Why we need business, operational and financial resilience to optimize cybersecurity

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Eric Swalwell, Congressman, 15th District of California, U.S. House Foreign Affairs Committee


  • To drive down risk and improve resilience against malicious cyber activity, governments and the private sector must evolve their respective approaches to cybersecurity risk management.The private sector and the government are well-served by building cybersecurity into every aspect of operations and governance.Investing in cybersecurity costs money, but shortchanging cybersecurity investments costs more.

The average cost of a data breach in 2022 was $4.35 million and is expected to reach $5 million in 2023. Cybersecurity research firm Cyber Ventures predicts that cybercrimes will cost the world $10.5 trillion by 2025. According to the Securities and Exchange Commission (SEC), “the potential costs and damage that can stem from a cybersecurity incident are extensive. Many smaller companies have been targets of cybersecurity attacks so severe that the companies have gone out of business as a result.”To drive down risk and improve resilience to malicious cyber activity, governments and the private sector must evolve their respective approaches to cybersecurity risk management. Both parties must leverage their capabilities more strategically and develop frameworks to prioritise investments aligned to cyber threats.

Call to action

In March 2023, the White House released its long-anticipated National Cybersecurity Strategy. Charting the course for this “decisive decade,” the Strategy recognizes that different actors throughout the digital ecosystem have comparative advantages when it comes to reducing risk, observing malicious cyber activity, synthesizing threat information and producing actionable guidance, disrupting threat actors and building resilience. To that end, the Strategy demands more from government and the private sector.Two overarching principles drive the National Cybersecurity Strategy. First, “most capable and best-positioned actors in cyberspace must be better stewards of the digital ecosystem.” Second, the “economy and society must incentivize decision-making to make cyberspace more resilient and defensible over the long term.” Aligning policy and business decisions with these principles will undoubtedly raise our national cybersecurity posture. A more secure and resilient cyber domain is also good for business – investing in security costs money, but cleaning up a breach costs more. Making the investments necessary to absorb additional responsibility for security may involve short-term costs, but it will also raise public confidence in the reliability of critical infrastructure and technology, increase productivity and profits and enable stronger, more strategic partnerships between the federal government and the private sector. In short, the private sector and the government are well-served by building cybersecurity into every aspect of operations and governance.

Discover

What is the World Economic Forum doing on cybersecurity?

The World Economic Forum Centre for Cybersecurity drives global action to address systemic cybersecurity challenges. It is an independent and impartial platform fostering collaboration on cybersecurity in the public and private sectors. Here are some examples of the impact delivered by the centre:Cybersecurity training: Salesforce, Fortinet, and the Global Cyber Alliance, in collaboration with the Forum, provide free and accessible training to the next generation of cybersecurity experts worldwide.Cyber resilience: Working its partners, the Centre is playing a pivotal role in enhancing cyber resilience across multiple industries: Oil and Gas, Electricity, Manufacturing and Aviation.IoT security: The Council on the Connected World, led by the Forum, has established IoT security requirements for consumer-facing devices, safeguarding them against cyber threats. This initiative calls upon major manufacturers and vendors globally to prioritize better IoT security measures.Paris Call for Trust and Security in Cyberspace: The Forum is proud to be a signatory of the Paris Call, which aims to ensure global digital peace and security, emphasizing the importance of trust and collaboration in cyberspace.

Contact us for more information on how to get involved.

A paradigm shift for government

Historically, the federal government relied on voluntary frameworks to encourage the adoption of strong cybersecurity standards by the private sector. Cyber incidents, such as the SolarWinds supply chain attack and the Colonial Pipeline ransomware attack, however, revealed the limitations of a purely voluntary model and underscored the cascading consequences of cyber incidents. Even before the release of the National Cybersecurity Strategy, high-profile cyberattacks in 2020 and 2021 forced the federal government to reassess its reliance on voluntary measures to improve cybersecurity for critical infrastructure and technology companies. Recognizing the need to raise the collective visibility of malicious activity on domestic networks, the US Congress enacted the Cyber Incident Reporting for Critical Infrastructure Act of 2021, which directed covered entities to report certain cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours. This legislation earned the buy-in of the private sector because it enabled the federal government to disrupt malicious cyber campaigns sooner and provide critical insights into the tactics of our adversariesMeanwhile, the Executive Branch has been prolific in its efforts to encourage the adoption of more robust cybersecurity practices. Deputy National Security Advisor for Cyber and Emerging Technology, Anne Neuberger, wrote an open letter to corporate executives and business leaders in June 2021, urging them to implement the five best practices from Executive Order 14028, including using third-party penetration testers and refining incident response plans. In July 2021, President Biden signed the National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems, directing the Department of Homeland Security (DHS) and the Department of Commerce to develop cybersecurity performance goals for critical infrastructure. The two departments released the first version of the baseline cross-sector Cybersecurity Performance Goals (CPG) in October 2022 and have updated them since. Since they were released, the CPGs have informed new federal cybersecurity requirements for surface transportation and aviation, among others. In February 2023, CISA Director, Jen Easterly, and Executive Assistant Director for Cybersecurity, Eric Goldstein, published an article in Foreign Affairs magazine making the case that: “in every business, the responsibility for cybersecurity needs to be elevated from the IT department to the board, the CEO and the senior executive level.” To that end, Director Easterly and Executive Assistant Director Goldstein declared “every technology provider must begin by creating products that are both ‘secure by default’ and ‘secure by design.’” They have been advocating for adoption of those principles ever since

Relatedly, in March 2022, the Securities and Exchange Commission (SEC) released a proposed rule on cybersecurity risk management and governance. The new SEC rules seek to engage senior management and the board in a meaningful way.

Among other things, the proposed rule clarifies disclosure requirements related to a registrant’s policies and procedures for identifying and managing cybersecurity risks, cybersecurity governance structure, management’s role in addressing and mitigating cybersecurity risks and whether an individual with cybersecurity expertise sits on the registrant’s board. These requirements underscore the importance of advancing risk management and governance efforts across the boardroom community to ensure resources and investments are applied to those cyber risks that have the most material financial, business and operational impact.The National Cybersecurity Strategy builds on the Administration’s work to date. While the federal approach to cybersecurity is evolving – and that evolution may result in new standards – it will also drive better cybersecurity practices for critical infrastructure and technology companies, reducing the risk for cyberattacks that hurt productivity, public confidence and, ultimately, profits.

Too often, cybersecurity gets lost in translation when engaging board members and the C-suite. This leaves leadership unsure of precisely what they are funding and where residual gaps remain.

— Chris Hetner, Chair of the Nasdaq Center for Board Excellence Insights Council

For its part, the government has an obligation to its private sector partners to demonstrate the security value of new cybersecurity requirements and public-private partnerships. As the Strategy demands more of the private sector, it makes bold commitments on behalf of the government. It envisions a full-court press to tackle malicious cyber activity – from international coordination on ransomware and aggressively going after cyber criminals to disrupting malicious cyber campaigns and taking down threat actors’ infrastructure.The government is doing a lot of that already – earlier this year the FBI infiltrated the Hive ransomware group, captured decryption keys and distributed them to victims. In April, the FBI and its international partners took down Genesis, an online store of hacked and stolen data. Together, these actions demonstrate how the government can leverage its unique resources and authorities to reduce risk to its partners and the public.Additionally, as the government creates new standards for the private sector, it should ensure that any additional burdens are harmonized across all levels of government. Compliance costs should not detract from security investments. The Strategy commits to harmonizing regulations through the Office of the National Cyber Director and the Office of Management and Budget, much like the Cyber Incident Reporting Council at DHS is working to deconflict various cyber incident reporting requirements. However, these harmonization efforts navigate the complexities of independent agency regulators.Finally, government must develop a framework to better assess interdependencies across critical infrastructure owners and operators and the potential cascading effects of cyber incidents. A sound framework for such analysis will drive strategic investments in security and facilitate greater resiliency. The Cybersecurity and Infrastructure Security Agency (CISA) is in the process of doing just that.

Working smarter

The cybersecurity ecosystem (people, processes, technology) is largely focused on addressing technical-level threats used to mitigate risk. While the cybersecurity ecosystem continues to evolve, it still lacks the ability to contextualize cyber threats and incidents to business, operational and financial exposures. The ‘material’ determination is influenced by the incident’s impact on the company’s business, operations and financial condition. Below is an enumeration of the types of business and financial factors that should be contemplated when determining incident materiality. The types of costs and adverse consequences that companies may incur or experience as a result of a cybersecurity incident include the following:• Costs due to business interruption, decreases in production and delays in product launches.• Payments to meet ransom and other extortion demands.• Remediation costs, such as liability for stolen assets or information, repairs of system damage and incentives to customers or business partners in an effort to maintain relationships after an attack.• Increased cybersecurity protection costs, which may include increased insurance premiums and the costs of making organizational changes, deploying additional personnel and protection technologies, training employees and engaging third-party experts and consultants.• Lost revenues resulting from intellectual property theft and the unauthorized use of proprietary information or the failure to retain or attract customers following an attack.• Litigation and legal risks, including regulatory actions by state and federal governmental authorities and non-U.S. authorities.• Harm to employees and customers, violation of privacy laws and reputational damage that adversely affects customer or investor confidence. • Damage to the company’s competitiveness, stock price and long-term shareholder value.Cyber risk management is a team sport that requires the entirety of the enterprise to ensure business resilience. What is required is a more inclusive message and collaboration that includes all enterprise risk management leaders.Technology changes quickly and so do cyber threats. Static analyses of today’s risk are less helpful than establishing a regular flow of information to the board that supports cybersecurity investment decisions based on business, operational and financial considerations. With the board’s eyes kept regularly on cybersecurity as an aspect of routine governance, directors will be equipped to comply with the SEC’s new requirements.

Cyber risk is a discussion for directors and officers

Chris Hetner, former senior cybersecurity advisor to the SEC Chair and Chair of the Nasdaq Center for Board Excellence Insights Council, says: “It is essential for boards to continuously incorporate cyber risk management discussions related to the most effective way to reduce the financial and business impact connected with cyber risk. The conversation isn’t just for the Chief Information Officer (CIO) and Chief Information Security Officer (CISO). It is a broader c-suite discussion, which must be led by the Chief Financial Officer (CFO) and General Counsel.”Hetner says that boards can no longer ignore cybersecurity, noting: “The default tendency of executives is to rely on periodic tactical and technical reports to justify tech solutions that may address technical security issues.” He adds that: “Too often, cybersecurity gets lost in translation when engaging board members and the C-suite. This leaves leadership unsure of precisely what they are funding and where residual gaps remain.”Hetner and the NACD recently supported the launch of a service where boards are supported to more effectively provide oversight related to cyber risk exposure. The X-Analytics and NACD Cyber Risk-Reporting Service is an annual subscription providing quarterly board reports highlighting the financial exposure attributed to an organization’s cyber risk. The platform relies on the same analytics used by leaders within the cyber insurance industry.This new NACD service facilitates a broader c-suite conversation related to cyber risk and assists boards in engaging in discussions that transcend the technical aspects of cybersecurity.

To conclude, investing in cybersecurity costs money. Shortchanging cybersecurity investments costs more.

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

This article is brought to you in association with the European Commission.

World News in Brief: US-Iran war intensifies, aid for Myanmar, casualties in Ukraine

This article is published in association with United Nations. Fighting between the United States and Iran has sharply escalated after a month-long lull, with the two sides exchanging strikes as fears grow over further civilian casualties. The US military struck rocket launchers on an island in the Strait of Hormuz over the weekend, days after US […]
© WFP/Hugh Rutherford A family eat lunch in the Bedouin community of Umm Al Khair, West Bank.

Food aid cutback in the occupied West Bank as health fears grow in Gaza

This article is published in association with United Nations. Lack of funding has forced the World Food Programme (WFP) to slash aid to families in the West Bank by half even though needs have more than doubled over the past two years. “We’re running out of funding, and that means that from today, some 200,000 people […]
© UNICEF/Laxmi Prasad Ngakhusi Mud covers Nuwakot district in central-northern Nepal following devastating flash floods.

Nepal flooding deaths surpass 900 as needs climb

This article is published in association with United Nations. The confirmed death toll from Nepal’s catastrophic floods has surged to 903, with more than 4,200 still missing as rescue crews and humanitarian workers battle blocked highways to reach the hardest-hit areas, UN Spokesperson Stéphane Dujarric said on Monday. Key points Triggered by a glacier collapse and […]
© WFP/Mohamad Al Hinnawi Brothers sitting outside their family’s tent in Gaza.

Four children killed as separate attacks in Gaza destroy aid supplies

This article is published in association with United Nations. Israeli attacks killed four children and destroyed humanitarian aid supplies in what turned out to be a deadly week in war-ravaged Gaza, the UN emergency relief agency, OCHA, said on Friday. Key points According to UNICEF, the four children – aged two to 16 – were reportedly […]
© UNICEF Buildings are submerged in mud following flash floods in Rasuwa district in central-northern Nepal.

Deadly floods cause widespread destruction in China, Nepal

This article is published in association with United Nations. Severe flooding in China and Nepal caused widespread destruction and mounting death tolls, UN agencies reported on Wednesday as aid efforts deployed to help provide emergency assistance. UN agencies and humanitarian partners are already providing support to local authorities, said UN Spokesperson Stéphane Dujarric. “The Secretary-General is […]
This article is published in association with European Investment Bank.

As wars spread, the global food system unravels

This article is published in association with United Nations. A family with four children abandoned its farm in Somalia after armed groups arrived and demanded payments for the right to continue cultivating the land. They walked roughly 100 kilometers to a displacement camp. One of the children died along the way. Carl Skau, the acting head […]
This article is published in association with United Nations.

Gaza: Children still at risk despite drop in acute hunger

This article is published in association with United Nations. Among tent cities pitched on the rubble of destroyed homes in Gaza, children are, by one measure, finally getting enough to eat. By another, however, many of them may never fully recover, according to a new study by the UN Children’s Fund (UNICEF) released on Monday. Key points Hunger […]
UN Photo/Elma Okic Secretary-General of the International Telecommunication Union (ITU) Doreen Bogdan-Martin speaks at the AI for Good Global Summit in Geneva. (file)

AI for Good: How the UN uses AI to advance human rights

This article is published in association with United Nations. For Ari, a six-year-old boy with learning difficulties in Jamaica, artificial intelligence (AI) opened the door to something many children take for granted: reading a book in his own language. Thousands of miles away, gold miners in Ethiopia are being screened more quickly for tuberculosis, while communities around […]
This article was exclusively written for The European Sting by Ms. Imane El Maimouni, a 22-year-old fifth-year Moroccan medical student at the Faculty of Medicine and Pharmacy of Casablanca. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on the topic, nor The European Sting’s one.

Who heals the healers?

This article was exclusively written for The European Sting by Ms. Levina Kulembeka, a Medical Doctor from Tanzania passionate about global health. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to the writer and do not necessarily reflect IFMSA’s view on […]
© WFP/Mohamad Al Hinnawi Brothers sitting outside their family’s tent in Gaza.

Middle East: 94 per cent need shelter in Gaza, Israel ramps up demolitions in Lebanon

This article is published in association with United Nations. Ninety-four cent of Gaza’s 2.1 million residents need shelter as Israeli gunfire and strikes continue inside the enclave, UN agencies and peacekeepers warned on Thursday. Key points More than four out of five families currently face critical or catastrophic living conditions, which lack fuel, energy and essential […]
© IOM/Lisa George Flooding in Sudan has displaced 20,000 people since June (file).

Sudan war: 200,000 newly displaced as fighting and floods intensify

This article is published in association with United Nations. Intensifying fighting in Sudan has displaced at least another 200,000 people since late 2025, while destructive seasonal floods are compounding the massive humanitarian emergency there, the UN International Organization for Migration (IOM) said on Wednesday. In an alert, the agency also warned that relief access has been […]
© UNRWA/Kazem Abu-Khalaf A girl looks out the window of her home in the Jenin refugee camp in the West Bank, where she and other family members were trapped during an Israeli military operation.

Raising alarm over new illegal Israeli outposts, UN condemns attacks, incitement against Palestinians

This article is published in association with United Nations. Reports of new illegal Israeli outposts in the occupied West Bank raised alarms at UN Headquarters on Wednesday while the UN rights office called on Israel to condemn its national security minister’s words that incite “violence amounting to atrocity crimes” against Palestinians. Key points “The Secretary-General is […]
© IOM/Lisa George Flooding in Sudan has displaced 20,000 people since June (file).

Sudan war: 200,000 newly displaced as fighting and floods intensify

This article is published in association with United Nations. Intensifying fighting in Sudan has displaced at least another 200,000 people since late 2025, while destructive seasonal floods are compounding the massive humanitarian emergency there, the UN International Organization for Migration (IOM) said on Wednesday. In an alert, the agency also warned that relief access has been disrupted further […]
This article is published in association with United Nations.

Gaza: Only three per cent of cropland available to grow food

Amid ongoing deadly hostilities in Gaza, the enclave’s farmers face the increasingly difficult challenge of finding safe land to grow their crops. Satellite images published on Tuesday in news analysis from the UN Food and Agriculture Organization (FAO) and UNOSAT, the UN Satellite Centre, indicate that just three per cent (448 hectares) of the shattered enclave’s […]
© UNOCHA/Themba Linden A UN team inspects an unexploded bomb lying on a main road in Khan Younis, Gaza.

Qusra siege eases as UN reaches trapped families, but crisis deepens in Gaza

This article is published in association with United Nations. Humanitarian workers have reached Palestinian families who had been trapped for days by Israeli settlers in Qusra village in the northern West Bank, the UN said on Monday, as officials warned that the standoff must not become “the new normal.” UN teams on the ground reached the […]
© UNFPA Palestine A woman and two children walk near the city of Jenin in the West Bank.

900 obstacles and counting: West Bank families trapped as aid access shrinks

This article is published in association with United Nations. Humanitarians continue to provide life-saving assistance to people across the Occupied Palestinian Territory despite facing obstacles such as checkpoints, instability and access restrictions, the United Nations said on Friday.  In the West Bank, aid partners warn that their work “is being delayed and limited by a network […]
© UNICEF/Eyad El Baba A nine-year-old girl outside her damaged home in Nuseirat camp in central Gaza.

Gaza: Destruction of buildings rises by nearly 10 per cent since ceasefire

This article is published in association with United Nations. New satellite assessments show the destruction of buildings in Gaza has climbed by nearly 10 per cent since October’s faltering ceasefire between Hamas and Israeli forces aim to end the two-year war, which reduced cities to rubble and displaced more than one million people, UN agencies said […]
© SOS Méditerranée/Anthony Jean A team completed a rescue mission, saving 98 people from a dangerous journey in the central Mediterranean region in 2020. (file)

Migrant deaths climb sharply in 2026, new UN data shows

This article is published in association with United Nations. Severe weather, war, economic pressure and shifting policies reshaped migration journeys across multiple regions in the first four months of 2026, driving a surge in deaths, according to new data released on Wednesday by the International Organization for Migration (IOM). The agency’s newest route-based data shows a […]
© UNFPA Emergency responders walk through a debris-strewn street in Quibdó in northern Colombia following the earthquake.

UN continues scaling up response to earthquake in Colombia

This article is published in association with United Nations. The UN on Wednesday continued scaling up assistance to areas affected by the deadly earthquake that hit Colombia two days earlier. Tweet URL https://platform.twitter.com/embed/Tweet.html?creatorScreenName=UN_News_Centre&dnt=false&embedId=twitter-widget-0&features=eyJ0ZndfdGltZWxpbmVfbGlzdCI6eyJidWNrZXQiOltdLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X2ZvbGxvd2VyX2NvdW50X3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9iYWNrZW5kIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19yZWZzcmNfc2Vzc2lvbiI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfZm9zbnJfc29mdF9pbnRlcnZlbnRpb25zX2VuYWJsZWQiOnsiYnVja2V0Ijoib24iLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X21peGVkX21lZGlhXzE1ODk3Ijp7ImJ1Y2tldCI6InRyZWF0bWVudCIsInZlcnNpb24iOm51bGx9LCJ0ZndfZXhwZXJpbWVudHNfY29va2llX2V4cGlyYXRpb24iOnsiYnVja2V0IjoxMjA5NjAwLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3Nob3dfYmlyZHdhdGNoX3Bpdm90c19lbmFibGVkIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19kdXBsaWNhdGVfc2NyaWJlc190b19zZXR0aW5ncyI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdXNlX3Byb2ZpbGVfaW1hZ2Vfc2hhcGVfZW5hYmxlZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdmlkZW9faGxzX2R5bmFtaWNfbWFuaWZlc3RzXzE1MDgyIjp7ImJ1Y2tldCI6InRydWVfYml0cmF0ZSIsInZlcnNpb24iOm51bGx9LCJ0ZndfbGVnYWN5X3RpbWVsaW5lX3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9mcm9udGVuZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9fQ%3D%3D&frame=false&hideCard=false&hideThread=false&id=2087424955390865660&lang=en&origin=https%3A%2F%2Fnews.un.org%2Fen%2Fstory%2F2026%2F08%2F1168128&sessionId=9eb4055aa89180f054a0f5e31c06fbfd46ddaf0c&siteScreenName=UN_News_Centre&theme=light&widgetsVersion=6a3ad42b224df%3A1778106238597&width=550px According to latest official figures, the 7.4 magnitude quake has left more than 200 dead and injured over 2,500, said UN Deputy Spokesperson […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com