Skip to Content
  • オフィス

    オフィス

    北米・南米
    • Atlanta
    • Austin
    • Bogota
    • Boston
    • Buenos Aires
    • Chicago
    • Dallas
    • Denver
    • Houston
    • Los Angeles
    • Mexico City
    • Minneapolis
    • Monterrey
    • Montreal
    • New York
    • Rio de Janeiro
    • San Francisco
    • Santiago
    • São Paulo
    • Seattle
    • Silicon Valley
    • Toronto
    • Washington, DC
    ヨーロッパ・中東・アフリカ
    • Amsterdam
    • Athens
    • Berlin
    • Brussels
    • Copenhagen
    • Doha
    • Dubai
    • Dusseldorf
    • Frankfurt
    • Helsinki
    • Istanbul
    • Johannesburg
    • Kyiv
    • Lisbon
    • London
    • Madrid
    • Milan
    • Munich
    • Oslo
    • Paris
    • Riyadh
    • Rome
    • Stockholm
    • Vienna
    • Warsaw
    • Zurich
    アジア・オーストラリア
    • Bangkok
    • Beijing
    • Bengaluru
    • Brisbane
    • Ho Chi Minh City
    • Hong Kong
    • Jakarta
    • Kuala Lumpur
    • Manila
    • Melbourne
    • Mumbai
    • New Delhi
    • Perth
    • Shanghai
    • Singapore
    • Sydney
    • Tokyo
    全てのオフィス
  • アルムナイ
  • メディア
  • お問い合わせ
  • 東京オフィス
  • Japan | 日本語

    地域と言語を選択

    グローバル
    • Global (English)
    北米・南米
    • Brazil (Português)
    • Argentina (Español)
    • Canada (Français)
    • Chile (Español)
    • Colombia (Español)
    ヨーロッパ・中東・アフリカ
    • France (Français)
    • DACH Region (Deutsch)
    • Italy (Italiano)
    • Spain (Español)
    • Greece (Elliniká)
    アジア・オーストラリア
    • China (中文版)
    • Korea (한국어)
    • Japan (日本語)
  • Saved items (0)
    Saved items (0)

    You have no saved items.

    後で閲読、共有できるようにするためにブックマークしてください

    Explore Bain Insights
  • 業界別プラクティス
    メインメニュー

    業界別プラクティス

    • 航空宇宙、防衛、政府関連
    • 農業
    • 化学製品
    • インフラ、建設
    • 消費財
    • 金融サービス
    • ヘルスケア
    • 産業機械、設備
    • メディア、エンターテインメント
    • 金属
    • 採掘・鉱業
    • 石油、ガス
    • 紙、パッケージ
    • プライベートエクイティ
    • 公共、社会セクター
    • 小売
    • テクノロジー
    • 通信
    • 交通
    • 観光産業
    • 公益事業、再生可能エネルギー
  • 機能別プラクティス
    メインメニュー

    機能別プラクティス

    • カスタマー・エクスペリエンス
    • サステイナビリティ、 社会貢献
    • Innovation
    • 企業買収、合併 (M&A)
    • オペレーション
    • 組織
    • プライベートエクイティ
    • マーケティング・営業
    • 戦略
    • アドバンスド・アナリティクス
    • Technology
    • フルポテンシャル・トランスフォーメーション
  • Digital
  • 知見/レポート
  • ベイン・アンド・カンパニーについて
    メインメニュー

    ベイン・アンド・カンパニーについて

    • ベインの信条
    • 活動内容
    • 社員とリーダーシップ
    • プレス・メディア情報
    • クライアントの結果
    • 受賞歴
    • パートナーシップを結んでいる団体
    Further: Our global responsibility
    • ダイバーシティ
    • 社会貢献
    • サステイナビリティへの取り組み
    • 世界経済フォーラム(WEF)
    Learn more about Further
  • キャリア
    メインメニュー

    キャリア

    • ベインで働く
      キャリア
      ベインで働く
      • Find Your Place
      • ベインで活躍する機会
      • ベインのチーム体制
      • 学生向けページ
      • インターンシップ
      • 採用イベント
    • ベインでの体験
      キャリア
      ベインでの体験
      • Blog: Inside Bain
      • キャリアストーリー
      • 社員紹介
      • Where We Work
      • 成長を後押しするサポート体制
      • アフィニティ・グループ
      • 福利厚生
    • Impact Stories
    • 採用情報
      キャリア
      採用情報
      • 採用プロセス
      • 面接内容
    FIND JOBS
  • オフィス
    メインメニュー

    オフィス

    • 北米・南米
      オフィス
      北米・南米
      • Atlanta
      • Austin
      • Bogota
      • Boston
      • Buenos Aires
      • Chicago
      • Dallas
      • Denver
      • Houston
      • Los Angeles
      • Mexico City
      • Minneapolis
      • Monterrey
      • Montreal
      • New York
      • Rio de Janeiro
      • San Francisco
      • Santiago
      • São Paulo
      • Seattle
      • Silicon Valley
      • Toronto
      • Washington, DC
    • ヨーロッパ・中東・アフリカ
      オフィス
      ヨーロッパ・中東・アフリカ
      • Amsterdam
      • Athens
      • Berlin
      • Brussels
      • Copenhagen
      • Doha
      • Dubai
      • Dusseldorf
      • Frankfurt
      • Helsinki
      • Istanbul
      • Johannesburg
      • Kyiv
      • Lisbon
      • London
      • Madrid
      • Milan
      • Munich
      • Oslo
      • Paris
      • Riyadh
      • Rome
      • Stockholm
      • Vienna
      • Warsaw
      • Zurich
    • アジア・オーストラリア
      オフィス
      アジア・オーストラリア
      • Bangkok
      • Beijing
      • Bengaluru
      • Brisbane
      • Ho Chi Minh City
      • Hong Kong
      • Jakarta
      • Kuala Lumpur
      • Manila
      • Melbourne
      • Mumbai
      • New Delhi
      • Perth
      • Shanghai
      • Singapore
      • Sydney
      • Tokyo
    全てのオフィス
  • アルムナイ
  • メディア
  • お問い合わせ
  • 東京オフィス
  • Japan | 日本語
    メインメニュー

    地域と言語を選択

    • グローバル
      地域と言語を選択
      グローバル
      • Global (English)
    • 北米・南米
      地域と言語を選択
      北米・南米
      • Brazil (Português)
      • Argentina (Español)
      • Canada (Français)
      • Chile (Español)
      • Colombia (Español)
    • ヨーロッパ・中東・アフリカ
      地域と言語を選択
      ヨーロッパ・中東・アフリカ
      • France (Français)
      • DACH Region (Deutsch)
      • Italy (Italiano)
      • Spain (Español)
      • Greece (Elliniká)
    • アジア・オーストラリア
      地域と言語を選択
      アジア・オーストラリア
      • China (中文版)
      • Korea (한국어)
      • Japan (日本語)
  • Saved items  (0)
    メインメニュー
    Saved items (0)

    You have no saved items.

    後で閲読、共有できるようにするためにブックマークしてください

    Explore Bain Insights
  • 業界別プラクティス
    • 業界別プラクティス

      • 航空宇宙、防衛、政府関連
      • 農業
      • 化学製品
      • インフラ、建設
      • 消費財
      • 金融サービス
      • ヘルスケア
      • 産業機械、設備
      • メディア、エンターテインメント
      • 金属
      • 採掘・鉱業
      • 石油、ガス
      • 紙、パッケージ
      • プライベートエクイティ
      • 公共、社会セクター
      • 小売
      • テクノロジー
      • 通信
      • 交通
      • 観光産業
      • 公益事業、再生可能エネルギー
  • 機能別プラクティス
    • 機能別プラクティス

      • カスタマー・エクスペリエンス
      • サステイナビリティ、 社会貢献
      • Innovation
      • 企業買収、合併 (M&A)
      • オペレーション
      • 組織
      • プライベートエクイティ
      • マーケティング・営業
      • 戦略
      • アドバンスド・アナリティクス
      • Technology
      • フルポテンシャル・トランスフォーメーション
  • Digital
  • 知見/レポート
  • ベイン・アンド・カンパニーについて
    • ベイン・アンド・カンパニーについて

      • ベインの信条
      • 活動内容
      • 社員とリーダーシップ
      • プレス・メディア情報
      • クライアントの結果
      • 受賞歴
      • パートナーシップを結んでいる団体
      Further: Our global responsibility
      • ダイバーシティ
      • 社会貢献
      • サステイナビリティへの取り組み
      • 世界経済フォーラム(WEF)
      Learn more about Further
  • キャリア
    人気検索キーワード
    • デジタル
    • 戦略
    前回の検索
      最近訪れたページ

      Content added to saved items

      Saved items (0)

      Removed from saved items

      Saved items (0)

      論説

      Building Strategic Cybersecurity Capabilities After the Invasion of Ukraine

      Building Strategic Cybersecurity Capabilities After the Invasion of Ukraine

      The war has underscored the need for companies to catch up with best practices—and then go further.

      著者:Frank Ford, Syed Ali, and Mark Leggate

      • min read
      }

      論説

      Building Strategic Cybersecurity Capabilities After the Invasion of Ukraine
      en
      概要
      • Amid warnings of increased malicious activity from Russia-linked groups, companies must swiftly get the cybersecurity basics right and avoid underspending on this critical function.
      • Companies with direct-but-dormant exposure to Russia face additional complications, while all executive teams will have to be on their guard against intellectual property theft.
      • The most resilient businesses will go beyond checklist-focused implementation of industry frameworks, nurturing strategic capabilities that evolve with shifting cyber threats.

      Cybersecurity is increasingly seen as risk No. 1 by large businesses—and with good reason. Even before the Russian invasion of Ukraine escalated the threat posed by hackers, cybercrime was costing the world an estimated $6 trillion annually according to Cybersecurity Ventures, through malign actions such as ransomware attacks, data destruction, embezzlement, and theft of intellectual property.

      By their own admission, many companies aren’t ready to contain this rising threat. When we surveyed executives on the topic, only 43% felt that their company followed cybersecurity best practices. Yet even that lowly figure looks like an overestimate. Deeper analysis of our survey sample showed that only about 24% actually met the best practice threshold. On a cybersecurity maturity scale of 1–5, a typical company is likely to rate only 1.5–2.5: way too low.

      With the heightened threat unlikely to ease soon, many companies need to refocus on getting the cybersecurity basics right. However, a truly strategic response to today’s dangers will require much more than a tactical alignment with industry norms. Over the coming months, the most resilient companies will also build and refine the capabilities needed to keep improving their defenses against the evolving situation in Russia and Ukraine—and against fresh threats yet to emerge.

      First things first: Get the basics right

      Ukraine-related cybersecurity incidents have been numerous both before and during the invasion, including distributed denial-of-service attacks, data-wiping malware, and website defacement. According to Microsoft, sustained pre-invasion cyber operations against Ukraine by groups aligned with Russia began as early as March 2021, ahead of intensifying activity that included more than 230 observed cyberattacks in Ukraine from December 2021 to March 2022.

      The impact of the hostile activity has been international. For instance, when a satellite-based Internet service suffered a cyberattack subsequently blamed on Russia, the outage hit tens of thousands of customers across Europe, not just Ukraine, and also affected German wind turbines. More than 90% of Russia-based attacks observed in Microsoft’s online services in 2021 were aimed at NATO member states, particularly the US, the UK, Norway, Germany, and Turkey.

      More online attacks are expected to follow. The US and other countries have warned companies inside and outside the conflict zone to brace themselves for increased malicious cyber activity from Russia-linked groups, in retaliation for sanctions and international support for Ukraine. The European Union said cyberattacks against Ukraine “could spill over into other countries and cause systemic effects, putting the security of Europe’s citizens at risk.”

      In response, companies should understand and swiftly act on government advisories. In the US, that includes communications from the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA). Companies outside the US should look to the local equivalents, many of which have been involved in cross-border cooperation.

      The absence of critical security patches is at the root of many breaches. As well as rigorously checking that patches are applied in a timely fashion, companies need to ensure that employees (particularly the high-value targets at the top of the organization) know how to identify and avoid malware-laced emails and other threats.

      Other basic hygiene measures include enforcing multifactor authentication, conducting extensive vulnerability scans, and instigating a general hardening of the technology environment (for instance, by shutting down unneeded services or ports).

      Gauging the right level of spending and investment in cybersecurity is critical—a challenge that includes ensuring that there are enough skilled cybersecurity professionals on the payroll. Our research and experience show many companies underinvest significantly (see Figure 1), which leaves them underprotected and prone to a range of issues, such as incomplete or outdated cyber-protection technology and inadequate training for both cyber specialists and general employees.

      Figure 1
      Underspending and understaffing are hallmarks of a business with low cybersecurity maturity—and higher cybersecurity risk
      Underspending and understaffing are hallmarks of a business with low cybersecurity maturity—and higher cybersecurity risk
      Underspending and understaffing are hallmarks of a business with low cybersecurity maturity—and higher cybersecurity risk

      Amid all this defensive preparation, there should be an understanding that digital assets will be breached at some point, and that business continuity plans will need to be activated so that critical services can continue. That means ensuring that incident response playbooks are fit for purpose and tested.

      Complications for directly exposed companies

      Getting the basics right will be different for companies that still have direct exposure to Russia, including multinationals that have continued to pay local employees after halting operations. This kind of residual involvement is likely to create cybersecurity complications beyond the obvious risk of direct attacks by hacktivists and other disruptive actors.

      For instance, operationally inactive workers still on the payroll may retain access to company laptops. When it comes to rolling out updates to those computers, employers will need to balance the need to remain protected with the need to observe sanctions. Information-sharing policies may also require modification.

      If the Ukraine war stretches on for many months or even years, accompanied by a continuation of sanctions, all companies will need to be on their guard against an increased risk of intellectual property theft, particularly in sectors such as technology, defense, and financial services. Lingering sanctions against Russia could also encourage ransomware attacks, making it particularly vital to heighten oversight of vectors commonly used by ransomware, such as remote desktop sessions.

      How to go beyond the basics

      Industry frameworks such as NIST and ISO 27002 are an essential building block of cybersecurity. But to protect themselves fully amid such global instability, companies need to go beyond checklist-focused implementation of the best practices enshrined in these frameworks.  

      For one thing, the guidance in frameworks is often control oriented and high level; the large amount of room they leave for interpretation makes good cybersecurity hard to define. It doesn’t help that events often move fast on the ground while frameworks are updated infrequently. Nor can frameworks give much guidance on the complex trade-offs that management teams must weigh, such as the right balance between organizational speed and security.

      Many leading companies are seeking greater long-term resilience by also focusing on building strategic cybersecurity capabilities. This holistic approach recognizes that companies need sophisticated, self-evolving capabilities to effectively manage complex and quickly changing cybersecurity risk. 

      A good example of what key capabilities look like in practice can be found in the management of third-party cybersecurity risk in the supply chain, which came to the fore early on in the Russian destabilization of Ukraine. (Microsoft observed supply chain vendors in Ukraine and abroad being targeted in mid-2021.) This is a complex area, with large companies typically having thousands of suppliers. These third parties can hold up supply chains if a cyberattack leaves them unable to operate—and they can also propagate the same issues to their customers.

      Tackling this area of risk successfully requires that companies:

      • identify and classify third parties based on the cybersecurity risk posed and the likely impact (both direct and supply chain related);
      • assess third parties both when they are first selected and on an ongoing basis—with in-house teams or through a new breed of external risk assessment service; and
      • reduce risk to an acceptable level through measures such as informal persuasion, contract stipulations, additional controls, and supply chain diversification to boost continuity.

      This is complicated to do reliably and at scale, which is why many companies end up living with large but unquantified levels of cybersecurity risk. Simply put, there is no shortcut around building the capabilities needed to manage this area of risk effectively. But companies often have more options at their disposal than they realize.

      When one consumer packaged goods company systematically tackled the risk presented by third parties, it uncovered a host of practical ways to strengthen its protection. These included improving contractual language, updating its formal policy on cybersecurity requirements for suppliers, clarifying which suppliers were most important to the business, and implementing risk controls and risk mitigation measures such as tighter third-party access to company systems.

      The effort and investment required to persuade suppliers to improve their cybersecurity can also lead to broader benefits. For instance, measures taken to mitigate third-party cybersecurity disruption risk (such as boosting inventory of essential manufacturing parts in case of a disabling cyberattack on a supplier) can contribute to a companywide push to enhance operational resilience.

      Going beyond the basics is essential if companies are to protect themselves in these hyperconnected and unstable times. Building strong strategic cybersecurity capabilities is the answer.

      The authors would like to thank Salman Faiz for his contribution to this brief.

      著者
      • Headshot of Frank Ford
        Frank Ford
        パートナー, London
      • Headshot of Syed Ali
        Syed Ali
        パートナー, Houston
      • Headshot of Mark Leggate
        Mark Leggate
        パートナー, London
      関連業種
      • Cybersecurity
      関連するコンサルティングサービス
      • Digital
      • IT
      CIO Insights
      Quantum Computing Moves from Theoretical to Inevitable

      Quantum will likely become part of a mosaic, working with classical computing to solve big problems.

      詳細
      CIO Insights
      Want More Out of Your AI Investments? Think People First

      To unlock AI’s exponential productivity potential, companies must modernize workflow and workforce in tandem.

      詳細
      Digital
      Reimagining Merchandising in the Era of Agentic AI

      The future of merchandising is not better analysis, but faster, smarter execution—and agentic AI is what makes that possible.

      詳細
      CIO Insights
      Life Sciences’ AI Momentum Requires a Workforce Redesign

      AI scalers aren't waiting for new talent—they're building it.

      詳細
      Cybersecurity
      Generative AI and Cybersecurity: Strengthening Both Defenses and Threats

      Breakthroughs in technologies built on large language models will accelerate the arms race between hackers and companies.

      詳細
      First published in 6月 2022
      Tags
      • CIO Insights
      • Cybersecurity
      • Digital
      • IT
      • Resilience amid Global Crisis

      クライアント支援事例

      Digital A European Banking Giant Rises to the Fintech Challenge

      ケーススタディを見る

      Digital A Strategic Separation Enables New Growth for GSK and Haleon

      ケーススタディを見る

      Digital How a Data-Driven Mindset Powers McAfee’s Growth

      ケーススタディを見る

      お気軽にご連絡下さい

      私達は、グローバルに活躍する経営者が抱える最重要経営課題に対して、厳しい競争環境の中でも成長し続け、「結果」を出すために支援しています。

      Digital is a service mark of Bain & Company, Inc.

      ベインの知見。競争が激化するグローバルビジネス環境で、日々直面するであろう問題について論じている知見を毎月お届けします。

      *プライバシーポリシーの内容を確認し、合意しました。

      プライバシーポリシーをご確認頂き、合意頂けますようお願い致します。
      Bain & Company
      お問い合わせ Sustainability Accessibility Terms of use Privacy Cookie Policy Sitemap Log In

      © 1996-2026 Bain & Company, Inc.

      お問い合わせ

      How can we help you?

      • ビジネスについて
      • プレス報道について
      • 採用について
      全てのオフィス