Why we need business, operational and financial resilience to optimize cybersecurity

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Eric Swalwell, Congressman, 15th District of California, U.S. House Foreign Affairs Committee


  • To drive down risk and improve resilience against malicious cyber activity, governments and the private sector must evolve their respective approaches to cybersecurity risk management.The private sector and the government are well-served by building cybersecurity into every aspect of operations and governance.Investing in cybersecurity costs money, but shortchanging cybersecurity investments costs more.

The average cost of a data breach in 2022 was $4.35 million and is expected to reach $5 million in 2023. Cybersecurity research firm Cyber Ventures predicts that cybercrimes will cost the world $10.5 trillion by 2025. According to the Securities and Exchange Commission (SEC), “the potential costs and damage that can stem from a cybersecurity incident are extensive. Many smaller companies have been targets of cybersecurity attacks so severe that the companies have gone out of business as a result.”To drive down risk and improve resilience to malicious cyber activity, governments and the private sector must evolve their respective approaches to cybersecurity risk management. Both parties must leverage their capabilities more strategically and develop frameworks to prioritise investments aligned to cyber threats.

Call to action

In March 2023, the White House released its long-anticipated National Cybersecurity Strategy. Charting the course for this “decisive decade,” the Strategy recognizes that different actors throughout the digital ecosystem have comparative advantages when it comes to reducing risk, observing malicious cyber activity, synthesizing threat information and producing actionable guidance, disrupting threat actors and building resilience. To that end, the Strategy demands more from government and the private sector.Two overarching principles drive the National Cybersecurity Strategy. First, “most capable and best-positioned actors in cyberspace must be better stewards of the digital ecosystem.” Second, the “economy and society must incentivize decision-making to make cyberspace more resilient and defensible over the long term.” Aligning policy and business decisions with these principles will undoubtedly raise our national cybersecurity posture. A more secure and resilient cyber domain is also good for business – investing in security costs money, but cleaning up a breach costs more. Making the investments necessary to absorb additional responsibility for security may involve short-term costs, but it will also raise public confidence in the reliability of critical infrastructure and technology, increase productivity and profits and enable stronger, more strategic partnerships between the federal government and the private sector. In short, the private sector and the government are well-served by building cybersecurity into every aspect of operations and governance.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum Centre for Cybersecurity drives global action to address systemic cybersecurity challenges. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors. Here are some examples of the impact delivered by the centre:Cybersecurity training: Salesforce, Fortinet, and the Global Cyber Alliance, in collaboration with the Forum, provide free and accessible training to the next generation of cybersecurity experts worldwide.Cyber resilience: Working its partners, the Centre is playing a pivotal role in enhancing cyber resilience across multiple industries: Oil and Gas, Electricity, Manufacturing and Aviation.IoT security: The Council on the Connected World, led by the Forum, has established IoT security requirements for consumer-facing devices, safeguarding them against cyber threats. This initiative calls upon major manufacturers and vendors globally to prioritize better IoT security measures.Paris Call for Trust and Security in Cyberspace: The Forum is proud to be a signatory of the Paris Call, which aims to ensure global digital peace and security, emphasizing the importance of trust and collaboration in cyberspace.

Contact us for more information on how to get involved.

A paradigm shift for government

Historically, the federal government relied on voluntary frameworks to encourage the adoption of strong cybersecurity standards by the private sector. Cyber incidents, such as the SolarWinds supply chain attack and the Colonial Pipeline ransomware attack, however, revealed the limitations of a purely voluntary model and underscored the cascading consequences of cyber incidents. Even before the release of the National Cybersecurity Strategy, high-profile cyberattacks in 2020 and 2021 forced the federal government to reassess its reliance on voluntary measures to improve cybersecurity for critical infrastructure and technology companies. Recognizing the need to raise the collective visibility of malicious activity on domestic networks, the US Congress enacted the Cyber Incident Reporting for Critical Infrastructure Act of 2021, which directed covered entities to report certain cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours. This legislation earned the buy-in of the private sector because it enabled the federal government to disrupt malicious cyber campaigns sooner and provide critical insights into the tactics of our adversariesMeanwhile, the Executive Branch has been prolific in its efforts to encourage the adoption of more robust cybersecurity practices. Deputy National Security Advisor for Cyber and Emerging Technology, Anne Neuberger, wrote an open letter to corporate executives and business leaders in June 2021, urging them to implement the five best practices from Executive Order 14028, including using third-party penetration testers and refining incident response plans. In July 2021, President Biden signed the National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems, directing the Department of Homeland Security (DHS) and the Department of Commerce to develop cybersecurity performance goals for critical infrastructure. The two departments released the first version of the baseline cross-sector Cybersecurity Performance Goals (CPG) in October 2022 and have updated them since. Since they were released, the CPGs have informed new federal cybersecurity requirements for surface transportation and aviation, among others. In February 2023, CISA Director, Jen Easterly, and Executive Assistant Director for Cybersecurity, Eric Goldstein, published an article in Foreign Affairs magazine making the case that: “in every business, the responsibility for cybersecurity needs to be elevated from the IT department to the board, the CEO and the senior executive level.” To that end, Director Easterly and Executive Assistant Director Goldstein declared “every technology provider must begin by creating products that are both ‘secure by default’ and ‘secure by design.’” They have been advocating for adoption of those principles ever since

Relatedly, in March 2022, the Securities and Exchange Commission (SEC) released a proposed rule on cybersecurity risk management and governance. The new SEC rules seek to engage senior management and the board in a meaningful way.

Among other things, the proposed rule clarifies disclosure requirements related to a registrant’s policies and procedures for identifying and managing cybersecurity risks, cybersecurity governance structure, management’s role in addressing and mitigating cybersecurity risks and whether an individual with cybersecurity expertise sits on the registrant’s board. These requirements underscore the importance of advancing risk management and governance efforts across the boardroom community to ensure resources and investments are applied to those cyber risks that have the most material financial, business and operational impact.The National Cybersecurity Strategy builds on the Administration’s work to date. While the federal approach to cybersecurity is evolving – and that evolution may result in new standards – it will also drive better cybersecurity practices for critical infrastructure and technology companies, reducing the risk for cyberattacks that hurt productivity, public confidence and, ultimately, profits.

Too often, cybersecurity gets lost in translation when engaging board members and the C-suite. This leaves leadership unsure of precisely what they are funding and where residual gaps remain.

— Chris Hetner, Chair of the Nasdaq Center for Board Excellence Insights Council

For its part, the government has an obligation to its private sector partners to demonstrate the security value of new cybersecurity requirements and public-private partnerships. As the Strategy demands more of the private sector, it makes bold commitments on behalf of the government. It envisions a full-court press to tackle malicious cyber activity – from international coordination on ransomware and aggressively going after cyber criminals to disrupting malicious cyber campaigns and taking down threat actors’ infrastructure.The government is doing a lot of that already – earlier this year the FBI infiltrated the Hive ransomware group, captured decryption keys and distributed them to victims. In April, the FBI and its international partners took down Genesis, an online store of hacked and stolen data. Together, these actions demonstrate how the government can leverage its unique resources and authorities to reduce risk to its partners and the public.Additionally, as the government creates new standards for the private sector, it should ensure that any additional burdens are harmonized across all levels of government. Compliance costs should not detract from security investments. The Strategy commits to harmonizing regulations through the Office of the National Cyber Director and the Office of Management and Budget, much like the Cyber Incident Reporting Council at DHS is working to deconflict various cyber incident reporting requirements. However, these harmonization efforts navigate the complexities of independent agency regulators.Finally, government must develop a framework to better assess interdependencies across critical infrastructure owners and operators and the potential cascading effects of cyber incidents. A sound framework for such analysis will drive strategic investments in security and facilitate greater resiliency. The Cybersecurity and Infrastructure Security Agency (CISA) is in the process of doing just that.

Working smarter

The cybersecurity ecosystem (people, processes, technology) is largely focused on addressing technical-level threats used to mitigate risk. While the cybersecurity ecosystem continues to evolve, it still lacks the ability to contextualize cyber threats and incidents to business, operational and financial exposures. The ‘material’ determination is influenced by the incident’s impact on the company’s business, operations and financial condition. Below is an enumeration of the types of business and financial factors that should be contemplated when determining incident materiality. The types of costs and adverse consequences that companies may incur or experience as a result of a cybersecurity incident include the following:• Costs due to business interruption, decreases in production and delays in product launches.• Payments to meet ransom and other extortion demands.• Remediation costs, such as liability for stolen assets or information, repairs of system damage and incentives to customers or business partners in an effort to maintain relationships after an attack.• Increased cybersecurity protection costs, which may include increased insurance premiums and the costs of making organizational changes, deploying additional personnel and protection technologies, training employees and engaging third-party experts and consultants.• Lost revenues resulting from intellectual property theft and the unauthorized use of proprietary information or the failure to retain or attract customers following an attack.• Litigation and legal risks, including regulatory actions by state and federal governmental authorities and non-U.S. authorities.• Harm to employees and customers, violation of privacy laws and reputational damage that adversely affects customer or investor confidence. • Damage to the company’s competitiveness, stock price and long-term shareholder value.Cyber risk management is a team sport that requires the entirety of the enterprise to ensure business resilience. What is required is a more inclusive message and collaboration that includes all enterprise risk management leaders.Technology changes quickly and so do cyber threats. Static analyses of today’s risk are less helpful than establishing a regular flow of information to the board that supports cybersecurity investment decisions based on business, operational and financial considerations. With the board’s eyes kept regularly on cybersecurity as an aspect of routine governance, directors will be equipped to comply with the SEC’s new requirements.

Cyber risk is a discussion for directors and officers

Chris Hetner, former senior cybersecurity advisor to the SEC Chair and Chair of the Nasdaq Center for Board Excellence Insights Council, says: “It is essential for boards to continuously incorporate cyber risk management discussions related to the most effective way to reduce the financial and business impact connected with cyber risk. The conversation isn’t just for the Chief Information Officer (CIO) and Chief Information Security Officer (CISO). It is a broader c-suite discussion, which must be led by the Chief Financial Officer (CFO) and General Counsel.”Hetner says that boards can no longer ignore cybersecurity, noting: “The default tendency of executives is to rely on periodic tactical and technical reports to justify tech solutions that may address technical security issues.” He adds that: “Too often, cybersecurity gets lost in translation when engaging board members and the C-suite. This leaves leadership unsure of precisely what they are funding and where residual gaps remain.”Hetner and the NACD recently supported the launch of a service where boards are supported to more effectively provide oversight related to cyber risk exposure. The X-Analytics and NACD Cyber Risk-Reporting Service is an annual subscription providing quarterly board reports highlighting the financial exposure attributed to an organization’s cyber risk. The platform relies on the same analytics used by leaders within the cyber insurance industry.This new NACD service facilitates a broader c-suite conversation related to cyber risk and assists boards in engaging in discussions that transcend the technical aspects of cybersecurity.

To conclude, investing in cybersecurity costs money. Shortchanging cybersecurity investments costs more.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© UNICEF A damaged ambulance in Tebnine in southern Lebanon.

In Lebanon, the same fears and dangers persist despite ceasefire: UNHCR

This article is published in association with United Nations. Death and destruction have continued unabated in Lebanon while communities are still unable to return to their homes despite a ceasefire that began on 17 April, humanitarians said on Tuesday. “Civilians in the south of Lebanon and parts of the Bekaa [Valley] are really living with the […]
© Unsplash/Planet Volumes A computer-generated image shows the Strait of Hormuz.

Uncertainty continues over safety in the Strait of Hormuz

This article is published in association with United Nations. Amid claims and counter-claims of strikes and confrontations in the crucial Strait of Hormuz between Iran and the United States, UN maritime officials continue to urge vessels to exercise “maximum caution”. “We are aware of the reports but do not have further details. We continue to urge […]
© ADB/Ariel Javellana Women farmers in India sell wheat grain and buy fertilizer with the proceeds.

Middle East crisis puts aid, food, fuel further out of reach for millions already struggling – UN agencies

This article is published in association with United Nations. As the Middle East crisis continues the humanitarian fallout is worsening, with aid route disruptions and food and fuel price hikes wrecking the lives and the rights of the most vulnerable people worldwide, UN agencies warned on Friday. Heightened insecurity and instability around key Gulf routes, including […]
© Unsplash/Angus Gray Ship transits through the Strait of Hormuz have dropped by over 90 per cent since the crisis escalated in late February 2026.

Hormuz crisis strangling global economy, Guterres warns, demanding solutions to end stalemate

This article is published in association with United Nations. The escalating crisis in the Strait of Hormuz could push tens of millions into poverty, trigger a surge in global hunger and even tip the world towards recession, the UN Secretary-General warned on Thursday. António Guterres decried the restrictions on free passage through the crucial chokepoint which […]
This article is published in association with United Nations.

AI in advertising risks fuelling information crisis, UN warns

This article is published in association with United Nations. With spending on advertising topping $1 trillion a year worldwide, the United Nations on Wednesday highlighted the untapped power of major brands to shape the future of Artificial Intelligence, warning that a failure to act could deepen a global information integrity crisis. In a new brief titled […]
This article is published in association with United Nations.

2015 nuclear deal ‘no basis’ for any new agreement with Iran

This article is published in association with United Nations. The 2015 nuclear accord with Iran cannot be the starting point for a new agreement with the country, the head of the International Atomic Energy Agency (IAEA) said on Wednesday in New York.  Rafael Mariano Grossi was speaking during a press conference at UN Headquarters held on […]
Credit:Unsplash)

From Hormuz to Lebanon, crisis reverberates through trade routes, upending humanitarian networks

© WHO/Hanan Balkhy In Gaza displaced families are living in overcrowded tents and makeshift shelters, surrounded by waste and debris, with limited access to safe water and sanitation services. This article is published in association with United Nations. Disruptions in the Strait of Hormuz continue to send shockwaves through global food systems, the UN Food and Agriculture […]
© UNICEF/Mohamed Zakaria A displacement centre in El Fasher, North Darfur (file).

World News in Brief: Sudan drone attacks condemned, South Sudan violence, airstrikes in Ukraine, South Africa Freedom Day

This article is published in association with United Nations. The United Nations has condemned two recent drone attacks in Sudan, one of which left seven dead, Spokesperson Stéphane Dujarric said on Monday during his regular media briefing in New York. An aid truck from the UN refugee agency (UNHCR) that was carrying emergency shelter kits came under attack by […]
© IMO/Cihancan Tunay A ship makes its way across an ocean.

Chokepoints and conflict: How the Hormuz crisis is exposing global shipping vulnerabilities

This article is published in association with United Nations. The blockading of ships in the Strait of Hormuz as a result of the conflict between the United States and Iran has demonstrated how ships and seafarers have become “leverage in geopolitical disputes,” according to the head of the UN’s International Maritime Organization (IMO). Since conflict began […]
Middle East war: After oil and gas, concerns grow over minerals crunch

Middle East war: After oil and gas, concerns grow over minerals crunch

This article is published in association with United Nations. The shipping crisis in the Strait of Hormuz caused by war in the Middle East has exposed a new threat: a looming shortage of strategic minerals that drive economies all over the world – and a race by countries to obtain them. Until war erupted on 28 […]
This article is published in association with United Nations.

Ceasefire extension offers diplomatic opening, but tensions persist in Strait of Hormuz

This article is published in association with United Nations. The United States’ decision to extend a fragile ceasefire with Iran has kept a narrow window open for diplomacy, but fresh security incidents in the Strait of Hormuz on Wednesday underscore the volatility of the situation and the risks to global shipping and regional stability. The UN […]
UN News Moreira da Silva (right), Executive Director of UNOPS on a visit to the Gaza Strip.

Strait of Hormuz: With hunger looming, life-saving fertiliser shipments cannot wait, head of UN task force says

This article is published in association with United Nations. As the Persian Gulf crisis continues, time is ticking for farmers who rely on fertilizer shipped via the Strait of Hormuz – and millions worldwide who depend on their crops, particularly in vulnerable countries such as war-torn Sudan.  In normal times, one third of global fertiliser trade […]
UN News A popular market in Khan Younis, southern Gaza Strip.

Economic collapse pushes highly educated Gazans into the ‘survival economy’

This article is published in association with United Nations. Young Palestinians in Gaza with university-level educations are setting aside dreams of putting their hard-won skills into practice and doing whatever they can to survive.  Abdullah al-Khawaja, an electrical engineering graduate displaced from Rafah to Khan Younis, now stands behind a small spice stall, having lost the […]
MONUSCO/Didier Vignon Dossou-Gbakon MONUSCO peacekeepers protect civilians in Ituri, eastern DRC.

World News in Brief: AI diagnostics, humanitarian deal for DR Congo, rights abuse allegations in Belarus, Ukraine children bear heaviest burden

This article is published in association with United Nations. New data shows that nearly three in four countries in Europe now use Artificial Intelligence in their health services to make a diagnosis. According to the UN World Health Organization (WHO) joint report with the European Union, 74% of countries in the bloc use AI tools in medical […]
© WFP The conflict in the Middle East is impacting the cost of food in many parts of the world.

Time running out on development goals as finance dries up, UN warns

This article is published in association with United Nations. Rising conflicts, the climate crisis and shrinking development finance are putting growing pressure on the poorest and most vulnerable countries – pushing development goals further off track. The warning comes in the Financing for Sustainable Development Report 2026 (FSDR), a new UN report launched on Monday, which finds […]
Ukraine’s women at breaking point after four years of war as attacks on energy, healthcare continue – UN humanitarians

World News in Brief: Myanmar amnesty, rising needs in Afghanistan, another power loss at Ukraine nuclear plant

This article is published in association with United Nations. Authorities in Myanmar released the country’s ousted president from prison on Friday, along with some 4,000 other people, as part of an amnesty to mark the traditional New Year festival. President Win Myint had been in jail since February 2021 when the military overthrew Myanmar’s democratically elected […]
UN Photo/Eskinder Debebe Siobhán Mullally, Special Rapporteur on Trafficking in Persons, especially women and children, one of the UN independent human rights experts calling for more accountability for the alleged trafficking victims in the Epstein files.

The Epstein files: Rights experts demand accountability, call for probe into trafficking allegations

This article is published in association with United Nations. UN independent human rights experts called on Thursday for justice and accountability for young women and girls who were trafficked systematically as part of allegations contained in the so-called Epstein files. The Human Rights Council-appointed experts also issued a general warning over the “continuing violence of patriarchal power systems” revealed […]
© World Bank A ship offloads its cargo at the port in Nuku'alofa, Tonga.

Middle East conflict chokes end of supply chain as lights go out in the Pacific

This article is published in association with United Nations. For Pacific Island countries, the Middle East crisis is not a distant geopolitical event. It is already showing up in higher fuel prices, electricity uncertainty and fears that communities sitting at the far end of global supply chains could be pushed into deeper economic insecurity. “We are […]
© UNICEF/Fouad Choufany The Basta neighbourhood in Beirut, Lebanon, lies in ruins.

‘Time for diplomacy over escalation’ in Middle East war: Guterres

This article is published in association with United Nations. As the war in the Middle East continues, the United Nations Secretary-General issued a passionate call for “serious negotiations” between the US and Iran to resume, warning that respect for international law “is being trampled” underfoot.  Addressing journalists at UN Headquarters in New York outside the Security […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com