世界经济论坛-网络安全领导原则:在COVID-19大流行期间吸取的经验教训为新的常态做准备(英文)-2020.5-16页_361kb
报告摘要
Cybersecurity Leadership Principles Summary
Core Content
This document outlines five key cybersecurity leadership principles that emerged from the lessons learned during the COVID-19 pandemic, providing a strategic framework for businesses to adapt to the new normal in cybersecurity. These principles emphasize the need for a culture of cyber resilience, protection of critical assets, risk-informed decision-making, updated response and continuity plans, and ecosystem-wide collaboration. The goal is to help leaders move beyond compliance and ensure that their organizations are prepared for both immediate and long-term challenges in a rapidly evolving digital environment.
Main Principles
1. Foster a Culture of Cyber Resilience
- Resilience is a leadership and cultural issue, not just a technical one.
- Leaders must acknowledge the importance of proactive risk management and ensure the organization can absorb and recover from cyberattacks.
- Cyber-resilience governance is essential, with a board-level accountable officer to align business, IT, OT, and physical security.
- Resilience by design should be integrated into all business processes, mergers, and third-party engagements.
- Beyond compliance is necessary to address the dynamic nature of cyber threats, especially during crises.
- Employee behavior is critical; regular training and awareness programs should be implemented to reduce human-related vulnerabilities.
- Least-privilege access and advanced anti-malware/anti-phishing capabilities should be adopted to minimize exposure to phishing campaigns.
2. Focus on Protecting Critical Capabilities and Services
- Leaders must take a holistic and systemic view of their critical services, applications, and suppliers.
- Strong cyber hygiene is essential to prevent attacks that exploit known vulnerabilities.
- Protecting access to critical assets is crucial, especially with the rise of remote work.
- Network segmentation, strong authentication, and defence-in-depth strategies should be implemented to secure remote connectivity.
- Invest in monitoring and response capabilities to detect and mitigate threats quickly.
- Cybersecurity automation using AI, ML, and big data can help manage vulnerabilities and improve response efficiency.
3. Balance Risk-Informed Decisions During the Crisis and Beyond
- Businesses must reassess their risk posture after the crisis and restore it to an acceptable level.
- A zero-trust approach to supply chain security is necessary due to the rapid development and integration of new technologies.
- Cyber-resilience metrics should be developed and aligned with business strategic objectives to guide decision-making.
- Focus on operational cyber risks to prioritize technologies and security capabilities that are essential for business continuity.
4. Update and Practice Response and Continuity Plans
- Comprehensive crisis management plans should be tested and practiced regularly.
- These plans must cover cyberattacks and pandemic scenarios, ensuring readiness across all functions.
- Cross-functional crisis teams are necessary to coordinate responses and maintain continuity during unexpected events.
- Businesses should adjust their response and resilience plans to reflect the evolving threat landscape and business needs.
- Prepare for the new normal by continuing secure remote working practices and accelerating digital transformation.
5. Strengthen Ecosystem-Wide Collaboration
- Collaboration between public and private sectors is vital to address systemic cyber risks.
- Collective situational awareness can be achieved through real-time, transparent information sharing.
- Regulatory protection for victims is essential to encourage information sharing without fear of repercussions.
- Collective action should be driven through industry alliances and threat intelligence sharing.
- A systemic approach to cyber-risk management is necessary, with a focus on mapping and prioritizing dependencies within the broader ecosystem.
Key Information
- The pandemic has accelerated digital transformation, increasing reliance on remote work and cloud services, which has also exposed new vulnerabilities.
- Cybersecurity is now a business imperative, not just an IT function.
- Leaders must take ownership of cyber risks and foster a culture of shared responsibility across the organization.
- Collaboration and transparency are key to managing cyber threats in a globalized and interconnected environment.
- The new normal requires continuous adaptation, testing, and updating of cybersecurity strategies to ensure resilience in the face of evolving threats.
Conclusion
The World Economic Forum highlights the need for strategic, proactive, and collaborative cybersecurity leadership to navigate the new digital reality shaped by the pandemic. By embracing these principles, organizations can better protect themselves and contribute to a more secure and resilient digital ecosystem.
试读结束,高清完整版pdf/doc/ppt,请点下载