Strategising cybersecurity: Why a risk-based approach is key

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Adham Etoom, Director of Policy and Compliance, National Cybersecurity Center of Jordan; Co-Chair of Jordan Chapter & Advisor, FAIR Institute


  • Cybercrime is predicted to cost the global economy nearly $24 trillion by 2027.
  • The cyber-risk landscape is ever-evolving — and businesses must continually adapt to it or risk financial, reputational or legal repercussions.
  • A risk-based approach to cybersecurity gauges and evaluates the risk landscape, allowing leadership to evaluate and prioritise the most pressing challenges at a given time.

By 2027, cybercrime could cost the global economy nearly $24 trillion. Businesses often find themselves at the sharp end of this challenge, and, as such, cybersecurity is a critical aspect of the modern business landscape. Cyber threats are multiplying and pose serious financial, legal and reputational challenges to organizations.

Modern and effective cybersecurity management entails more than managing technology risk; it encompasses managing business risk. Organizations must recognise cybersecurity as a strategic imperative integrated into their overall risk management framework — and this can be done at the board level.

Boards can set an organization’s risk appetite, oversee risk management processes, allocate resources and ensure preparedness to respond to cyber threats. They can ensure accurate and timely reporting from management on risks and incidents as part of their broader role in managing risk.

A risk-based approach to cybersecurity

Senior and executive management must understand that organizations can adopt two main approaches to enhance cybersecurity: maturity-based and risk-based.

Organizations widely use the maturity-based approach to enhance their cybersecurity posture. It involves adopting a set of industry-established best practices or standards to achieve a higher level of cybersecurity maturity. It does, however, have limitations.

It relies heavily on subjective assessments that can be influenced by factors such as communication skills, bias and experience of the assessor. Also, achieving a specific level of maturity does not guarantee protection from cyber threats and may create a false sense of security. The maturity-based approach may not adequately address an organization’s unique risk profile, leaving them vulnerable to targeted attacks. It can be resource-intensive, diverting resources from other cybersecurity activities.

The risk-based approach to cybersecurity is flexible and customisable to meet an organization’s specific needs and risks. It emphasises the identification and prioritisation of the most critical cybersecurity risks, followed by the application of controls to mitigate them. This approach involves continuous monitoring and reassessment to ensure that controls remain effective and relevant in the face of ever-evolving cyber threats.

It is effective because it allows organizations to align their cybersecurity strategy with their unique risk profile, enabling them to focus on the most significant threats and vulnerabilities. This approach also promotes a proactive cybersecurity culture by continuously evaluating and addressing risks, minimising the impact of cyber incidents. As a result, organizations can make informed decisions about where to allocate their cybersecurity resources and prioritise cybersecurity efforts based on their most critical assets and vulnerabilities.

Creating a quantified risk grid

Organizations can use risk quantification methodologies such as quantitative risk analysis and Monte Carlo simulation (i.e. FAIR Model) to measure the potential impact of cyber risks and prioritize risk mitigation efforts.

By incorporating cyber risk quantification into their risk-based approach to cybersecurity, organizations can better understand their cybersecurity risks, prioritise resources and make informed decisions about risk management. This can help them achieve more effective and efficient enterprise-risk management, ultimately improving cybersecurity outcomes.

Quantified cyber risk can be applied in real-life situations to assign a financial value to potential losses from cybersecurity incidents. This helps organizations manage their digital assets and prioritise risk mitigation efforts. It involves evaluating threats and vulnerabilities, and assessing the financial impact of incidents on productivity, legality, reputation and recovery.

Quantified cyber risk enables business leaders to make informed decisions about cybersecurity investments and take proactive measures against cyber threats.

Measuring outcomes and taking action

Key Risk Indicators (KRI) provide a snapshot of the current risk level of the enterprise. At the same time, Key Performance Indicators (KPI) indicate the direction towards or away from an enterprise’s risk-appetite level. By linking KRIs to KPIs, cybersecurity teams can help executives engage in constructive discussions to identify which risks are within acceptable levels and which require immediate attention. This enables informed decision-making and effective problem-solving at the board level and below.

The risk-based approach is interactive and helps to translate executive decisions about risk reduction into control implementation, ensuring an organization is aligned and working towards a common goal. By implementing controls in a coordinated and strategic way, companies can manage risks more effectively and achieve their desired outcomes.

To implement the risk-based approach successfully, organizations should adopt a comprehensive roadmap that includes conducting a thorough risk assessment, developing KRIs and KPIs that align with their objectives and risk appetite, establishing robust risk management processes and continuously monitoring and evaluating their cybersecurity posture. Technology is crucial in automating and streamlining risk management processes, implementing security controls and tracking KRIs and KPIs in real-time.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum’s Centre for Cybersecurity drives global action to address systemic cybersecurity challenges and improve digital trust. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors.

Contact us for more information on how to get involved.

Organizations must continuously reassess their cybersecurity strategy as the threat landscape evolves. The maturity-based approach is no longer effective in protecting against modern cyber threats. A risk-based approach helps identify and prioritise risks, meaning a more efficient and effective cybersecurity programme. Investments in employee education and training, and effective risk management, can build a strong security posture that protects assets, reputation and customers from cyber-attacks.

Adopting a risk-based cybersecurity model also confers benefits beyond simply preventing cyber-attacks. It builds resilience and agility, and this method of continuously assessing and adapting makes for more streamlined and competitive organizations more generally.

Cybersecurity is a shared responsibility that requires collaboration from all stakeholders to safeguard organizations. The risk-based approach results in more effective and efficient enterprise-risk management and builds stronger and more secure organizations capable of responding to an evolving cyber risk landscape.

Widespread adoption of the risk-based approach would not only preserve organizations’ reputation, customers and stakeholders — it would create a safer digital ecosystem for all.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNHCR People gather at the Masnaa border point in Lebanon as they wait to cross into Syria.

Nearly 700,000 displaced in Lebanon as Middle East crisis escalates

This article is published in association with United Nations. On day 10 of the war engulfing the Middle East, UN agencies on Monday reported massive displacement across the region, along with surging food and fuel prices that risk increasing hunger and suffering for the most vulnerable. In Lebanon alone, nearly 700,000 people including around 200,000 children […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

Lebanon ‘dragged back into turmoil’, UN envoy warns

This article is published in association with United Nations. Lebanon has been “dragged back into a state of turmoil and violence”, the UN’s top envoy in the country warned on Saturday, after the latest round of regional strikes triggered a fast‑escalating crisis along the Blue Line. What had been fragile but real momentum, she said, has […]
UNHCR Smoke rises after an airstrike in Beirut, Lebanon.

MIDDLE EAST LIVE: Strikes continue across Middle East as humanitarian concerns grow

This article is published in association with United Nations. Highlights Production team: Vibhu Mishra with Daniel Johnson in GenevaToday 12:15 μ.μ. UN rights office warns displacement orders in Lebanon affecting hundreds of thousands The UN human rights office has warned that large-scale displacement orders and ongoing airstrikes in Lebanon are worsening the suffering of civilians already affected […]
© UNICEF/Ramzi Haidar Destroyed buildings and debris in the southern suburbs of Beirut, Lebanon, following airstrikes.

MIDDLE EAST LIVE: Further escalation drives uncertainty and suffering

This article is published in association with United Nations. On day six of the war in the Middle East, there’s been no let-up in bombs, drones and rockets targeting Iran, Israel, Lebanon and many Gulf States, while NATO forces reportedly intercepted a missile fired at Türkiye by Iran, a claim denied by Tehran. We’ll bring you […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

MIDDLE EAST LIVE: Conflict continues across region amid US, Israeli and Iranian strikes

This article is published in association with United Nations. Violence in the Middle East is continuing into a fifth day, with US and Israeli strikes against Iran and Iranian missile and drone attacks reported across several countries in the region. The escalating confrontation is disrupting airspace, transport and daily life while raising fears of a wider […]
© IAEA/Paolo Contri The Bushehr Nuclear Power Plant in Iran.

Iran crisis: Schoolgirls killed, thousands displaced and aid compromised

This article is published in association with United Nations. On the fourth day of Israeli and United States airstrikes against Iran and amid growing violence and instability in the Middle East, the UN urgently called for protection of civilians and warned of growing displacement and humanitarian needs. UN human rights office spokesperson Ravina Shamdasani also recalled […]
© Unsplash/Kamran Gholami Tehran, the capital of Iran. (file photo)

MIDDLE EAST LIVE: Strikes continue from US, Israel and Iran as UN urges restraint

This article is published in association with United Nations. Violent escalation in the Middle East has entered a third day as coordinated US and Israeli strikes against Iran aimed at regime change continue to cause loss of life and damage across the region, prompting Iranian missile and drone counter-strikes hitting targets in multiple countries. Explosions, airspace […]
Iran attacks

Deadly bombing of Iran primary school ‘a grave violation of humanitarian law’: UNESCO

This article is published in association with United Nations. The UN education agency, UNESCO, says that the bombing of a primary school during the US and Israeli military attacks on Iran on Saturday constitutes a grave violation of humanitarian law. The missiles reportedly destroyed a girl’s primary school in Minab, southern Iran, killing around 150 and […]
© UNRCO Iran Tehran, the capital of Iran.

Attacks on Iran and retaliatory strikes ‘undermine international peace and security’

This article is published in association with United Nations. UN Secretary-General António Guterres and the heads of UN agencies have condemned Saturday’s joint Israeli and US attacks on Iran and the Iranian retaliatory strikes on Israel and the Gulf Regions. The attack on Iran reportedly targeted military sites as well as the leadership of the Iranian […]
© WFP/Maxime Le Lijour A woman holds a child as a storm approaches Khan Younis in Gaza.

Palestine: UN rights chief highlights suffering, atrocity crimes ‘that remain unpunished

This article is published in association with United Nations. The UN rights chief Volker Türk on Thursday highlighted the “human-made disaster” across the Occupied Palestinian Territory stemming from Israel’s disregard for human rights norms and serious violations also committed by Hamas and other Palestinian armed groups. Citing a new report from his office (OHCHR) covering the […]
Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia.

Not the Future, the Present: Young Voices Shaping Global Health in 2026

This article was exclusively written for The European Sting by Ms. Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to […]
© UNOCHA Many rural areas of Ukraine have been blasted by shelling and drone strikes. The country is also one of the most mined in the world, top UN aid officials warn.

Ukraine wakes to more violence as Russia’s invasion enters fifth year

This article is published in association with United Nations. The full-scale invasion of Ukraine by Russian troops on 24 February 2022 shattered the peaceful aspirations of an entire continent, but war must never be the new normal, UN General Assembly President Annalena Baerbock said on Tuesday. “Four years ago, people in Europe woke up in another […]
Fokah Wembe Darrell Dupray is a 4th-year medical student at Université des Montagnes, Bangangté Cameroon and a student leader within the Cameroon Medical Students’ Association (CAMSA).

From Local Barriers to Global Lessons: Practical Paths Toward Inclusive Healthcare

This article was exclusively written for The European Sting by Ms. Zainatun Nawwariyah is a fifth-year medical student at the Faculty of Medicine, University of North Sumatera, who is passionate about advancing medicine through research, advocacy, and service. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed […]
© UNICEF/Bullen Chol A grandmother takes care of her 17-month-old malnourished grandson in South Sudan.

World News in Brief: UN humanitarian chief visits South Sudan, shelter fire risks in Gaza, West Bank violence

This article is published in association with United Nations. The UN Emergency Relief Coordinator arrived in South Sudan on Friday to visit one of the most under-reported humanitarian crises in the world, as clashes between government and opposition forces continue in Jonglei state.  Tom Fletcher will focus on the deteriorating humanitarian situation in the world’s youngest country and escalating protection risks for both civilians and aid workers.  […]
Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

This article is published in association with United Nations. Four years into Russia’s full-scale invasion, millions in Ukraine struggle to keep the lights on and heat their homes, with the crisis taking a particular toll on women, humanitarians warned on Friday. Freshly back from a visit to the country UN Women’s Chief of Humanitarian Action Sofia […]
Fears of ethnic cleansing in Gaza and the West Bank: UN rights report

Fears of ethnic cleansing in Gaza and the West Bank: UN rights report

This article is published in association with United Nations. Increased Israeli attacks and the forced transfer of Palestinians have sparked concern over ethnic cleansing in the Gaza Strip and the West Bank, the UN human rights office, OHCHR, said in a report issued on Thursday.  The report covers the period from 1 November 2024 to 31 October 2025 and is […]
Samaya Rahimova  is a public health student at the Azerbaijan Medical University and an active member of SCOPH at Azermeds

Inclusive Healthcare Fails When We Design for the “Average Patient”

This article was exclusively written for The European Sting by Ms. Samaya Rahimova , a public health student at the Azerbaijan Medical University and an active member of SCOPH at Azermeds. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer […]
IOM Women make up the majority of victims of human trafficking for sexual exploitation. (file photo)

Epstein files: ‘No one is too wealthy or too powerful to be above the law’; rights experts demand accountability

This article is published in association with United Nations. The large-scale disclosure of materials known as the “Epstein Files” has revealed “disturbing and credible evidence” of what independent human rights experts describe as a possible global criminal enterprise involving systematic sexual abuse, trafficking and exploitation of women and girls. In a statement on Monday, the independent […]
© UNICEF/Dmytrii Bortkevych A young girl carries firewood for a warming stove at a house in the Kyiv region.

As conditions worsen in Ukraine, refugees struggle to return

This article is published in association with United Nations. As Ukraine prepares to enter the fifth year of the full-scale Russian invasion on 24 February, UN monitors say harm to civilians has “demonstrably worsened”, while energy attacks and freezing temperatures are making it harder for displaced families to return. “More people are killed and injured each […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com