by Brianna Crandall — March 8, 2017 — Cyberattack is once again the top threat perceived by businesses, according to research published today by the Business Continuity Institute (BCI) in association with BSI (British Standards Institution). A full 88% of organizations surveyed (out of 726 respondents from 79 countries) are either “extremely concerned” or “concerned” about the possibility of a cyberattack. The threat of a data breach remains in second place (81%), while unplanned information technology (IT) and telecommunications outage stays in third place (80%).
For the first time in the study’s six-year history, the threat of uncertainty around the introduction of new laws and regulations has entered the list of top ten business continuity concerns in the Horizon Scan Report.
These external events underscore the interconnected nature of risks and demonstrate the need for businesses to take them into account and plan accordingly.
This year’s global top ten threats to business continuity are:
- Cyberattack — same position as last year
- Data breach — same
- Unplanned IT and telecom outages — same
- Security incident — up 1
- Adverse weather — up 3
- Interruption to utility supply — same
- Act of terrorism — down 3
- Supply chain disruption — down 1
- Availability of key skills — same
- New laws or regulations — new entry
For the first time, the survey also asked which disruptions respondents had experienced during the previous year in order to understand what lies behind the worry. The results showed that nine of the top ten concerns also appeared in the top ten list of disruptions, with transport network disruption appearing at the expense of act of terrorism. Unplanned IT and telecom outages came in at number one, followed by interruption to utility supply and then cyberattack. Data breach came in at eighth place.
With the top four threats all showing an increase in level of concern, it is worrying that 14% of respondents will experience business continuity budget cuts over the next year, making them less likely to be able to respond effectively to these threats, points out the report.
Despite growing fears over the resilience of their organizations, the report records another fall in the use of long-term trend analysis to assess and understand threats, down 1% to 69% this year. Of those carrying out trend analysis, around a third of organizations (32%) do not use the results to inform their business continuity management programs.
David Thorp, executive director at the Business Continuity Institute, commented:
Given the diversity of the threats out there, it is absolutely essential to adopt agile and dynamic responses. Planning to recover from a data breach is very different from planning for the aftermath of a terrorist attack, and, as this year’s report highlights, the risk spectrum can be very broad. Malicious Internet actors, political shake-ups, and climate change are all amongst the main worries for societies around the world.
As always, the key takeaway should be that with challenges come opportunities. Change does not have to mean less favorable environments, but the landscape may be different. As organizations venture into uncharted territory now is the time to identify and undertake the measures that will increase resilience within your organization by ensuring that effective business continuity planning is in place.
Howard Kerr, chief executive at BSI, stated:
2016 continued to see high-profile businesses affected by cyberattack and disruption, so it’s not surprising to see it remains as the top threat to business. However, we remain concerned to see that businesses are still not fully utilizing the information available to them to identify and remedy weaknesses in their organizational resilience.
Ultimately, organizations must recognize that, while there is risk, and plenty of it, there is also opportunity. Taking advantage of this means that leaders can steer their businesses to not just survive, but thrive.
Globally there were some variations to the top three threats: In Belgium, act of terrorism was in third; in Central and Latin America, new laws or regulations featured in third place; and in Sub Saharan Africa, exchange rate volatility was third.
There was more variation when it came to actual disruptions, with adverse weather appearing in second place throughout North America, Asia and Australasia; while the loss of key employee featured in the top three throughout the Middle East and North Africa, Central and Latin America, and the United Kingdom.