




版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Bridgingthegaps
tocyberresilience:TheC-suiteplaybook
Findingsfromthe2025GlobalDigitalTrustInsights
DigitalTrustInsights2
Findingsfromthe2025GlobalDigitalTrustInsights
2%50%13%
Only2%haveimplementedcyberresilienceactionsacrosstheir
organisationinallareassurveyed
Under50%ofCISOsareinvolvedtoalargeextentinkeybusinessactivities
pointgapinconfidencebetweenCISO/CSOsandCEOsregardingcompliancewithAIandresilienceregulations
Withtheattacksurfacecontinuingtoexpandthrough
advancesinAI,connecteddevicesandcloudtechnologiesandtheregulatoryenvironmentinconstantflux,achievingcyberresilienceatanenterpriseleveliscritical.
Yetdespitewidespreadawarenessofthechallenges,
significantgapspersist.Tosafeguardtheirorganisations,executivesshouldtreatcybersecurityasastandingitemonthebusinessagenda,embeddingitintoeverystrategicdecisionanddemandingC-suitecollaboration.
PwC’s2025GlobalDigitalTrustInsightssurveyof4,042businessandtechexecutivesfromacross77countriesrevealedsignificantgapscompaniesmustbridgebeforeachievingcyberresilience.
Gapsinimplementationofcyberresilience:
Despiteheightenedconcernsaboutcyberrisk,only2%oftheexecutivessaytheircompanyhasimplementedcyberresilienceactions
acrosstheirorganisationinallareassurveyed.
Gapsinpreparedness:Organisationsfeelleastpreparedtoaddressthecyberthreatstheyfindmostconcerning,suchascloud-relatedrisksandthird-partybreaches.
GapsinCISOinvolvement:FewerthanhalfoftheexecutivessaytheirCISOsareinvolvedtoalargeextentinstrategicplanning,boardreportingandoverseeingtechdeployments.
Gapsinregulatorycomplianceconfidence:
CEOsandCISO/CSOshavedifferinglevelsofconfidenceintheircompany’sabilitytocomplywithregulations,particularlyregardingAI,
resilienceandcriticalinfrastructure.
Gapsinmeasuringcyberrisk:Although
executivesacknowledgetheimportanceof
measuringcyberrisk,fewerthanhalfdoso
effectively,withonly15%measuringthefinancialimpactofcyberriskstoasignificantextent.
AllofthispointstotheneedforbetterC-suitecollaborationandstrategicinvestmenttostrengthencyberresilience.Byaddressingthesegapsandmakingcybersecurityabusinesspriority,executivescanbridgetoamoresecurefuture.
CISOscanhelpdrivethisoutcomebysharingtech-enabledinsightsandbyexplainingcyberprioritiesinbusinessterms(cost,opportunity,risk).
Table
4...............
7...............
10.............
13.............
16.............
19.............
ofcontents
Navigatingcyberthreats:Establishingasharedvisionforpreparedness
GenAIandemergingtech:Balancingopportunityandrisk
Ahighlyregulatedcyberworld:Arecompaniesreallyready?
Unlockingthepotentialofcyberriskquantification:What’sholding
organisationsback?
Investinginresilience,buildingtrust
Isyourcyberstrategyandleadershipdrivingrealresilience?
PwC|2025GlobalDigitalTrustInsights|3
Threatoutlookandemergingrisks
Navigatingcyberthreats:
Establishingasharedvisionforpreparedness
66%42%Top2
oftechexecutivesrankcyberasthehighestriskformitigation,comparedto48%ofbusinessexecutives
ofexecutivesrankcloud-relatedthreatsastheirmostconcerningcyberthreat
Cloudandconnectedproductattacksarewhatsecurityexecutivesfeelleastpreparedtoaddress
Whilethecybersecuritylandscapecontinuestoevolve,
organisationsarestrugglingwithincreasinglyvolatile
andunpredictablethreats.Anexpandingattacksurface
—spurredbygrowingrelianceoncloud,AI,connected
devicesandthirdparties—demandsanagile,enterprise-wideapproachtoresilience.Aligningorganisational
prioritiesandreadinessisessentialformaintainingsecurityandbusinesscontinuity.
Unpreparedforthemostconcerningthreats
Whatworriesorganisationsmostiswhatthey’releast
preparedfor.Thetopfourcyberthreatsfoundmost
concerning—cloud-relatedthreats,hack-and-leak
operations,third-partybreachesandattacksonconnected
products—arethesameonessecurityexecutivesfeelleastpreparedtoaddress.Thisgaphighlightstheurgentneedforbetterinvestmentsandstrongerresponsecapabilities.
Additionally,aperceptiongapexistsbetweensecurity
executivesandtherestoftheorganisation,withCISOs
andCSOsmorelikelytorankransomwareamongtheirtopthreemostconcerningthreats.Thismayreflecttheirrole,asransomwareismorecentraltocyber/ITdutiesandthoseinthatfunctionlikelyunderstandthevulnerabilitiesbetterthantheirbusinesspeers.Thisfurtherreinforcestheimportanceofbetterinformation-sharingacrossleadershipteamsto
createalignmentonpriorities.
cyberthreatconcernVspreparedness(showing%ranked1-3)
CISO/CSOleadersaremorelikelyto
rankransomwareintheirtopthreemostconcerningcyber
cloud-relatedthreats
Hack-and-
leak
operations
Third-partybreach
Ransomware
Attackson
connected
products
Mostconcerningcyberthreats
cyberthreatsleastpreparedtoaddress
Ascomparedto27%globally
Q2.overthenext12months,whichofthefollowingcyberthreatsisyourorganisationmostconcernedabout(e.g.,risktoyourbrand,lossofbusinessorbusinessdisruption,
compliance)?(Rankedintopthree)Base:Arespondents=4042
Q3.overthenext12months,whichofthecyberthreatsdoyouthinkyourorganisationisleastpreparedtoaddress?(Rankedintopthree)Base:securityleadersandCFO
respondents=1951
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Athreat-informedcyberinvestmentstrategyis
essential.Prioritiseinvestmentsinthemostpressingcyberrisksandtakeacloserlookatwhereresourcesarebeingappliedintermsofpeople,processand
defencecapabilities.
ThreatoutlookandemergingrisksPwC
|2025GlobalDigitalTrustInsights|
4
PwC|2025GlobalDigitalTrustInsights|5
Thestrategicdivide:Businessandtechpriorities
Businessexecutivesandtechexecutivesprioritisedifferentrisks.Whilebusinessexecutivesaremoreconcernedwithinflation,techexecutivesrankcyberrisksastheirtop
priority—likelyduetotheirproximitytothecyberthreatlandscape.Evenso,nearlyhalfofbusinessexecutives
stillrankcyberrisksamongtheirtopthreeconcerns,
underscoringitscriticalimportance.ThissharedconcernrepresentsanopportunityforCISOstoconnectthecyberagendatothebusinessagenda.
RiskmitigationprioritiesforbusinessVstechleaders
(showing%ranked1-3)Inflation
Digitalandtechnologyrisks
cyberrisks
48%
Techleaders
Businessleaders
Q1.whichofthefollowingrisksisyourorganisationprioritisingformitigationoverthenext12months?(Rankedintopthree)Base:Allrespondents=4042
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Businessandtechexecutives—it’stimetogetaligned.
Balanceprioritisationofcyberriskswitheconomicpressurestohelpsafeguardassetsandcreate
resilience.Regularcross-functionalassessmentswillkeepyourstrategyandprioritiesinsync.
Threatoutlookandemergingrisks
Globalaveragedatabreachcostexceeds$3million
Overaquarterofexecutivestellustheirmostdamaging
databreachinthepastthreeyearscosttheirorganisationatleast$1million.Thisissomewhatlowerthanlastyear’ssurveyacrossorganisationsofallsizesandinmostregionsandsectors.Overall,theaveragedatabreachisestimatedat$3.32million.
Topperformers—identifiedasthosewhorespondedthattheirorganisationismorelikelytodemonstratehighqualitycybersecuritypracticesonausualbasis—werelesslikelytoexperienceanydatabreachesinthepastthreeyears.
Thesetopperformersaretypicallyfromlarger,high-growthorganisationswithcyberbudgetsexpectedtoincrease
by15%ormorenextyear,indicatingthatcyberprogrammaturityandfundingcorrelatetobetterresilience.
“
Don’tstopshortonyourjourneyforcybersecurityandresilience.Criminalsandnation-state
actorsarebecomingexpertat
findingunprotectedseams:weakidentityandaccesscontrols,
unpatcheddevicesandsecuritymisconfigurations.”
RobJoyce,Cyber,Risk&RegulatorySeniorFellow,PwCUS,formerSpecialAssistanttothePresident&ActingHomelandSecurityAdvisor
PwC|2025GlobalTrustInsights|
Wake-upcall
Prioritiseholisticriskmitigationstrategiesthat
encompassprevention,detection,responseand
recovery.Understandthebroaderimpactsofabreach—beyondfinancialharm—tobuildtrueresilience.
Executivecall-to-action
Asorganisationsfaceamoresophisticatedthreatlandscape,it’simportantfor
executivesacrosstheC-suite
totakea
proactiveroleinassessingbothcurrentandemergingrisks.Byaligningcybersecuritystrategieswithbroaderbusinessobjectives,executivescanbetterpreparetheirorganisationstomanageriskandbuildresilience.
CISOs:UnderscoretotherestoftheC-suitethe
threatsthatjeopardiseyourbusinessmost,especiallyifinvestmenteffortsneedtobeshifted.
CIOsandchieftechnologyofficers(CTOs):Basedonconversationswiththeriskexecutives,gauge
howcertainthreatscandamageinformationand
infrastructuresecurityatlargeandwhichthreatsposethebiggestbarrierstoresilience.
CFOs:GaindeeperinsightfromtheCISOand
CROonthemostcriticalcybermanagementandinvestmentpriorities.
CEOs:MeetregularlywiththeCROandCISOto
understandthethreatvectorsthey’remostconcernedabout.Makesureyou’rereceivingregularreportingoncurrentthreatmitigationefforts.
Board:Understandthetopcyberriskstothe
organisationandaskthetoughquestionsof
management.Howarerisksbeingmitigated?Dowe
haveadequateplansandfundinginplacetoproactivelyaddressrisksandrespondshouldaneventoccur?
Threatoutlookandemergingrisks
EmergingtechnologiesandGenAI
GenAIandemergingtech:
Balancingopportunityandrisk
67%78%72%
ofsecurityexecutivessaythatGenAIhasincreasedtheirattacksurface
overthelastyear
haveincreasedtheirinvestmentinGenAIoverthelast12months
haveincreasedtheirriskmanagementinvestmentinAIgovernance
WhiletherapidadvancementofgenerativeAI(GenAI)is
usheringinnewopportunitiesacrossindustries,italso
presentscybersecurityrisks.AsorganisationsadoptGenAIandotheremergingtechnologies,theC-suiteshould
navigatemorecomplexandunpredictableattackvectors,integrationobstaclesandthedual-edgednatureofGenAIin
bothcyberdefenceandoffence.UnderlyingthesechallengesaresignificantdataandlegalissuesthatcancomplicatethedeploymentandgovernanceofGenAI.
“
Cybersecurityispredominantlyadatascienceproblem.It’s
becomingimperativeforcyberdefenderstoleveragethepowerofgenerativeAIandmachine
learningtogetclosertothedatatodrivetimelyandactionable
insightsthatmatterthemost.”
MikeElmore,GlobalCISO,GSK
Anevolvingattacksurface
SecurityexecutivesreportthatGenAI(67%)andcloud
technologies(66%)haveexpandedthecyberattacksurfaceoverthepastyear,makingcompaniesmorevulnerableto
sophisticatedthreats.GenAIcanalsoreducebarriersto
entryforlesssophisticatedthreatactors,enablingthemtocrafteffectivephishingattacksanddeepfakesatscale.Thisalignswiththefindingsofour
27thCEOSurvey
,in
which64%ofCEOsgloballyagreedthatGenAIislikelytoincreasecybersecurityriskintheirorganisation.UseofGenAIalsoraisesconcernsaboutdataintegrity,privacyandcomplianceascompaniesdealwithregulatory
obligationsthatarestillevolving.
Alsoexpandingtheattacksurfaceareothertechnologies
suchasconnecteddevicesandoperationaltechnology(OT),whichwillaffectindustriessuchasmanufacturing,healthcareandenergy.Asmoredevicesbecomeinterconnected,
securingthesesystemsbecomesharder.Inaddition,whilequantumcomputingisstillonthehorizon,42%percentofsecurityexecutivesreportthatithasalreadycausedthemtoaddressvulnerabilities.
Technologiesaffectingthecyberattacksurface*
*showingcombinedpercentagewhoselected'increasesignificantly'or'increaseslightly'
Q4.TowhatextenthavethefollowingtechnologiesaffectedthecyberattacksurfaceinyourTenvironmentoverthelast12months?Base:securityleaders=1762
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Continuousassessmentofnewvulnerabilities,
investmentinadvancedsecuritymeasuresand
fosteringclosercollaborationbetweentechnology,security,riskandlegalteamsareparamount.Bystayingpreparedforthesethreats,companies
canbettersafeguardcriticalassetsandmaintainstakeholdertrust.
EmergingtechnologiesandGenAIPwC|2025GlobalDigitalTrustInsights|7
LeveragingGenAIforcyberdefence:Opportunitiesandchallenges
AlthoughGenAIisincreasingthecyberriskattacksurfaceformostorganisations,executivesarealsousingthatsametechnologyforcyberdefence.Thetopthreewaysthey’releveragingGenAIincludethreatdetectionandresponse,
threatintelligenceandmalware/phishingdetection.
However,despitetheseopportunities,organisationsface
severalobstacleswhenincorporatingGenAIintotheircyberdefencestrategies.
Difficultyincorporatingwithexistingsystems/processes(39%)
LackoftrustinGenAIbyinternalstakeholders(39%)
Inadequateinternalcontrolsandriskmanagement
(38%)
Lackofstandardisedinternalpoliciesgoverningitsuse(37%)
Wake-upcall
GenAIcantransformyourcyberdefences,butonlyifyouovercomethechallengestointegrate,trustand
governiteffectively,applying
ResponsibleAI
practices.Otherwise,youriskfallingbehindinthearmsrace
againstthreatactors.
GenAIleadsincyberinvestmentpriorities
Recognisingtheincreasedcyberrisks,78%ofexecutives
haverampeduptheircyberinvestmentinGenAI,
particularlyfocusingongovernance.ThisinvestmentinGenAIunderscorestheimportanceofmanagingbothitscapabilitiesandrisks.
Companiesarealsobeginningto
investinquantum
preparedness.
Althoughadoptionremainsyearsaway,
there’salreadyagrowingimperativetopursuequantum-
resistanttechnologiesandpost-quantumsecuritymeasurestocombatfuturethreatsposedbythistechnologyinthe
wronghands.
EmergingtechnologiesandGenAI
Wake-upcall
InvestinginGenAIisjustthestart.Movetheneedlemorebyexploringtheuntappedpotentialofother
technologies,includingquantum-resistantsolutions,tohelpyourdefencesoutpaceevolvingthreats.
Executivecall-to-action
Asemergingtechnologiesreshapethecybersecurity
landscape,it’scriticalforexecutivesacrosstheC-suiteto
takeanactiveroleinguidingtheirorganisationsthroughboththeopportunitiesandriskstheseinnovationspresent.
CISOs:Helptodrivestandardisationacrossthe
technologyestatetohelpintegrateAIintocyberdefences.Enforceaccessrightsonauser-by-userbasistoidentifyprobableattackvectors.
CIOsandCTOs:DevelopanAIimpactassessmenttoeducatebusinessexecutivesonwhereinvestmentandimplementationmakesthemostsense.PrepareyourplatformsforscalabilityasGenAIusegrows.
CFOs:WorkwiththeCISOonprioritisingthesecurityandconfidentialityoffinancialdataprotection.
Chiefdataofficers(CDOs):Enhanceyourdata
governanceprotocolsandassessanydataprivacyrisksagainstprivacylawsandregulatorguidance.
Chieflegalofficers(CLOs)andgeneralcounsel(GCs):Collaboratewithotherriskandcomplianceteamstoguardagainstimpropersecondaryusesofdataandpotentiallegalexposure.
PwCGlobalDigitalTrustInsights|9
EmergingtechnologiesandGenAI
Regulatorydevelopments
Ahighlyregulatedcyberworld:Arecompaniesreallyready?
96%78%13%
reportthatcybersecurityregulations
havespurredthemtoincreasetheir
cyberinvestmentinthelast12months
believethatregulationshavehelpedtochallenge,improveorincreasetheircybersecurityposture
pointgapinconfidencebetweenCISO/CSOsandCEOsregardingcompliancewithAIandresilienceregulations
Regulatoryframeworksareaskingcompaniestoswiftly
complywithagrowingarrayofrequirements.Asurgeof
newregulations—DORA,CyberResilienceAct,AIAct,
CIRCIA,SingaporeCybersecurityAct,etc.—underscores
theurgencyfororganisationstoaligntheirpracticestotheseheightenedexpectations.Asbusinessesnavigatethese
demands,theyfaceacriticalgapinconfidencebetween
CISO/CSOsandCEOsregardingtheirabilitytoachievefullcompliance.Addressingthesechallengesisessentialto
buildingaresilientandcompliantcybersecurityposturethatcanwithstandbothregulatoryscrutinyandemergingthreats.
Cyberregulationsaredrivingpositivechange
Cyberregulationsareprovingtobeamajordriverfor
cybersecurityinvestment,with96%ofexecutives
acknowledgingthatregulatoryrequirementshavespurred
themtoenhancetheirsecuritymeasures.Moreover,78%
believethatregulationshavehelpedtochallenge,improve
orincreasetheircybersecurityposture.Thisindicatesthat,
despitethedifficultiesofcompliance,regulationsareservingtofurthermaturecybersecuritycapabilitiesacrossindustries.
Regulatorydevelopments
Impactofcybersecurityregulationsonincreasingcybersecurityinvestment
32%
37%Toa
Toalargeextent
moderateextent
14%
13%
Toalimitedextent
3%
Notatall
Toasignificantextent
1%unsure/Notapplicable
Q16.Towhatextent,ifatall,havecybersecurityregulationsincreasedyourorganisation'Scybersecurityinvestmentoverthelast12months?Base:securityleadersandCFO
respondents=1951
source:Pwc2025GlobalDigitalTrustInsights
Helpfulimpactonorganisations
cybersecurityregulationshelped78%oforganisations
24%20%19%15%
challenged
ourorganisationtostrengthen
currentcyberriskmanagement
program,
processesandovernance
approaches
helped
establishguardrails
fortechnologyinnovationandtransformationefforts
helpedbecomemoreresilient
bymandatinganindustry-
wideframework
ledus
toconsider
cybermanagedservicesto
address
regulatory
requirements
Q17.whichonestatement,ifany,bestreflectstheimpactofnewcybersecurityregulationsonyourorganisationoverthelast12months?Base:Allrespondents=4042
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
Organisationsthatembraceregulatoryrequirementstendtobenefitfromstrongersecurityframeworks
andamorerobustpostureagainstemergingthreats.Complianceshouldn’tbeviewedasabox-ticking
exercisebutasanopportunitytobuildlong-termresilienceandtrustwithstakeholders.
confidenceinorganisation'sregulationcompliance
showing%highconfidenceforCEOVsCso/cso
Confidencegap:CISOsfeellesscertainthanCEOsaboutcybercompliance
Despitethebeliefthatcyberregulationsarehelpingthe
Artificialintelligence
organisation,there’sasignificantdifferencebetweenCEO
andCISO/CSOconfidenceintheirabilitytocomplywith
Resilience
theseregulations.ThebiggestgapsinvolvecompliancewithAI,resilienceandcriticalinfrastructurerequirements.CISOs,whoareonthefrontlinesofcybersecurity,arelessoptimisticthanCEOsabouttheirorganisation’sabilitytomeetthese
regulatoryrequirements.
criticalinfrastructure
BecauseCISOsaremoreattunedtotheday-to-day
operationaldifficulties,resourceconstraintsandpotentialvulnerabilitiesthatcanhindercybercompliance,it’svital
thattheymoreeffectivelycommunicatetheserisksto
Dataprotection
theleadershipteam.What’spreventingthem?Potential
obstaclesincludebarrierstoCISOparticipationinstrategicdecisionsandaninabilitytojustifytheamountofcyberriskinvestmentneeded.
cyberdisclosure
consumerprivacy
Networkandinformationsecurity
CEO
CSO/CSO
Globalisdenotedbyyellowbar
Q15.Howconfidentareyouinyourorganisation'sabilitytobeincompliancewiththefollowingtypesofregulationsthatmayapplytothegeographicarea(s)inwhichyourorganisationoperates?Base:Allrespondents=4042
source:Pwc2025GlobalDigitalTrustInsights
Wake-upcall
BridgingthisconfidencegaprequiresbetteralignmentandcommunicationbetweensecurityexecutivesandtheC-suite.CEOsshouldmakesurethatCISOsaren’tonlyheardbutalsohavetheresourcesandsupport
necessarytomeetregulatorydemands.CISOsneedtoprovidedata-backedinsightsandmakethebusinesscaseforelevatingcompliancetoastrategicimperative.
Regulatorydevelopments
PwC|2025GlobalDigitalTrustInsights|11
PwC2025GlobalDigitalTrust|
Executivecall-to-action
Asregulatoryrequirementscontinuetoshapethe
cybersecuritylandscape,it’sessentialthatexecutivesacrosstheC-suitestayaheadofcomplianceissueswhileleveragingregulationsasacatalystforinnovation.Creatingalignment
acrosssecurityteams,riskfunctionsandexecutive
leadershipiscrucialformaintainingcompliancereadinessanddrivingstrategicimprovements.
CISOsandCROs:Deliverfrequentreportingtootherexecutiveleadersonthestateofregulationsthat
directlyimpactrespectiveindustryorterritoryneeds,andworktowardsimplementingtechnologyand
regulatorychangemanagementprocesses.
CFOs:Verifytheaccuracy,completenessand
defensibilityofallregulatorydisclosuresofcyberriskmanagementandprogramposture.Developaclear
understandingofmaterialityandthespecificimpactofacyberincident,incorporatingcyberriskquantificationtoaccuratelyassessandcommunicatepotentialrisks.
CEOs:Understandoversightresponsibilitiesto
guidecomplianceefforts,includinganynecessary
coordinationbetweendifferentbusinessunits.IdentifykeyquestionstoaskCISOstocloseanyknowledgegapsoncomplianceposture.
Chiefcomplianceofficers:Stayabreastof
regulatorycompliancerequirementsandcollaboratewiththeCISOandCROtoincorporateproactive
compliancemeasuresandmonitoringtoperiodicallyconfirmcompliance.
CLOsandGCs:Determinetherightamountofdisclosuredetailsneededtofulfilcyberprogramreportingobligations,strikingabalancebetweentransparencyandconfidentiality.
Board:Stayabreastofemergingregulatory
requirementsandseekinputfrommanagementon
proactivemeasuresbeingtakentopreparefornew
requirements.Understandmanagement’sapproachtoassessinganddisclosingcyberincidents.
Regulatorydevelopments
Cyberriskquantification
Unlockingthepotentialofcyberriskquantification:What’s
holdingorganisationsback?
15%87%44%
Only15%aremeasuringthe
financialimpactofcyberriskstoasignificantextent
sayallocatingresourcestoareasofhighestriskisofhighimportance
saydataissuesareatopchallengefacedwhenquantifyingthefinancialimpactofcyberrisk
Ascyberthreatsrapidlyevolveinscopeand
sophistication,cyberriskquantificationhasbecomeacriticaltoolthatorganisationscan’taffordtooverlook.
Butdespiteitswidelyacknowledgedbenefits,several
challenges(dataqualityissues,outputreliability,etc.)haveimpededbroaderadoption.
Measuringcyberriskiscriticalbutlimited
Whileexecutiveslargelyagreethatmeasuringcyberrisk
iscrucialforprioritisingcyberriskinvestments(88%)and
allocatingresourcestoareasofhighestrisk(87%),only15%oforganisationsareactuallydoingittoasignificantextent
(e.g.,extensivecyberriskquantificationwithautomationandextensivereporting).
Fortheorganisationsthatdomeasurerisk,sevenin10
executivesindicatetheyusesecuritypostureassessmentstoquantifyresidualriskbyconsideringtheeffectivenessofkeycontrolssuchascompliancewithvulnerabilityremediation,useraccessreviewsandtrainingcompletion.Theadoptionofmoreholisticcyberriskquantificationpractices,however,remainslimited.
Benefitsofquantifyingcyberrisk
88%88%87%86%84%
Tohelpprioritisecyberinvestments
Tohelpevaluateandcommunicatecyberrisksinlinewithdefinedrisktolerance
Tohelpallocateresourcestoareasofhighestrisk
Todemonstratethecyberriskmanagementprogram'svalue
Tomeasureandcomparethreatsandincidentsonanapples-to-applesbasis
Q27.pleaseindicatehowimportantorunimportantthefollowingaspectsaretoyour
organisationinquantifyingcyberrisk.Base:securityleaders,CEO,BoardMember,CFOandCROrespondentsmeasuringthepotentialfinancialimpactofcyberrisks=1899
Wake-upcall
It’stimetorealisethefullpotentialofcyberrisk
quantification.Thegapbetweenrecognitionand
implementationisamissedopportunitythatcan
nolongerbeignored.Organisationsthatdon’t
measurecyberriskorhaven’tfullydevelopedthiscapabilityareleavingcriticalintelligenceonthe
table,particularlywhenitcomestoinformingboarddecisionsandcapitalallocation.
source:Pwc2025GlobalDigitalTrustInsights
CyberriskquantificationPwC
|2025GlobalDigitalTrustInsights|
13
PwC|2025GlobalDigitalInsights|
Wake-upcall
Whatarethebarrierstowiderimplementation?
Thebarrierstocyberriskquantificationadoption—
anduse—maybestallingprogress.Organisations
can’taffordtoletthesechallengeshindercritical
decision-making.Addresstheseobstaclesheadon,
buildtrustincyberriskquantificationandfullyintegrateitintoyourstrategicprocess.
Dataissues,scopeuncertaintyandlegalconcernsrank
highonthelistofobstaclestoimplementingcyberrisk
quantification.Lackoftrustinthereliabilityofquantificationoutputsisanother.FurthercomplicatingadoptionisthegapbetweenwhatseniorexecutivesexpectandwhatCISOs
deliver,asmeasuringcyberriskrequiresalignmentbetweensecurityexecutivesandbusinessriskappetite.
challengesfacedinquantifyingfinancialimpactofcyberrisk
(showing%rank
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 阮郎归题目及答案
- 日语高考阅读题目及答案
- 2023年学业水平合格考试三年分类汇编(真题)-专题三地球上的水03海水的运动
- 4 4 解三角形-2026版53高考数学总复习A版精炼
- 2023-2024学年江苏省南京市江宁区高二下学期期末考试数学试卷(解析版)
- 2023-2024学年广东省阳江市高二下学期期末测试数学试题(解析版)
- 整改内容回复函
- 2025年湖南省中考英语试卷真题(含答案)
- 合法的员工劳动合同
- 年产30万平方米生态木护墙板新型环保材料研发生产项目可行性研究报告写作模板-申批备案
- 论网络言论自由的法律规制分析研究-以当前网络暴力现象为解析 法学专业
- 2024阀控式铅酸密封蓄电池
- 2024-2025形势与政策:发展新质生产力-推动高质量发展的内在要求和重要着力点
- 仓库搬运装卸服务方案
- 示范区城区控制性详细规划说明书
- 马鞍山二中理科创新人才实验班招生考试物理试题
- CJJT 182-2014 城镇供水与污水处理化验室技术规范
- 福建省2024年中考英语真题(含答案)
- GB/T 44198-2024空间站科学实验系统集成与验证要求
- 中考物理最后一课
- 2024年四川省凉山州“千名英才.智汇凉山”行动第二批引才395人历年(高频重点复习提升训练)共500题附带答案详解
评论
0/150
提交评论