揭示网络弹性(英)_23页_2mb
报告摘要
Unpacking Cyber Resilience - Summary
Foreword
Cyber resilience is critical for organizations dependent on digital technologies and data. It requires leadership and a collaborative ecosystem to protect core business objectives, safeguard stakeholder trust, and maintain operational continuity during cyber incidents.
Executive Summary
- Cyber resilience is an organization's ability to minimize the impact of significant cyber incidents on its primary goals.
- Investing in cyber resilience reduces economic costs of cyber events, improves organizational reputation, and supports long-term growth.
- It involves anticipating, withstanding, recovering from, and adapting to cyber threats in a contested environment, regardless of their source.
- Challenges include dynamic threats, supply chain risks, skills shortages, and the need for collaborative ecosystem resilience.
2 Unpacking Cyber Resilience
2.1 The Evolution of Cyber Resilience
Cybersecurity has evolved from data protection to a broader concept of cyber resilience, influenced by disruptive attacks and data breaches. The journey from information security to cyber resilience focuses on operational continuity and recovery.
2.2 The Concept of Cyber Resilience
- Cyber resilience enables organizations to achieve business objectives despite cyber threats.
- Key principles include anticipating risks, designing for recovery, learning from incidents, and taking a broad view of cyber threats beyond IT.
- NIST defines it as the ability to ensure mission objectives achieved in a contested cyber environment.
2.3 Cyber Resilience Includes IT and OT
- Cyber resilience extends to Operational Technology (OT), which operates industrial control systems (ICS) and monitors critical infrastructure.
- The convergence of IT and OT introduces new vulnerabilities, requiring a comprehensive strategy to address both areas.
2.4 Influencing Factors
- Organizations face challenges shaped by geopolitical instability, technological advancements, societal changes, economic contexts, and environmental factors.
- Cyber resilience strategies must account for these external factors to align with business objectives and regulatory requirements.
3 Next Steps: Sharing Cyber-Resilience Practices from the Front Line
- Peer collaboration and shared insights enhance cyber resilience.
- Key strategies include fostering a cyber-resilient mindset, embedding decision-making into governance structures, developing adaptable processes, and collaborating across sectors.
- Organizations should use regulations and frameworks like the Cyber Resilience Act to incentivize resilience.
Appendix
A1 Methodology
Derived from three virtual workshops, one in-person, and interviews with 76 experts from 71 organizations.
A2 Definitions of Cyber Resilience
- NIST: Ability to anticipate, withstand, recover, and adapt to cyber threats.
- Broader definition: Minimizes impact on operations, finances, and strategic goals across IT and OT.
A3 Divergent Cyber-Resilience Profiles
Organizations can have profiles of low/high risk and low/high resilience, affecting their response to cyber incidents.
A4 Broader Global Context
Factors like geopolitics (e.g., state-sponsored attacks), technology (e.g., AI/OT convergence), society (e.g., disinformation), and the economy shape cyber resilience strategies.
Disclaimer
This report reflects a collaborative process, but does not represent the sole views of the World Economic Forum or its stakeholders.
试读结束,高清完整版pdf/doc/ppt,请点下载