How to align cyber risk management with business needs

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Sander Zeijlemaker, Research Affiliate Cybersecurity, MIT Sloan (CAMS), Managing Director, Disem Institute, Michael Siegel, Principal Research Scientist and Director, MIT CAMS, Daniel Goldsmith, Managing Director, Julius Education, Shaharyar Khan, Research Affiliate, MIT CAMS, System Engineer, Shell


  • Living in an advanced digital society means that organizations need to have an in-depth understanding of cybersecurity in order to take effective action.
  • The dynamic nature of cyber risk means that boards of directors must take a multi-dimensional approach in order to mitigate any potential impact.
  • Leaders can develop better foresight to manage cyber risk through exploratory and interactive technology solutions, such as MIT CAMS.

We live in an advanced digital society, in which technological developments are evolving rapidly – with powerful networks, increasing interconnectedness, and highly automated concepts such as e-health, smart cities, and the Fourth Industrial Revolution playing increasingly prominent roles.

This rise of such technologies means that cybersecurity is an extremely important and growing precondition for a successfully functioning society.

Our new digital reality requires business leaders to adequately assess and govern cyber risk and executive decision-makers are needed, to have a strong understanding of cyber risk concepts and issues in order to take effective action.

However, both the dynamic nature of cyber risk and exponential growth in cyber attacks can introduce challenges in decision-making.

To that end, the World Economic Forum and its partners, in collaboration with the National Association of Corporate Directors (NACD), Internet Security Alliance (ISA) and PwC, have published six Principles for Board Governance of Cyber Risk to enable organizations to better manage and understand how to navigate cyber risk-related strategic and operational choices.

A key principle in this guidance is that boards of directors must “align cyber-risk management with business needs” across every facet of decision-making, including innovation, mergers and acquisitions, product development and more.

Exposure to cyber risk threatens reputation and customer trust

Leaders routinely face difficult decisions in managing cyber risk, as exposure to cyber risk may threaten reputation, customer trust and competitive positioning, and possibly result in fines and lawsuits.

In this context, leaders must cope simultaneously with shifting organizational priorities, changing budgets, technologies and employee headcounts as well as evolving adversary tactics and emerging security events, among other things.

This complexity as a whole is referred to as the dynamic nature of cyber risk.

However, executive decision-makers are often overwhelmed by the complexity and pressure to act when dealing with cyber risk issues and in such situations, the risk of security blind spots exist.

Scientific research indicates that 56% of experienced security specialists and managers take suboptimal decisions and these sub-optimal decisions may yield up to a 200% higher cost base.

Many approaches are available to support business leaders and executives in their role to define and implement a sustainable cybersecurity and cyber resilience strategy.

Examples include periodic risk assessments using industry recognized frameworks – such as NIST Cybersecurity framework, C2M2 and ISO 27001 – or execution of cyber event simulations and exercises.

Risk assessment is the process of identifying cyber risk and evaluating the consequences of these risks when they happen.

Cyber event simulations and exercises are techniques that mimics cyber attacks in a controlled manner. Often, they appear as tabletop exercises or approved predefined attacks against the defender’s infrastructure.

Although these activities are helpful in establishing a baseline for cyber risk management, the dynamic nature of cyber risk is not captured. They can be best described as a one-dimensional approach, resulting in decision-makers frequently underestimating risk.

In their most advanced form, these activities can capture the near real-time situation, while business leaders and executives also have a need to see what the future outcome of their intended decisions.

Therefore, forecasting decision support systems for cyber risk management are needed. These systems require dealing with multi-dimensional dynamic problems, such as dynamic nature of cyber risk, and nonlinear variables, like the exponential increase in cyber attacks, so that they can represent the organizations that are managed.

Forward-looking cyber risk management decision support system

MIT CAMS has developed a cyber risk dashboard that provides the means to establish forward-looking projections on multiple critical performance indicators relevant to an organization’s cybersecurity strategy because there was a lack of solutions that captures the dynamic nature of cyber risk.

The MIT CAMS dashboard accounts for the dynamic nature of cyber risk as it is supported by scientifically-grounded computational modelling. The simulation is based on control theory and uses stocks and flows determined by differentially equations to represent the actions of people, process and technology in an organization.

It considers the dynamic effects as well as the interdependency of various security efforts, enabling strategic and effective cyber risk management decision-making.

The dashboard focuses on a highly innovative approach that enables leaders to simulate the impact of their decisions before making large investments. It exists to determine what areas organizations want to optimize when it comes to prioritization.

An anonymized exploratory case study leveraging the CAMS dashboard was conducted at a Fortune-500 company called Smart Wealth Management Inc.

As part of the case study, common managerial challenges such as resource allocation and budget prioritization were selected as levers to analyze their impact on cyber risk management decisions and the broader cybersecurity strategy.

This was done as the CAMS dashboard mimics a real-life decision-making environment in a safe and isolated testing, or sandbox, environment. This provides leaders the means to explore and experiment with a wide range of strategic decisions without true cyber impact on the organization.

Poor cyber risk management can negatively impact an organization

An important lesson from the case study was that poor cyber risk management decisions can impact and cripple the entire organization. Effective interventions need to consider the interconnectedness of decisions and the interactions between different mechanisms and departments prevalent in the organization.

Another important lesson from the case study was that traditional approaches can be augmented by the CAMS dashboard.

In our case study, we used Smart Wealth Management’s existing cyber risk reports and assessments to populate the model parameters for simulation and analysis.

This approach has sustainable advantages for executives as they can:

  • Visualize how their strategic choices will evolve in real life through organizational-specific simulations.
  • Observe how strategic choices can contribute to maintain the organization’s risk appetite.
  • Prioritize cyber budgets and resource allocation to ensure timely risk response.
  • Identify counterintuitive strategies that maximize the benefits of cyber risk management decisions.

Executives must do more on managing and mitigating cyber risk

Ongoing exponential growth in cyber attacks presses executive decision-makers more to stay ahead of the curve.

Reacting after the fact can be very costly and increase needs for regulatory ex-post evaluation and sanctioning. We see and understand that cyber risk is dynamic in nature, and now we must act on it.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. The centre is an independent and impartial platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors.

Since its launch, the centre has driven impact throughout the cybersecurity ecosystem:

Contact us for more information on how to get involved.

Through exploratory and interactive technology solutions, leaders can develop better foresight to manage economic aspects of cyber risk and alignment to business needs.

The CAMS dashboard is leading example of this direction.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNOCHA A heavily damaged apartment building in Sloviansk, eastern Ukraine.

UN warns Ukraine war risks spiralling ‘out of control’

This article is published in association with United Nations. The United Nations on Thursday warned of a dangerous escalation in the war in Ukraine after a wave of large-scale Russian strikes and threats of further attacks, with Secretary-General António Guterres saying “the death spiral must stop.” Addressing the Security Council in New York, Mr. Guterres said […]
© WHO A frontline health worker in PPE (personal protective equipment) takes part in the Ebola response in eastern Democratic Republic of the Congo.

Ebola outbreak in DR Congo collides with conflict and hunger, WHO warns

This article is published in association with United Nations. The UN World Health Organization (WHO) on Wednesday warned that eastern Democratic Republic of the Congo faces a “catastrophic collision of disease and conflict” as a fast-spreading Ebola outbreak outpaces containment efforts in a region already battered by armed violence, mass displacement and acute hunger. WHO Director-General […]
© WFP/Michael Castofas WFP staff and responders handle boxes of supplies at a logistics site in DR Congo during the Ebola outbreak.

International airlines urged to stick to safety measures in wake of Ebola outbreak

This article is published in association with United Nations. As a deadly Ebola strain continues to spread in the Democratic Republic of the Congo (DRC), with cases confirmed in neighbouring Uganda, the UN aviation agency is urging governments and flight operators to closely follow guidelines put in place following the COVID-19 pandemic. The outbreak of the […]
© WHO Supplies to bolster the response against the Ebola outbreak in Ituri province arrive in the town of Bunia.

Ebola epidemic spreading rapidly and outpacing containment efforts

This article is published in association with United Nations. There are more than 900 suspected cases of the Bundibugyo strain of Ebola in the Democratic Republic of the Congo, and 220 suspected deaths, the head of the World Health Organization (WHO), Tedros Ghebreyesus, said on Monday. The latest outbreak of the deadly disease, which WHO has declared […]
This article is published in association with United Nations.

WHO chief calls for urgent Ebola action and pandemic preparedness

This article is published in association with United Nations. The recent Ebola and hantavirus outbreaks demonstrate that the world is still vulnerable to rapidly spreading infectious diseases, Tedros Ghebreyesus, the head of the World Health Organization (WHO), warned on Saturday at the close of the 79th World Health Assembly in Geneva. His call came as Ugandan […]
This article is published in association with United Nations.

UN agencies step up Ebola response in eastern DR Congo

This article is published in association with United Nations. United Nations agencies have moved swiftly to support efforts to contain the latest Ebola outbreak in eastern Democratic Republic of the Congo (DRC), delivering emergency medical supplies, protective equipment and logistics support. As health authorities in both the DRC and Uganda respond to the deadly resurgence, the […]
© UNICEF/Josue Mulala Emergency aid is prepared for delivery to Kasaï province in response to the recently declared Ebola virus disease outbreak in DR Congo.

Ebola risk is high inside DR Congo but it’s no pandemic emergency: WHO

This article is published in association with United Nations. The deadly Ebola outbreak in Democratic Republic of the Congo (DRC) and Uganda does not represent a global pandemic emergency, although the risk is high at a regional and national level, the UN health agency chief said on Wednesday. In an update on the fast-developing situation in […]
This article is published in association with United Nations.

How the Hormuz crisis keeps disrupting kitchens, ports and paychecks

This article is published in association with United Nations. The fragile ceasefire between the United States and Iran may have eased fears of a wider regional war, but persistent instability around the Strait of Hormuz continues to disrupt global trade, drive up energy costs and fuel a growing jobs and cost-of-living crisis. The fallout is being […]
© UNFPA Ukraine In March 2026, a maternity hospital in Odesa, Ukraine was attacked by Russian forces.

World News in Brief: More attacks in Ukraine, violence against children in Haiti, refugee IDs in Africa

This article is published in association with United Nations. Civilians, including humanitarians, continue to face great danger across war-torn Ukraine amid ongoing hostilities, according to the UN humanitarian relief coordination office there, OCHA. Over the past three days, frontline attacks killed at least 11 civilians and injured nearly 200 others, including five children, as reported by […]
UN Photo/Milton Grant Sculpture depicting St. George slaying the dragon. The dragon is created from fragments of Soviet SS-20 andUnited States Pershing nuclear missiles.

Nuclear terror threat ‘has never been so high’

This article is published in association with United Nations. The widespread availability of new technology, such as militarised drones and artificial intelligence, means that the current threat of nuclear terrorism is higher than it has ever been. The humanitarian, environmental, and economic consequences of a radiological or nuclear terrorist attack would be global, undermining international peace […]
© UNICEF/Nyan Zay Htet Recent disruptions to energy supplies and global supply chains have reverberated across development and humanitarian sectors, including relief efforts in Myanmar, where millions remain in need of assistance.

Global energy and trade disruption pushing millions towards poverty

This article is published in association with United Nations. Disruptions to global energy supplies and trade corridors are driving up the cost of food, transport and essential goods worldwide, slowing economic growth and increasing pressure on vulnerable households and debt-strapped developing countries. The warnings came during a special meeting of the UN Economic and Social Council […]
UN Photo/Eskinder Debebe UN Relief Chief Tom Fletcher (centre) along with Ambassador Mike Waltz (right) and Jeremy P. Lewin of the United States hold a joint press briefing on funding to the humanitarian system.

UN welcomes $1.8 billion US boost for humanitarian operations

This article is published in association with United Nations. An additional $1.8 billion in US humanitarian funding will allow the United Nations and its partners to expand emergency relief operations reaching millions of people worldwide, as rising global needs and funding shortfalls force aid agencies to scale back assistance. The funding announcement, made on Wednesday by […]
© WHO/Hanan Balkhy Displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services.

World News in Brief: Mounting waste in Gaza, drone attacks in Sudan, aid truck struck in Ukraine

This article is published in association with United Nations. Mounting waste and limited access to sanitation sites are deepening health risks for families across Gaza, as humanitarian workers warn that overcrowded dumping areas and worsening living conditions threaten vulnerable communities. Ramiz Alakbarov, UN’s top aid official in Occupied Palestinian Territory visited a dumping site in Gaza […]
This article was exclusively written for The European Sting by Mr. Franco Miguel Nodado, a 4th-year medical student from the Philippines. He is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Autism Spectrum Disorders in Global Health: Bridging the Gap in  Awareness, Early Diagnosis, and Inclusive Care 

This article was exclusively written for The European Sting by Ms. Georgia Maria Vardalachaki, a medical student from the Medical University of Crete, Greece. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s […]
© WHO/Hedinn Halldorsson WHO Director-General Tedros and a health expert during operations involving the MV Hondius off Tenerife amid the hantavirus response.

Hantavirus-hit ship evacuation completed as quarantines begin

This article is published in association with United Nations. The passengers and crew have disembarked from the hantavirus-hit cruise ship MV Hondius in Tenerife and many have returned to their home countries, as the UN World Health Organization (WHO) said the operation demonstrated a “triumph of solidarity”. The repatriation effort, coordinated by Spanish authorities with support […]
© NASA The Strait of Hormuz which separates the United Arab Emirates and Iran is a strategically important shipping route

Strait of Hormuz de-escalation is urgent, says UN chief

This article is published in association with United Nations. As the Strait of Hormuz crisis deepens and tensions between Iran and the United States remain unresolved, oil prices rose again early Monday, prompting the UN Secretary-General to call for a peaceful resolution and warn of the widening fallout across Africa and beyond. “My strong appeal is […]
This article is published in association with United Nations.

Ukraine: Over 3,000 attacks on healthcare since full-scale Russian invasion

This article is published in association with United Nations. The World Health Organization (WHO) has verified more than 3,000 attacks on healthcare in Ukraine since Russia launched its full-scale invasion in February 2022, the UN agency reported on Friday. “During 1,534 days of war, Ukraine’s healthcare system has experienced repeated attacks,” it said.  Every aspect of the system has been […]
WHO Passengers from MV Hondius assisted by Spanish and WHO health teams after disembarking.

Passengers leave hantavirus-hit cruise ship in Tenerife as WHO says outbreak ‘not another COVID’

This article is published in association with United Nations. Passengers and crew from the cruise ship MV Hondius began disembarking in Tenerife on Sunday under a tightly coordinated international health operation led by Spanish authorities and the World Health Organization (WHO), as officials sought to reassure the public that the outbreak “is not another COVID.” The […]
Nuclear energy in the Middle East: A realistic choice or a risk?

Nuclear energy in the Middle East: A realistic choice or a risk?

This article is published in association with United Nations. As global electricity demand grows, so does the popularity of nuclear energy. In the Middle East, several countries are evaluating or advancing nuclear power projects, balancing weighty issues such as regional security, climatic conditions and international cooperation. “Nuclear energy is at the intersection of energy demands, technological […]

Trackbacks

  1. […] How to align cyber risk management with business needs  The European Sting […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com