版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Bridgingthegaps
tocyberresilience:TheC-suiteplaybook
Findingsfromthe2025GlobalDigitalTrustInsights
DigitalTrustInsights2
Findingsfromthe2025GlobalDigitalTrustInsights
2%50%13%
Only2%haveimplementedcyberresilienceactionsacrosstheir
organisationinallareassurveyed
Under50%ofCISOsareinvolvedtoalargeextentinkeybusinessactivities
pointgapinconfidencebetweenCISO/CSOsandCEOsregardingcompliancewithAIandresilienceregulations
Withtheattacksurfacecontinuingtoexpandthrough
advancesinAI,connecteddevicesandcloudtechnologiesandtheregulatoryenvironmentinconstantflux,achievingcyberresilienceatanenterpriseleveliscritical.
Yetdespitewidespreadawarenessofthechallenges,
significantgapspersist.Tosafeguardtheirorganisations,executivesshouldtreatcybersecurityasastandingitemonthebusinessagenda,embeddingitintoeverystrategicdecisionanddemandingC-suitecollaboration.
PwC’s2025GlobalDigitalTrustInsightssurveyof4,042businessandtechexecutivesfromacross77countriesrevealedsignificantgapscompaniesmustbridgebeforeachievingcyberresilience.
Gapsinimplementationofcyberresilience:
Despiteheightenedconcernsaboutcyberrisk,only2%oftheexecutivessaytheircompanyhasimplementedcyberresilienceactions
acrosstheirorganisationinallareassurveyed.
Gapsinpreparedness:Organisationsfeelleastpreparedtoaddressthecyberthreatstheyfindmostconcerning,suchascloud-relatedrisksandthird-partybreaches.
GapsinCISOinvolvement:FewerthanhalfoftheexecutivessaytheirCISOsareinvolvedtoalargeextentinstrategicplanning,boardreportingandoverseeingtechdeployments.
Gapsinregulatorycomplianceconfidence:
CEOsandCISO/CSOshavedifferinglevelsofconfidenceintheircompany’sabilitytocomplywithregulations,particularlyregardingAI,
resilienceandcriticalinfrastructure.
Gapsinmeasuringcyberrisk:Although
executivesacknowledgetheimportanceof
measuringcyberrisk,fewerthanhalfdoso
effectively,withonly15%measuringthefinancialimpactofcyberriskstoasignificantextent.
AllofthispointstotheneedforbetterC-suitecollaborationandstrategicinvestmenttostrengthencyberresilience.Byaddressingthesegapsandmakingcybersecurityabusinesspriority,executivescanbridgetoamoresecurefuture.
CISOscanhelpdrivethisoutcomebysharingtech-enabledinsightsandbyexplainingcyberprioritiesinbusinessterms(cost,opportunity,risk).
Table
4...............
7...............
10.............
13.............
16.............
19.............
ofcontents
Navigatingcyberthreats:Establishingasharedvisionforpreparedness
GenAIandemergingtech:Balancingopportunityandrisk
Ahighlyregulatedcyberworld:Arecompaniesreallyready?
Unlockingthepotentialofcyberriskquantification:What’sholding
organisationsback?
Investinginresilience,buildingtrust
Isyourcyberstrategyandleadershipdrivingrealresilience?
PwC|2025GlobalDigitalTrustInsights|3
Threatoutlookandemergingrisks
Navigatingcyberthreats:
Establishingasharedvisionforpreparedness
66%42%Top2
oftechexecutivesrankcyberasthehighestriskformitigation,comparedto48%ofbusinessexecutives
ofexecutivesrankcloud-relatedthreatsastheirmostconcerningcyberthreat
Cloudandconnectedproductattacksarewhatsecurityexecutivesfeelleastpreparedtoaddress
Whilethecybersecuritylandscapecontinuestoevolve,
organisationsarestrugglingwithincreasinglyvolatile
andunpredictablethreats.Anexpandingattacksurface
—spurredbygrowingrelianceoncloud,AI,connected
devicesandthirdparties—demandsanagile,enterprise-wideapproachtoresilience.Aligningorganisational
prioritiesandreadinessisessentialformaintainingsecurityandbusinesscontinuity.
Unpreparedforthemostconcerningthreats
Whatworriesorganisationsmostiswhatthey’releast
preparedfor.Thetopfourcyberthreatsfoundmost
concerning—cloud-relatedthreats,hack-and-leak
operations,third-partybreachesandattacksonconnected
products—arethesameonessecurityexecutivesfeelleastpreparedtoaddress.Thisgaphighlightstheurgentneedforbetterinvestmentsandstrongerresponsecapabilities.
Additionally,aperceptiongapexistsbetweensecurity
executivesandtherestoftheorganisation,withCISOs
andCSOsmorelikelytorankransomwareamongtheirtopthreemostconcerningthreats.Thismayreflecttheirrole,asransomwareismorecentraltocyber/ITdutiesandthoseinthatfunctionlikelyunderstandthevulnerabilitiesbetterthantheirbusinesspeers.Thisfurtherreinforcestheimportanceofbetterinformation-sharingacrossleadershipteamsto
createalignmentonpriorities.
cyberthreatconcernVspreparedness(showing%ranked1-3)
CISO/CSOleadersaremorelikelyto
rankransomwareintheirtopthreemostconcerningcyber
cloud-relatedthreats
Hack-and-
leak
operations
Third-partybreach
Ransomware
Attackson
connected
products
Mostconcerningcyberthreats
cyberthreatsleastpreparedtoaddress
Ascomparedto27%globally
Q2.overthenext12months,whichofthefollowingcyberthreatsisyourorganisationmostconcernedabout(e.g.,risktoyourbrand,lossofbusinessorbusinessdisruption,
compliance)?(Rankedintopthree)Base:Arespondents=4042
Q3.overthenext12months,whichofthecyberthreatsdoyouthinkyourorganisationisleastpreparedtoaddress?(Rankedintopthree)Base:securityleadersandCFO
respondents=1951
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Athreat-informedcyberinvestmentstrategyis
essential.Prioritiseinvestmentsinthemostpressingcyberrisksandtakeacloserlookatwhereresourcesarebeingappliedintermsofpeople,processand
defencecapabilities.
ThreatoutlookandemergingrisksPwC
|2025GlobalDigitalTrustInsights|
4
PwC|2025GlobalDigitalTrustInsights|5
Thestrategicdivide:Businessandtechpriorities
Businessexecutivesandtechexecutivesprioritisedifferentrisks.Whilebusinessexecutivesaremoreconcernedwithinflation,techexecutivesrankcyberrisksastheirtop
priority—likelyduetotheirproximitytothecyberthreatlandscape.Evenso,nearlyhalfofbusinessexecutives
stillrankcyberrisksamongtheirtopthreeconcerns,
underscoringitscriticalimportance.ThissharedconcernrepresentsanopportunityforCISOstoconnectthecyberagendatothebusinessagenda.
RiskmitigationprioritiesforbusinessVstechleaders
(showing%ranked1-3)Inflation
Digitalandtechnologyrisks
cyberrisks
48%
Techleaders
Businessleaders
Q1.whichofthefollowingrisksisyourorganisationprioritisingformitigationoverthenext12months?(Rankedintopthree)Base:Allrespondents=4042
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Businessandtechexecutives—it’stimetogetaligned.
Balanceprioritisationofcyberriskswitheconomicpressurestohelpsafeguardassetsandcreate
resilience.Regularcross-functionalassessmentswillkeepyourstrategyandprioritiesinsync.
Threatoutlookandemergingrisks
Globalaveragedatabreachcostexceeds$3million
Overaquarterofexecutivestellustheirmostdamaging
databreachinthepastthreeyearscosttheirorganisationatleast$1million.Thisissomewhatlowerthanlastyear’ssurveyacrossorganisationsofallsizesandinmostregionsandsectors.Overall,theaveragedatabreachisestimatedat$3.32million.
Topperformers—identifiedasthosewhorespondedthattheirorganisationismorelikelytodemonstratehighqualitycybersecuritypracticesonausualbasis—werelesslikelytoexperienceanydatabreachesinthepastthreeyears.
Thesetopperformersaretypicallyfromlarger,high-growthorganisationswithcyberbudgetsexpectedtoincrease
by15%ormorenextyear,indicatingthatcyberprogrammaturityandfundingcorrelatetobetterresilience.
“
Don’tstopshortonyourjourneyforcybersecurityandresilience.Criminalsandnation-state
actorsarebecomingexpertat
findingunprotectedseams:weakidentityandaccesscontrols,
unpatcheddevicesandsecuritymisconfigurations.”
RobJoyce,Cyber,Risk&RegulatorySeniorFellow,PwCUS,formerSpecialAssistanttothePresident&ActingHomelandSecurityAdvisor
PwC|2025GlobalTrustInsights|
Wake-upcall
Prioritiseholisticriskmitigationstrategiesthat
encompassprevention,detection,responseand
recovery.Understandthebroaderimpactsofabreach—beyondfinancialharm—tobuildtrueresilience.
Executivecall-to-action
Asorganisationsfaceamoresophisticatedthreatlandscape,it’simportantfor
executivesacrosstheC-suite
totakea
proactiveroleinassessingbothcurrentandemergingrisks.Byaligningcybersecuritystrategieswithbroaderbusinessobjectives,executivescanbetterpreparetheirorganisationstomanageriskandbuildresilience.
CISOs:UnderscoretotherestoftheC-suitethe
threatsthatjeopardiseyourbusinessmost,especiallyifinvestmenteffortsneedtobeshifted.
CIOsandchieftechnologyofficers(CTOs):Basedonconversationswiththeriskexecutives,gauge
howcertainthreatscandamageinformationand
infrastructuresecurityatlargeandwhichthreatsposethebiggestbarrierstoresilience.
CFOs:GaindeeperinsightfromtheCISOand
CROonthemostcriticalcybermanagementandinvestmentpriorities.
CEOs:MeetregularlywiththeCROandCISOto
understandthethreatvectorsthey’remostconcernedabout.Makesureyou’rereceivingregularreportingoncurrentthreatmitigationefforts.
Board:Understandthetopcyberriskstothe
organisationandaskthetoughquestionsof
management.Howarerisksbeingmitigated?Dowe
haveadequateplansandfundinginplacetoproactivelyaddressrisksandrespondshouldaneventoccur?
Threatoutlookandemergingrisks
EmergingtechnologiesandGenAI
GenAIandemergingtech:
Balancingopportunityandrisk
67%78%72%
ofsecurityexecutivessaythatGenAIhasincreasedtheirattacksurface
overthelastyear
haveincreasedtheirinvestmentinGenAIoverthelast12months
haveincreasedtheirriskmanagementinvestmentinAIgovernance
WhiletherapidadvancementofgenerativeAI(GenAI)is
usheringinnewopportunitiesacrossindustries,italso
presentscybersecurityrisks.AsorganisationsadoptGenAIandotheremergingtechnologies,theC-suiteshould
navigatemorecomplexandunpredictableattackvectors,integrationobstaclesandthedual-edgednatureofGenAIin
bothcyberdefenceandoffence.UnderlyingthesechallengesaresignificantdataandlegalissuesthatcancomplicatethedeploymentandgovernanceofGenAI.
“
Cybersecurityispredominantlyadatascienceproblem.It’s
becomingimperativeforcyberdefenderstoleveragethepowerofgenerativeAIandmachine
learningtogetclosertothedatatodrivetimelyandactionable
insightsthatmatterthemost.”
MikeElmore,GlobalCISO,GSK
Anevolvingattacksurface
SecurityexecutivesreportthatGenAI(67%)andcloud
technologies(66%)haveexpandedthecyberattacksurfaceoverthepastyear,makingcompaniesmorevulnerableto
sophisticatedthreats.GenAIcanalsoreducebarriersto
entryforlesssophisticatedthreatactors,enablingthemtocrafteffectivephishingattacksanddeepfakesatscale.Thisalignswiththefindingsofour
27thCEOSurvey
,in
which64%ofCEOsgloballyagreedthatGenAIislikelytoincreasecybersecurityriskintheirorganisation.UseofGenAIalsoraisesconcernsaboutdataintegrity,privacyandcomplianceascompaniesdealwithregulatory
obligationsthatarestillevolving.
Alsoexpandingtheattacksurfaceareothertechnologies
suchasconnecteddevicesandoperationaltechnology(OT),whichwillaffectindustriessuchasmanufacturing,healthcareandenergy.Asmoredevicesbecomeinterconnected,
securingthesesystemsbecomesharder.Inaddition,whilequantumcomputingisstillonthehorizon,42%percentofsecurityexecutivesreportthatithasalreadycausedthemtoaddressvulnerabilities.
Technologiesaffectingthecyberattacksurface*
*showingcombinedpercentagewhoselected'increasesignificantly'or'increaseslightly'
Q4.TowhatextenthavethefollowingtechnologiesaffectedthecyberattacksurfaceinyourTenvironmentoverthelast12months?Base:securityleaders=1762
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Continuousassessmentofnewvulnerabilities,
investmentinadvancedsecuritymeasuresand
fosteringclosercollaborationbetweentechnology,security,riskandlegalteamsareparamount.Bystayingpreparedforthesethreats,companies
canbettersafeguardcriticalassetsandmaintainstakeholdertrust.
EmergingtechnologiesandGenAIPwC|2025GlobalDigitalTrustInsights|7
LeveragingGenAIforcyberdefence:Opportunitiesandchallenges
AlthoughGenAIisincreasingthecyberriskattacksurfaceformostorganisations,executivesarealsousingthatsametechnologyforcyberdefence.Thetopthreewaysthey’releveragingGenAIincludethreatdetectionandresponse,
threatintelligenceandmalware/phishingdetection.
However,despitetheseopportunities,organisationsface
severalobstacleswhenincorporatingGenAIintotheircyberdefencestrategies.
Difficultyincorporatingwithexistingsystems/processes(39%)
LackoftrustinGenAIbyinternalstakeholders(39%)
Inadequateinternalcontrolsandriskmanagement
(38%)
Lackofstandardisedinternalpoliciesgoverningitsuse(37%)
Wake-upcall
GenAIcantransformyourcyberdefences,butonlyifyouovercomethechallengestointegrate,trustand
governiteffectively,applying
ResponsibleAI
practices.Otherwise,youriskfallingbehindinthearmsrace
againstthreatactors.
GenAIleadsincyberinvestmentpriorities
Recognisingtheincreasedcyberrisks,78%ofexecutives
haverampeduptheircyberinvestmentinGenAI,
particularlyfocusingongovernance.ThisinvestmentinGenAIunderscorestheimportanceofmanagingbothitscapabilitiesandrisks.
Companiesarealsobeginningto
investinquantum
preparedness.
Althoughadoptionremainsyearsaway,
there’salreadyagrowingimperativetopursuequantum-
resistanttechnologiesandpost-quantumsecuritymeasurestocombatfuturethreatsposedbythistechnologyinthe
wronghands.
EmergingtechnologiesandGenAI
Wake-upcall
InvestinginGenAIisjustthestart.Movetheneedlemorebyexploringtheuntappedpotentialofother
technologies,includingquantum-resistantsolutions,tohelpyourdefencesoutpaceevolvingthreats.
Executivecall-to-action
Asemergingtechnologiesreshapethecybersecurity
landscape,it’scriticalforexecutivesacrosstheC-suiteto
takeanactiveroleinguidingtheirorganisationsthroughboththeopportunitiesandriskstheseinnovationspresent.
CISOs:Helptodrivestandardisationacrossthe
technologyestatetohelpintegrateAIintocyberdefences.Enforceaccessrightsonauser-by-userbasistoidentifyprobableattackvectors.
CIOsandCTOs:DevelopanAIimpactassessmenttoeducatebusinessexecutivesonwhereinvestmentandimplementationmakesthemostsense.PrepareyourplatformsforscalabilityasGenAIusegrows.
CFOs:WorkwiththeCISOonprioritisingthesecurityandconfidentialityoffinancialdataprotection.
Chiefdataofficers(CDOs):Enhanceyourdata
governanceprotocolsandassessanydataprivacyrisksagainstprivacylawsandregulatorguidance.
Chieflegalofficers(CLOs)andgeneralcounsel(GCs):Collaboratewithotherriskandcomplianceteamstoguardagainstimpropersecondaryusesofdataandpotentiallegalexposure.
PwCGlobalDigitalTrustInsights|9
EmergingtechnologiesandGenAI
Regulatorydevelopments
Ahighlyregulatedcyberworld:Arecompaniesreallyready?
96%78%13%
reportthatcybersecurityregulations
havespurredthemtoincreasetheir
cyberinvestmentinthelast12months
believethatregulationshavehelpedtochallenge,improveorincreasetheircybersecurityposture
pointgapinconfidencebetweenCISO/CSOsandCEOsregardingcompliancewithAIandresilienceregulations
Regulatoryframeworksareaskingcompaniestoswiftly
complywithagrowingarrayofrequirements.Asurgeof
newregulations—DORA,CyberResilienceAct,AIAct,
CIRCIA,SingaporeCybersecurityAct,etc.—underscores
theurgencyfororganisationstoaligntheirpracticestotheseheightenedexpectations.Asbusinessesnavigatethese
demands,theyfaceacriticalgapinconfidencebetween
CISO/CSOsandCEOsregardingtheirabilitytoachievefullcompliance.Addressingthesechallengesisessentialto
buildingaresilientandcompliantcybersecurityposturethatcanwithstandbothregulatoryscrutinyandemergingthreats.
Cyberregulationsaredrivingpositivechange
Cyberregulationsareprovingtobeamajordriverfor
cybersecurityinvestment,with96%ofexecutives
acknowledgingthatregulatoryrequirementshavespurred
themtoenhancetheirsecuritymeasures.Moreover,78%
believethatregulationshavehelpedtochallenge,improve
orincreasetheircybersecurityposture.Thisindicatesthat,
despitethedifficultiesofcompliance,regulationsareservingtofurthermaturecybersecuritycapabilitiesacrossindustries.
Regulatorydevelopments
Impactofcybersecurityregulationsonincreasingcybersecurityinvestment
32%
37%Toa
Toalargeextent
moderateextent
14%
13%
Toalimitedextent
3%
Notatall
Toasignificantextent
1%unsure/Notapplicable
Q16.Towhatextent,ifatall,havecybersecurityregulationsincreasedyourorganisation'Scybersecurityinvestmentoverthelast12months?Base:securityleadersandCFO
respondents=1951
source:Pwc2025GlobalDigitalTrustInsights
Helpfulimpactonorganisations
cybersecurityregulationshelped78%oforganisations
24%20%19%15%
challenged
ourorganisationtostrengthen
currentcyberriskmanagement
program,
processesandovernance
approaches
helped
establishguardrails
fortechnologyinnovationandtransformationefforts
helpedbecomemoreresilient
bymandatinganindustry-
wideframework
ledus
toconsider
cybermanagedservicesto
address
regulatory
requirements
Q17.whichonestatement,ifany,bestreflectstheimpactofnewcybersecurityregulationsonyourorganisationoverthelast12months?Base:Allrespondents=4042
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Organisationsthatembraceregulatoryrequirementstendtobenefitfromstrongersecurityframeworks
andamorerobustpostureagainstemergingthreats.Complianceshouldn’tbeviewedasabox-ticking
exercisebutasanopportunitytobuildlong-termresilienceandtrustwithstakeholders.
confidenceinorganisation'sregulationcompliance
showing%highconfidenceforCEOVsCso/cso
Confidencegap:CISOsfeellesscertainthanCEOsaboutcybercompliance
Despitethebeliefthatcyberregulationsarehelpingthe
Artificialintelligence
organisation,there’sasignificantdifferencebetweenCEO
andCISO/CSOconfidenceintheirabilitytocomplywith
Resilience
theseregulations.ThebiggestgapsinvolvecompliancewithAI,resilienceandcriticalinfrastructurerequirements.CISOs,whoareonthefrontlinesofcybersecurity,arelessoptimisticthanCEOsabouttheirorganisation’sabilitytomeetthese
regulatoryrequirements.
criticalinfrastructure
BecauseCISOsaremoreattunedtotheday-to-day
operationaldifficulties,resourceconstraintsandpotentialvulnerabilitiesthatcanhindercybercompliance,it’svital
thattheymoreeffectivelycommunicatetheserisksto
Dataprotection
theleadershipteam.What’spreventingthem?Potential
obstaclesincludebarrierstoCISOparticipationinstrategicdecisionsandaninabilitytojustifytheamountofcyberriskinvestmentneeded.
cyberdisclosure
consumerprivacy
Networkandinformationsecurity
CEO
CSO/CSO
Globalisdenotedbyyellowbar
Q15.Howconfidentareyouinyourorganisation'sabilitytobeincompliancewiththefollowingtypesofregulationsthatmayapplytothegeographicarea(s)inwhichyourorganisationoperates?Base:Allrespondents=4042
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
BridgingthisconfidencegaprequiresbetteralignmentandcommunicationbetweensecurityexecutivesandtheC-suite.CEOsshouldmakesurethatCISOsaren’tonlyheardbutalsohavetheresourcesandsupport
necessarytomeetregulatorydemands.CISOsneedtoprovidedata-backedinsightsandmakethebusinesscaseforelevatingcompliancetoastrategicimperative.
Regulatorydevelopments
PwC|2025GlobalDigitalTrustInsights|11
PwC2025GlobalDigitalTrust|
Executivecall-to-action
Asregulatoryrequirementscontinuetoshapethe
cybersecuritylandscape,it’sessentialthatexecutivesacrosstheC-suitestayaheadofcomplianceissueswhileleveragingregulationsasacatalystforinnovation.Creatingalignment
acrosssecurityteams,riskfunctionsandexecutive
leadershipiscrucialformaintainingcompliancereadinessanddrivingstrategicimprovements.
CISOsandCROs:Deliverfrequentreportingtootherexecutiveleadersonthestateofregulationsthat
directlyimpactrespectiveindustryorterritoryneeds,andworktowardsimplementingtechnologyand
regulatorychangemanagementprocesses.
CFOs:Verifytheaccuracy,completenessand
defensibilityofallregulatorydisclosuresofcyberriskmanagementandprogramposture.Developaclear
understandingofmaterialityandthespecificimpactofacyberincident,incorporatingcyberriskquantificationtoaccuratelyassessandcommunicatepotentialrisks.
CEOs:Understandoversightresponsibilitiesto
guidecomplianceefforts,includinganynecessary
coordinationbetweendifferentbusinessunits.IdentifykeyquestionstoaskCISOstocloseanyknowledgegapsoncomplianceposture.
Chiefcomplianceofficers:Stayabreastof
regulatorycompliancerequirementsandcollaboratewiththeCISOandCROtoincorporateproactive
compliancemeasuresandmonitoringtoperiodicallyconfirmcompliance.
CLOsandGCs:Determinetherightamountofdisclosuredetailsneededtofulfilcyberprogramreportingobligations,strikingabalancebetweentransparencyandconfidentiality.
Board:Stayabreastofemergingregulatory
requirementsandseekinputfrommanagementon
proactivemeasuresbeingtakentopreparefornew
requirements.Understandmanagement’sapproachtoassessinganddisclosingcyberincidents.
Regulatorydevelopments
Cyberriskquantification
Unlockingthepotentialofcyberriskquantification:What’s
holdingorganisationsback?
15%87%44%
Only15%aremeasuringthe
financialimpactofcyberriskstoasignificantextent
sayallocatingresourcestoareasofhighestriskisofhighimportance
saydataissuesareatopchallengefacedwhenquantifyingthefinancialimpactofcyberrisk
Ascyberthreatsrapidlyevolveinscopeand
sophistication,cyberriskquantificationhasbecomeacriticaltoolthatorganisationscan’taffordtooverlook.
Butdespiteitswidelyacknowledgedbenefits,several
challenges(dataqualityissues,outputreliability,etc.)haveimpededbroaderadoption.
Measuringcyberriskiscriticalbutlimited
Whileexecutiveslargelyagreethatmeasuringcyberrisk
iscrucialforprioritisingcyberriskinvestments(88%)and
allocatingresourcestoareasofhighestrisk(87%),only15%oforganisationsareactuallydoingittoasignificantextent
(e.g.,extensivecyberriskquantificationwithautomationandextensivereporting).
Fortheorganisationsthatdomeasurerisk,sevenin10
executivesindicatetheyusesecuritypostureassessmentstoquantifyresidualriskbyconsideringtheeffectivenessofkeycontrolssuchascompliancewithvulnerabilityremediation,useraccessreviewsandtrainingcompletion.Theadoptionofmoreholisticcyberriskquantificationpractices,however,remainslimited.
Benefitsofquantifyingcyberrisk
88%88%87%86%84%
Tohelpprioritisecyberinvestments
Tohelpevaluateandcommunicatecyberrisksinlinewithdefinedrisktolerance
Tohelpallocateresourcestoareasofhighestrisk
Todemonstratethecyberriskmanagementprogram'svalue
Tomeasureandcomparethreatsandincidentsonanapples-to-applesbasis
Q27.pleaseindicatehowimportantorunimportantthefollowingaspectsaretoyour
organisationinquantifyingcyberrisk.Base:securityleaders,CEO,BoardMember,CFOandCROrespondentsmeasuringthepotentialfinancialimpactofcyberrisks=1899
Wake-upcall
It’stimetorealisethefullpotentialofcyberrisk
quantification.Thegapbetweenrecognitionand
implementationisamissedopportunitythatcan
nolongerbeignored.Organisationsthatdon’t
measurecyberriskorhaven’tfullydevelopedthiscapabilityareleavingcriticalintelligenceonthe
table,particularlywhenitcomestoinformingboarddecisionsandcapitalallocation.
source:Pwc2025GlobalDigitalTrustInsights
CyberriskquantificationPwC
|2025GlobalDigitalTrustInsights|
13
PwC|2025GlobalDigitalInsights|
Wake-upcall
Whatarethebarrierstowiderimplementation?
Thebarrierstocyberriskquantificationadoption—
anduse—maybestallingprogress.Organisations
can’taffordtoletthesechallengeshindercritical
decision-making.Addresstheseobstaclesheadon,
buildtrustincyberriskquantificationandfullyintegrateitintoyourstrategicprocess.
Dataissues,scopeuncertaintyandlegalconcernsrank
highonthelistofobstaclestoimplementingcyberrisk
quantification.Lackoftrustinthereliabilityofquantificationoutputsisanother.FurthercomplicatingadoptionisthegapbetweenwhatseniorexecutivesexpectandwhatCISOs
deliver,asmeasuringcyberriskrequiresalignmentbetweensecurityexecutivesandbusinessriskappetite.
challengesfacedinquantifyingfinancialimpactofcyberrisk
(showing%rank
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 安全生产财务保障讲解
- 光头强课件教学课件
- 光催化技术教学课件
- 热力工程考试题及答案
- 光伏组件车间安全培训课件
- 光伏组件低效培训课件
- 楼宇管理考试题及答案
- 2025-2026学年广东省八年级上学期英语期中测试卷
- 光伏厂安全生产培训内容课件
- 2024人教版八年级英语上册期末复习:Unit 1~8+期中+期末素养测试卷汇编(共10套含答案)
- DB11∕T 1831-2021 装配式建筑评价标准
- 航空附件相关知识培训课件
- 年末安全生产知识培训课件
- 南网综合能源公开招聘笔试题库2025
- 人工智能导论第4版-课件 第7章-神经计算
- 山东省安装工程消耗量定额 第十二册 刷油、防腐蚀、绝热工程2025
- 汉语水平考试HSK四级真题4-真题-无答案
- 银行金融消费者权益保护工作测试题及答案
- 2025年c2安全员考试题库
- 人工智能赋能基础教育应用蓝皮书 2025
- 北师大版高中数学必修二讲义:第一章 三角函数(十九种常考题型)学生版+解析
评论
0/150
提交评论