“Cyber resilience in an organization must extend beyond the technical IT domain to the domains of people, culture and processes. A company’s protective strategies and practices should apply to everything the company does — to every process on every level, across departments, units and borders — in order to foster an appropriately security-conscious culture.” – Walter Bohmayr and Alexander Türk, The Boston Consulting Group

The World Economic Forum (WEF) is known for its yearly meetings of the global elite held in Davos, Switzerland, as well as its “Global Risks Report,” which is typically released around the same time. Recently, the WEF has taken on a new role on the global scene and is spearheading a global effort to help organizations become more cyber resilient. In January 2017, the WEF released a report entitled “Advancing Cyber-Resilience: Principles and Tools for Boards.”

Getting the Board On Board With Resilience Efforts

Recognizing the key role that business leadership must play to improve cyber resilience, the WEF sought to raise the visibility of this issue to “build a more effective cyber strategy and incorporate it into overall strategic thinking” that encompasses entire systems and industries instead of just leading organizations.

The report noted that while some organizations today have built resilience into their business fabric, being cyber resilient is gaining traction rather slowly among boards of directors. To ensure continued performance, the report explained, organizations must recognize that “resilience as a focus of strategy includes the actions an enterprise takes before, during and after an incident, thereby more fully mitigating potential threats.”

10 Cyber Resilience Principles for Boards of Directors

The report outlines 10 key principles for boards of directors to keep in mind when discussing cyber resilience. The principles are:

  1. Responsibility for cyber resilience is a full-board issue, even if the board delegates primary oversight to a particular committee.
  2. Board members should have a certain level of education on the subject. New board members should be provided with an orientation, and all members should receive regular updates. They should also have access to independent, external experts to seek different opinions or validate management’s assertions.
  3. There should be an accountable officer who is provided with appropriate authority, access and resources to report on how effectively the organization is managing cyber resilience.
  4. The board should ensure that the enterprise risk management approach includes an assessment of cyber risks across the business and a focus on resilience.
  5. The board should conduct yearly reviews to determine whether its risk appetite is consistent with its strategy and seek to quantify the amount of business risk it is willing to tolerate.
  6. Management is accountable for the regular assessment and reporting of cyber risks. The board should then validate the impact of these risks on board strategy using the Board Cyber Risk Framework outlined in the report.
  7. The board should ensure that the cyber resilience officer has the support and resources he or she needs to effectively create, implement, test and refine resilience efforts across the organization. The board should receive regular updates on the organization’s performance.
  8. The board must recognize the communal nature of cyber resilience and support collaboration with other stakeholders in the community.
  9. The board should commission a yearly formal review of the organization’s progress toward resilience.
  10. The board should review its own ability to provide effective oversight of cyber resilience efforts and, when needed, seek an independent assessment of its performance.

A Turning Point

While the concept of cyber resilience is not new, this report marks a turning point of awareness and advises business leaders across the globe to pay attention to one of the key security issues of the decade — and likely many decades to come.

More from CISO

Emotional Blowback: Dealing With Post-Incident Stress

Cyberattacks are on the rise as adversaries find new ways of creating chaos and increasing profits. Attacks evolve constantly and often involve real-world consequences. The growing criminal Software-as-a-Service enterprise puts ready-made tools in the hands of threat actors who can use them against the software supply chain and other critical systems. And then there's the threat of nation-state attacks, with major incidents reported every month and no sign of them slowing. Amidst these growing concerns, cybersecurity professionals continue to report…

Moving at the Speed of Business — Challenging Our Assumptions About Cybersecurity

The traditional narrative for cybersecurity has been about limited visibility and operational constraints — not business opportunities. These conversations are grounded in various assumptions, such as limited budgets, scarce resources, skills being at a premium, the attack surface growing, and increased complexity. For years, conventional thinking has been that cybersecurity costs a lot, takes a long time, and is more of a cost center than an enabler of growth. In our upcoming paper, Prosper in the Cyber Economy, published by…

Reporting Healthcare Cyber Incidents Under New CIRCIA Rules

Numerous high-profile cybersecurity events in recent years, such as the Colonial Pipeline and SolarWinds attacks, spurred the US government to implement new legislation. In response to the growing threat, President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) in March 2022.While the law has passed, many healthcare organizations remain uncertain about how it will directly affect them. If your organization has questions about what steps to take and what the law means for your processes,…

Charles Henderson’s Cybersecurity Awareness Month Content Roundup

In some parts of the world during October, we have Halloween, which conjures the specter of imagined monsters lurking in the dark. Simultaneously, October is Cybersecurity Awareness Month, which evokes the specter of threats lurking behind our screens. Bombarded with horror stories about data breaches, ransomware, and malware, everyone’s suddenly in the latest cybersecurity trends and data, and the intricacies of their organization’s incident response plan. What does all this fear and uncertainty stem from? It’s the unknowns. Who might…