The disparity between what cyber leaders CISO’s CTO’s and anyone else who has to convince a boardroom to invest in cybersecurity remains formidable, but is showing signs of improvement.
This is the broadest of broad takeaways from the World Economic Forum’s Global Cybersecurity Outlook report.
Business leaders are more aware of their organisations cyber issues and are more willing to address those risks. However, as the report breaks down in detail – and we will illuminate the report’s most pertinent stats – cyber leaders still struggle to articulate cyber risks in a way that compels leaders to action.
Geopolitics
Global political instability has been a driver for interest rates, an energy crisis and general unease, so it’s no surprise that it’s playing its part in defining a large part of the global cybersecurity discourse.
According to the report, 93% of cyber leaders and 86% of business leaders think it is “moderately likely” or “very likely” that global geopolitical instability will lead to a far-reaching, catastrophic cyber event in the next two years.
Furthermore, 74% of organisation leaders say that global geopolitical instability has influenced their cyber strategy “moderately” or “substantially”. What concerns business leaders most in this regard is continuity (67%) and reputational damage (65%).
Leaders intend to address these concerns by ‘strengthening controls for third parties with access to their environments (73%) or data (66%), as well as re-evaluating the countries with whom they do business (50%).
Emerging Tech and Emerging Threats
Emerging technology is where the report found the greatest alignment between business and cyber leaders. In this regard, respondents said that artificial intelligence (AI) and machine learning (20%), greater adoption of cloud technology (19%) and advances in user identity and access management (15%) will have the greatest influence on their cyber risk strategies over the next two years.
The findings for the report indicated that a series of major global cyber incidents in 2021–2022, such as the exploitation of the widespread Log4j vulnerability, forced many organisations to focus on monitoring and assessing threat information.
Commenting, Derek Manky, Chief Security Strategist and Vice-President, Global Threat Intelligence, Fortinet, said: “Core resources are being thrown at cybercrime campaigns by criminal groups.
“There’s a sense that cybercrime is converging with nation-state actors and that this is leading to a higher number of new campaigns being launched as well as attacks that are more clearly tailored to the target organisation.
“The greater the volatility in the threat, the more time is being spent on tactical defence by CISOs and their teams. It’s important to create the space for strategic development and effective risk management.”
Laws and Regulations
This year’s Outlook report showed a large shift in the perception of how regulation affects cyber risk. The report states that in 2022, ‘more than half of respondents did not agree that cyber and privacy regulations are effective in reducing their organisations’ cyber risks.
This year’s report, however, indicates that 73% of respondents agree with the same statement.
Business and cyber leaders also support effective enforcement of regulatory requirements with 76% of business leaders and 70% of cyber leaders agreeing that further enforcement would lead to an increase in their organisations’ cyber resilience,
Prioritising Cyber-risk in Business Decisions
As could be arguably expected, this is where we historically saw – based on last year’s data – a large disparity between the attitudes of cyber and business leaders. However this year’s report shows a marked narrowing of this disparity.
95% of business executives and 93% (up from 75% in the 2022 edition) of cyber executives agreeing that cyber resilience is integrated into their organisation’s enterprise risk-management strategies.
The report goes on to note that ‘Not only is there a shift in leaders’ perception of their priorities, but there is a shift in reported behaviours among cyber leaders. More than half (56%) of cyber leaders meet with business leaders monthly, or more frequently, to discuss cyber-focused topics.’
The Role of Cyber-insurance
Similar to something like supply-chain risk, an organisation’s size plays a huge role in whether or not they’re likely to have cyber insurance. As expected, smaller organisations were more likely to report they did not have cyber insurance (48%) than larger organisations (16%).
The issues this creates is in the fragility of the broader ecosystem – if a smaller organisation has issues, it can affect others upstream.
Cybersecurity and the Board’s Duty of Care
According to the report, ‘Organisational leadership has begun to listen to the concerns of cyber leaders.’
The main challenge, however, is turning wider board support into meaningful action. In an interview conducted in support of the report, the respondent said: ““Being able to clearly describe the key operational risks and, as part of this, the key cyber-related risks, and then having the link between these risks and the operational or technical controls is important.
Recommended
- Linux Malware Hit Record Highs in 2022
- Microsoft Set to Cut 10,000 Jobs
- New Ruling to ‘Free the Nipple’ on Meta Platforms
“This allows business leaders to gauge whether they know what their risks are and whether the organisation is doing the right thing to protect itself.”
Cyber-talent Management
The shortfall between supply and demand for cybersecurity experts was estimated at 2.27 million in 2021.
The fact is. recruitment in this space has been a well-documented challenge across the entire business spectrum, a fact that’s clearly not lost on business leaders with the perception gap on the issue narrowing significantly compared to 2022.
The 2022 Outlook report found that 10% of cyber leaders indicated they lacked the critical people and skills needed to deal with a cyber-attack. No business leaders indicated that there was any deficit.
This year, however, the report states that 10% of business leaders now feel they have critical gaps in personnel, with cyber leaders increasing to 13% with the same question.
Improving Communication
Once again, in this regard, the report showed incremental improvement over last year’s report. As it states, ‘17% of security executives expressed concern about the level of cyber resilience in their business. This was up slightly from 13% of security executives the year before.’
This increased awareness around the issue cyber resilience had an inevitable knock-on effect of increasing the concern around the topic (quantified at 27%, up 11% from last year).
Explaining ROI in Cybersecurity and Steps to Close the Communication Gap
During a workshop at last year’s WEF Cybersecurity Outlook Series, one participant lamented the difficulty in translating cybersecurity investment into clear returns at board level.
They commented: “The three things board members are interested in are risk, opportunities and investment in cost. In cybersecurity, we talk about the cost a lot, but we need to better respond to the question, ‘what is the return?’
“That is something we struggled with in cybersecurity. How do I know this is a good investment across the myriad of things that I could potentially be invested in? How can we improve at making effective metrics to help boards make better-informed decisions?”
To answer this, the report calls for cyber leaders to use ‘less technical jargon when speaking with business leaders.’
It adds: ‘Boards of directors should help cybersecurity leaders understand what assets and processes must be prioritized for protection. Boards should then make themselves accountable for these priorities once they are set because cybersecurity resources are rarely sufficient to effectively defend all parts of an organisation all of the time.’
Reviewing Organisational Design
As observed in the 2023 Global Cybersecurity Outlook survey results, only 25% of all respondents indicated that the most senior cybersecurity executive in their organisation reports directly to the CEO.
However, other security executives pointed to the importance of the chief information officer (CIO) as a champion for cybersecurity across a business.
The report adds that ‘there is no single approach to making this work, but it is important that security executives have access to senior business leadership.’
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





