2025-06-18-普华永道-高管层行动指南_24页_4mb
报告摘要
Summary of "Bridging the gaps to cyber resilience: The C-suite playbook"
Core Content
The document highlights the challenges and opportunities in achieving cyber resilience for enterprises in the context of evolving threats and regulations. It outlines the key gaps in cyber resilience implementation, preparedness, and C-suite collaboration, and provides actionable steps for executives to address these issues.
Main Findings
- Low Cyber Resilience Implementation: Only 2% of executives report that their organisation has implemented cyber resilience actions across all areas surveyed.
- Preparedness Gaps: Organisations are least prepared to address cloud-related threats, hack-and-leak operations, third-party breaches, and attacks on connected products.
- CISO Involvement: Less than 50% of executives say their CISOs are involved to a large extent in strategic planning, board reporting, and overseeing tech deployments.
- Confidence Gap: There is a 13% confidence gap between CEOs and CISOs/CSOs regarding compliance with AI and resilience regulations.
- Cyber Risk Measurement: Only 15% of executives measure the financial impact of cyber risks to a significant extent, despite its importance for strategic decision-making.
- Data Breach Costs: The average data breach cost globally exceeds $3.32 million, with over a quarter of executives reporting breaches costing at least $1 million.
- GenAI and Cyber Risks: 67% of security executives believe GenAI has increased the attack surface, and 78% have increased investment in GenAI, especially in governance.
- Regulatory Impact: 96% of executives say cybersecurity regulations have increased their cyber investment, and 78% believe they have improved their cybersecurity posture.
- Cyber Budget Expectations: 77% of executives expect their cyber budget to increase in 2025, with 82% in North America and the TMT sector expecting growth.
Key Gaps
- Implementation Gap: Limited adoption of cyber resilience across the organisation.
- Preparedness Gap: Inadequate readiness to address the most concerning cyber threats.
- CISO Involvement Gap: Insufficient strategic engagement of CISOs by the C-suite.
- Confidence Gap: Disparity in confidence between CEOs and CISOs regarding regulatory compliance.
- Risk Measurement Gap: Ineffective quantification of cyber risks, especially their financial impact.
Major Threats and Concerns
- Cloud and Connected Devices: Ranked as the most concerning threats, with security executives feeling least prepared to address them.
- GenAI: Expands the attack surface and requires new strategies for integration, trust, and governance.
- Quantum Computing: 42% of security executives report it has already prompted them to address vulnerabilities.
Strategic Recommendations
- CISOs: Communicate cyber threats in business terms, drive standardisation, and enforce access rights.
- CIOs and CTOs: Develop AI impact assessments and prepare platforms for scalability.
- CFOs: Prioritise financial data protection and understand materiality and risk quantification.
- CEOs: Engage with CISOs and CROs to align cyber strategy with business goals and identify key compliance questions.
- Board: Monitor regulatory developments and ensure transparency in cyber risk reporting.
- CDOs: Enhance data governance and assess privacy risks against legal frameworks.
- CLOs and GCs: Determine appropriate disclosure levels for cyber program reporting and legal exposure.
Cyber Risk Quantification
- Importance: 88% of executives agree that measuring cyber risk is important for prioritising investments and aligning with risk tolerance.
- Challenges: Data quality, scope uncertainty, legal concerns, and trust in quantification outputs are major barriers to adoption.
- Call to Action: Organizations should build trust in cyber risk quantification and integrate it into strategic decision-making.
Conclusion
The document emphasizes the need for a unified approach to cyber resilience, with the C-suite playing a critical role in driving strategic investment, fostering collaboration, and ensuring regulatory compliance. By addressing the identified gaps and leveraging emerging technologies like GenAI and quantum-resistant solutions, organisations can enhance their cybersecurity posture and build long-term trust with stakeholders.
试读结束,高清完整版pdf/doc/ppt,请点下载