Why we need business, operational and financial resilience to optimize cybersecurity

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Eric Swalwell, Congressman, 15th District of California, U.S. House Foreign Affairs Committee


  • To drive down risk and improve resilience against malicious cyber activity, governments and the private sector must evolve their respective approaches to cybersecurity risk management.The private sector and the government are well-served by building cybersecurity into every aspect of operations and governance.Investing in cybersecurity costs money, but shortchanging cybersecurity investments costs more.

The average cost of a data breach in 2022 was $4.35 million and is expected to reach $5 million in 2023. Cybersecurity research firm Cyber Ventures predicts that cybercrimes will cost the world $10.5 trillion by 2025. According to the Securities and Exchange Commission (SEC), “the potential costs and damage that can stem from a cybersecurity incident are extensive. Many smaller companies have been targets of cybersecurity attacks so severe that the companies have gone out of business as a result.”To drive down risk and improve resilience to malicious cyber activity, governments and the private sector must evolve their respective approaches to cybersecurity risk management. Both parties must leverage their capabilities more strategically and develop frameworks to prioritise investments aligned to cyber threats.

Call to action

In March 2023, the White House released its long-anticipated National Cybersecurity Strategy. Charting the course for this “decisive decade,” the Strategy recognizes that different actors throughout the digital ecosystem have comparative advantages when it comes to reducing risk, observing malicious cyber activity, synthesizing threat information and producing actionable guidance, disrupting threat actors and building resilience. To that end, the Strategy demands more from government and the private sector.Two overarching principles drive the National Cybersecurity Strategy. First, “most capable and best-positioned actors in cyberspace must be better stewards of the digital ecosystem.” Second, the “economy and society must incentivize decision-making to make cyberspace more resilient and defensible over the long term.” Aligning policy and business decisions with these principles will undoubtedly raise our national cybersecurity posture. A more secure and resilient cyber domain is also good for business – investing in security costs money, but cleaning up a breach costs more. Making the investments necessary to absorb additional responsibility for security may involve short-term costs, but it will also raise public confidence in the reliability of critical infrastructure and technology, increase productivity and profits and enable stronger, more strategic partnerships between the federal government and the private sector. In short, the private sector and the government are well-served by building cybersecurity into every aspect of operations and governance.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum Centre for Cybersecurity drives global action to address systemic cybersecurity challenges. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors. Here are some examples of the impact delivered by the centre:Cybersecurity training: Salesforce, Fortinet, and the Global Cyber Alliance, in collaboration with the Forum, provide free and accessible training to the next generation of cybersecurity experts worldwide.Cyber resilience: Working its partners, the Centre is playing a pivotal role in enhancing cyber resilience across multiple industries: Oil and Gas, Electricity, Manufacturing and Aviation.IoT security: The Council on the Connected World, led by the Forum, has established IoT security requirements for consumer-facing devices, safeguarding them against cyber threats. This initiative calls upon major manufacturers and vendors globally to prioritize better IoT security measures.Paris Call for Trust and Security in Cyberspace: The Forum is proud to be a signatory of the Paris Call, which aims to ensure global digital peace and security, emphasizing the importance of trust and collaboration in cyberspace.

Contact us for more information on how to get involved.

A paradigm shift for government

Historically, the federal government relied on voluntary frameworks to encourage the adoption of strong cybersecurity standards by the private sector. Cyber incidents, such as the SolarWinds supply chain attack and the Colonial Pipeline ransomware attack, however, revealed the limitations of a purely voluntary model and underscored the cascading consequences of cyber incidents. Even before the release of the National Cybersecurity Strategy, high-profile cyberattacks in 2020 and 2021 forced the federal government to reassess its reliance on voluntary measures to improve cybersecurity for critical infrastructure and technology companies. Recognizing the need to raise the collective visibility of malicious activity on domestic networks, the US Congress enacted the Cyber Incident Reporting for Critical Infrastructure Act of 2021, which directed covered entities to report certain cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours. This legislation earned the buy-in of the private sector because it enabled the federal government to disrupt malicious cyber campaigns sooner and provide critical insights into the tactics of our adversariesMeanwhile, the Executive Branch has been prolific in its efforts to encourage the adoption of more robust cybersecurity practices. Deputy National Security Advisor for Cyber and Emerging Technology, Anne Neuberger, wrote an open letter to corporate executives and business leaders in June 2021, urging them to implement the five best practices from Executive Order 14028, including using third-party penetration testers and refining incident response plans. In July 2021, President Biden signed the National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems, directing the Department of Homeland Security (DHS) and the Department of Commerce to develop cybersecurity performance goals for critical infrastructure. The two departments released the first version of the baseline cross-sector Cybersecurity Performance Goals (CPG) in October 2022 and have updated them since. Since they were released, the CPGs have informed new federal cybersecurity requirements for surface transportation and aviation, among others. In February 2023, CISA Director, Jen Easterly, and Executive Assistant Director for Cybersecurity, Eric Goldstein, published an article in Foreign Affairs magazine making the case that: “in every business, the responsibility for cybersecurity needs to be elevated from the IT department to the board, the CEO and the senior executive level.” To that end, Director Easterly and Executive Assistant Director Goldstein declared “every technology provider must begin by creating products that are both ‘secure by default’ and ‘secure by design.’” They have been advocating for adoption of those principles ever since

Relatedly, in March 2022, the Securities and Exchange Commission (SEC) released a proposed rule on cybersecurity risk management and governance. The new SEC rules seek to engage senior management and the board in a meaningful way.

Among other things, the proposed rule clarifies disclosure requirements related to a registrant’s policies and procedures for identifying and managing cybersecurity risks, cybersecurity governance structure, management’s role in addressing and mitigating cybersecurity risks and whether an individual with cybersecurity expertise sits on the registrant’s board. These requirements underscore the importance of advancing risk management and governance efforts across the boardroom community to ensure resources and investments are applied to those cyber risks that have the most material financial, business and operational impact.The National Cybersecurity Strategy builds on the Administration’s work to date. While the federal approach to cybersecurity is evolving – and that evolution may result in new standards – it will also drive better cybersecurity practices for critical infrastructure and technology companies, reducing the risk for cyberattacks that hurt productivity, public confidence and, ultimately, profits.

Too often, cybersecurity gets lost in translation when engaging board members and the C-suite. This leaves leadership unsure of precisely what they are funding and where residual gaps remain.

— Chris Hetner, Chair of the Nasdaq Center for Board Excellence Insights Council

For its part, the government has an obligation to its private sector partners to demonstrate the security value of new cybersecurity requirements and public-private partnerships. As the Strategy demands more of the private sector, it makes bold commitments on behalf of the government. It envisions a full-court press to tackle malicious cyber activity – from international coordination on ransomware and aggressively going after cyber criminals to disrupting malicious cyber campaigns and taking down threat actors’ infrastructure.The government is doing a lot of that already – earlier this year the FBI infiltrated the Hive ransomware group, captured decryption keys and distributed them to victims. In April, the FBI and its international partners took down Genesis, an online store of hacked and stolen data. Together, these actions demonstrate how the government can leverage its unique resources and authorities to reduce risk to its partners and the public.Additionally, as the government creates new standards for the private sector, it should ensure that any additional burdens are harmonized across all levels of government. Compliance costs should not detract from security investments. The Strategy commits to harmonizing regulations through the Office of the National Cyber Director and the Office of Management and Budget, much like the Cyber Incident Reporting Council at DHS is working to deconflict various cyber incident reporting requirements. However, these harmonization efforts navigate the complexities of independent agency regulators.Finally, government must develop a framework to better assess interdependencies across critical infrastructure owners and operators and the potential cascading effects of cyber incidents. A sound framework for such analysis will drive strategic investments in security and facilitate greater resiliency. The Cybersecurity and Infrastructure Security Agency (CISA) is in the process of doing just that.

Working smarter

The cybersecurity ecosystem (people, processes, technology) is largely focused on addressing technical-level threats used to mitigate risk. While the cybersecurity ecosystem continues to evolve, it still lacks the ability to contextualize cyber threats and incidents to business, operational and financial exposures. The ‘material’ determination is influenced by the incident’s impact on the company’s business, operations and financial condition. Below is an enumeration of the types of business and financial factors that should be contemplated when determining incident materiality. The types of costs and adverse consequences that companies may incur or experience as a result of a cybersecurity incident include the following:• Costs due to business interruption, decreases in production and delays in product launches.• Payments to meet ransom and other extortion demands.• Remediation costs, such as liability for stolen assets or information, repairs of system damage and incentives to customers or business partners in an effort to maintain relationships after an attack.• Increased cybersecurity protection costs, which may include increased insurance premiums and the costs of making organizational changes, deploying additional personnel and protection technologies, training employees and engaging third-party experts and consultants.• Lost revenues resulting from intellectual property theft and the unauthorized use of proprietary information or the failure to retain or attract customers following an attack.• Litigation and legal risks, including regulatory actions by state and federal governmental authorities and non-U.S. authorities.• Harm to employees and customers, violation of privacy laws and reputational damage that adversely affects customer or investor confidence. • Damage to the company’s competitiveness, stock price and long-term shareholder value.Cyber risk management is a team sport that requires the entirety of the enterprise to ensure business resilience. What is required is a more inclusive message and collaboration that includes all enterprise risk management leaders.Technology changes quickly and so do cyber threats. Static analyses of today’s risk are less helpful than establishing a regular flow of information to the board that supports cybersecurity investment decisions based on business, operational and financial considerations. With the board’s eyes kept regularly on cybersecurity as an aspect of routine governance, directors will be equipped to comply with the SEC’s new requirements.

Cyber risk is a discussion for directors and officers

Chris Hetner, former senior cybersecurity advisor to the SEC Chair and Chair of the Nasdaq Center for Board Excellence Insights Council, says: “It is essential for boards to continuously incorporate cyber risk management discussions related to the most effective way to reduce the financial and business impact connected with cyber risk. The conversation isn’t just for the Chief Information Officer (CIO) and Chief Information Security Officer (CISO). It is a broader c-suite discussion, which must be led by the Chief Financial Officer (CFO) and General Counsel.”Hetner says that boards can no longer ignore cybersecurity, noting: “The default tendency of executives is to rely on periodic tactical and technical reports to justify tech solutions that may address technical security issues.” He adds that: “Too often, cybersecurity gets lost in translation when engaging board members and the C-suite. This leaves leadership unsure of precisely what they are funding and where residual gaps remain.”Hetner and the NACD recently supported the launch of a service where boards are supported to more effectively provide oversight related to cyber risk exposure. The X-Analytics and NACD Cyber Risk-Reporting Service is an annual subscription providing quarterly board reports highlighting the financial exposure attributed to an organization’s cyber risk. The platform relies on the same analytics used by leaders within the cyber insurance industry.This new NACD service facilitates a broader c-suite conversation related to cyber risk and assists boards in engaging in discussions that transcend the technical aspects of cybersecurity.

To conclude, investing in cybersecurity costs money. Shortchanging cybersecurity investments costs more.

Trending now:


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

UN Photo/Manuel Elías Ramiz Alakbarov (on screen), Deputy Special Coordinator for the Middle East Peace Process, briefs the Security Council meeting on the situation in the Middle East.

Potential turning point for Gaza as peace plan enters second phase: UN envoy

This article is published in association with United Nations. The start of a second phase of a stabilisation plan for Gaza offers a potential turning point for the war-ravaged enclave, a senior UN official told the Security Council on Wednesday. Ramiz Alakbarov warned that risks of violence escalating again remain high, while the situation in the […]

This article is published in association with United Nations.

Gaza ceasefire improves aid access, but children still face deadly conditions

The fragile ceasefire in the Gaza Strip is making a difference to the lives of over a million children, and improving overall access to food – but more aid still needs to enter.  That’s the assessment of two senior officials from the UN Children’s Fund (UNICEF) and the World Food Programme (WFP), speaking on Monday to journalists in New York following a […]

A new blow for UNRWA as headquarters in East Jerusalem ‘set on fire’

© UNRWA Destruction at UNRWA headquarters in East Jerusalem after Israeli authorities sent in bulldozers on 20 January. This article is published in association with United Nations. The head of embattled UN relief agency for Palestinians, UNRWA, has condemned reports that its headquarters in East Jerusalem have been set alight deliberately. It comes after Israeli authorities […]

© UNHCR/Yevheniia Kozun This cinema in Saltivka, Kharkiv, was hit during an earlier strike (file Jan 2026).

‘Cycle of attacks must end’: Lead UN official in Ukraine

This article is published in association with United Nations. The senior UN official in Ukraine, Matthias Schmale, has issued a condemnation of the massive overnight Russian drone and missile strike on several major Ukrainian cities, killing and injuring civilians, and knocking out energy infrastructure amid sub-zero temperatures. The attacks on some of Ukraine’s most important population […]

WHO/P. Virot The flag of the UN World Health Organization (WHO) flies at its headquarters in Geneva, Switzerland.

US withdrawal from WHO ‘risks global safety’, agency says in detailed rebuttal

This article is published in association with United Nations. The World Health Organization (WHO) has issued a detailed statement regretting the United States decision to leave the UN agency, and declaring that it will leave both the US and the world less safe as a result. The statement, released on Saturday, also includes a rebuttal of […]

© UNOCHA/Ximena Borrazas Kateryna and her two children warm up at a heating point and use rhe available electricity to charge their devices.

Keeping people warm amid hostilities and harsh winter weather in Ukraine

This article is published in association with United Nations. As people in war-torn Ukraine face the coldest winter in more than a decade, authorities and humanitarians are working to help them stay warm, particularly the most vulnerable residents.  Russian forces continue to attack Ukraine’s energy grid, leaving families without electricity and heating as temperatures plummet to -20° Celsius.  Since 2022, the Government has established so-called “Invincibility Points” – located in tents or public […]

UN News A UN emergency shelter set up amid the ruins of Gaza.

Gaza: War crimes probe pledges to continue work for justice and accountability

This article is published in association with United Nations. As President Trump launched the international Board of Peace plan for Gaza on Thursday, top independent rights experts tasked by the UN Human Rights Council with investigating grave abuses linked to the Hamas-Israel war pledged to continue their work seeking justice and accountability for all. “The Board […]

© WFP/Maxime Le Lijour Children wait for a hot meal at a kitchen in Khan Younis, Gaza, supported by the World Food Programme.

Cold kills another infant in Gaza as West Bank displacement intensifies

This article is published in association with United Nations. Another child in the Gaza Strip has died from hypothermia as winter weather continues to whip the enclave, the UN said on Wednesday, citing information from the health authorities.  The baby girl – just three months old – was found frozen to death on Tuesday morning at her home in […]

Critical medicines: EU measures to boost competitiveness and tackle shortages 

Critical medicines: EU measures to boost competitiveness and tackle shortages 

This article is brought to you in association with the European Parliament. On Tuesday, Parliament adopted proposals to enhance the availability and supply of essential medicines in the EU. The report, adopted with 503 votes in favour, 57 against and 108 abstentions, aims to ensure a high level of public health protection for EU citizens by […]

Europe Was Warned: Why the Next Pandemic Could Be  Worse 

This article was exclusively written for The European Sting by one of our passionate readers, Dr Taimoor Ahmed Shumail , MD | Dr Ahmed Bilal , MD , Vice  President Global Health and Diplomacy Wing – Pakistan International Medical Students  Association. The opinions expressed within reflect only the writer’s views and not necessarily The European Sting’s position […]

UN News Many Palestinian families are living in poorly equipped shelters that are highly vulnerable to flooding, leaving people inevitably exposed to harsh, stormy weather..

Gaza humanitarian crisis ‘far from being over,’ UN aid coordination office warns

This article is published in association with United Nations. Three months into the ceasefire in the Gaza Strip, the UN and partners have delivered tonnes of assistance items and carried out critical repairs, but this is only a temporary “Band-Aid” solution, a veteran aid worker has warned. “The humanitarian situation and crisis in Gaza is far […]

This article is published in association with European Investment Bank.

Will AI kickstart a new age of nuclear power?

This article is published in association with United Nations. The rapidly expanding use of artificial intelligence worldwide is putting electrical grids under huge pressure and many believe that, to meet that need without contributing to the climate crisis, a full-scale expansion of nuclear energy is essential. The global demand for electricity is growing at a vertiginous […]

UN Photo/Loey Felipe Martha Ama Akyaa Pobee, Assistant Secretary-General for Political Affairs briefs the Security Council meeting on the situation in Iran.

Iran: UN urges ‘maximum restraint’ to avert more death, wider escalation

This article is published in association with United Nations. As nationwide protests in Iran appear to ease after nearly three weeks of unrest and bloodshed, a senior UN official called on Thursday for action to prevent further escalation.  Assistant Secretary-General Martha Pobee briefed an emergency meeting of the Security Council in New York called by the […]

UNRWA UNRWA Headquarters in East Jerusalem

East Jerusalem: Forced shutdown of UN clinic signals escalating disregard for international law

This article is published in association with United Nations. The temporary closure of a UN-run health centre in East Jerusalem is the latest phase in “a pattern of deliberate disregard” for international law, the head of the UN agency that assists Palestine refugees, UNRWA, said on Wednesday.  Israeli forces stormed the UNRWA-operated health centre on Monday and ordered it […]

Unsplash

Iran: ‘The killing of peaceful demonstrators must stop,’ UN rights chief says

This article is published in association with United Nations.  As anti-government demonstrations continue across Iran, the UN human rights chief said on Tuesday that he was horrified at the mounting violence directed by security forces against protestors, with reports of hundreds killed and thousands arrested.  Volker Türk urged the authorities to immediately halt all forms of violence and repression against peaceful […]

© UNHCR/Yevheniia Kozun The bombing of residential buildings in Saltivka, Kharkiv, has left many Ukrainians without power.

Ukraine: Deadly Russian strikes push civilians deeper into winter crisis

This article is published in association with United Nations. Ukraine has entered the new year under intensifying and deadly Russian attacks which have crippled energy systems and left millions without heating, electricity or water amid freezing temperatures, senior UN officials told the Security Council on Monday. Under-Secretary-General for Political Affairs Rosemary DiCarlo told ambassadors the start […]

UN Photo/Eskinder Debebe UN Secretary-General António Guterres. (file photo)

UN chief ‘shocked’ by reports of excessive force against protesters in Iran

This article is published in association with United Nations. The UN Secretary-General is shocked by reports of violence and excessive use of force by Iranian authorities against protesters across the country, urging restraint and the immediate restoration of communications as unrest enters its third week. “All Iranians must be able to express their grievances peacefully and […]

Ukraine: New strikes disrupt basic services for millions

Ukraine: New strikes disrupt basic services for millions

This article is published in association with United Nations. Several parts of Ukraine were hit by a new wave of Russian strikes between Wednesday and Thursday morning. The attacks over the last 24 hours left civilians reportedly killed and injured in the port city of Odesa, interrupting power and water supplies there, as well as in […]

©WFP/Sayed Asif Mahmud Oleg Kemin from the UN World Food Programme (WFP) stands in front of his vehicle in Kherson, Ukraine.

Drones, fear and exhaustion: The daily reality of providing aid to Ukraine

This article is published in association with United Nations. Almost four years since Russia’s full-scale invasion of Ukraine, aid teams continue to adapt to the lethal reality of working in a modern war zone.  For frontline workers like Oleg Kemin from the UN World Food Programme (WFP), this involves travelling deep into disputed territory along the […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading