Search
Close this search box.
Search
Close this search box.

Sony’s Initial Decision to Give in to Terror Threats Has CEOs Up in Arms

Never has so inconsequential a film had such a major impact on international politics or business.

The lesson CEOs have drawn from the Sony incident is that the bullying and blackmail is merely the opening salvo of a much more serious conflict. As one leader said, “ I am thankful that this threat was aimed at an incidental industry—entertainment—that affects practically no one directly. What happens when an aerospace company, a bank, or a major electric utility is successfully hacked and their systems are wiped out? Our economy and the general public could be seriously compromised.”

“It’s one thing if a company’s email is hacked, it’s quite another when the company’s entire system goes down as it did with Sony.”

“Electric utility companies are much more vulnerable than, say, banks,” observes Tom Pettibone, CEO of  Reston, VA-based IT services firm Transition Partners. For example, many are still using Windows XP, which has a lot of holes where would-be attackers can readily penetrate. It’s one thing if a company’s email is hacked, it’s quite another when the company’s entire system goes down as it did with Sony,”  he says.

The global risk of cyberattacks is a real and growing threat, and could carry a whopping cost, according to a McKinsey & Company report on enterprise IT security implications. As a result, the price tag—the material effect of slowing the pace of technology and innovation due to a lack of cyber-resiliency—could be as high as $3 trillion by 2020, McKinsey says. The asymmetric effect of a small number of successful attackers, leading to tighter government restrictions, could mean that: “the world would capture less of the $10 trillion to $20 trillion available from big data, mobility and other innovations by 2020—the ultimate impact could be as much as $3 trillion in lost productivity and growth.”

Business’ vulnerability is by no means confined to large-cap companies. Many attacks involve mid-market and smaller businesses because their systems are less robust and typically more vulnerable. The effects can be devastating, leading to loss of livelihood and, in some cases, the entire business. A 2013 Verizon Data Breach Investigations Report found that 62% of breaches impacted smaller companies and that this number is likely undercounting the true volume, because it assumes organizations are fully aware when they are breached.

The vulnerability is accentuated by the “bring-your-own-device” era as employees access an increasing amount of a company’s business-critical applications from their personal mobile devices. Such devices sit outside the established security controls of most companies allowing cyber thieves easier access to data. Small business owners and operators understand that the impact of an embarrassing or costly data breach can mean much more—up to and including loss of livelihood or the entire business enterprise. The majority of attacks target small and medium-sized businesses because they are typically much more vulnerable than large enterprises, and the effects can be devastating.

McKinsey and the World Economic Forum conducted a survey in 2013 of 200 enterprises, tech vendors, and public sector agencies. Executives in the survey displayed “an emerging consensus” on what those models should be. Here are the seven cybersecurity best practices described in the report:

  1.  Prioritize information assets based on business risks.
  2.  Provide differentiated protection based on importance of assets.
  3.  Deeply integrate security into the technology environment to drive scalability.
  4.  Deploy active defenses to uncover attacks proactively.
  5.  Test continuously to improve incident responses.
  6.  Enlist frontline personnel to help understand the value of information assets.
  7.  Integrate cyber-resistance into enterprise-wide risk-management and governance processes.

As we head into 2015, a cutting-edge cybersecurity strategy must be on the top of every CEO’s to-do list.

McKinsey: Risk and responsibility in a hyperconnected world: Implications for enterprises

World Economic Forum: Risk and Responsibility in a Hyperconnected World

 


MORE LIKE THIS

  • Get the CEO Briefing

    Sign up today to get weekly access to the latest issues affecting CEOs in every industry
  • upcoming events

    Roundtable

    Strategic Planning Workshop

    1:00 - 5:00 pm

    Over 70% of Executives Surveyed Agree: Many Strategic Planning Efforts Lack Systematic Approach Tips for Enhancing Your Strategic Planning Process

    Executives expressed frustration with their current strategic planning process. Issues include:

    1. Lack of systematic approach (70%)
    2. Laundry lists without prioritization (68%)
    3. Decisions based on personalities rather than facts and information (65%)

     

    Steve Rutan and Denise Harrison have put together an afternoon workshop that will provide the tools you need to address these concerns.  They have worked with hundreds of executives to develop a systematic approach that will enable your team to make better decisions during strategic planning.  Steve and Denise will walk you through exercises for prioritizing your lists and steps that will reset and reinvigorate your process.  This will be a hands-on workshop that will enable you to think about your business as you use the tools that are being presented.  If you are ready for a Strategic Planning tune-up, select this workshop in your registration form.  The additional fee of $695 will be added to your total.

    To sign up, select this option in your registration form. Additional fee of $695 will be added to your total.

    New York, NY: ​​​Chief Executive's Corporate Citizenship Awards 2017

    Women in Leadership Seminar and Peer Discussion

    2:00 - 5:00 pm

    Female leaders face the same issues all leaders do, but they often face additional challenges too. In this peer session, we will facilitate a discussion of best practices and how to overcome common barriers to help women leaders be more effective within and outside their organizations. 

    Limited space available.

    To sign up, select this option in your registration form. Additional fee of $495 will be added to your total.

    Golf Outing

    10:30 - 5:00 pm
    General’s Retreat at Hermitage Golf Course
    Sponsored by UBS

    General’s Retreat, built in 1986 with architect Gary Roger Baird, has been voted the “Best Golf Course in Nashville” and is a “must play” when visiting the Nashville, Tennessee area. With the beautiful setting along the Cumberland River, golfers of all capabilities will thoroughly enjoy the golf, scenery and hospitality.

    The golf outing fee includes transportation to and from the hotel, greens/cart fees, use of practice facilities, and boxed lunch. The bus will leave the hotel at 10:30 am for a noon shotgun start and return to the hotel after the cocktail reception following the completion of the round.

    To sign up, select this option in your registration form. Additional fee of $295 will be added to your total.