How to align cyber risk management with business needs

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Sander Zeijlemaker, Research Affiliate Cybersecurity, MIT Sloan (CAMS), Managing Director, Disem Institute, Michael Siegel, Principal Research Scientist and Director, MIT CAMS, Daniel Goldsmith, Managing Director, Julius Education, Shaharyar Khan, Research Affiliate, MIT CAMS, System Engineer, Shell


  • Living in an advanced digital society means that organizations need to have an in-depth understanding of cybersecurity in order to take effective action.
  • The dynamic nature of cyber risk means that boards of directors must take a multi-dimensional approach in order to mitigate any potential impact.
  • Leaders can develop better foresight to manage cyber risk through exploratory and interactive technology solutions, such as MIT CAMS.

We live in an advanced digital society, in which technological developments are evolving rapidly – with powerful networks, increasing interconnectedness, and highly automated concepts such as e-health, smart cities, and the Fourth Industrial Revolution playing increasingly prominent roles.

This rise of such technologies means that cybersecurity is an extremely important and growing precondition for a successfully functioning society.

Our new digital reality requires business leaders to adequately assess and govern cyber risk and executive decision-makers are needed, to have a strong understanding of cyber risk concepts and issues in order to take effective action.

However, both the dynamic nature of cyber risk and exponential growth in cyber attacks can introduce challenges in decision-making.

To that end, the World Economic Forum and its partners, in collaboration with the National Association of Corporate Directors (NACD), Internet Security Alliance (ISA) and PwC, have published six Principles for Board Governance of Cyber Risk to enable organizations to better manage and understand how to navigate cyber risk-related strategic and operational choices.

A key principle in this guidance is that boards of directors must “align cyber-risk management with business needs” across every facet of decision-making, including innovation, mergers and acquisitions, product development and more.

Exposure to cyber risk threatens reputation and customer trust

Leaders routinely face difficult decisions in managing cyber risk, as exposure to cyber risk may threaten reputation, customer trust and competitive positioning, and possibly result in fines and lawsuits.

In this context, leaders must cope simultaneously with shifting organizational priorities, changing budgets, technologies and employee headcounts as well as evolving adversary tactics and emerging security events, among other things.

This complexity as a whole is referred to as the dynamic nature of cyber risk.

However, executive decision-makers are often overwhelmed by the complexity and pressure to act when dealing with cyber risk issues and in such situations, the risk of security blind spots exist.

Scientific research indicates that 56% of experienced security specialists and managers take suboptimal decisions and these sub-optimal decisions may yield up to a 200% higher cost base.

Many approaches are available to support business leaders and executives in their role to define and implement a sustainable cybersecurity and cyber resilience strategy.

Examples include periodic risk assessments using industry recognized frameworks – such as NIST Cybersecurity framework, C2M2 and ISO 27001 – or execution of cyber event simulations and exercises.

Risk assessment is the process of identifying cyber risk and evaluating the consequences of these risks when they happen.

Cyber event simulations and exercises are techniques that mimics cyber attacks in a controlled manner. Often, they appear as tabletop exercises or approved predefined attacks against the defender’s infrastructure.

Although these activities are helpful in establishing a baseline for cyber risk management, the dynamic nature of cyber risk is not captured. They can be best described as a one-dimensional approach, resulting in decision-makers frequently underestimating risk.

In their most advanced form, these activities can capture the near real-time situation, while business leaders and executives also have a need to see what the future outcome of their intended decisions.

Therefore, forecasting decision support systems for cyber risk management are needed. These systems require dealing with multi-dimensional dynamic problems, such as dynamic nature of cyber risk, and nonlinear variables, like the exponential increase in cyber attacks, so that they can represent the organizations that are managed.

Forward-looking cyber risk management decision support system

MIT CAMS has developed a cyber risk dashboard that provides the means to establish forward-looking projections on multiple critical performance indicators relevant to an organization’s cybersecurity strategy because there was a lack of solutions that captures the dynamic nature of cyber risk.

The MIT CAMS dashboard accounts for the dynamic nature of cyber risk as it is supported by scientifically-grounded computational modelling. The simulation is based on control theory and uses stocks and flows determined by differentially equations to represent the actions of people, process and technology in an organization.

It considers the dynamic effects as well as the interdependency of various security efforts, enabling strategic and effective cyber risk management decision-making.

The dashboard focuses on a highly innovative approach that enables leaders to simulate the impact of their decisions before making large investments. It exists to determine what areas organizations want to optimize when it comes to prioritization.

An anonymized exploratory case study leveraging the CAMS dashboard was conducted at a Fortune-500 company called Smart Wealth Management Inc.

As part of the case study, common managerial challenges such as resource allocation and budget prioritization were selected as levers to analyze their impact on cyber risk management decisions and the broader cybersecurity strategy.

This was done as the CAMS dashboard mimics a real-life decision-making environment in a safe and isolated testing, or sandbox, environment. This provides leaders the means to explore and experiment with a wide range of strategic decisions without true cyber impact on the organization.

Poor cyber risk management can negatively impact an organization

An important lesson from the case study was that poor cyber risk management decisions can impact and cripple the entire organization. Effective interventions need to consider the interconnectedness of decisions and the interactions between different mechanisms and departments prevalent in the organization.

Another important lesson from the case study was that traditional approaches can be augmented by the CAMS dashboard.

In our case study, we used Smart Wealth Management’s existing cyber risk reports and assessments to populate the model parameters for simulation and analysis.

This approach has sustainable advantages for executives as they can:

  • Visualize how their strategic choices will evolve in real life through organizational-specific simulations.
  • Observe how strategic choices can contribute to maintain the organization’s risk appetite.
  • Prioritize cyber budgets and resource allocation to ensure timely risk response.
  • Identify counterintuitive strategies that maximize the benefits of cyber risk management decisions.

Executives must do more on managing and mitigating cyber risk

Ongoing exponential growth in cyber attacks presses executive decision-makers more to stay ahead of the curve.

Reacting after the fact can be very costly and increase needs for regulatory ex-post evaluation and sanctioning. We see and understand that cyber risk is dynamic in nature, and now we must act on it.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. The centre is an independent and impartial platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors.

Since its launch, the centre has driven impact throughout the cybersecurity ecosystem:

Contact us for more information on how to get involved.

Through exploratory and interactive technology solutions, leaders can develop better foresight to manage economic aspects of cyber risk and alignment to business needs.

The CAMS dashboard is leading example of this direction.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© WFP/Maxime Le Lijour People living in Gaza have received humanitarian aid from the UN throughout the conflict with Israel.

UN relief chief condemns ‘$1 billion-a-day’ cost of war in Middle East

This article is published in association with United Nations. The UN’s emergency relief chief on Wednesday condemned the “$1 billion-a-day” cost of the war in the Middle East, at a time when humanitarian needs are soaring and aid funding is falling dangerously short. “We’re seeing the consequences spread faster than we can respond”, warned the UN emergency […]
© UNICEF/Azizullah Karimi Afghan returnees from Iran gather at the Islam-Border, near Herat in western Afghanistan (file).

‘Toxic rain’ warning from oil depot strikes amid ongoing Middle East war

This article is published in association with United Nations. Toxic “black rain” linked to strikes on oil depots, mass displacement and continuing disruption to aid supply chains are upending lives across the Middle East and beyond after 10 days of war in the region, UN humanitarians said on Tuesday.  Speaking to reporters in Geneva, UN Human […]
© UNHCR People gather at the Masnaa border point in Lebanon as they wait to cross into Syria.

Nearly 700,000 displaced in Lebanon as Middle East crisis escalates

This article is published in association with United Nations. On day 10 of the war engulfing the Middle East, UN agencies on Monday reported massive displacement across the region, along with surging food and fuel prices that risk increasing hunger and suffering for the most vulnerable. In Lebanon alone, nearly 700,000 people including around 200,000 children […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

Lebanon ‘dragged back into turmoil’, UN envoy warns

This article is published in association with United Nations. Lebanon has been “dragged back into a state of turmoil and violence”, the UN’s top envoy in the country warned on Saturday, after the latest round of regional strikes triggered a fast‑escalating crisis along the Blue Line. What had been fragile but real momentum, she said, has […]
UNHCR Smoke rises after an airstrike in Beirut, Lebanon.

MIDDLE EAST LIVE: Strikes continue across Middle East as humanitarian concerns grow

This article is published in association with United Nations. Highlights Production team: Vibhu Mishra with Daniel Johnson in GenevaToday 12:15 μ.μ. UN rights office warns displacement orders in Lebanon affecting hundreds of thousands The UN human rights office has warned that large-scale displacement orders and ongoing airstrikes in Lebanon are worsening the suffering of civilians already affected […]
© UNICEF/Ramzi Haidar Destroyed buildings and debris in the southern suburbs of Beirut, Lebanon, following airstrikes.

MIDDLE EAST LIVE: Further escalation drives uncertainty and suffering

This article is published in association with United Nations. On day six of the war in the Middle East, there’s been no let-up in bombs, drones and rockets targeting Iran, Israel, Lebanon and many Gulf States, while NATO forces reportedly intercepted a missile fired at Türkiye by Iran, a claim denied by Tehran. We’ll bring you […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

MIDDLE EAST LIVE: Conflict continues across region amid US, Israeli and Iranian strikes

This article is published in association with United Nations. Violence in the Middle East is continuing into a fifth day, with US and Israeli strikes against Iran and Iranian missile and drone attacks reported across several countries in the region. The escalating confrontation is disrupting airspace, transport and daily life while raising fears of a wider […]
© IAEA/Paolo Contri The Bushehr Nuclear Power Plant in Iran.

Iran crisis: Schoolgirls killed, thousands displaced and aid compromised

This article is published in association with United Nations. On the fourth day of Israeli and United States airstrikes against Iran and amid growing violence and instability in the Middle East, the UN urgently called for protection of civilians and warned of growing displacement and humanitarian needs. UN human rights office spokesperson Ravina Shamdasani also recalled […]
© Unsplash/Kamran Gholami Tehran, the capital of Iran. (file photo)

MIDDLE EAST LIVE: Strikes continue from US, Israel and Iran as UN urges restraint

This article is published in association with United Nations. Violent escalation in the Middle East has entered a third day as coordinated US and Israeli strikes against Iran aimed at regime change continue to cause loss of life and damage across the region, prompting Iranian missile and drone counter-strikes hitting targets in multiple countries. Explosions, airspace […]
Iran attacks

Deadly bombing of Iran primary school ‘a grave violation of humanitarian law’: UNESCO

This article is published in association with United Nations. The UN education agency, UNESCO, says that the bombing of a primary school during the US and Israeli military attacks on Iran on Saturday constitutes a grave violation of humanitarian law. The missiles reportedly destroyed a girl’s primary school in Minab, southern Iran, killing around 150 and […]
© UNRCO Iran Tehran, the capital of Iran.

Attacks on Iran and retaliatory strikes ‘undermine international peace and security’

This article is published in association with United Nations. UN Secretary-General António Guterres and the heads of UN agencies have condemned Saturday’s joint Israeli and US attacks on Iran and the Iranian retaliatory strikes on Israel and the Gulf Regions. The attack on Iran reportedly targeted military sites as well as the leadership of the Iranian […]
© WFP/Maxime Le Lijour A woman holds a child as a storm approaches Khan Younis in Gaza.

Palestine: UN rights chief highlights suffering, atrocity crimes ‘that remain unpunished

This article is published in association with United Nations. The UN rights chief Volker Türk on Thursday highlighted the “human-made disaster” across the Occupied Palestinian Territory stemming from Israel’s disregard for human rights norms and serious violations also committed by Hamas and other Palestinian armed groups. Citing a new report from his office (OHCHR) covering the […]
Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia.

Not the Future, the Present: Young Voices Shaping Global Health in 2026

This article was exclusively written for The European Sting by Ms. Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to […]
© UNOCHA Many rural areas of Ukraine have been blasted by shelling and drone strikes. The country is also one of the most mined in the world, top UN aid officials warn.

Ukraine wakes to more violence as Russia’s invasion enters fifth year

This article is published in association with United Nations. The full-scale invasion of Ukraine by Russian troops on 24 February 2022 shattered the peaceful aspirations of an entire continent, but war must never be the new normal, UN General Assembly President Annalena Baerbock said on Tuesday. “Four years ago, people in Europe woke up in another […]
Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

From Local Barriers to Global Lessons: Practical Paths Toward Inclusive Healthcare

This article was exclusively written for The European Sting by Ms. Zainatun Nawwariyah is a fifth-year medical student at the Faculty of Medicine, University of North Sumatera, who is passionate about advancing medicine through research, advocacy, and service. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed […]
© UNICEF/Bullen Chol A grandmother takes care of her 17-month-old malnourished grandson in South Sudan.

World News in Brief: UN humanitarian chief visits South Sudan, shelter fire risks in Gaza, West Bank violence

This article is published in association with United Nations. The UN Emergency Relief Coordinator arrived in South Sudan on Friday to visit one of the most under-reported humanitarian crises in the world, as clashes between government and opposition forces continue in Jonglei state.  Tom Fletcher will focus on the deteriorating humanitarian situation in the world’s youngest country and escalating protection risks for both civilians and aid workers.  […]
Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

This article is published in association with United Nations. Four years into Russia’s full-scale invasion, millions in Ukraine struggle to keep the lights on and heat their homes, with the crisis taking a particular toll on women, humanitarians warned on Friday. Freshly back from a visit to the country UN Women’s Chief of Humanitarian Action Sofia […]
Fears of ethnic cleansing in Gaza and the West Bank: UN rights report

Fears of ethnic cleansing in Gaza and the West Bank: UN rights report

This article is published in association with United Nations. Increased Israeli attacks and the forced transfer of Palestinians have sparked concern over ethnic cleansing in the Gaza Strip and the West Bank, the UN human rights office, OHCHR, said in a report issued on Thursday.  The report covers the period from 1 November 2024 to 31 October 2025 and is […]
Samaya Rahimova  is a public health student at the Azerbaijan Medical University and an active member of SCOPH at Azermeds

Inclusive Healthcare Fails When We Design for the “Average Patient”

This article was exclusively written for The European Sting by Ms. Samaya Rahimova , a public health student at the Azerbaijan Medical University and an active member of SCOPH at Azermeds. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer […]

Trackbacks

  1. […] How to align cyber risk management with business needs  The European Sting […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com