies highlighted the dangers for civilians and particularly pregnant women and migrant workers, amid ongoing airstrikes and rocket fire between Hezbollah fighters and Israel.  “There’s 11,600 pregnant women who […]
© WFP/Arete/Ali Yunes Some residents of Beirut who have been displaced by the conflict are now living on the streets of the Lebanese capital.

‘Perfect storm’: Lebanon crisis deepens as civilians bear the brunt

This article is published in association with United Nations. Lebanon is facing a “perfect storm of unpredictable challenges” as conflict, mass displacement and dwindling humanitarian resources converge, the UN’s Resident and Humanitarian Coordinator in Lebanon, Imran Riza, has warned. The current escalation began on 2 March, when outgoing fire by Hezbollah drew a strong retaliation from […]
© WFP/Maxime Le Lijour People living in Gaza have received humanitarian aid from the UN throughout the conflict with Israel.

UN relief chief condemns ‘$1 billion-a-day’ cost of war in Middle East

This article is published in association with United Nations. The UN’s emergency relief chief on Wednesday condemned the “$1 billion-a-day” cost of the war in the Middle East, at a time when humanitarian needs are soaring and aid funding is falling dangerously short. “We’re seeing the consequences spread faster than we can respond”, warned the UN emergency […]
© UNICEF/Azizullah Karimi Afghan returnees from Iran gather at the Islam-Border, near Herat in western Afghanistan (file).

‘Toxic rain’ warning from oil depot strikes amid ongoing Middle East war

This article is published in association with United Nations. Toxic “black rain” linked to strikes on oil depots, mass displacement and continuing disruption to aid supply chains are upending lives across the Middle East and beyond after 10 days of war in the region, UN humanitarians said on Tuesday.  Speaking to reporters in Geneva, UN Human […]
© UNHCR People gather at the Masnaa border point in Lebanon as they wait to cross into Syria.

Nearly 700,000 displaced in Lebanon as Middle East crisis escalates

This article is published in association with United Nations. On day 10 of the war engulfing the Middle East, UN agencies on Monday reported massive displacement across the region, along with surging food and fuel prices that risk increasing hunger and suffering for the most vulnerable. In Lebanon alone, nearly 700,000 people including around 200,000 children […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

Lebanon ‘dragged back into turmoil’, UN envoy warns

This article is published in association with United Nations. Lebanon has been “dragged back into a state of turmoil and violence”, the UN’s top envoy in the country warned on Saturday, after the latest round of regional strikes triggered a fast‑escalating crisis along the Blue Line. What had been fragile but real momentum, she said, has […]
UNHCR Smoke rises after an airstrike in Beirut, Lebanon.

MIDDLE EAST LIVE: Strikes continue across Middle East as humanitarian concerns grow

This article is published in association with United Nations. Highlights Production team: Vibhu Mishra with Daniel Johnson in GenevaToday 12:15 μ.μ. UN rights office warns displacement orders in Lebanon affecting hundreds of thousands The UN human rights office has warned that large-scale displacement orders and ongoing airstrikes in Lebanon are worsening the suffering of civilians already affected […]
© UNICEF/Ramzi Haidar Destroyed buildings and debris in the southern suburbs of Beirut, Lebanon, following airstrikes.

MIDDLE EAST LIVE: Further escalation drives uncertainty and suffering

This article is published in association with United Nations. On day six of the war in the Middle East, there’s been no let-up in bombs, drones and rockets targeting Iran, Israel, Lebanon and many Gulf States, while NATO forces reportedly intercepted a missile fired at Türkiye by Iran, a claim denied by Tehran. We’ll bring you […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

MIDDLE EAST LIVE: Conflict continues across region amid US, Israeli and Iranian strikes

This article is published in association with United Nations. Violence in the Middle East is continuing into a fifth day, with US and Israeli strikes against Iran and Iranian missile and drone attacks reported across several countries in the region. The escalating confrontation is disrupting airspace, transport and daily life while raising fears of a wider […]
© IAEA/Paolo Contri The Bushehr Nuclear Power Plant in Iran.

Iran crisis: Schoolgirls killed, thousands displaced and aid compromised

This article is published in association with United Nations. On the fourth day of Israeli and United States airstrikes against Iran and amid growing violence and instability in the Middle East, the UN urgently called for protection of civilians and warned of growing displacement and humanitarian needs. UN human rights office spokesperson Ravina Shamdasani also recalled […]
© Unsplash/Kamran Gholami Tehran, the capital of Iran. (file photo)

MIDDLE EAST LIVE: Strikes continue from US, Israel and Iran as UN urges restraint

This article is published in association with United Nations. Violent escalation in the Middle East has entered a third day as coordinated US and Israeli strikes against Iran aimed at regime change continue to cause loss of life and damage across the region, prompting Iranian missile and drone counter-strikes hitting targets in multiple countries. Explosions, airspace […]
Iran attacks

Deadly bombing of Iran primary school ‘a grave violation of humanitarian law’: UNESCO

This article is published in association with United Nations. The UN education agency, UNESCO, says that the bombing of a primary school during the US and Israeli military attacks on Iran on Saturday constitutes a grave violation of humanitarian law. The missiles reportedly destroyed a girl’s primary school in Minab, southern Iran, killing around 150 and […]
© UNRCO Iran Tehran, the capital of Iran.

Attacks on Iran and retaliatory strikes ‘undermine international peace and security’

This article is published in association with United Nations. UN Secretary-General António Guterres and the heads of UN agencies have condemned Saturday’s joint Israeli and US attacks on Iran and the Iranian retaliatory strikes on Israel and the Gulf Regions. The attack on Iran reportedly targeted military sites as well as the leadership of the Iranian […]
© WFP/Maxime Le Lijour A woman holds a child as a storm approaches Khan Younis in Gaza.

Palestine: UN rights chief highlights suffering, atrocity crimes ‘that remain unpunished

This article is published in association with United Nations. The UN rights chief Volker Türk on Thursday highlighted the “human-made disaster” across the Occupied Palestinian Territory stemming from Israel’s disregard for human rights norms and serious violations also committed by Hamas and other Palestinian armed groups. Citing a new report from his office (OHCHR) covering the […]
Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia.

Not the Future, the Present: Young Voices Shaping Global Health in 2026

This article was exclusively written for The European Sting by Ms. Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to […]
© UNOCHA Many rural areas of Ukraine have been blasted by shelling and drone strikes. The country is also one of the most mined in the world, top UN aid officials warn.

Ukraine wakes to more violence as Russia’s invasion enters fifth year

This article is published in association with United Nations. The full-scale invasion of Ukraine by Russian troops on 24 February 2022 shattered the peaceful aspirations of an entire continent, but war must never be the new normal, UN General Assembly President Annalena Baerbock said on Tuesday. “Four years ago, people in Europe woke up in another […]
Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

From Local Barriers to Global Lessons: Practical Paths Toward Inclusive Healthcare

This article was exclusively written for The European Sting by Ms. Zainatun Nawwariyah is a fifth-year medical student at the Faculty of Medicine, University of North Sumatera, who is passionate about advancing medicine through research, advocacy, and service. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed […]
© UNICEF/Bullen Chol A grandmother takes care of her 17-month-old malnourished grandson in South Sudan.

World News in Brief: UN humanitarian chief visits South Sudan, shelter fire risks in Gaza, West Bank violence

This article is published in association with United Nations. The UN Emergency Relief Coordinator arrived in South Sudan on Friday to visit one of the most under-reported humanitarian crises in the world, as clashes between government and opposition forces continue in Jonglei state.  Tom Fletcher will focus on the deteriorating humanitarian situation in the world’s youngest country and escalating protection risks for both civilians and aid workers.  […]

Comments

  1. The leading factor in my opinion, is budgeting and resources. Cyber resilience even for mature cybersecurity programs is challenging to accomplish. It takes at least three years to obtain goals on information security program. Also, designing and maintain a penetration resistance architecture has a high maintenance. If it’s not upgraded with current threats landscape, it will lose its value and decay. Hence, lowering the effect of cyber resilience for the company.

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com