埃森哲-网络攻击成本报告(网络安全)(英文)-2019.6-43页_895kb
报告摘要
Summary of THE COST OF CYBERCRIME Study
Core Content
The Ninth Annual Cost of Cybercrime Study provides a comprehensive analysis of the economic impact of cybercrime and offers insights into how organizations can improve their cybersecurity strategies to reduce costs and unlock new revenue opportunities. The study is conducted by Accenture Security in collaboration with the Ponemon Institute, covering 11 countries and 16 industry sectors, with data collected from over 2,600 senior security professionals.
Main Findings
Cybercrime Evolution
- Evolving Targets: Cyberattacks are increasingly targeting core systems, such as industrial control systems (ICS), to disrupt and destroy rather than just steal data.
- Evolving Impact: Data integrity is now a major concern, with attacks leading to data destruction or alteration, which can damage trust and reputation.
- Evolving Techniques: Cybercriminals are using more sophisticated methods, including phishing and malicious insiders, to exploit human vulnerabilities. Nation-state attacks are also changing the nature of cyber threats and recovery processes.
Humans as the Weakest Link
- Employees are often the root cause of successful cyberattacks, either through accidental actions or intentional insider threats.
- Training and awareness programs are underfunded and critical for reducing human-related risks.
- A collaborative approach involving HR, legal, and IT teams is necessary to embed cybersecurity into organizational culture.
Benchmarking Cybersecurity Investment
- More Attacks, Higher Costs: The number of cyberattacks and the associated costs have increased over the past few years. In 2018, the average number of security breaches rose to 145, up from 130 in 2017.
- Cost Trends: The average annual cost of cybercrime increased by 12% from $11.7 million in 2017 to $13.0 million in 2018.
- Industry Impact: Banking and Utilities industries had the highest costs, with increases of 11% and 16%, respectively. The Health industry saw a slight decrease in costs.
- Country Analysis: The U.S. had the highest average annual cost of cybercrime at $27.4 million, while the U.K. experienced the highest increase (31%) to $11.5 million.
Value at Risk from Cybercrime
- Over the next five years, the total value at risk from cybercrime is projected to be $5.2 trillion.
- Indirect Attacks: These could account for 23% of the total value at risk, emphasizing the need for collaboration across the supply chain.
- Industry-Specific Risks: High Tech, Life Sciences, and Automotive industries face the highest value at risk, at $753 billion, $642 billion, and $505 billion, respectively.
Key Recommendations
Improving Cybersecurity Protection
- Attack Costs: All types of cyberattacks are becoming more expensive. Malware and ransomware have seen the highest increases, with ransomware costs rising by 21% in the last year.
- Consequences of Cybercrime: The main consequences include business disruption, information loss, revenue loss, and equipment damage. Information loss is the most costly, at $5.9 million annually.
- Investment Prioritization: Organizations should focus on malware, Web-based attacks, and malicious insiders to reduce information loss. For business disruption, efforts should target denial-of-service attacks, malicious insiders, and malware.
Targeted Investments
- Organizations should invest in security technologies that offer the most value in terms of cost savings, such as advanced identity and access management, which provides a net saving of $1.83 million.
- Security Intelligence and Threat Sharing: Widely adopted by 67% of organizations, it provides the highest cost savings at $2.26 million.
- Automation and AI: These technologies are gaining traction, with 38% of organizations using them, offering $2.09 million in savings.
Unlocking Cybersecurity Value
- Three Steps to Unlock Value:
- Invest in security technologies that reduce the risk of attacks and associated costs.
- Improve employee training to mitigate human-related vulnerabilities.
- Collaborate across the supply chain to enhance overall security posture and reduce indirect threats.
About the Research
- The study includes a framework for analyzing cybersecurity costs, benchmarking methods to evaluate investment levels, and a sample of over 2,600 senior security professionals.
- Limitations include the reliance on self-reported data and the exclusion of certain costs, such as those related to maintaining a secure posture or compliance with standards.
Conclusion
The study highlights the increasing economic burden of cybercrime and the urgent need for organizations to invest in cybersecurity. It underscores the importance of human-centric security, technological innovation, and collaborative efforts in mitigating risks and unlocking value. By understanding the evolving nature of cyber threats and their financial impact, businesses can make informed decisions to protect their assets and drive growth.
试读结束,高清完整版pdf/doc/ppt,请点下载