WEF outlines three principles of cyber resilience

WEF outlines three principles of cyber resilience

The World Economic Forum (WEF) recently outlined its three principles of cyber resilience, which focus on governance, operating models and business outcomes. While cyber attacks such as ransomware are steeply increasing, it said, too few business focus mitigation efforts on key business activities. Instead, they deploy technologies to fix individual problems with IT systems. But…

The World Economic Forum (WEF) recently outlined its three principles of cyber resilience, which focus on governance, operating models and business outcomes.

While cyber attacks such as ransomware are steeply increasing, it said, too few business focus mitigation efforts on key business activities. Instead, they deploy technologies to fix individual problems with IT systems.

But WEF said this approach was short-sighted. Businesses are more resilient against attack when they protect the underlying business functions that those systems are supposed to protect.

“No company has the resources to fix all cyber issues and not all fixes are equally important,” it said. “It is only by starting to identify activities that are important to a business, and understanding how attacks could disrupt them, that one could start to prioritise the process of risk mitigation.”

Three principles

“Three principles to help build a cyber resilient organisation” aims to help leaders embed cyber resilience in their businesses.

First, cyber resilience must be governed from the top. Too many leaders who are not technical experts delegate cyber defence because they think it is too complex. That is a mistake, WEF said.

In addition to taking responsibility, a dedicated cyber resilience officer needs to report directly to the board. In fact, boards should focus on which systems support critical activities, rather than approaching the problem through the lens of software vulnerabilities.

Balance

Second, leaders need to strike the right balance between defence and bounce-back capabilities. The business’ operating model must be cyber resilient at its core. That means cyber security should be embedded in everything from employee skills to change management programmes.

“It doesn’t have to be an onerous activity, but it is important that business leaders pay attention to the risk they are accepting,” WEF said.

Finally, business need to balance the risks between security and technological transformation. Cyber resilience must support these change programmes if the business is to achieve its return on investment in IT.

 





← Previous

IRM issues guidance for charities on embedding emerging risk management
The political, economic, sociological, technological, legal and environmental (PESTLE) context in which we live and…






Next →

Right to repair gathers pace
The right to repair movement that seeks to enable consumers to mend broken technologies is…

7 OCTOBER 2026

Key elements of a mature programme risk capability

Hosted by Vinay Shrivastava. Vinay's presentation will cover lessons he has learned over the course of his career. These insights will be shared using the principles of ISO31000 risk management.

Find out more

8 OCTOBER 2026

Pre-deployment agentic risk management

Delivered by Adam Grainger, the outcome of this session is to be able to support an agentic implementation with effective pre-deployment risk identification and mitigation.

Find out more

14 OCTOBER 2026

AI Transforming Enterprise Risk Management Activities

Risk management has changed considerably over the years, with new frameworks, standards and expectations shaping the way organisations manage risk. However, many of the day-to-day activities within Enterprise Risk Management (ERM) functions have remained much the same.

Find out more

Advertisement