Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - World Economic Forum’s Partnering for Cyber Resilience
Articles

World Economic Forum’s Partnering for Cyber Resilience

ISBuzz TeamBy ISBuzz TeamJuly 7, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
World Economic Forum’s Partnering for Cyber Resilience
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Introduction

Partnering for Cyber Resilience was compiled by the World Economic Forum’s Partnering for Cyber Resilience ( the complete paper can be found here).

This organization and its current initiative aim to establish awareness of cyber risk and to build commitment regarding the need for more rigorous approaches to cyber risk mitigation. The initiative started at the 2011 World Economic Forum Annual Meeting in Davos, Switzerland. Early efforts included raising awareness through workshops and introductory publications. Since 2011, the initiative has managed to grow immensely by gathering more than 100 signatories to focus on ways to assess the impact of and exposure to cyber threats. Some of the notable names among these signatories include: Francis Bouchard (Group Head of Government and Industry Affairs, Zurich Insurance), Andres Ruzo (CEO, Link America), Jan Verplancke (Director, Chief Information Officer and Group Head, Technology and Operations, Standard Chartered Bank), Thom Mason (Laboratory Director Oak Ridge National Lab), Brian Behlendorf (Managing Director, Mithril Capital Management), Preston McAfee (Chief Economist, Microsoft). The following is a summary of the report, highlighting the values of the initiative and explanation of the framework.

Partnering for Cyber Resilience Introduction

The digitization of today’s world, which includes the convergence of web, social, mobile and the Internet of Things has promoted the notion of sharing data. However, this modern trend has not focused adequately enough on securing all this digital data. As firms continue to grow their cyber capabilities – they raise the risk of their cyber vulnerabilities. The challenge – how to protect against targeted threats without disrupting business innovation or hindering growth? The solution – develop a framework than can model and quantify the impact and risk of cyber threats. A solution that is being referred to as The Cyber Value-at-risk concept. This solution (or framework) seeks to unify: technical, behavioral and economic factors from both internal (enterprise) and external (systemic) perspectives. By doing so, the framework will eventually be able to provide organizations with a somewhat-holistic approach to dealing with cyber threats while minimizing the compromise it has on business activities.

In order for organization to make sound and informed decisions, they must have a way to quantify cyber risk. The Cyber value-at-risk framework helps them do so, and it does that by following a three-folded approach.

  • Understand the key cyber risk drivers (or components) required for modelling cyber risks.
  • Understand the dependencies between these components that can be embedded in a quantification model.
  • Understand ways to incorporate cyber risk quantification into enterprise risk management.

By following this three-folded approach, organizations will set themselves up to successfully quantify the risk of cyber-attacks.

However, an organization must also understand the key components identified in the cyber value-at-risk model concept. The following three components help one understand the goal of cyber value-at-risk – to standardize and unify different factors into a single normal distribution that can quantify the value at risk in case of a cyberattack.

Vulnerability – This component focuses on how vulnerable an organization is. It is further broken down into: existing vulnerabilities, Maturity level of defending systems and the number of successful breaches. These three sub-components help us understand the range of vulnerability within an organization. It ranges from number of security updates, to the number of unpatched vulnerabilities to the success rate of compromises of machines.

Assets – Arguably the core of the entire model but the organizations assets must be evaluated. There are two types of assets that the framework takes into consideration for evaluation, those being: Tangible and Intangible assets. This is considered by many as the core of the entire model because the assets of an organization is what is sought after by an attacker. There for, understanding and evaluating the current assets of an organization is critical for understanding and quantifying the model.

Profile of Attacker – The last component of the model takes into consideration the attacker themselves. This tries to identity the type of attacker, the attack method and the motivation behind an attack. This is a crucial input in the cyber value-at-risk model as it helps us understand the profile of the adversaries targeting valuable assets.

After taking into consideration these three components and following the three-folded approach, one can have a clearer understanding of the cyber value-at-risk model. This model, as stated earlier, is intending to help an organization make more informed decision by quantifying their risk of a cyberattack. As any model, it is only successful when implemented and when a culture change occurs within an organization to adopt it. Successful cyber risk includes organization leadership, cyber life-cycle process management, and solution life-cycle implementation management. As such, further specifying and promoting cyber value-at-risk as a vehicle for global cyber resilience sustainability would benefit organizations and global stakeholders and support the creation of a more resilient cyber ecosystem.

Conclusion

As mentioned previously, the World Economic Forum’s Partnering for Cyber Resilience has managed to grow rapidly in the last couple of years. This latest publication is just another step towards achieving their goal of establishing awareness for cyber risk. As this initiative gains more and more momentum we will begin to see more publications regarding cyber resilience and potentially a more advanced version of the cyber value-at-risk framework. With over 100 signatories include key figures in the cyber world, we should not be surprised with the value this organization is bringing to the cyber world and their ability to really create awareness and change for cyber risk.

[su_box title=”About Cytegic” style=”noise” box_color=”#336588″]

Cy-te-gic /pronounced: sʌɪ-ˈtē-jik/ adjective: A plan of action or strategy designed to achieve a long-term and overall successful Cyber Security Posture Optimization – “That firm made a wise Cytegic decision”.

Cytegic develops a full suite of cyber management and decision-support products that enable to monitor, measure and manage organizational cyber-security resources.

Cytegic helps organization to identify threat trends, assess organizational readiness, and optimize resource allocation to mitigate risk for business assets.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}