Elevating Cybersecurity 2025

Page 11 of 26 · WEF_Elevating_Cybersecurity_2025.pdf

National cybersecurity agencies and incident response centres Responsibilities of the CISO to cybersecurity agencies and incident response centres –Share intelligence on vulnerabilities and threats that are intercepted –Develop a trusted relationship and open a communication channel in case of an incidentResponsibilities of cybersecurity agencies and incident response centres to the CISO –Consult the organizations and industry when developing guidance and frameworks for cybersecurity –Issue pragmatic cybersecurity frameworks, policies and guidelines to help businesses adopt robust security measures –Assist the organization in mitigating and recovering from cyber incidents through coordination, technical support and forensic analysis Regulatory/standards bodies Responsibilities of the CISO to regulatory/ standards bodies –Develop a trusted relationship and open a communication channel in case of an incidentResponsibilities of regulatory/standards bodies to the CISO –Set and enforce cybersecurity regulations (for example, data protection laws, sector-specific requirements) –Oversee private-sector cybersecurity practices to reduce risk and protect consumers Audit firms Responsibilities of the CISO to audit firms –Present a clear and transparent overview of the organization’s cybersecurity strategy, governance model and control framework –Provide an accurate overview of risks, incidents or control weaknessesResponsibilities of audit firms to the CISO –Evaluate the effectiveness of the organization’s information security controls, policies and procedures and provide unbiased insights into risks –Provide assurance to external and internal stakeholders (for example, regulators, board, customers) that the CISO’s security function is effective and trustworthy Cybersecurity peer groups Responsibilities of the CISO to cybersecurity peer groups –Participate in the community by sharing best practices and threat intelligenceResponsibilities of cybersecurity peer groups to the CISO –Provide support and mentoring as well as share useful practices (for example, benchmarking on security programmes, incident response plans templates and so forth) Elevating Cybersecurity: Ensuring Strategic and Sustainable Impact for CISOs 11
Ask AI what this page says about a topic: