Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

WEF cyber risk ranking: what should security teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Cybercrime and cyber insecurity entered the WEF Global Risks Report 2023 top 10, underscoring that digital disruption is now treated as a persistent business risk rather than a passing threat, according to INTIGRITI's analysis of the report. For practitioners, the signal is that resilience, identity control, and operational recovery must be governed as core risk-management capabilities, not separate security workstreams.

NHIMG editorial — based on content published by INTIGRITI: WEF Global Risks Report 2023 and cybersecurity implications

By the numbers:

Questions worth separating out

Q: What breaks when cyber risk is not treated as an identity governance issue?

A: Access sprawl becomes a resilience problem when organisations separate security controls from identity governance.

Q: Why do non-human identities matter in critical infrastructure risk planning?

A: Non-human identities often control the systems that keep infrastructure running, including APIs, service accounts, and automation tools.

Q: How can security teams know whether identity controls are actually reducing breach impact?

A: Look for evidence that suspicious accounts are contained fast, active sessions are terminated, and privileged access is limited to the smallest possible set of systems.

Practitioner guidance

  • Map identity dependencies into critical service recovery plans Document which human and non-human identities can alter, pause, or restore essential services, then test recovery paths against loss of those identities.
  • Review privileged access across infrastructure-facing accounts Identify accounts and tokens that can touch production, network, cloud, or operational systems.
  • Track non-human identities alongside human identity estates Include service accounts, APIs, certificates, and automation identities in the same inventory and review process as user identities.

What's in the full article

INTIGRITI's full article covers the report excerpts and contextual analysis this post intentionally leaves at a governance level:

  • The article's broader discussion of WEF's short-term and long-term risk framing for cybercrime, infrastructure, and technology dependence.
  • The specific examples it uses to connect cyber risk to smart cities, IoT networks, and critical services.
  • The surrounding commentary on how businesses should interpret cyber threats as a permanent condition rather than a short-lived spike.
  • The original article's links to related cybersecurity commentary and further reading.

👉 Read INTIGRITI's analysis of the WEF Global Risks Report 2023 and cybersecurity →

WEF cyber risk ranking: what should security teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Cyber risk has become an identity governance problem, not just a security category. The WEF framing is useful because it links operational dependence, digital trust, and systemic disruption. Once business processes and critical services rely on connected identities, access control quality directly shapes resilience. That is why IAM, PAM, and non-human identity governance belong in enterprise risk discussions, not only security operations. Practitioners should treat identity control as part of the organisation's continuity model.

A question worth separating out:

Q: Who is accountable when emergency access causes a service outage?

A: Accountability should sit with both the system owner and the access owner, because emergency access is a governance decision as much as an operational one. If access was granted without a clear approval path, session traceability, and review process, the organisation owns the failure, not just the individual who executed the change.

👉 Read our full editorial: WEF global risks and the cybersecurity governance gap



   
ReplyQuote
Share: