2018年网络安全预测报告(英文版)_24页_775kb
报告摘要
2018 Cybersecurity Predictions Summary
Core Content
The 2018 Cybersecurity Predictions report outlines the evolving nature of cyber risk and its increasing integration into enterprise risk management. It emphasizes the shift from viewing cybersecurity as an IT issue to a broader enterprise risk that affects all functions and departments. The report highlights the growing sophistication and scale of cyber attacks, the increasing regulatory scrutiny, and the need for organizations to adopt more comprehensive and proactive cybersecurity measures.
Main Points
1. Cyber as Enterprise Risk
- Cyber risk is no longer confined to IT; it affects business operations, financial stability, and organizational reputation.
- The 2017 cyber attacks, such as WannaCry and NotPetya, demonstrated the real-world impact of cyber threats, leading to operational disruptions, financial losses, and executive resignations.
- As a result, boards and executives are becoming more aware of their liability in managing cyber risks, prompting a shift in how organizations approach cybersecurity.
2. Adoption of Standalone Cyber Insurance Policies
- More businesses will adopt standalone cyber insurance policies to address the full spectrum of cyber-related risks.
- Traditional insurance policies will increasingly exclude cyber coverage, pushing companies to seek specialized policies.
- Cyber insurance will be more prevalent in sectors beyond retail, financial services, and healthcare, including manufacturing, utilities, and transportation.
3. Chief Risk Officers (CROs) Take Center Stage
- CROs will collaborate closely with CISOs and other executives to manage cyber risk holistically.
- Cyber risk will be integrated into broader enterprise risk management frameworks, breaking down silos.
- CROs will use advanced modeling tools and data analytics to assess the operational and financial impact of cyber threats.
4. Regulatory Pressures Intensify and Become More Complex
- Regulators will enforce existing cybersecurity laws more strictly and introduce new regulations.
- The EU's GDPR will have global implications, with strict enforcement and high fines (up to 4% of global revenue or €20 million).
- U.S. regulators, including NYDFS, will continue to enforce cybersecurity standards, particularly in the financial sector.
- Companies will face increasing compliance burdens and will push for regulatory harmonization.
5. Third-Party Risk Management Gains Importance
- Large organizations will face cyber risks through their vendors and contractors, particularly those using IoT.
- The report predicts a major breach of a small to mid-sized company (SMB) will have a cascading effect on larger organizations.
- SMBs will be under pressure to improve their cybersecurity practices and demonstrate better security around IoT devices.
6. Multi-Factor Authentication (MFA) Becomes Standard Practice
- As passwords and biometrics become increasingly vulnerable, MFA will be adopted more widely.
- MFA will be used in customer service, online banking, and cloud platforms to enhance security.
- Despite its benefits, MFA will not be a foolproof solution, and attackers will continue to find ways to bypass it.
Key Information
-
Cyber Insurance Trends:
- 24% of risk management professionals reported their companies had cyber insurance in 2017.
- 87% viewed cyber liability as one of their top ten business risks.
- Cyber insurance will expand to include more comprehensive coverage, moving away from "silent" coverage in other policies.
-
Regulatory Enforcement:
- GDPR fines can reach up to 4% of global revenue or €20 million.
- Compliance will become more complex, and companies will demand alignment across regulations.
-
Third-Party Risks:
- 55% of small businesses reported breaches between 2015 and 2016, but few viewed it as a critical issue.
- Cyber attacks on SMBs can have a significant impact on larger organizations.
-
Authentication Trends:
- 81% of hacking-related breaches involved stolen or weak passwords.
- Biometrics will be adopted more widely, but they are also vulnerable to attacks.
- MFA will become standard, with companies requiring at least two forms of authentication.
Bottom Line
In 2018, cybersecurity will be treated as a core enterprise risk, not just an IT concern. The adoption of standalone cyber insurance policies, increased regulatory scrutiny, and the integration of MFA and other advanced security measures will be key trends. CROs will play a central role in managing these risks, and organizations will need to improve third-party risk management, particularly with the growing use of IoT. The year will mark a significant shift in how businesses approach and mitigate cyber threats.
试读结束,高清完整版pdf/doc/ppt,请点下载