Cybersecurity

Why a sustainable finance mechanism for cybersecurity is key to securing the global economy

Close up of a laptop keyboard with a half opened screen as the Global Future Council on Cybersecurity outlines how a meaningful sustainable cybersecurity finance mechanism

Safer internet for all ... why cybersecurity needs a sustainable finance mechanism. Image: Getty Images/iStockphoto

Global Future Council on Cybersecurity
Network of Global Future Councils (2025-2026), World Economic Forum
  • Cybersecurity philanthropy amounts to just $100–200 million annually - tiny compared with overall charitable giving or AI investment.
  • Only a small share of cybersecurity funding reaches emerging economies and least-developed countries.
  • Members of the World Economic Forum's Global Future Council on Cybersecurity propose a 'sustainable cybersecurity finance mechanism' to close this funding gap and help create a safer internet for all.

Imagine a world in which every small business can access an expert cyber volunteer to defend against artificial intelligence (AI)-enabled cybercrime.

In this world, nongovernmental organizations (NGOs) are notified of botnet activity in time to prevent ransomware attacks, and international aid organizations routinely earmark digital security allocations for their beneficiaries, whether to protect health management systems powering disease eradication or to bake operational technology security into new wastewater infrastructure.

The standards, policy frameworks, and technology needed to achieve this vision largely exist. What is missing is funding.

Have you read?
  • Global Cybersecurity Outlook 2026

We estimate that private and corporate philanthropy together contribute $100-$200 million annually to cybersecurity-specific causes. Recently, government grant programmes – notably the State and Local Cybersecurity Grants Program in the US, the UK Integrated Security Fund, and the EU’s Digital Europe Programme – have begun contributing hundreds of millions annually in their respective jurisdictions, but little of this funding is directed towards emerging economies and least-developed countries.

For comparison, the $100-$200 million allocated to cybersecurity philanthropy is a rounding error against the estimated $885 billion given to general charitable causes in 2023, or the $580 billion that flooded into corporate AI investment in 2025.

We are rapidly scaling AI engines without funding the digital brakes. A small fraction of this funding would be enough to create a meaningful sustainable cybersecurity finance mechanism (SCFM) dedicated to making the internet safe and secure for all.

Laying the groundwork for a sustainable cybersecurity finance mechanism

The SCFM would not operate as a single fund, but rather as a coordinated ecosystem of diverse funding sources including individual philanthropy, corporate giving, multilateral funds, and pooled mechanisms aligned under shared principles and scope.

As such, the SCFM would provide a stable funding base to unlock additional resources and fill the gap in funding for under-resourced but critical internet functions. However, as it cannot support every beneficial digital safety service or activity, we suggest narrowing its strategic focus across five parameters to maximize impact:

  • Cybersecurity as the priority: While acknowledging the overlap between cybersecurity and other domains such as democracy promotion, human rights and misinformation, positive effects on other domains should be considered ancillary benefits rather than primary funding criteria.
  • Intersection with disinformation: The mechanism would not fund disinformation as a standalone priority but would support activities where cyber and disinformation intersect such as online fraud by impersonation, market manipulation or information operations using compromised infrastructure.
  • Civil resilience, not military/defence: Supported activities should focus on civil resilience and victim-centric measures and capacity building.
  • Capacity before compliance: In digitally nascent regions, the SCFM will prioritize building foundational capabilities ahead of compliance with international frameworks that presuppose capacities not yet in place.
  • Global equity and neutrality: Cybersecurity risk is not uniformly distributed. Emerging economies and least-developed countries face the greatest exposure relative to their capacity to respond, and they are least represented in global governance discussions. The SCFM will be guided by political neutrality, differentiated contributions and diverse geographic representation.

Ensuring the SCFM is beneficiary-centric

To ensure optimal outcomes, the mechanism must adhere to three operational principles that empower the organizations delivering critical frontline services.

First of all, infrastructure needs to be prioritized over specificity. Funding should prioritize broad capabilities and core infrastructure rather than being restricted to narrow, programme-specific silos, granting organizations the operational flexibility to pivot against evolving threats.

Loading...

Secondly, the mechanism needs to ensure consistency and longevity. To foster organizational stability, the SCFM will prioritize predictable, long-term allocations over large, volatile, one-time grants, while streamlining fragmented reporting structures.

The third operational principle is mixed funding models. The SCFM would legitimize mixed funding models, including allowing beneficiary organizations to implement cost recovery from capable users such as law enforcement agencies, while subsidizing users who cannot pay.

Funding architecture of the SCFM

Capital does not flow to problems it cannot price. For as long as cybersecurity is treated as a discretionary cost rather than a quantified systemic risk, the funding architecture for cyber as a global public good will remain donor-dependent, fragmented and vulnerable to political cycles. The SCFM should introduce economic legibility through five core pillars:

  • Avoided-loss modelling as a core output: The SCFM must publish rigorous, credible models demonstrating economic losses avoided through cyber resilience. This requires quantifying both the systemic disruption of offline infrastructure and the direct financial and societal toll of victim harm. This exercise is not a communications effort; it is the foundational work required to make cybersecurity more understandable to capital markets.
  • Risk-adjusted return framing for impact capital: To attract impact investors, foundations and development finance institutions, the mechanism must move beyond moral urgency to articulate a clear economic thesis based on market-rate risk-adjusted return logic.
  • Standardized resilience accounting: The SCFM will champion standardized frameworks to measure and report cyber resilience in economic terms, aligning with impact-weighted accounting to make digital health visible on financial balance sheets.
  • Civil resilience reclassification: The SCFM should actively advocate for the reclassification of cybersecurity from “military/defence” to “civil resilience” in OECD, development finance, and pension fund categorization systems. This misclassification currently prevents significant pools of capital from accessing the sector.
  • Embedded measurement: Impact measurement frameworks must be designed into the fund’s structure from inception, ensuring all grant recipients systematically generate data that proves their contribution to macroeconomic stability.

“Capital flows toward problems that demonstrate economic inevitability and material impact. For cyber: what is the material economic unlock? What economic problem does solving cyber resilience address? Impact must link to economic value,” says Fleur Heyns, CEO of Proof of Impact.

Brazil’s innovative initiative to improve SME cyber resilience

As governments and financial institutions explore new sustainable finance mechanisms for cybersecurity, Brazil is emerging as an example of innovation in cyber resilience funding for small and medium-sized enterprises (SMEs).

Through its Institutional Security Office of the Presidency of the Republic (GSI/PR) aligned with the National Cybersecurity Strategy (E-Ciber), Brazil is partnering with the Inter-American Development Bank, National Bank for Economic and Social Development (BNDES) and other institutions to create a subsidized credit model that combines financing with technical support, training, compliance assistance, maturity assessments and post-incident recovery.

The initiative reframes cybersecurity as an economic resilience issue rather than an IT cost. By improving SME access to affordable cyber resources, Brazil aims to reduce systemic cyber risk, strengthen supply chains, and improve the resilience of a sector that represents a major share of national employment and gross domestic product.

Through the Hackers do Bem (Good Hackers) initiative, the programme also offers training and free technical assistance while providing an employment opportunity for youth.

SCFM key to securing technical infrastructure of the global economy

The internet connects over two-thirds of the world’s population, serving as the foundational terrain for AI and emerging technologies. Its integrity deeply affects national security, economic prosperity, and public health and safety.

A sustainable, impactful, and transparent finance mechanism for cybersecurity is the baseline requirement to secure the technical infrastructure of our global economy and protect under-resourced organizations and people.

It is time to establish a sustainable cybersecurity finance mechanism if we are to realize the full upside of technological advances and make our digital public space safe and secure for all.

Authors of this blog were Global Future Council on Cybersecurity members Anna Maria Collard, SVP, Content Strategy & CISO Advisor Africa, KnowBe4; Ann Cleaveland, Executive Director, Center for Long-Term Cybersecurity, UC Berkeley; Hoda Al Khzaimi, Associate Vice-Provost for Research Translation and Entrepreneurship, New York University Abu Dhabi; Jamie Saunders, Oxford Martin Fellow,University of Oxford; Michael Daniel, President and Chief Executive Officer, Cyber Threat Alliance; and Sameer Suryakant Patil, Director, Centre for Security, Strategy and Technology, Observer Research Foundation (ORF).

Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

Why cyber resilience depends on trust

Mark Orsi, Keri Pearlson and Luna Rohland

August 3, 2026

3:29

The biggest threats to cybersecurity today, according to 5 experts

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum