Full report
Published: 11 January 2022

Global Risks Report 2022

Chapter 3. Digital Dependencies and Cyber Vulnerabilities

Digital distress

Governments, societies and companies increasingly rely on technology to manage everything from public services to business processes, even routine grocery shopping.1 Converging technological platforms, tools and interfaces connected via an internet that is rapidly shifting to a more decentralized version 3.0 are at once creating a more complex cyber threat landscape and a growing number of critical failure points. As society continues to migrate into the digital world, the threat of cybercrime looms large, routinely costing organizations tens—even hundreds—of millions of dollars. The costs are not just financial: critical infrastructure, societal cohesion and mental well-being are also in jeopardy.

Digital everything

Growing dependency on digital systems over the last 20 years has drastically shifted the way many societies function.2 The COVID-19-induced shift to remote work has accelerated the adoption of platforms and devices that allow sensitive data to be shared with third parties—cloud service providers, data aggregators, application programming interfaces (APIs), and other technology-related intermediaries.3 These systems, while powerful tools for data and processing, attach an additional layer of dependency on service providers. Remote work has also moved digital exchanges from office networks to residential ones, which have a greater variety of connected devices with less protection against cyber intrusion. In parallel, the appetite for capabilities predicated upon using multiple technologies working in concert—including artificial intelligence (AI), Internet of Things (IoT)/Internet of Robotic Things-enabled devices, edge computing, blockchain and 5G—is only growing.4 While these capabilities afford tremendous opportunities for businesses and societies to use technology in ways that can dramatically improve efficiency, quality and productivity, these same capabilities also expose users to elevated and more pernicious forms of digital and cyber risk.

In the future, the interconnectedness and convergence of these digital tools will continue to increase as society embraces the next version of the internet built upon blockchain technology. One manifestation of this migration will be the metaverse: a network of 3D virtual spaces, enabled by cryptocurrencies and non-fungible tokens (NFTs) among other technologies, with unprecedented socio-economic interoperability and immersive virtual reality experiences.5 Users will be required to navigate security vulnerabilities inherent in both increased dependency on and growing fragmentation in these types of complex technologies often characterized by decentralization and lack of structured guardrails or sophisticated onboarding infrastructure.

Cyber vulnerabilities

In the context of widespread dependency on increasingly complex digital systems, growing cyberthreats are outpacing societies’ ability to effectively prevent and manage them. For example, the digitalization of physical supply chains creates new vulnerabilities because those supply chains rely on technology providers and other third parties, which are also exposed to similar, potentially contagious, threats.6 In December 2021, just one week after discovering a critical security flaw in a widely used software library (Log4j), more than 100 attempts at exploiting the vulnerability were detected every minute, illustrating how free access coding can spread vulnerabilities widely.7 Information technology (IT) monitoring and management software also illustrate the potential for contagious exposure, which can break through the defences of critical cybersecurity supply chains, as shown by the Solar Winds Orion attack that occurred in late 2020.8 While a state-based institution with highly sophisticated capabilities probably lodged this attack, other criminal organizations will certainly attempt to replicate this approach.9 At the same time, older vulnerabilities persist with many organizations still relying on outdated systems or technologies.

Malicious activity is proliferating, in part because of the growing vulnerabilities—but also because there are few barriers to entry for participants in the ransomware industry and little risk of extradition, prosecution or sanction.10 Malware increased by 358% in 2020, while ransomware increased by 435%,11 with a four-fold rise in the total cryptocurrency value received by ransomware addresses (see Figure 4.1).12 “Ransomware as a service” allows even non-technical criminals to execute attacks, a trend that might intensify with the advent of artificial intelligence (AI)-powered malware.13 In fact, profit-seeking groups of cyber mercenaries stand ready to provide access to sophisticated cyber-intrusion tools to facilitate such attacks. Furthermore, cryptocurrencies have also allowed cybercriminals to collect payments with only modest risk of detection or monetary clawback.14

Total Cryptocurrency Value received by Ransomeware Addresses, 2013-2020 - Global Risks Report 2022

Attacks themselves are also becoming more aggressive and widespread.15 Cyberthreat actors using ransomware are leveraging tougher pressure tactics as well as going after more vulnerable targets, impacting public utilities, healthcare systems and data-rich companies.16 For example, before it disbanded, DarkSide—the group accused of being responsible for the Colonial Pipeline attack—offered a suite of services (“triple” or “quadruple” extortion) to clients beyond simply encrypting files; these included data leaks and distributed denial-of-service (DDoS) attacks. Hacker groups will also contact victims’ clients or partners to get them to urge the victims to pay ransoms. Among the services offered is the collection of top executive information for blackmail.17

Sophisticated cyber tools are also allowing cyber threat actors to attack targets of choice more efficiently, rather than settling for targets of opportunity, highlighting the potential to carry out more goal-oriented attacks that could lead to even higher financial, societal and reputational damage in the future. Increasingly sophisticated use of spyware technologies, for example, has allowed for targeted attacks against journalists and civil rights activists across geographies–spurring a wave of political and industrial blowback in the form of government sanctions and lawsuits.18 The ability to tailor attacks at will includes timing them for when cybersecurity teams and leadership could be distracted by other priorities, such as during peak COVID-19 outbreaks or a natural disaster. Cyberthreat actors are also accessing higher-quality and more sensitive information from victims. And deepfake technology is allowing cyber threat actors to improve social engineering ploys, proliferate disinformation and wreak societal havoc, especially at times of high volatility.19

Global Risks Perception Survey (GRPS) respondents reflect these trends, ranking “cybersecurity failure” among the top-10 risks that have worsened most since the start of the COVID-19 crisis. Moreover, 85% of the Cybersecurity Leadership Community of the World Economic Forum have stressed that ransomware is becoming a dangerously growing threat and presents a major concern for public safety.20 At a regional level, “cybersecurity failure” ranks as a top-five risk in East Asia and the Pacific as well as in Europe, while four countries—Australia, Great Britain, Ireland, and New Zealand—ranked it as the number one risk. Many small, highly digitalized economies—such as Denmark, Israel, Japan, Taiwan (China), Singapore, and the United Arab Emirates—also ranked the risk as a top-five concern.

Already-stretched IT and cybersecurity professionals are under an increasing burden, not only because of the expansion of remote work but also because of the growing complexity of regulations for data and privacy, even though such regulations are critical to ensuring public trust in digital systems.21 There is an undersupply of cyber professionals—a gap of more than 3 million worldwide22—who can provide cyber leadership, test and secure systems, and train people in digital hygiene.23 As with other key commodities, a continued lack of cybersecurity professionals could ultimately hamper economic growth,24 although new initiatives to “democratize” cybersecurity, for example, by providing free cybersecurity risk management tools, could help fill some of the gaps for small businesses or other institutions.25

There are concerns that quantum computing could be powerful enough to break encryption keys—which poses a significant security risk because of the sensitivity and criticality of the financial, personal and other data protected by these keys. The emergence of the metaverse could also expand the attack surface for malicious actors by creating more entry points for malware and data breaches.26 As the value of digital commerce in the metaverse grows in scope and scale—by some estimates projected to be over US$800 billion by 2024—these types of attacks will grow in frequency and aggression.27 The myriad forms of digital property, such as NFT art collections and digital real estate, could further entice criminal activity.

For governments attempting to prevent cybersecurity failures, patchwork enforcement mechanisms across jurisdictions continue to hamper efforts to control cybercrime.28 Geopolitical rifts hinder potential cross-border collaboration, with some governments unwilling or unable to regulate cyber intrusions that originate inside and impact outside their borders. Unsurprisingly, given the geopolitical tensions around digital sovereignty, according to GRPS respondents, “cross-border cyberattacks and misinformation” and “artificial intelligence” were among the areas with the least “established” or “effective” international risk mitigation efforts.

Companies must also act ahead of new regulatory shifts, as the political undercurrents/geopolitical tensions between various countries might impact cross-border data flows. This might mean moving data processing to jurisdictions that might allow for better customer protection around data privacy issues.29


Often-repeated examples of past cyber intrusions are worth re-examination, as these cases demonstrate how damaging attacks on large and strategically significant systems—such as banking, hospital, Global Positioning System (GPS) or air traffic control systems—could be.30 As resources are increasingly digitized, notable as well is the heightened risk of cyber espionage attacks that typically target intellectual property and result in high developmental and reputational costs to both private and public sector organizations.31

The interaction between digitalization and growing cyber threats carries intangible consequences as well. The growth of deepfakes and “disinformation-for-hire” is likely to deepen mistrust between societies, businesses, and governments.32 For example, deepfakes could be used to sway elections or political outcomes.33 More concretely, in one recent case, cybercriminals cloned the voice of a company director to authorize the transfer of US$35 million to fraudulent accounts.34 There is also a booming market for services designed to manipulate public opinion in favour of clients, public or private, or to damage rivals.35 Fraud, too, will become easier and therefore more frequent with banking, health and civic processes going remote. In 2021, UK internet banking fraud rose by 117% in volume and 43% in value compared with 2020 levels, as people spent more time shopping online.36 Digital safety overall—from health misinformation and extremism to child exploitation—faces new challenges with inexperienced and more vulnerable populations coming online.37

Even in the best-case scenario of aggressive digital threat defences, there will be significant increases in the cost of operations for all stakeholders. This could be particularly challenging for small or medium-sized businesses that might spend 4% or more of their operational budget on security, compared to larger organizations that might spend closer to 1–2%.38 Indeed, amid the rising frequency and severity of ransomware claims, cyber insurance pricing in the United States rose by 96% in the third quarter of 2021, marking the most significant increase since 2015 and a 204% year-over-year increase.39 Respondents to the GRPS indicate a long-term concern with these developments, with “adverse tech advances” appearing as a top-10 risk over a 5-to-10-year horizon.

Cyberthreats also continue to drive states apart, with governments following increasingly unilateral paths to control risks. As attacks become more severe and broadly impactful, already-sharp tensions between governments impacted by cybercrime and governments complicit in their commission will rise as cybersecurity becomes another wedge for divergence, rather than cooperation, among nation states.40 Particularly in an era of rising tensions between superpowers, cyberattacks are another battlefront in which escalation is a key risk (see Chapter 1).41 If cyber threats continue without mitigation, governments will continue to retaliate against perpetrators (actual or perceived), leading to open cyberwarfare, further disruption for societies and loss of trust in governments’ ability to act as digital stewards.

Digital security divides: Consequences for people

Among the most vulnerable are those who are only now coming online or will soon do so. Around 40% of the world’s population is not yet connected to the internet.42 These individuals are already facing inequalities in digital security, which will only widen with the advent of internet 3.0 and the metaverse.43 Within digitally advanced societies, vulnerable populations are also often more digitally at risk: for example, a recent study finds that low-income residents of San Francisco—the cultural heart of Silicon Valley—are more likely than wealthier residents to be cybercrime victims.44 In other situations, obligatory digital identity markers could introduce new risks for citizens, particularly evident in the growing risk that deepfakes could compromise biometric authentication.45

Individuals will increasingly experience anxiety as control over their data becomes more precarious and they are subjected to personal attacks, fraud, cyberbullying and stalking (see Figure 4.2).46 A perceived lack of agency could also lead to apathy in taking responsibility for securing one's own digital footprint, as evinced by the continued market dominance of instant messenger applications plagued by privacy controversies.47 Even with more widespread “reject all” options on websites intended to simplify personal data privacy, there are drawbacks and caveats—such as limiting functionality and other options. Importantly, these features are just a tiny part of the larger privacy equation. Websites are still littered with tracking pixels and third-party scripts that remain powerful ways to fingerprint online behaviours.48

Emotions experienced after detecting unauthorized access - Global Risks Report 2022

Overreaching or underdelivering: Consequences for governments

Government at all levels faces mounting responsibilities and many are struggling to uphold their end of the digital social contract: securing critical infrastructure; addressing threats to “epistemic security” from disinformation; protecting the integrity of civic processes and public services; legislating against cybercrime; training and educating populaces around cyber literacy; regulating digital service providers; and ensuring the availability of resources, such as rare-earth minerals, for the digital economy. The necessary oversight could lead to overreach as governments move to shut down systems, erect higher digital barriers or embark on digital colonization (by monopolizing digital systems) for geopolitical ends.49 While such actions might carry the ostensible goal of reducing attacks and disruption, these policies could quickly become a vehicle for oppression. Already suffering from a loss in public trust as a result of the COVID-19 crisis, governments may face further societal anger if they are unable to both keep up with the shifting threat landscape and responsibly manage these challenges.

Pay, secure or perish: Consequences for businesses

As cyber threats continue to grow, insuring against such risks will become increasingly precarious, with insurers themselves facing retaliatory attacks for attempting to curb ransomware payments.50 Thus, when an attack occurs, businesses will be forced either to pay increasingly high ransoms or to suffer the reputational, financial, regulatory and legal consequences of cyberattacks. As previous incursions (like SolarWinds) have demonstrated, exposure to vendors and supply chain partners must also be assessed and managed. The impact of disruptive cyberattacks could be financially devastating for businesses that fail to invest in protections for their digital infrastructure, particularly in a scenario in which governments begin prohibiting ransom payments or penalizing poor cybersecurity practices.51 Furthermore, as environmental, social and governance (ESG) concerns come increasingly into focus (see Chapter 2), businesses that fail to demonstrate strong corporate governance around cybersecurity—such as by implementing robust systems and process oversight protocols, and by practicing accountability and transparency in the event of a breach—could suffer reputational harm in the eyes of ESG-focused investors.

Businesses also operate in a world in which 95% of cybersecurity issues can be traced to human error,52 and where insider threats (intentional or accidental) represent 43% of all breaches.53 Some companies will inevitably move to greater segmentation of digital systems to better account for insider risk. Companies could begin or continue to lock up key data as a result of cybersecurity issues. Workforce efficiency, too, could suffer if accessing data and information is less seamless.

Digital Shocks - Global Risks Report 2022

Towards greater cyber resilience

As our reliance on digital technologies grows and Internet 3.0 becomes reality, efforts aimed at building norms and defining rules of behaviour for all stakeholders in cyberspace are intensifying. While multistakeholder international dialogues can help strengthen links between actors operating in the digital security realm, cooperation between organizations could unlock best practices that can be replicated across industries and economies. Initiatives should focus on emerging technologies, such as blockchain, quantum and artificial intelligence, as well as the modes of digital exchange they facilitate, like the metaverse. Leaders must remain attentive to perennial concerns like cybercrime and ransomware attacks as well. At the organizational level, upskilling leaders on cybersecurity issues and elevating emerging cyber risks to board-level conversations will strengthen cyber-resilience. In a deeply connected society, digital trust is the currency that facilitates future innovation and prosperity. Trustworthy technologies, in turn, represent the foundation on which the scaffolding of a fair and cohesive society is built. Unless we act to improve digital trust with intentional and persistent trust-building initiatives, the digital world will continue to drift towards fragmentation and the promise of one of the most dynamic eras of human progress may be lost.


