{"id":4396,"date":"2023-02-11T20:40:05","date_gmt":"2023-02-11T18:40:05","guid":{"rendered":"https:\/\/10guards.com\/?p=4396"},"modified":"2023-02-13T09:56:55","modified_gmt":"2023-02-13T07:56:55","slug":"at-least-10-years-of-cyber-risk-ahead-wefs-global-risks-report-2023","status":"publish","type":"post","link":"https:\/\/10guards.com\/de\/blog\/2023\/02\/11\/at-least-10-years-of-cyber-risk-ahead-wefs-global-risks-report-2023\/","title":{"rendered":"At Least 10 Years of Cyber Risk Ahead \u2014 WEF&#8217;s Global Risks Report 2023"},"content":{"rendered":"<p class=\"qtranxs-available-languages-message qtranxs-available-languages-message-de\">Leider ist der Eintrag nur auf <a href=\"https:\/\/10guards.com\/en\/wp-json\/wp\/v2\/posts\/4396\" class=\"qtranxs-available-language-link qtranxs-available-language-link-en\" title=\"en\">en<\/a>, <a href=\"https:\/\/10guards.com\/ru\/wp-json\/wp\/v2\/posts\/4396\" class=\"qtranxs-available-language-link qtranxs-available-language-link-ru\" title=\"ru\">ru<\/a> und <a href=\"https:\/\/10guards.com\/ua\/wp-json\/wp\/v2\/posts\/4396\" class=\"qtranxs-available-language-link qtranxs-available-language-link-ua\" title=\"ua\">ua<\/a> verf\u00fcgbar.<\/p><p>WEF&#8217;s Global Risks Report 2023 keeps cybersecurity on the agenda.<\/p>\n<p>&nbsp;<\/p>\n<p>2022 was a difficult year for enterprise security, with russia\u2019s war against Ukraine emboldening cybercriminals and ransomware-as-a-service beginning to thrive. Unfortunately, the Global Cyber Security Outlook 2023 from the World Economic Forum (WEF) and Accenture anticipates that the threat landscape could be getting worse.<\/p>\n<p>&nbsp;<\/p>\n<p>WEF\u2019s and Accenture\u2019s research found that 86% of business leaders and 93% of cyber leaders believe that global geopolitical instability is likely to lead to a catastrophic cyber event in the next two years.<\/p>\n<p>&nbsp;<\/p>\n<p>In addition, the report found that geopolitical uncertainty was forcing organizations to adjust where they invest, with 49% of business leaders and cyber leaders claiming they would \u201cre-evaluate the countries in which their organization does business\u201d in response to geopolitical risk.<\/p>\n<p>&nbsp;<\/p>\n<p>On a more positive note, the study also found that organizations that embed cyber risk into the decision-making process are more confident in their cyber resilience and better able to recover from cyberattacks.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #afcf60;\"><strong>GEOPOLITICAL CONFLICT WILL PROVIDE AN OPPORTUNITY TO START THE CONVERSATION ABOUT RISK <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>While it remains to be seen whether these predictions of a catastrophic cyberattack will come to fruition, there have been several high-profile breaches over the past few years with enough momentum to be considered catastrophic.<\/p>\n<p>&nbsp;<\/p>\n<p>One of the most notorious occurred in 2020. The SolarWinds supply chain attack resulted in the compromise of 100 companies and nine federal agencies. Likewise, in 2021, the Colonial Pipeline ransomware attack forced the organization to shut down 5,500 miles of pipelines.<\/p>\n<p>&nbsp;<\/p>\n<p>With the russia-Ukraine war continuing, the report finds that geopolitical risk \u201cis an entry point for the wider conversation between security leaders and business leaders on how cyber threats are changing,\u201d and how risk can impact business continuity planning.<\/p>\n<p>&nbsp;<\/p>\n<p>Having that conversation is critical for mitigating the risk created by emerging cyber threats. How those threats will manifest is up to debate, but Jon France, CISO of (ISC)2, argues ICS\/OT compromise is the most likely avenue for a large cyber event.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cI think we may see a significant event in the next year, and it will be one in the ICS\/OT technologies space. Due to long life, lack of security by design (due in many cases to age) and difficulty to patch, in mission critical areas \u2014 an attack in this space would have immense effects that will be felt,\u201d France said.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cSo I somewhat agree with the hypothesis of the report and the contributors to the survey. You could already argue that we have seen a moderate attack with UK Royal Mail, where ransomware stopped the sending of international parcels for a week or more,\u201d France said.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>France argues that organizations can insulate themselves from these threats by putting more resources into defensive measures and by treating cybersecurity as a board issue.<\/p>\n<p>&nbsp;<\/p>\n<p>Key steps include Implementing responsive measures, providing employees with exercises on how to react, implementing recovery plans, planning for supply chain instability, and looking for alternative vendors who can provide critical services in the event of a disruption.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"color: #afcf60;\">A GAP BETWEEN CYBER-RISK AWARENESS AND ACTION<\/span> <\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Another key finding from the report is that in many organizations, there is a gap between awareness of cyber threats and implementing the necessary actions to mitigate these risks.<\/p>\n<p>&nbsp;<\/p>\n<p>For instance, while 86% of business leaders believe there will be a catastrophic cyber event in the next two years, and 43% believe an attack will affect their organization in the next two years, only 27% believe their organizations are cyber-resilient.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cThis is like saying you are fairly certain water will flood your house and there will be significant damage, but you are pretty sure you are not prepared for it,\u201d said Paolo Dal Cin global lead of Accenture Security.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>As a result, security leaders need to enhance internal communication with the board if they want to implement cyber-risk management into top-down decision-making. One way to improve communication is to get better at translating risk into business outcomes.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cBusiness leaders know they have to do more to embed cyber-risk into decision-making because cyber-resilience equals business resilience. It requires a closely coordinated team effort across the C-suite to gain a clearer view of current and emerging risks so security can be embedded across all the strategic business priorities and <span style=\"color: #afcf60;\"><strong>protect the digital code<\/strong><\/span>,\u201d Dal Cin said.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #afcf60;\"><strong>RETRAINING IS THE ANSWER TO THE CYBER SKILLS GAP<\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>Finally, the report prescribes ways that organizations can work to fix the cyber skills gap. This comes down to better-using generalists as well as specialists to secure the environment.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cPeople think that cybersecurity is something that\u2019s highly technical. Yes, some roles require deep technical expertise, but cybersecurity is a vast domain and making an organization cyber-resilient also requires generalist roles that need a broader skill set, from education and awareness to policy writing, governance and others. We need more people in both the technical and generalist roles,\u201d said Bobby Ford, senior vice president and chief security officer, Hewlett Packard Enterprise.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>Rather than competing for a small cross-section of highly qualified cybersecurity experts who are in high demand, organizations should look to help increase the flow of cybersecurity talent into the workforce by expanding the talent pool.<\/p>\n<p>&nbsp;<\/p>\n<p>In practical terms, the report suggests \u201cbroadening the narrative about who can work in cybersecurity.\u201d This means enabling and\/or educating people with non-technical backgrounds, as well as those outside the education system and those from underrepresented groups \u2014 opening the door to retraining opportunities via learning on the job or through apprenticeships.<\/p>\n<p>&nbsp;<\/p>\n<p>Source: <a href=\"https:\/\/www3.weforum.org\/docs\/WEF_Global_Security_Outlook_Report_2023.pdf\">WEF Global Security Outlook Report 2023<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Leider ist der Eintrag nur auf en, ru und ua verf\u00fcgbar.WEF&#8217;s Global Risks Report 2023 keeps cybersecurity on the agenda. &nbsp; 2022 was a difficult year for enterprise security, with russia\u2019s war against Ukraine emboldening cybercriminals and ransomware-as-a-service beginning to thrive. Unfortunately, the Global Cyber Security Outlook 2023 from the World Economic Forum (WEF) and [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":4397,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-4396","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/10guards.com\/wp-content\/uploads\/world-economic-forum-01.png","_links":{"self":[{"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/posts\/4396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/comments?post=4396"}],"version-history":[{"count":4,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/posts\/4396\/revisions"}],"predecessor-version":[{"id":4404,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/posts\/4396\/revisions\/4404"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/media\/4397"}],"wp:attachment":[{"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/media?parent=4396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/categories?post=4396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/10guards.com\/de\/wp-json\/wp\/v2\/tags?post=4396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}