Skip to Content
  • 오피스

    오피스

    미주
    • Atlanta
    • Austin
    • Bogota
    • Boston
    • Buenos Aires
    • Chicago
    • Dallas
    • Denver
    • Houston
    • Los Angeles
    • Mexico City
    • Minneapolis
    • Monterrey
    • Montreal
    • New York
    • Rio de Janeiro
    • San Francisco
    • Santiago
    • São Paulo
    • Seattle
    • Silicon Valley
    • Toronto
    • Washington, DC
    유럽, 중동, 아프리카
    • Amsterdam
    • Athens
    • Berlin
    • Brussels
    • Copenhagen
    • Doha
    • Dubai
    • Dusseldorf
    • Frankfurt
    • Helsinki
    • Istanbul
    • Johannesburg
    • Kyiv
    • Lisbon
    • London
    • Madrid
    • Milan
    • Munich
    • Oslo
    • Paris
    • Riyadh
    • Rome
    • Stockholm
    • Vienna
    • Warsaw
    • Zurich
    아시아, 호주
    • Bangkok
    • Beijing
    • Bengaluru
    • Brisbane
    • Ho Chi Minh City
    • Hong Kong
    • Jakarta
    • Kuala Lumpur
    • Manila
    • Melbourne
    • Mumbai
    • New Delhi
    • Perth
    • Seoul
    • Shanghai
    • Singapore
    • Sydney
    • Tokyo
    오피스 전체보기
  • 얼럼나이
  • 미디어 센터
  • 구독
  • 연락처
  • Korea | 한국어

    지역 및 언어 선택

    글로벌
    • Global (English)
    미주
    • Brazil (Português)
    • Argentina (Español)
    • Canada (Français)
    • Chile (Español)
    • Colombia (Español)
    유럽, 중동, 아프리카
    • France (Français)
    • DACH Region (Deutsch)
    • Italy (Italiano)
    • Spain (Español)
    • Greece (Elliniká)
    아시아, 호주
    • China (中文版)
    • Korea (한국어)
    • Japan (日本語)
  • Saved items (0)
    Saved items (0)

    You have no saved items.

    관심 있는 내용을 북마크하여 Red 폴더에 저장할 수 있습니다. Red 폴더 에서 저장된 내용을 읽거나 공유해보세요.

    Explore Bain Insights
  • 산업
    메인 메뉴

    산업

    • 우주항공, 방산 및 정부 서비스
    • 농업 관련 산업
    • 화학
    • 인프라, 건설 및 건축 자재
    • 소비재
    • 금융 서비스
    • 헬스케어
    • 산업용 기계 및 장비
    • 미디어 및 엔터테인먼트
    • 금속
    • 광업
    • 석유 및 가스
    • 제지 및 패키징 산업
    • 사모펀드
    • 사회 및 공공 부문
    • 유통
    • 기술
    • 텔레콤
    • 운송
    • 여행·여가
    • 유틸리티 및 재생가능 에너지
  • 컨설팅 서비스
    메인 메뉴

    컨설팅 서비스

    • Customer Experience
    • ESG
    • Innovation
    • M&A
    • 운영
    • 조직
    • 사모펀드
    • 고객 전략 및 마케팅
    • 전략
    • AI, 인사이트 및 솔루션
    • Technology
    • 변화 혁신
  • Digital
  • 인사이트
  • 베인 소개
    메인 메뉴

    베인 소개

    • 업무 소개
    • 베인의 신념
    • 구성원 및 리더십 소개
    • 고객 성과
    • 주요 수상 경력
    • 글로벌 파트너사
    Further: Our global responsibility
    • 다양성과 포용
    • 사회 공헌 활동
    • Sustainability
    • World Economic Forum
    Learn more about Further
  • Careers
    메인 메뉴

    Careers

    • Work with Us
      Careers
      Work with Us
      • Find Your Place
      • Our Work Areas
      • Integrated Teams
      • Students
      • Internships & Programs
      • Recruiting Events
    • Life at Bain
      Careers
      Life at Bain
      • Blog: Inside Bain
      • Career Stories
      • Our People
      • Where We Work
      • Supporting Your Growth
      • Affinity Groups
      • Benefits
    • Impact Stories
    • Hiring Process
      Careers
      Hiring Process
      • What to Expect
      • Interviewing
    FIND JOBS
  • 오피스
    메인 메뉴

    오피스

    • 미주
      오피스
      미주
      • Atlanta
      • Austin
      • Bogota
      • Boston
      • Buenos Aires
      • Chicago
      • Dallas
      • Denver
      • Houston
      • Los Angeles
      • Mexico City
      • Minneapolis
      • Monterrey
      • Montreal
      • New York
      • Rio de Janeiro
      • San Francisco
      • Santiago
      • São Paulo
      • Seattle
      • Silicon Valley
      • Toronto
      • Washington, DC
    • 유럽, 중동, 아프리카
      오피스
      유럽, 중동, 아프리카
      • Amsterdam
      • Athens
      • Berlin
      • Brussels
      • Copenhagen
      • Doha
      • Dubai
      • Dusseldorf
      • Frankfurt
      • Helsinki
      • Istanbul
      • Johannesburg
      • Kyiv
      • Lisbon
      • London
      • Madrid
      • Milan
      • Munich
      • Oslo
      • Paris
      • Riyadh
      • Rome
      • Stockholm
      • Vienna
      • Warsaw
      • Zurich
    • 아시아, 호주
      오피스
      아시아, 호주
      • Bangkok
      • Beijing
      • Bengaluru
      • Brisbane
      • Ho Chi Minh City
      • Hong Kong
      • Jakarta
      • Kuala Lumpur
      • Manila
      • Melbourne
      • Mumbai
      • New Delhi
      • Perth
      • Seoul
      • Shanghai
      • Singapore
      • Sydney
      • Tokyo
    오피스 전체보기
  • 얼럼나이
  • 미디어 센터
  • 구독
  • 연락처
  • Korea | 한국어
    메인 메뉴

    지역 및 언어 선택

    • 글로벌
      지역 및 언어 선택
      글로벌
      • Global (English)
    • 미주
      지역 및 언어 선택
      미주
      • Brazil (Português)
      • Argentina (Español)
      • Canada (Français)
      • Chile (Español)
      • Colombia (Español)
    • 유럽, 중동, 아프리카
      지역 및 언어 선택
      유럽, 중동, 아프리카
      • France (Français)
      • DACH Region (Deutsch)
      • Italy (Italiano)
      • Spain (Español)
      • Greece (Elliniká)
    • 아시아, 호주
      지역 및 언어 선택
      아시아, 호주
      • China (中文版)
      • Korea (한국어)
      • Japan (日本語)
  • Saved items  (0)
    메인 메뉴
    Saved items (0)

    You have no saved items.

    관심 있는 내용을 북마크하여 Red 폴더에 저장할 수 있습니다. Red 폴더 에서 저장된 내용을 읽거나 공유해보세요.

    Explore Bain Insights
  • 산업
    • 산업

      • 우주항공, 방산 및 정부 서비스
      • 농업 관련 산업
      • 화학
      • 인프라, 건설 및 건축 자재
      • 소비재
      • 금융 서비스
      • 헬스케어
      • 산업용 기계 및 장비
      • 미디어 및 엔터테인먼트
      • 금속
      • 광업
      • 석유 및 가스
      • 제지 및 패키징 산업
      • 사모펀드
      • 사회 및 공공 부문
      • 유통
      • 기술
      • 텔레콤
      • 운송
      • 여행·여가
      • 유틸리티 및 재생가능 에너지
  • 컨설팅 서비스
    • 컨설팅 서비스

      • Customer Experience
      • ESG
      • Innovation
      • M&A
      • 운영
      • 조직
      • 사모펀드
      • 고객 전략 및 마케팅
      • 전략
      • AI, 인사이트 및 솔루션
      • Technology
      • 변화 혁신
  • Digital
  • 인사이트
  • 베인 소개
    • 베인 소개

      • 업무 소개
      • 베인의 신념
      • 구성원 및 리더십 소개
      • 고객 성과
      • 주요 수상 경력
      • 글로벌 파트너사
      Further: Our global responsibility
      • 다양성과 포용
      • 사회 공헌 활동
      • Sustainability
      • World Economic Forum
      Learn more about Further
  • Careers
    최근 검색어
      최근 방문 페이지

      Content added to saved items

      Saved items (0)

      Removed from saved items

      Saved items (0)

      Brief

      Building Strategic Cybersecurity Capabilities After the Invasion of Ukraine

      Building Strategic Cybersecurity Capabilities After the Invasion of Ukraine

      The war has underscored the need for companies to catch up with best practices—and then go further.

      글 Frank Ford, Syed Ali, and Mark Leggate

      • 읽기 소요시간
      }

      Brief

      Building Strategic Cybersecurity Capabilities After the Invasion of Ukraine
      en
      한눈에 보기
      • Amid warnings of increased malicious activity from Russia-linked groups, companies must swiftly get the cybersecurity basics right and avoid underspending on this critical function.
      • Companies with direct-but-dormant exposure to Russia face additional complications, while all executive teams will have to be on their guard against intellectual property theft.
      • The most resilient businesses will go beyond checklist-focused implementation of industry frameworks, nurturing strategic capabilities that evolve with shifting cyber threats.

      Cybersecurity is increasingly seen as risk No. 1 by large businesses—and with good reason. Even before the Russian invasion of Ukraine escalated the threat posed by hackers, cybercrime was costing the world an estimated $6 trillion annually according to Cybersecurity Ventures, through malign actions such as ransomware attacks, data destruction, embezzlement, and theft of intellectual property.

      By their own admission, many companies aren’t ready to contain this rising threat. When we surveyed executives on the topic, only 43% felt that their company followed cybersecurity best practices. Yet even that lowly figure looks like an overestimate. Deeper analysis of our survey sample showed that only about 24% actually met the best practice threshold. On a cybersecurity maturity scale of 1–5, a typical company is likely to rate only 1.5–2.5: way too low.

      With the heightened threat unlikely to ease soon, many companies need to refocus on getting the cybersecurity basics right. However, a truly strategic response to today’s dangers will require much more than a tactical alignment with industry norms. Over the coming months, the most resilient companies will also build and refine the capabilities needed to keep improving their defenses against the evolving situation in Russia and Ukraine—and against fresh threats yet to emerge.

      First things first: Get the basics right

      Ukraine-related cybersecurity incidents have been numerous both before and during the invasion, including distributed denial-of-service attacks, data-wiping malware, and website defacement. According to Microsoft, sustained pre-invasion cyber operations against Ukraine by groups aligned with Russia began as early as March 2021, ahead of intensifying activity that included more than 230 observed cyberattacks in Ukraine from December 2021 to March 2022.

      The impact of the hostile activity has been international. For instance, when a satellite-based Internet service suffered a cyberattack subsequently blamed on Russia, the outage hit tens of thousands of customers across Europe, not just Ukraine, and also affected German wind turbines. More than 90% of Russia-based attacks observed in Microsoft’s online services in 2021 were aimed at NATO member states, particularly the US, the UK, Norway, Germany, and Turkey.

      More online attacks are expected to follow. The US and other countries have warned companies inside and outside the conflict zone to brace themselves for increased malicious cyber activity from Russia-linked groups, in retaliation for sanctions and international support for Ukraine. The European Union said cyberattacks against Ukraine “could spill over into other countries and cause systemic effects, putting the security of Europe’s citizens at risk.”

      In response, companies should understand and swiftly act on government advisories. In the US, that includes communications from the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA). Companies outside the US should look to the local equivalents, many of which have been involved in cross-border cooperation.

      The absence of critical security patches is at the root of many breaches. As well as rigorously checking that patches are applied in a timely fashion, companies need to ensure that employees (particularly the high-value targets at the top of the organization) know how to identify and avoid malware-laced emails and other threats.

      Other basic hygiene measures include enforcing multifactor authentication, conducting extensive vulnerability scans, and instigating a general hardening of the technology environment (for instance, by shutting down unneeded services or ports).

      Gauging the right level of spending and investment in cybersecurity is critical—a challenge that includes ensuring that there are enough skilled cybersecurity professionals on the payroll. Our research and experience show many companies underinvest significantly (see Figure 1), which leaves them underprotected and prone to a range of issues, such as incomplete or outdated cyber-protection technology and inadequate training for both cyber specialists and general employees.

      Figure 1
      Underspending and understaffing are hallmarks of a business with low cybersecurity maturity—and higher cybersecurity risk
      Underspending and understaffing are hallmarks of a business with low cybersecurity maturity—and higher cybersecurity risk
      Underspending and understaffing are hallmarks of a business with low cybersecurity maturity—and higher cybersecurity risk

      Amid all this defensive preparation, there should be an understanding that digital assets will be breached at some point, and that business continuity plans will need to be activated so that critical services can continue. That means ensuring that incident response playbooks are fit for purpose and tested.

      Complications for directly exposed companies

      Getting the basics right will be different for companies that still have direct exposure to Russia, including multinationals that have continued to pay local employees after halting operations. This kind of residual involvement is likely to create cybersecurity complications beyond the obvious risk of direct attacks by hacktivists and other disruptive actors.

      For instance, operationally inactive workers still on the payroll may retain access to company laptops. When it comes to rolling out updates to those computers, employers will need to balance the need to remain protected with the need to observe sanctions. Information-sharing policies may also require modification.

      If the Ukraine war stretches on for many months or even years, accompanied by a continuation of sanctions, all companies will need to be on their guard against an increased risk of intellectual property theft, particularly in sectors such as technology, defense, and financial services. Lingering sanctions against Russia could also encourage ransomware attacks, making it particularly vital to heighten oversight of vectors commonly used by ransomware, such as remote desktop sessions.

      How to go beyond the basics

      Industry frameworks such as NIST and ISO 27002 are an essential building block of cybersecurity. But to protect themselves fully amid such global instability, companies need to go beyond checklist-focused implementation of the best practices enshrined in these frameworks.  

      For one thing, the guidance in frameworks is often control oriented and high level; the large amount of room they leave for interpretation makes good cybersecurity hard to define. It doesn’t help that events often move fast on the ground while frameworks are updated infrequently. Nor can frameworks give much guidance on the complex trade-offs that management teams must weigh, such as the right balance between organizational speed and security.

      Many leading companies are seeking greater long-term resilience by also focusing on building strategic cybersecurity capabilities. This holistic approach recognizes that companies need sophisticated, self-evolving capabilities to effectively manage complex and quickly changing cybersecurity risk. 

      A good example of what key capabilities look like in practice can be found in the management of third-party cybersecurity risk in the supply chain, which came to the fore early on in the Russian destabilization of Ukraine. (Microsoft observed supply chain vendors in Ukraine and abroad being targeted in mid-2021.) This is a complex area, with large companies typically having thousands of suppliers. These third parties can hold up supply chains if a cyberattack leaves them unable to operate—and they can also propagate the same issues to their customers.

      Tackling this area of risk successfully requires that companies:

      • identify and classify third parties based on the cybersecurity risk posed and the likely impact (both direct and supply chain related);
      • assess third parties both when they are first selected and on an ongoing basis—with in-house teams or through a new breed of external risk assessment service; and
      • reduce risk to an acceptable level through measures such as informal persuasion, contract stipulations, additional controls, and supply chain diversification to boost continuity.

      This is complicated to do reliably and at scale, which is why many companies end up living with large but unquantified levels of cybersecurity risk. Simply put, there is no shortcut around building the capabilities needed to manage this area of risk effectively. But companies often have more options at their disposal than they realize.

      When one consumer packaged goods company systematically tackled the risk presented by third parties, it uncovered a host of practical ways to strengthen its protection. These included improving contractual language, updating its formal policy on cybersecurity requirements for suppliers, clarifying which suppliers were most important to the business, and implementing risk controls and risk mitigation measures such as tighter third-party access to company systems.

      The effort and investment required to persuade suppliers to improve their cybersecurity can also lead to broader benefits. For instance, measures taken to mitigate third-party cybersecurity disruption risk (such as boosting inventory of essential manufacturing parts in case of a disabling cyberattack on a supplier) can contribute to a companywide push to enhance operational resilience.

      Going beyond the basics is essential if companies are to protect themselves in these hyperconnected and unstable times. Building strong strategic cybersecurity capabilities is the answer.

      The authors would like to thank Salman Faiz for his contribution to this brief.

      저자
      • Headshot of Frank Ford
        Frank Ford
        파트너, London
      • Headshot of Syed Ali
        Syed Ali
        파트너, Houston
      • Headshot of Mark Leggate
        Mark Leggate
        파트너, London
      문의하기
      관련 산업
      • Cybersecurity
      관련 컨설팅 서비스
      • 정보기술(IT)
      • Digital
      CIO Insights
      Quantum Computing Moves from Theoretical to Inevitable

      Quantum will likely become part of a mosaic, working with classical computing to solve big problems.

      자세히 보기
      CIO Insights
      Want More Out of Your AI Investments? Think People First

      To unlock AI’s exponential productivity potential, companies must modernize workflow and workforce in tandem.

      자세히 보기
      Digital
      Reimagining Merchandising in the Era of Agentic AI

      The future of merchandising is not better analysis, but faster, smarter execution—and agentic AI is what makes that possible.

      자세히 보기
      CIO Insights
      Life Sciences’ AI Momentum Requires a Workforce Redesign

      AI scalers aren't waiting for new talent—they're building it.

      자세히 보기
      Cybersecurity
      Generative AI and Cybersecurity: Strengthening Both Defenses and Threats

      Breakthroughs in technologies built on large language models will accelerate the arms race between hackers and companies.

      자세히 보기
      First published in 6월 2022
      태그
      • 정보기술(IT)
      • CIO Insights
      • Cybersecurity
      • Digital
      • Resilience amid Global Crisis

      프로젝트 사례

      Digital A European Banking Giant Rises to the Fintech Challenge

      See more related case studies

      Digital A Strategic Separation Enables New Growth for GSK and Haleon

      See more related case studies

      Digital How a Data-Driven Mindset Powers McAfee’s Growth

      See more related case studies

      베인에 궁금하신 점이 있으신가요?

      베인은 주저 없이 변화를 마주할 줄 아는 용감한 리더들과 함께합니다. 그리고, 이들의 담대한 용기는 고객사의 성공으로 이어집니다.

      급변하는 비즈니스 환경에서 살아남기 위한 선도자의 시각. 월간 Bain Insights에서 글로벌 비즈니스의 핵심 이슈를 확인하십시오.

      *개인정보 정책을 읽었으며 그 내용에 동의합니다.

      Privacy Policy를 읽고 동의해주십시오.
      Bain & Company
      문의하기 환경정책 Accessibility 이용약관 개인정보 보호 쿠키 사용 정책 Sitemap Log In

      © 1996-2026 Bain & Company, Inc.

      문의하기

      무엇을 도와드릴까요?

      • 프로젝트 문의
      • 채용 정보
      • 언론
      • 제휴 문의
      • 연사 초청
      오피스 전체보기