FireEye-网络风险不断演变:亚太企业增强网络风险应变能力势在必行(英文版)-2018.10-24页-3mb
报告摘要
Summary of "CYBER EVOLUTION: En Route to Strengthening Resilience in Asia-Pacific"
Core Content
This white paper explores the evolving cyber threat landscape in the Asia-Pacific (APAC) region, highlighting the increasing sophistication of cyber attacks and the critical need for improved cybersecurity resilience. It emphasizes the region's vulnerability due to low investment in cybersecurity, lack of awareness, and the shortage of skilled professionals. The paper also discusses the regulatory developments and provides recommendations for companies to enhance their cyber resilience strategies.
Main Points
Cyber Threat Landscape in APAC
- The cyber threat landscape is rapidly changing, with attackers becoming more sophisticated and leveraging digital interconnectivity to expand their attack surface.
- Cyber attacks are not limited to the region; incidents from North America and Europe significantly impact APAC, causing financial and personal data losses, as well as business interruptions.
- APAC has the highest dwell times globally, indicating that cyber threats often go undetected for a long period before being identified.
Key Cyber Trends in APAC
- Financial Motivation: Cyber attacks with financial motives are perceived as the top threat (39% of respondents).
- Insider Threats: These are the second-largest concern (54%), including both malicious intent and human error.
- Ransomware and DDoS Attacks: Notable incidents such as WannaCry and Petya have caused widespread disruption and financial loss, with WannaCry estimated to have cost up to $4 billion globally.
- Targeted Industries: Financial services, energy and utilities, and telecommunications are the most frequently targeted sectors, with cyber crime being a top concern.
Cyber Risk Perception
- Cyber risk is perceived as a top concern across APAC, but the region's preparedness is lagging.
- Only 58% of global respondents and 50% of Pacific-based companies estimate the financial impact of a cyber incident.
- Many companies lack awareness of their cyber exposure and are unprepared for potential attacks.
Key Drivers of Cyber Challenges
- Geopolitical Tensions: These create an environment conducive to cyber espionage and intelligence gathering.
- Exposed Critical Infrastructure: Essential services such as energy, transportation, and healthcare remain vulnerable to increasingly frequent and sophisticated attacks.
- Cybersecurity Talent Shortage: A global shortage of cybersecurity professionals (projected to reach 1.5 million by 2020) exacerbates the challenges in securing networks and responding to threats.
Key Information
- Dwell Time: APAC companies have significantly longer dwell times than their global counterparts, with a median of 172 days in 2016 compared to the global median of 99 days.
- Regulatory Climate: Most APAC countries do not have mandatory breach notification laws, leading to a lack of transparency and underreporting of cyber incidents.
- High-Profile Attacks: Examples include the WannaCry ransomware attack, which impacted over 29,000 institutions and 15% of universities' IP addresses, and the Petya ransomware attack in Australia, which demanded $300 in Bitcoin per incident.
Recommendations for Building Cyber Resilience
Prepare
- Understand Cyber Risk Exposure: Conduct industry benchmarking, quantify risks, and map threat vectors.
- Scenario Analysis: Prepare for potential outcomes of cyber incidents by analyzing different attack scenarios.
- Testing and Drills: Regularly test preparedness through tabletop exercises and live-fire drills to improve response capabilities.
Prevent
- Strengthen Internal Capabilities: Invest in infrastructure protection and network security.
- Talent Management: Attract and retain cybersecurity professionals to bolster internal expertise.
- Proactive Incident Prep: Conduct regular incident response simulations to ensure readiness.
Respond
- Incident Response Procedures: Develop clear and effective procedures for detecting, responding to, and recovering from cyber incidents.
- Threat Intelligence: Utilize comprehensive threat intelligence to identify and mitigate risks.
- Security Hygiene: Promote good security practices to prevent vulnerabilities from being exploited.
Call to Action
- Governments and businesses must recognize the severity of cyber risks and take active steps to address them.
- Collaboration between cybersecurity experts and legal advisors is essential to ensure compliance with both current and emerging regulations.
- The regulatory climate in APAC is slowly evolving, with countries like Singapore and Australia moving towards mandatory breach notification laws.
- Cyber resilience should be a strategic priority for all organizations operating in the region, given the increasing frequency and severity of cyber threats.
Conclusion
The Asia-Pacific region faces a growing and complex cyber threat landscape. Despite the region's economic importance, it remains underprepared for cyber incidents due to low investment, lack of awareness, and insufficient regulatory frameworks. Companies must adopt a more holistic approach to cybersecurity, focusing on preparation, prevention, and response, to build and maintain resilience in the face of evolving threats.
试读结束,高清完整版pdf/doc/ppt,请点下载