2025年网络安全弹性报告_33页_3mb
报告摘要
Executive Summary
Allianz Commercial's "Cyber Security Resilience 2025" report highlights a complex and evolving threat environment. Key points include:
- Reduced Attack-Driven Claims: The frequency and severity of attack-driven claims dropped in 2025, but the risk landscape broadened to include non-attack incidents like technical failures and privacy litigation, which accounted for 28% of large claims in 2024.
- Ransomware Shift: While ransomware remains the top loss driver, it shifted to mid-sized and less protected firms in 2025. Data exfiltration became a significant threat, leading to higher losses.
- Expanding Risks: Retailers, healthcare, and education sectors are particularly targeted. Supply chain dependencies and contingent business interruption (CBI) are key emerging threats.
- Role of AI: AI is being used by threat actors to enhance attacks (e.g., more effective phishing) but also helps defenders improve detection and response.
- Regulatory Trends: Regulations like GDPR, DORA, and NIS2 (EU) are raising cyber resiliency standards, requiring better incident reporting and supply chain management.
- Cyber Insurance Market: Demand for cyber insurance is growing, especially among mid-sized firms. Insured companies are investing more in security measures, creating a growing resilience gap.
- Best Practices: Effective cybersecurity hygiene, robust incident response strategies, tabletop exercises, and employee training are crucial for reducing costs. AI-powered tools are highlighting the need for greater investments in cyber security.
The report concludes that cyber insurance remains essential, providing both financial protection and access to expertise to enhance resilience. The global cyber insurance market is expected to grow significantly.
Analysis Summary
1. Key Findings and Trends
- Decline in Attack-Driven Claims: Attack-driven losses (60% of covered values) decreased due to improved defenses (multi-factor authentication, segmentation), but non-attack losses grew due to technical failures and privacy litigation.
- Ransomware Evolution: Adapted toward mid-sized firms; data exfiltration became prevalent, with losses nearly doubling those without it.
- Emerging Risks: Retailers and highly connected sectors are key targets. Supply chain failures caused 15% of high-value claims.
- AI Impact: AI automates and escalates attacks. Defenders use AI for detection and response, reducing costs (e.g., ~$2.2m saved by AI users vs. $8M for non-users).
- Regulatory Expansion: DORA and NIS2 are pushing resilience requirements across sectors, including supply chains, presenting implementation challenges.
- Cyber Insurance Penetration: Growth is notable in smaller firms and new markets, but awareness of policy terms remains low.
2. Most Impacted Sectors
- Retailers (24% share of claims), manufacturing, and professional services are most affected, driven by high revenues, personal data volumes, and supply chain dependencies.
3. Insurance Implications
- Cyber insurance underwriting includes financial protection and risk management services, but insurers face challenges from increasing litigation (privacy class actions, AI litigation) and supply chain complexities.
- Insureds exhibit greater resilience compared to uninsured companies, a trend expected to widen due to investments in MFA, cybersecurity, and tabletop exercises.
4. Recommendations
- Strengthen multi-factor authentication and supply chain controls.
- Use AI-focused tools for proactive threat management.
- Conduct regular tabletop exercises for incident response preparedness.
- Stay compliant with evolving data privacy regulations.
- Increase awareness of cyber insurance co-management requirements.
By addressing gaps in cybersecurity protocols, enhancing AI-driven capabilities, and strategically leveraging insurance coverage, firms can mitigate risks in this evolving threat landscape.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载