• About
  • Subscribe
  • Contact
Monday, May 12, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Resources Blogs

How do CIOs prepare smart energy systems for a secure future?

Jeremy Pizzala by Jeremy Pizzala
November 22, 2023
How do CIOs prepare smart energy systems for a secure future?

Photo by Anete Lusina: https://www.pexels.com/photo/unrecognizable-woman-demonstrating-light-bulb-in-hands-4792509/

Share on FacebookShare on Twitter

Our complex technology ecosystems are an increasing headache for all cybersecurity specialists. Cybercrime is now in the World Economic Forum’s Top 10 rankings of the most severe global risks over the next decade. The global cost of cybercrime is expected to top US$8 trillion in 2023.

But for the energy sector, the two-way flow of energy and information between renewable generators and batteries, solar rooftops and the grid, and a host of other connections, presents an enormous and exponentially increasing attack surface.

That “host of other connections” is particularly important. The global Internet of Things (IoT) market in the energy sector is expected to surpass US$700 billion by 2031, but around nine in 10 cybersecurity professionals say unsecured IoT devices are putting their organizations at risk of cyberattacks and data breaches.

Without smart technology, we are unlikely to achieve our global net-zero goals. But without a clear strategy to address cyber risk, energy companies cannot unlock the opportunities of smart technology.

Building a case for investment

If you’re not sure how to proceed, you are not alone. Earlier this year, EY teams asked 500 global cybersecurity leaders, nearly a quarter of those in Asia-Pacific countries, how they were navigating the complex cybersecurity landscape. Just one in five considered their cybersecurity effective today and well-positioned for tomorrow.

The EY 2023 Global Cybersecurity Leadership Insights Study revealed it takes 79% of respondents six months or longer to detect and respond to a cybersecurity incident.

We also found companies aren’t investing enough in their cyber defences, especially in Asia-Pacific. Cybersecurity budgets were a concern for 44% of Asia-Pacific respondents compared to 36% globally.

Related:  Standard Foods deploys Nutanix’s HCI technology

How do CIOs in the energy sector build an investment case? How do they create a compelling story around cybersecurity when the infrastructure is invisible, and the measure of cybersecurity success is “nothing happened”?

Speaking the language of business

As part of our research, and with the help of statistical modelling, we isolated the organizations, including those in the energy sector, with the most effective cybersecurity and identified several key characteristics they shared. We call this group “secure creators” because they have fewer cyber incidents, are quicker to detect and respond when they do, and have translated cybersecurity into a value creator rather than an inhibitor.

Secure creators behave (see Figure 1) differently in three specific ways. They are quick to adopt emerging technology and use automation to streamline processes. They have specific strategies to manage complex attack surfaces. And they build bridges across their organization – the C-suite, the cybersecurity team, and the broader workforce – by speaking the language of business.

Figure 1: Secure creators are more focused on technologies that enable automation

Source: EY 2023

The most successful CIOs can tell a story that resonates with their business in terms of risk buydown, business impact, and value creation. We have seen some companies build actuarial models to quantify the risks of underinvestment.

If a threat materializes, what is the dollar impact of energy networks and systems going offline? How does that translate into lost customers, brand damage, regulatory fines, or lower transaction revenue?

From value defender to value creator

In the energy sector, the missed opportunity is far more than money – it is, potentially, safeguarding the future of the planet.

Related:  Microsoft gets cybersecurity boost from Sophos and Veeam

Done well, cybersecurity is not just about value protection. It is also about value creation.

What does this look like? Our research is clear. Secure creators move faster on the digital journey because their cybersecurity specialists are there from the beginning of every project.

Rather than retrofitting security tools around existing systems or ticking off items from compliance checklists, cybersecurity is embedded into every new initiative from the outset. We call this “Security by Design” – and this approach builds trust, which in turn creates new value.

This new value may come in the form of stronger relationships with customers, with new partnerships, joint ventures or participation in ecosystems, or through new products or services. Most valuable of all, secure energy companies will support the world’s transition to a zero-emissions future.

Tags: EYsmart energyvalue creator
Jeremy Pizzala

Jeremy Pizzala

Jeremy Pizzala is EY’s Asia-Pacific Cybersecurity Consulting Leader. He has 30 years’ experience in Consulting, Outsourcing and Business Transformation and has helped clients across the banking, capital markets and insurance sectors implement large scale technology led transformation. Pizzala has recently focused on helping clients embed Cloud, Cybersecurity and Application modernization as pillars of their digital transformation. He has also developed novel solutions leveraging quantitative modelling techniques to help clients get a firmer grip on their potential cyber economic losses and the associated responses. Pizzala has in-house banking experience gained from working in a leading regional bank for 5 plus years. He has diverse international experience, having lived and worked in locations including Hong Kong, London and Sydney.

No Result
View All Result

Recent Posts

  • From endpoint defence to supply chain security
  • Legacy systems may be sabotaging bank's cyber resilience posture
  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl