top of page

World Economic Forum: Governing cyber resilience as an economic risk

18 hours ago
13 min read
  • Cybersecurity now conditions payments, production, public services and supply chains, but most institutions still govern it as a technical cost rather than an economic input.

  • The World Economic Forum’s October 2026 agenda argues the gap is one of conversion: recognition has not become measurement, capital allocation or financing.

  • The 2027 programme is deliberately institutional — a shared executive vocabulary, comparable resilience metrics, pricing cyber posture into finance, and funding for under-resourced environments — not a new global agency.




Governing the Shock


Published on 6 October 2026, the report is not another catalogue of threats. It is an argument about conversion. Digital systems already carry payments, production, public services and supply chains. Severe failures already spill across firms and borders. What has not kept pace, the Council says, is the way institutions govern, measure, value and finance that dependence. The priority it sets for 2027 is blunt: turn recognition into decisions.


The Council’s twenty members, co-chaired by Öykü Işık of Thunderbird School of Global Management and Sami Khoury, formerly the Canadian government’s senior official for cybersecurity, organized the 2025–2026 term into five streams: a common language, cyber as a value-creating opportunity, cyber as a global stabilizer, a sustainable finance mechanism, and a call to action aimed at institutions that already exist. The quantitative spine is the Survey on Cyber Language and Executive Decision-Making, fielded from 9 to 30 April 2026. Alongside it sit structured mini-cases from five sectors and five regions, thirteen expert interviews from January to March 2026, and a desk review of twenty-eight cyber and cyber-adjacent funds. Case outcomes were largely validated by the organizations themselves, not independently audited by the Council. They illustrate reported mechanisms. They are not a sample from which a return on security spend can be generalized.


Read with those caveats, it is still a sharper brief on the economics of resilience than the threat catalogues that usually circulate at this level. It sits beside the Forum’s Global Cybersecurity Outlook 2026, which tracked AI, geopolitics and fraud, and asks a different question: once leaders accept that cyber failure can move the real economy, why do budgets and supervisory tools still treat it as a technical cost?


The conversion gap


The survey draws the gap in four strokes. Forty-two percent of respondents recognized that cybersecurity has measurable effects on economic output, markets and supply chains. Only 9 percent said their institutions treat it as an economic stabilizer. More than half said cyber investment is driven primarily by crisis events. Only 8 percent cited demonstrated returns as the trigger. More than 60 percent reported communication breakdowns during high-stress incidents. Recognition is no longer the scarce commodity. Conversion is.



The pattern is a familiar board cycle: a near-miss produces a supplementary budget, a quiet year produces a cut. The report treats that as a failure of governance, not of awareness. United Kingdom government research cited in the paper puts the average significant cyberattack at nearly £195,000, about $250,000, and national losses at an estimated £14.7 billion, about $19.4 billion, a year. The International Monetary Fund had already warned that extreme cyber losses are several multiples of their 2017 levels and can transmit stress through service disruption, confidence shocks and contagion. None of this is news to a well-briefed risk committee. What has not happened is absorption into ordinary capital allocation.


The proposed remedy is deliberately unglamorous. The response does not require new institutions. It requires more deliberate use of the ones that already shape economic policy, financial stability and investment: finance ministries, central banks, prudential supervisors, infrastructure investors, multilateral lenders, and the political forums that convene their leaders. That is the report’s most important design choice. A call for a new global cyber agency would have been easier to applaud and easier to ignore. A call to insert cyber resilience into mandates that already exist is harder, because it names the people who can act this year.


Language is a control system


Pillar 1 treats vocabulary as a governance problem, not a communications problem. Cybersecurity grew up as a technical discipline and is still described in technical terms. Boards, ministers and investors are now expected to decide how much to invest, when to disclose and how to coordinate across borders. Seventy-five percent of respondents identified the gap between technical language and business impact as the dominant source of conflict across cyber frameworks. Nearly two-thirds deliberately avoid technical language in senior discussions. One in five avoids the word “cybersecurity” itself when speaking with peers and executives. Translation is already happening, informally, ahead of decisions. It is just happening badly, and under time pressure.


The cost shows up in incidents. Sixty-two percent said communication challenges had delayed or weakened their organization’s response; more than a third specifically identified language gaps in high-stress situations. One respondent from a critical-infrastructure organization described repeated attempts to brief the chief information officer in technical terms that failed to land, until the team reframed the same facts in business terms. A senior leader who cannot translate cyber risk into operational, legal or economic consequences cannot make a confident decision, and that delay is itself a loss.


The words leaders already reach for are more useful than a new lexicon.



In the survey, 77 percent used “resilience,” 61 percent “continuity,” 55 percent “trust,” 37 percent “economic risk” and 33 percent “stability.” Framework names, architectural acronyms and defence terminology did not feature in the same way. Those terms remain essential at the operational level. At the governance level they have to be translated into consequences, trade-offs and decisions. The Council is not asking for an invented dialect. It is asking for consistency around terms institutions already use, so that “resilience” in a risk-committee paper and “cyber resilience” in a security report refer to the same thing.


Two definitions need settling before the rest of the agenda can travel. Sixty-two percent said senior leaders confuse cyber risk, the potential for loss, with cyber resilience, the capacity to anticipate, withstand and recover. An organization can catalogue risk and still be unable to keep a critical function alive. Thirty-four percent flagged inconsistent definitions of critical infrastructure. The useful unit is a function or service, not a whole organization: designating entities both over-includes activities that could be lost for weeks and misses critical dependencies inside firms no framework names. The Council does not want one global definition. It wants shared criteria — substitutability, concentration, time to restore — that jurisdictions can apply to their own circumstances.


What leaders say they need once an incident is under way reinforces the same translation. Fifty-nine percent highlighted quantified economic impact, including costs, sectoral disruption and effects on national output. Fifty-five percent wanted clear recovery indicators, such as expected time to restore operations. Fifty-three percent wanted human-centred framing: consequences for people rather than systems. The common thread is not more technical detail. It is a usable account of exposure, recovery path and human consequence. Without that shared vocabulary, the later pillars fail in sequence. Valuation models cannot compare firms if the chief information security officer and the chief financial officer mean different things by resilience. Stability metrics cannot be aggregated if criticality means different things in neighbouring jurisdictions. Financing cannot be aligned if funders and recipients measure impact differently.


From a cost centre to productive capital


Pillar 2 tries to answer the question boards actually ask: what does the money buy, other than the absence of a headline? Thirty-nine percent named clear economic valuation models as the most significant unmet need for positioning cybersecurity as a strategic investment rather than a cost. The destination of those models is already specified. Sixty-seven percent want metrics tied to revenue and productivity, 58 percent to financial loss avoided, 50 percent to downtime reduction, and 48 percent to a risk-adjusted return such as cyber-adjusted return on investment. The vocabulary of finance is ready. The evidence base is not. The Forum has tried to thicken it through a Centre for Cyber Economics, launched with the Global Cybersecurity Forum. This report’s contribution is a set of structured cases, offered as mechanisms rather than as a league table of returns.



Four mechanisms emerge. The first is a shift from compliance spending to a risk-informed capital conversation. A state-owned investment holding company in the United Arab Emirates is the complianc

e-triggered version. A Dubai Electronic Security Center directive pushed cybersecurity from an audit checklist into capital allocation. Leadership now approves cloud-migration and identity investments on return and risk-reduction grounds rather than best practice alone. The clearest metric is a maximum two-hour downtime tolerance for a critical-system outage, a compliance threshold repurposed as a continuity commitment. Banco do Brasil illustrates the same discipline more structurally. Regulatory pressure and remote work during the pandemic pushed cybersecurity from IT into enterprise risk management. The distinctive change was organizational: the business units that own risk day to day and the independent risk function jointly defined a shared set of key risk indicators, expressed as financial loss and service disruption, and debated alongside other risks in senior committees. The bank estimates exposure reductions in the order of tens of millions in potential losses a year. That is the bank’s estimate, not an independent valuation.


The other three mechanisms are commercial rather than defensive. Ecosystem trust: Schneider Electric reports that independent certifications and transparency reporting shortened partner onboarding and cut duplicative third-party assessments over two to three years. Transformation that would otherwise fail its own business case: the UAE Ministry of Cabinet Affairs brought security into planning early enough to set conditions for cloud, data and AI before approval, and SwissPost judged that a zero-trust architecture was what made exiting its data centres viable, estimating recurring costs about CHF 9 million, or $11.2 million, lower. Governance as a multiplier: Absa created a board IT subcommittee for cyber risk and a dual reporting line for the security chief after Barclays reduced its stake; with executive backing, simulated phishing clicks fell from about 24 percent to below 10 percent and suspicious-email reporting rose from about 1 percent to above 20 percent. An Israeli bank, under Bank of Israel Directive 364, grew a champion network from zero to forty between 2022 and 2026. Technology did not move those numbers. Shared accountability did.



The lesson for boards and investors is less about adopting a single metric than about insisting that some translation discipline exists at all. Cyber capability, the Council argues, should be reported as an enabling input to value creation, not only as a cost or risk category, and should enter strategic planning, capital allocation and merger due diligence as a factor of production alongside human capital and physical infrastructure. The peer advice that follows points the same way across sectors: treat cyber as business risk in financial services, bring it into public-sector transformation at the design stage, engineer it into platforms as a product capability, and use external assurance as a trust credential in industrial and energy ecosystems.


When a firm-level failure becomes a macro shock


Pillar 3 makes the macroeconomic claim explicit. Digital systems now carry the routine operating load of the economy: payment clearing, public administration, production lines, and the records on which entitlements depend. Where those services have no offline substitute, continuity is no longer only a private operational concern. It is a condition of economic stability. The digital economy is estimated to account for roughly a quarter of global GDP, and is expected to generate more than two-thirds of new value creation over the next decade. Modelled effects of severe incidents on national output range from 0.2 percent to 2 percent of GDP in the year of the event, and econometric work has found a persistent drag on total factor productivity across high-income economies. Cyber posture, on this reading, is a determinant of economic performance rather than a subsidiary risk category.


Disruption reaches the wider economy through four channels, each anchored to an observable incident. Financial systems are the first: payment, settlement and market infrastructure, amplified by shared dependencies. When many institutions rely on the same cloud provider or clearing house, a single failure becomes correlated stress. The February 2024 ransomware attack on Change Healthcare caused widespread disruption across the US healthcare system and resulted in approximately $3.1 billion in costs and business-disruption impacts for UnitedHealth Group over 2024. The real economy and supply chains are the second channel, running through logistics, industrial control and manufacturing. The 2024 faulty update to CrowdStrike’s cloud-based security software, which produced a global IT outage, is the exhibit. Government services are the third: identity, welfare, tax and customs systems for which there is rarely an alternative provider. Trust and information integrity are the fourth. Compromises of data and public information systems reduce confidence in institutions and accelerate risk aversion, most sharply where governance is already fragile.


Senior leaders in the survey rank the same channels in almost the same order.



Sixty-one percent selected supplier and third-party disruption as a primary route. Fifty-nine percent selected public trust and societal stability. Fifty-four percent selected internal operational disruption. Forty-six percent selected sector-wide disruption. The prominence of the third-party route carries a governance implication the report does not soften: critical dependencies, including non-technology suppliers and shared service providers, require monitoring and credible substitution arrangements, not acknowledgement alone.


Understanding the channels is not the same as pricing them. The Council proposes six questions in the language those audiences already use: whether essential services stay available under stress; how wide the gap is between planned and proven recovery; how many critical functions rest on the same providers; what a severe incident would cost over a defined horizon; what economic value resilience investment has protected; and how cyber posture changes financing, insurance and market access. Boards and supervisors need the first two, ministries the concentration picture, insurers and finance chiefs the tail, investors and ratings agencies the cost of capital.


Measurement that records only damage avoided understates the investment case, because it counts what did not happen and omits what was created. Measurement that also captures value preserved and value enabled — a lower cost of capital, wider market access, a ratings uplift, cheaper insurance — lets cyber capability be appraised as productive capital. That is where this pillar meets the value mechanisms above.


Comparison across countries is the harder step. The Council proposes a benchmark scoring cyber capacity across countries and sectors on four dimensions: concentration of critical dependencies, preparedness capacity, demonstrated ability to sustain and recover essential services, and assurance of data integrity and transparency. It scores sectors alongside countries, because national aggregates conceal concentration in a single provider, and it weights demonstrated recovery above declared resilience, on the principle that a capability which has not been exercised has not been established. A pilot across two sectors and five countries would test whether the scoring travels. The working precedent is the Bank of England’s CBEST framework, in place since 2014, which moved cyber posture for systemically important UK financial institutions from a self-declared attribute to a supervised prudential category. The proposed benchmark applies that logic at country and sector level.


Cyber shocks do not land evenly. In frontier and developing markets, an incident that an advanced economy could absorb within hours can escalate into a national emergency. Dependence often concentrates on a single national payment switch, identity system or telecommunications provider; offline fallbacks are thinner; insurance penetration is below 10 percent; recovery doctrine is less established. Costa Rica’s 2022 ransomware campaign is the illustration: a declared national emergency and roughly two months of disruption to tax and customs. Preparedness financing in these markets is not only a development question. It reduces fragility in a system where exposure is shared across borders.


The financing problem is a classification problem


Even with a common language, a value case and decent measurement, the binding constraint the Council emphasizes is money, and it does not flow to where exposure is greatest. A review of twenty-eight funds suggests private and corporate philanthropy together contribute on the order of $100 million to $200 million a year to cybersecurity-specific causes. Government programmes — the US State and Local Cybersecurity Grant Program, the UK Integrated Security Fund, the EU Digital Europe Programme — have begun adding millions inside their own jurisdictions. Little of that reaches emerging economies, least-developed countries or civil society. Set against $885 billion given to charitable causes in 2023, or $580 billion that flowed into corporate AI investment in 2025, cyber philanthropy is a rounding error. The line the report uses is the right one: the AI engine is being scaled without funding the guardrails.



The proposed instrument is a Sustainable Cybersecurity Finance Mechanism, and it is carefully not a single new fund. It is a coordinated ecosystem of individual philanthropy, corporate giving, multilateral funds and pooled mechanisms. It should fund broad capabilities rather than programme silos, prefer multi-year allocations over one-off grants, and allow mixed funding, with cost recovery from capable users and subsidy for those who cannot pay. Capital will not flow to a risk it cannot price, so the mechanism also needs avoided-loss models, risk-adjusted return estimates, resilience accounting visible on balance sheets, and routine outcome measurement by recipients.


The most consequential recommendation may be the driest: reclassify cybersecurity from “military/defence” to “civil resilience” in the categorization systems used by the OECD, development-finance institutions and pension funds. The current misclassification, the Council argues, locks significant pools of capital out of the sector. Scope is bounded so the mechanism does not become a slush fund: cybersecurity as the primary objective; acceptance of the overlap with disinformation; civil resilience and victim-centred capacity-building rather than military applications; foundational capability ahead of compliance in digitally nascent regions; and global equity, political neutrality and differentiated contributions. The closing claim is systemic rather than charitable. The digital ecosystem will never be secure if many people and organizations cannot afford basic cybersecurity. Realizing the upside of AI depends on it.


Five moves by 2027


Senior leaders, the final pillar says, can no longer treat cybersecurity as a specialist concern delegated to technical teams. When the digital layer fails, the consequences appear as halted production, delayed public services, disrupted payments, supply-chain fragility, reduced trust and, in the most exposed economies, national instability. The obligation is to govern cyber resilience as economic resilience, through levers leaders already control.


The five moves follow directly. Adopt a common executive vocabulary, tested by whether a board paper states what is at risk, which services may fail, how long recovery will take, what value is exposed and who decides. Require value and recovery metrics in board and public-sector reporting, without waiting for a global standard; they need not be perfect, but they must be comparable and usable before a crisis. Price cyber posture into borrowing costs, premiums, ratings and market access, so boards no longer have to argue for security funding on its own terms. Finance preparedness in under-resourced environments as civil resilience rather than as defence, a reclassification that sits with the leaders who set funding mandates. And make cyber resilience a standing item for finance ministries, central banks, prudential supervisors and international financial institutions, so attention does not rise only after an incident and recede before the next.

The closing line is a choice, not a forecast. Otherwise 2027 is another year of reactive spending after preventable disruption. Cyber resilience becomes a foundation of economic stability only when senior leaders choose to govern it that way.


What the agenda leaves open


Three limits should travel with the recommendations. The survey is a perception study of 110 self-selected respondents, weighted toward Latin America and the Caribbean. It is evidence of how a particular senior cohort talks and decides. It is not a global census, and a reader in Frankfurt or Singapore should not treat 9 percent or 42 percent as a world figure. The cases are self-reported and mostly self-validated. SwissPost’s cost estimate, Banco do Brasil’s loss reduction and Schneider Electric’s onboarding gains are useful as mechanisms. They are not yet a basis for a standard cyber-adjusted return. The financing estimate of $100–200 million a year comes from a mapping whose coverage is strongest for North America, the European Union and the United Kingdom, with some fund sizes approximate or bundled with adjacent programmes. The order of magnitude is the claim that survives.


The political gap is the one the report names and does not fill. There is no standing senior constituency that owns the agenda. Putting cyber resilience on financial-stability agendas is the proposed substitute, and it works only if finance ministers accept digital dependence as inside their remit. Pricing posture into the cost of capital likewise assumes that ratings agencies and insurers can observe recovery credibility and concentration. Today they mostly cannot. Measurement is not a technical annex. It is the condition for the pricing pillar.


Still, the central distinction holds. The inflection point is not the arrival of a new class of attack. It is the moment at which the economic consequences of digital failure are widely recognized and the instruments for governing them are not. Closing that gap by 2027 does not require leaders to become technologists. It requires them to govern dependence in the language, the metrics and the forums they already trust — and to pay for resilience in the places where a single payment switch or a single identity system is the economy’s single point of failure.

Comments


connexion_panel_edited.jpg
CXO_8-in-1.png
subscribe_button.png

​

Disclaimer: The "Industry Events" section in Inno-Thought website serves as a platform for event organizers and vendors to list their events for free. Ho Hon Asia reserves the right, at its discretion, to not proceed with publication/posting at any time or to remove the content following publication.

 

By providing your email address and submitting this form, you agree to receive updates about the event listed, including schedule changes, reminders, and important information.

 

The event information contained in the listing above is for reference only. While we have made every attempt to ensure that the info has been obtained from reliable sources, we are not responsible for any errors or omissions, or for the results obtained from the use of this info. In no event will Ho Hon Asia Limited, its related partnerships or corporations, or the partners, agents or employees thereof be liable to you or anyone else for any decision made or action taken in reliance on the information in this site or for any consequential, special or similar damages, even if advised of the possibility of such damages.

 

Information subject to change; check official sources. The Organisers reserve the right to modify the Event program, schedule, speakers, and activities without prior notice.

 

Also, the event organizers reserve the right to accept or reject any registration application at its sole discretion, without providing reasons or explanation. Submission of a registration does not guarantee participation in the event.

​​

2026 @ Inno-Thought and its affiliates. All rights reserved.

bottom of page