Site navigation

WEF Global Cybersecurity Outlook 2023 | Key Takeaways

Graham Turner

,

Global Cybersecurity Outlook 2023
The broad spectrum report looks at the relationship between business and cyber leaders, detailing each ones perspective on leading cyber issues and creating a narrative between what’s advised, and what’s actually actioned in board rooms with regards to cybersecurity.

The disparity between what cyber leaders CISO’s CTO’s and anyone else who has to convince a boardroom to invest in cybersecurity remains formidable, but is showing signs of improvement.

This is the broadest of broad takeaways from the World Economic Forum’s Global Cybersecurity Outlook report.

Business leaders are more aware of their organisations cyber issues and are more willing to address those risks. However, as the report breaks down in detail – and we will illuminate the report’s most pertinent stats – cyber leaders still struggle to articulate cyber risks in a way that compels leaders to action.

Geopolitics 

Global political instability has been a driver for interest rates, an energy crisis and general unease, so it’s no surprise that it’s playing its part in defining a large part of the global cybersecurity discourse.

According to the report, 93% of cyber leaders and 86% of business leaders think it is “moderately likely” or “very likely” that global geopolitical instability will lead to a far-reaching, catastrophic cyber event in the next two years.

Furthermore, 74% of organisation leaders say that global geopolitical instability has influenced their cyber strategy “moderately” or “substantially”. What concerns business leaders most in this regard is continuity (67%) and reputational damage (65%).

Leaders intend to address these concerns by ‘strengthening controls for third parties with access to their environments (73%) or data (66%), as well as re-evaluating the countries with whom they do business (50%).

Emerging Tech and Emerging Threats

Emerging technology is where the report found the greatest alignment between business and cyber leaders. In this regard, respondents said that artificial intelligence (AI) and machine learning (20%), greater adoption of cloud technology (19%) and advances in user identity and access management (15%) will have the greatest influence on their cyber risk strategies over the next two years.

The findings for the report indicated that a series of major global cyber incidents in 2021–2022, such as the exploitation of the widespread Log4j vulnerability, forced many organisations to focus on monitoring and assessing threat information.

Commenting, Derek Manky, Chief Security Strategist and Vice-President, Global Threat Intelligence, Fortinet, said: “Core resources are being thrown at cybercrime campaigns by criminal groups.

“There’s a sense that cybercrime is converging with nation-state actors and that this is leading to a higher number of new campaigns being launched as well as attacks that are more clearly tailored to the target organisation.

“The greater the volatility in the threat, the more time is being spent on tactical defence by CISOs and their teams. It’s important to create the space for strategic development and effective risk management.”

Laws and Regulations

This year’s Outlook report showed a large shift in the perception of how regulation affects cyber risk. The report states that in 2022, ‘more than half of respondents did not agree that cyber and privacy regulations are effective in reducing their organisations’ cyber risks.

This year’s report, however, indicates that 73% of respondents agree with the same statement.

Business and cyber leaders also support effective enforcement of regulatory requirements with 76% of business leaders and 70% of cyber leaders agreeing that further enforcement would lead to an increase in their organisations’ cyber resilience,

Prioritising Cyber-risk in Business Decisions 

As could be arguably expected, this is where we historically saw – based on last year’s data – a large disparity between the attitudes of cyber and business leaders. However this year’s report shows a marked narrowing of this disparity.

95% of business executives and 93% (up from 75% in the 2022 edition) of cyber executives agreeing that cyber resilience is integrated into their organisation’s enterprise risk-management strategies.

The report goes on to note that ‘Not only is there a shift in leaders’ perception of their priorities, but there is a shift in reported behaviours among cyber leaders. More than half (56%) of cyber leaders meet with business leaders monthly, or more frequently, to discuss cyber-focused topics.’

The Role of Cyber-insurance

Similar to something like supply-chain risk, an organisation’s size plays a huge role in whether or not they’re likely to have cyber insurance. As expected, smaller organisations were more likely to report they did not have cyber insurance (48%) than larger organisations (16%).

The issues this creates is in the fragility of the broader ecosystem – if a smaller organisation has issues, it can affect others upstream.

Cybersecurity and the Board’s Duty of Care

According to the report, ‘Organisational leadership has begun to listen to the concerns of cyber leaders.’

The main challenge, however, is turning wider board support into meaningful action. In an interview conducted in support of the report, the respondent said: ““Being able to clearly describe the key operational risks and, as part of this, the key cyber-related risks, and then having the link between these risks and the operational or technical controls is important.


Recommended


“This allows business leaders to gauge whether they know what their risks are and whether the organisation is doing the right thing to protect itself.”

Cyber-talent Management

The shortfall between supply and demand for cybersecurity experts was estimated at 2.27 million in 2021.

The fact is. recruitment in this space has been a well-documented challenge across the entire business spectrum, a fact that’s clearly not lost on business leaders with the perception gap on the issue narrowing significantly compared to 2022.

The 2022 Outlook report found that 10% of cyber leaders indicated they lacked the critical people and skills needed to deal with a cyber-attack. No business leaders indicated that there was any deficit.

This year, however, the report states that 10% of business leaders now feel they have critical gaps in personnel, with cyber leaders increasing to 13% with the same question.

Improving Communication

Once again, in this regard, the report showed incremental improvement over last year’s report. As it states, ‘17% of security executives expressed concern about the level of cyber resilience in their business. This was up slightly from 13% of security executives the year before.’

This increased awareness around the issue cyber resilience had an inevitable knock-on effect of increasing the concern around the topic (quantified at 27%, up 11% from last year).

Explaining ROI in Cybersecurity and Steps to Close the Communication Gap

During a workshop at last year’s WEF Cybersecurity Outlook Series, one participant lamented the difficulty in translating cybersecurity investment into clear returns at board level.

They commented: “The three things board members are interested in are risk, opportunities and investment in cost. In cybersecurity, we talk about the cost a lot, but we need to better respond to the question, ‘what is the return?’

“That is something we struggled with in cybersecurity. How do I know this is a good investment across the myriad of things that I could potentially be invested in? How can we improve at making effective metrics to help boards make better-informed decisions?”

To answer this, the report calls for cyber leaders to use ‘less technical jargon when speaking with business leaders.’

It adds: ‘Boards of directors should help cybersecurity leaders understand what assets and processes must be prioritized for protection. Boards should then make themselves accountable for these priorities once they are set because cybersecurity resources are rarely sufficient to effectively defend all parts of an organisation all of the time.’

Reviewing Organisational Design

As observed in the 2023 Global Cybersecurity Outlook survey results, only 25% of all respondents indicated that the most senior cybersecurity executive in their organisation reports directly to the CEO.

However, other security executives pointed to the importance of the chief information officer (CIO) as a champion for cybersecurity across a business.

The report adds that ‘there is no single approach to making this work, but it is important that security executives have access to senior business leadership.’


Get all the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data