信息风险洞察研究2025_36页_2mb
报告摘要
IRIS 2025 Summary: Information Risk Insights Study
Core Content
The Information Risk Insights Study (IRIS) 2025 provides a comprehensive analysis of cyber risk trends from 2008 to 2024, focusing on the frequency, likelihood, and financial impact of security incidents across different sectors and organization sizes.
Main Questions and Findings
Q1: Are Security Incidents Becoming More Common?
- The number of publicly reported or discovered security incidents has increased by 650% over the last 15 years, averaging 3,000 incidents per quarter in 2024.
- System intrusion remains the most common incident type, though the specific techniques used have evolved.
- Smaller businesses (<$100M annual revenue) experience the largest absolute number of incidents, but larger corporations (> $1B annual revenue) have a much higher relative incident frequency (620 times higher).
- Ransomware has seen a significant rise, while accidental disclosure and insider misuse have declined, likely due to increased awareness and better controls.
Q2: Do Incident Trends Differ Across Organizations?
- Smaller and midsize businesses (SMBs) are more frequently affected by incidents overall.
- Large enterprises (> $100B annual revenue) have a higher relative incident frequency compared to smaller firms.
- Public and Management sectors have historically had the highest relative incident frequency, possibly due to mandatory disclosure requirements.
- Finance and Information sectors also show high incident rates, while Energy and Supply Chain sectors are increasing in relative frequency.
- Professional Services have the highest loss magnitude, with median losses up 25x since 2008.
- Retail has seen a significant reduction in incident costs, possibly due to PCI compliance and Chip-and-Pin technology.
Q3: Is the Probability of Incidents Increasing?
- The annual probability of a firm experiencing a cyber event has almost quadrupled since 2008.
- Smaller firms (<$100M) have seen their incident probability more than double.
- Large organizations (> $100B) have experienced a 33% decrease in annualized incident probability.
- Manufacturing firms now have an 11% chance of an incident in the next 12 months, up from ~2% 15 years ago.
- Incident probability varies significantly by industry and firm size, reflecting evolving business models and threat landscapes.
Q4: Have Security Incidents Gotten More Costly?
- Median incident losses have increased 15-fold, from $190K to ~$3 million.
- Extreme (95th percentile) losses have risen 5-fold, reaching $32 million.
- Losses relative to annual revenue have increased by 8x on average.
- Large organizations experience higher absolute losses, but smaller businesses face greater relative impact.
- Professional Services have the highest median losses, up 25x since 2008.
- Retail has seen declining loss trends, suggesting improved security measures.
Q5: Do Loss Trends Differ Among Event Types?
- The overall loss distribution has a pronounced "shoulder", indicating a rise in smaller losses from accidental disclosure and insider misuse.
- Ransomware and system intrusion are the most costly incident types, with median losses rising significantly.
- Ransomware losses at the high end have surged past $27M, while system intrusion losses have dropped sharply from over $200M to ~$7.4M.
- Accidental disclosure and insider misuse now account for only ~5% of median costs, down from ~25% in 2008.
Key Risk Insights
- Incident frequency has increased significantly over the last 15 years, but relative frequency among large corporations is much higher.
- Incident probability has almost quadrupled for all organizations, with smaller firms experiencing the largest increase.
- Incident costs have exploded, with median losses rising 15x and extreme losses 5x.
- Losses relative to revenue have increased by 8x, highlighting the growing financial impact of cyber events.
- Industry and size matter in assessing cyber risk, as different sectors and firm sizes face distinct trends in both frequency and cost.
Methodology
- The study uses Zywave's Cyber Loss Data, which includes over 150,000 security incidents and associated financial losses.
- Data is compiled from public sources such as breach disclosures, public company filings, and legal records.
- The data is processed and enriched to support cyber risk analysis and trend modeling.
Conclusion
The IRIS 2025 underscores the dynamic and evolving nature of the cyber threat landscape. While incident frequency and likelihood have increased, loss magnitude and relative impact have also grown substantially. Organizations must adjust their risk assessments to reflect these changes, particularly in firmographic footprint and industry-specific trends. The study emphasizes the importance of contextual analysis and time-sensitive modeling to better understand and manage information risk.
试读结束,高清完整版pdf/doc/ppt,请点下载