2020网络安全风险报告(英文版)_17页_2mb
报告摘要
总结:Aon 2020 Cyber Security Risk Report
核心内容
Aon's 2020 Cyber Security Risk Report, titled Solving the Cyber Puzzle: The Unexpected Ways Cyber Risk Impacts Your Business, highlights the growing complexity of cyber risk and its impact across various business areas. The report outlines six less-appreciated areas of cyber risk: Intellectual Property, Mergers and Acquisitions, Retirement, Executives, Computer Crime, and The Corporation. It emphasizes the need for a holistic approach to managing cyber risk, combining technology, people, and processes in a circular strategy known as the Cyber Loop.
主要观点
- Cyber risk is not just a technology issue but an enterprise risk that affects business continuity, customer data, and financial stability.
- The report provides a playbook for each of the six areas to help organizations understand and mitigate cyber risk.
- A holistic and integrated approach is essential to manage the complexity of cyber threats effectively.
关键信息
1. Intellectual Property (IP)
- IP theft, including patents, trademarks, copyrights, data rights, and trade secrets, is a significant and growing risk.
- The value of IP has increased dramatically from $9.28 trillion to $25.03 trillion for the five largest companies from 2005 to 2018.
- IP theft is estimated to cost $1 trillion annually, yet less than one-third of companies have basic measures to protect trade secrets.
- IP is often more difficult to value and insure compared to traditional physical assets.
- Organizations should identify, tag, and classify critical IP to ensure it is protected both physically and digitally.
- Training employees on IP exposure and using advanced control technologies are vital steps.
2. Mergers and Acquisitions (M&A)
- M&A activity has increased significantly, with a 96% rise in global transactions from 2014 to 2017.
- Less than 10% of M&A deals include cyber security due diligence, often leading to post-deal assessments.
- Cyber risks can lead to legal, operational, and reputational consequences, including data breaches, IP theft, and regulatory noncompliance.
- Cybersecurity due diligence should be conducted pre-deal, including a cyber red flag review, dark web scans, and financial loss quantification.
- M&A insurance is becoming more popular, with 45% of North American deals using it in 2018.
- It is important to note that M&A insurance should not replace a dedicated cyber insurance policy.
3. Retirement
- Retirement plans hold sensitive personal data and are a gateway to large sums of money.
- These plans are increasingly accessed through online platforms and mobile devices, making them vulnerable to cyber breaches.
- ERISA (Employee Retirement Income Security Act) imposes fiduciary duties on plan administrators to protect data.
- Many organizations have false confidence in the security of retirement data, assuming it is held by the plan provider.
- Third-party record keepers may hold the data, and they can introduce additional risks.
- A gap assessment is crucial to identify vulnerabilities and implement protective measures.
- Incident response plans should consider privacy regulations and notification requirements.
- Cyber insurance and fiduciary liability insurance can be used to transfer risk and indemnify the company.
4. Executives
- C-level executives are 12 times more likely to be pursued and 9 times more likely to be victimized in cyber attacks.
- Social engineering and stolen credentials are common methods used to compromise executives' web-based email accounts.
- Financial motivation is a key driver in 71% of executive breaches, with attackers seeking ransomware or access to critical data.
- Identity theft and personal financial account breaches are also significant threats to executives.
- Personal cyber insurance is an evolving area that can help executives mitigate risks outside the corporate veil.
- Security technology such as identity theft monitoring, secure VPNs, and password managers is recommended for executives and their families.
5. Computer Crime
- Cybercrime is on the rise globally, with the FBI's IC3 reporting $2.7 billion in financial losses in 2018.
- Business Email Compromise (BEC) and Email Account Compromise (EAC) are growing threats, with 6,000 victims per month and over $12 billion in losses in less than five years.
- Ransomware has seen a 350% increase in 2018, with global damage costs predicted to reach $20 billion by 2021.
- These attacks can target both individuals and businesses, often through social engineering and pretending to be executives or vendors.
- Wire transfer authentication protocols are critical in preventing BEC and EAC attacks.
6. The Corporation
- Cyber risk is an enterprise risk, not just a technology concern.
- The Cyber Loop is a circular strategy that includes assessment, quantification, insurance, and incident response readiness.
- This approach is necessary to insulate the company from a variety of cyber risks.
- The report underscores the importance of collaboration between risk, technology, and human resources teams to address the multifaceted nature of cyber threats.
结论
The report emphasizes that cyber risk is complex and multifaceted, affecting various areas of business operations. A comprehensive and integrated strategy is essential to manage these risks effectively. Organizations must identify, assess, and protect their critical assets, and leverage insurance and training to mitigate potential losses. The Cyber Loop provides a framework for understanding and responding to cyber risk in a non-linear and strategic manner.
试读结束,高清完整版pdf/doc/ppt,请点下载