For the fourth year in a row, cybersecurity and the interconnectedness of infrastructure was named as the top emerging risk in an anonymous international survey of actuaries.

The “11th Annual Survey of Emerging Risks,” issued by the Casualty Actuarial Society, Canadian Institute of Actuaries and the Society of Actuaries’ Joint Risk Management Section, asked a group of approximately 220 risk managers to weigh in on everything from terrorism and financial volatility to regional instability and asset price collapse.

Ranking Emerging Risks

Since 2014, cybersecurity and the interconnectedness of infrastructure has led the pack of imminent risks, though the percentages have stabilized somewhat. Cyberthreats represented the top concern for 65 percent of those surveyed in 2015, for example, but this number fell to 53 percent in 2016 and remained constant in 2017.

After cybersecurity, terrorism, technology, regional instability and asset price collapse rounded out the list of the top five emerging risks. Financial volatility, meanwhile, fell off of the list in 2017 despite holding the No. 2 spot for the three previous years.

The survey asked actuaries to identify the top current risk, emerging risk and “risk combinations.” Cyber/interconnectedness of infrastructure was the No. 1 choice across all categories, including the “Top Risk Combinations” category, where it was paired with technology. Terrorism and cyber/interconnectedness of infrastructure also placed third on this list.

Looking Toward the Future

The authors noted that there is a difference between looking at emerging risks that could affect our short-term future and those that might pose problems for the next generation. Looking out to 2050, for example, 30 percent of respondents cited geopolitical issues as their top concern, while technological risk ranked lower at 23 percent.

The Joint Risk Management Section, which convened several associations to conduct the survey, said it would release additional results with more open-ended answers from respondents later this year.

More from

The White House on Quantum Encryption and IoT Labels

A recent White House Fact Sheet outlined the current and future U.S. cybersecurity priorities. While most of the topics covered were in line with expectations, others drew more attention. The emphasis on critical infrastructure protection is clearly a top national priority. However, the plan is to create a labeling system for IoT devices, identifying the ones with the highest cybersecurity standards. Few expected that news. The topic of quantum-resistant encryption reveals that such concerns may become a reality sooner than…

Contain Breaches and Gain Visibility With Microsegmentation

Organizations must grapple with challenges from various market forces. Digital transformation, cloud adoption, hybrid work environments and geopolitical and economic challenges all have a part to play. These forces have especially manifested in more significant security threats to expanding IT attack surfaces. Breach containment is essential, and zero trust security principles can be applied to curtail attacks across IT environments, minimizing business disruption proactively. Microsegmentation has emerged as a viable solution through its continuous visualization of workload and device communications…

CEO, CIO or CFO: Who Should Your CISO Report To?

As we move deeper into a digitally dependent future, the growing concern of data breaches and other cyber threats has led to the rise of the Chief Information Security Officer (CISO). This position is essential in almost every company that relies on digital information. They are responsible for developing and implementing strategies to harden the organization's defenses against cyberattacks. However, while many organizations don't question the value of a CISO, there should be more debate over who this important role…

Malware-as-a-Service Flaunts Its Tally of Users and Victims

As time passes, the security landscape keeps getting stranger and scarier. How long did the “not if, but when” mentality towards cyberattacks last — a few years, maybe? Now, security pros think in terms of how often will their organization be attacked and at what cost. Or they consider how the difference between legitimate Software-as-a-Service (SaaS) brands and Malware-as-a-Service (MaaS) gangs keeps getting blurrier. MaaS operators provide web-based services, slick UX, tiered subscriptions, newsletters and Telegram channels that keep users…