Cybersecurity has become a hot topic in recent weeks with the US government accusing Russia of hacking Democratic Party emails and of interfering with its presidential election. Cybersecurity fears were not allayed when in the same month sites such as Twitter, Netflix, CNN, the Guardian and Reddit were brought down by widespread internet disruption, the result of a new kind of malware that infects computers and turns them into a remotely controlled network of ‘bots’. We appear to be entering an era where science fiction meets a new science reality.
With an increasing number of cyber-attacks reports entering the public domain, there has been an incremental awareness of the need for this type of threat to be managed reliably, not just by governments but also by businesses, universities, and, well, everyone. An illustration of how a gross lapse in business oversight can turn into a large-scale debacle is this month’s cyber heist of the UK’s Tesco Bank in which 9,000 customers are believed to have lost a total of £2.5 million (c. US$3.1m). Security specialists are said to have repeatedly warned the bank of vulnerabilities in their mobile app software, advice that senior management allegedly ignored.
We are living in an increasingly tech-savvy world where almost anyone anywhere has the potential to become a hacker, and many governments, businesses and universities appear to be combining forces in an attempt to thwart the impending scale of the threat. The UK chancellor, for example, announced a government initiative to inject £1.9 billion (c.US$2.4 billion) into cybersecurity research and innovation, as part of the country’s official ‘National Cyber Security Strategy’. Many education leaders also understand that cybersecurity training can no longer be the restricted domain of IT specialists, but is a form of education that needs to instead be applied more generally.
TopMBA.com spoke to Dr David Upton, operations management professor and co-director of the ‘Cyber Risk for Leaders Programme’ at the University of Oxford’s Saïd Business School to gain an insight into why a course in cybersecurity can present itself as a very valuable asset to MBAs in particular.
Saïd Business School on cybersecurity: Business leaders must understand the true nature of cyber risk
"The scale, nature and growth of the problem is not well understood,” says Upton. The truth of the matter is that business leaders are not yet fully aware, or are not taking the time to understand the risks posed by cyber-attacks. Upton points to the scarcity of qualified people on the technical side as well. 2016 stats indicate that there are one million cybersecurity positions left unfilled globally, a number that is only projected to rise. "Managers in companies who know how to manage [cybersecurity risks] are even scarcer," Upton explains.
Cybercrime cost the UK economy around US$13.7 billion in 2015, a figure Upton believes to be underestimated. "But government is not, and cannot, be the defender against all of this activity. It is businesses that are on the front line. And there are many recent examples pointing to poor management as the source of the problem," says Upton. The cyber-attack on Tesco Bank is one such instance of probable mismanagement.
Get closer to your dream programme
Your consent preferences have been set.
Time to start exploring.
Your account has been removed.
You can still browse the site or sign up again once you have parental consent.
Get closer to your dream programme