AON-2018年网络安全预测报告(英文版)-2018.1-26页-1mb
报告摘要
2018 Cybersecurity Predictions Summary
Core Content
The 2018 Cybersecurity Predictions report outlines the evolving landscape of cybersecurity risk management, emphasizing the need for a more integrated and enterprise-wide approach. It highlights the increasing sophistication and impact of cyber attacks, the role of regulatory pressures, and the necessity for businesses to adopt more comprehensive risk mitigation strategies.
Main Predictions
1. Businesses adopt standalone cyber insurance policies
- Key Point: As cyber attacks have demonstrated significant financial and operational impacts, businesses are expected to seek standalone cyber insurance policies to address these risks.
- Trend: Traditional insurance policies will increasingly exclude cyber-related losses, pushing companies to adopt dedicated cyber insurance.
- Data: Only 24% of risk management professionals reported having cyber insurance in 2017, despite 87% viewing cyber liability as a top business risk.
- Impact: Insurers will focus on developing enterprise-specific policies, and C-suite executives will be held personally accountable for cybersecurity failures.
2. Chief Risk Officers (CROs) take center stage
- Key Point: Cyber risk will be viewed as an enterprise risk, requiring collaboration between CROs and CISOs.
- Trend: CROs will play a more prominent role in modeling and assessing cyber risk across all business functions.
- Impact: Cybersecurity will move beyond IT departments and be integrated into broader risk management frameworks, especially in sectors like logistics, marketing, and manufacturing.
3. Regulatory spotlight widens and becomes more complex
- Key Point: Regulatory enforcement will intensify, with new rules and increased compliance demands.
- Trend: The EU's GDPR will be strictly enforced globally, while U.S. regulators like NYDFS will also intensify scrutiny.
- Impact: Companies across multiple sectors, including education and big data aggregators, will face new compliance requirements. There will be calls for regulatory harmonization to reduce complexity.
4. Criminals attack businesses embracing IoT
- Key Point: Small to mid-sized businesses (SMBs) providing IoT services to large organizations will become prime targets.
- Trend: Large organizations will need to reassess their third-party risk management strategies.
- Impact: SMBs will be forced to improve and document their cybersecurity measures, especially around IoT security, to remain competitive and avoid being exploited.
5. Multi-factor authentication (MFA) becomes standard practice
- Key Point: As passwords and biometrics are increasingly targeted, MFA will become essential for securing access.
- Trend: MFA will move from niche use to mainstream adoption, particularly in financial institutions and cloud platforms.
- Impact: Even with MFA, companies must remain proactive in testing and improving their security defenses as attackers continue to evolve their techniques.
6. Bug bounty programs go mainstream
- Key Point: Bug bounty programs will become a common practice for identifying and addressing vulnerabilities.
- Trend: Companies will leverage external experts and innovative methods to enhance their security posture.
- Impact: The adoption of bug bounty programs will be driven by the need for more robust security testing and the increasing value of non-physical assets.
Key Information
- Cyber Risk as Enterprise Risk: Cybersecurity will no longer be treated as an IT issue but as a core enterprise risk that affects all departments and functions.
- Regulatory Pressure: The GDPR will have global implications, and other regions will introduce stricter regulations. This will lead to increased compliance costs and a demand for harmonization.
- Insurance Market Changes: Cyber insurance will become more prominent, with a focus on comprehensive coverage and reduced "silent" cyber coverage in traditional policies.
- IoT Vulnerabilities: The proliferation of IoT devices will create new attack vectors, especially for large organizations relying on SMBs for services.
- MFA and Biometrics: While biometrics are being adopted, they are not foolproof, and MFA will be essential to mitigate risks.
- Bug Bounty Programs: These programs will be used more widely to identify and reward security researchers for finding vulnerabilities.
Conclusion
The 2018 report underscores the shift from siloed, IT-centric approaches to a more integrated, enterprise-wide view of cybersecurity. It predicts increased regulatory scrutiny, the rise of cyber insurance, and the mainstream adoption of MFA and bug bounty programs. The report calls for a collaborative approach involving CROs, CISOs, and other executives to better understand and manage cyber risk.
试读结束,高清完整版pdf/doc/ppt,请点下载