Elevating Cybersecurity 2025
Page 11 of 26 · WEF_Elevating_Cybersecurity_2025.pdf
National cybersecurity agencies and incident response centres
Responsibilities of the CISO to cybersecurity
agencies and incident response centres
–Share intelligence on vulnerabilities and threats
that are intercepted
–Develop a trusted relationship and open a
communication channel in case of an incidentResponsibilities of cybersecurity agencies and
incident response centres to the CISO
–Consult the organizations and industry when
developing guidance and frameworks for
cybersecurity
–Issue pragmatic cybersecurity frameworks,
policies and guidelines to help businesses
adopt robust security measures
–Assist the organization in mitigating and
recovering from cyber incidents through
coordination, technical support and
forensic analysis
Regulatory/standards bodies
Responsibilities of the CISO to regulatory/
standards bodies
–Develop a trusted relationship and open a
communication channel in case of an incidentResponsibilities of regulatory/standards bodies
to the CISO
–Set and enforce cybersecurity regulations (for
example, data protection laws, sector-specific
requirements)
–Oversee private-sector cybersecurity practices
to reduce risk and protect consumers
Audit firms
Responsibilities of the CISO to audit firms
–Present a clear and transparent overview
of the organization’s cybersecurity strategy,
governance model and control framework
–Provide an accurate overview of risks,
incidents or control weaknessesResponsibilities of audit firms to the CISO
–Evaluate the effectiveness of the organization’s
information security controls, policies and
procedures and provide unbiased insights
into risks
–Provide assurance to external and internal
stakeholders (for example, regulators, board,
customers) that the CISO’s security function is
effective and trustworthy
Cybersecurity peer groups
Responsibilities of the CISO to cybersecurity
peer groups
–Participate in the community by sharing best
practices and threat intelligenceResponsibilities of cybersecurity peer groups to
the CISO
–Provide support and mentoring as well
as share useful practices (for example,
benchmarking on security programmes,
incident response plans templates and
so forth)
Elevating Cybersecurity: Ensuring Strategic and Sustainable Impact for CISOs
11
Ask AI what this page says about a topic: