2014-12-03-奥纬咨询-Combating_Cyber_Risk_4页_111kb
报告摘要
Summary of "Combating Cyber Risk: How to Attack a Growing Threat"
Overview
This report examines the rising threat of cyber attacks and outlines strategies for managing this risk in the context of modern digital connectivity. Advances in electronic connectivity have brought significant benefits, such as increased efficiency and consumer gains, but they have also expanded opportunities for crime. Cyber risk is presented as an unavoidable aspect of business operations, comparable to credit risk in banking, and requires proactive management.
Growth of Cyber Attacks
Cyberattacks have grown at a rate of 23% annually since 2010. Currently, there are approximately 116 registered attacks daily worldwide. The average annual cost to affected businesses ranges from $1 million to $9 million, due to factors like compensation payments, business disruption, reputational damage, ransom payments, or loss recovery.
Defense Strategies
Traditional cybersecurity approaches involve erecting barriers, such as strict access controls and identity verification, granting entry only to trusted users. However, this method is no longer feasible, as many business models depend on open computer systems and data exchange to function and provide services easily to customers.
Quantitative Risk Management
The first step in managing cyber risk is to assign a monetary value or cost, enabling firms to evaluate whether it is worth spending money to reduce risks. Cyber risk can be insured, with premiums serving as a cost metric. If an insurance premium or calculated capital requirement makes a venture unprofitable, it may not justify the risk. Scenario analysis is recommended for evaluating risks, as historical data is insufficient for rare events, and it should incorporate observed attack frequencies and potential copycat risks.
Enterprise-Wide Framework
Effective cyber risk management requires a holistic strategy developed across all organizational levels. Key components include establishing a governance structure for continuous monitoring, deriving security policies aligned with industry standards (e.g., PCI, ISO), selecting and training personnel with cybersecurity expertise, deploying secure technology infrastructure, designing physical security measures, and conducting regular audits to ensure compliance. This framework integrates cybersecurity into broader operational risk management.
Cross-Enterprise and Strategic Management
Cyber risk should be addressed as part of strategic decision-making by executives, boards, and cross-functional teams, similar to how operational risks are handled. It is simply a variant of operational risk, but its complexity and rapid evolution may require additional skills. The goal is to determine the acceptable level of risk and allocate resources for mitigation, using scenario analysis to identify "tripwires" that signal attacks and trigger preventative actions.
Conclusion
Cyber risk management is an evolving challenge that demands adaptation, with lessons from traditional risk approaches applicable to its unique aspects. By implementing a structured framework and recognizing cyber risk as integral to business, firms can better defend against threats.
试读结束,高清完整版pdf/doc/ppt,请点下载