2016年-数据局_普华永道:2016年全球信息安全状况®调查-网络安全领域的转变和转型_EN_32页_2mb
报告摘要
Summary of "Turnaround and Transformation in Cybersecurity"
Core Content
This document presents key findings from the Global State of Information Security® Survey 2016, highlighting the increasing importance of cybersecurity in today's digital landscape. It outlines how organizations are responding to the growing threat of cyberattacks by adopting innovative strategies and technologies, and how the role of executives and the board is evolving in this context.
Main Points and Key Information
1. Rising Cybersecurity Risks
- Cyberattacks are increasing in frequency, severity, and impact, with traditional prevention and detection methods proving ineffective.
- 38% of organizations have seen an increase in detected information security incidents.
- Cybersecurity is now a top priority for many executives, who see it as a defining risk for the generation.
- Technological change is disrupting business models and increasing exposure to cyber threats, especially with the rise of data analytics, digitization, and cross-industry service blending.
- Over-regulation and nation-state cyberattacks are also seen as long-term disruptive trends.
2. Enterprise-Wide Cybersecurity Strategy
- Most organizations are adopting a risk-based cybersecurity framework, often combining multiple standards such as ISO 27001 and NIST Cybersecurity Framework.
- These frameworks help in identifying, prioritizing, and measuring cybersecurity risks, as well as improving internal and external communication.
- Examples include CIBC using a scorecard to assess the maturity of its security program based on framework controls.
3. Cloud-Enabled Cybersecurity
- Cloud computing is central to modern cybersecurity efforts, enabling advanced threat detection, real-time monitoring, and scalable analytics.
- Cloud providers offer massive processing power and technical expertise, making them ideal for handling complex cybersecurity tasks.
- Global Payments uses a private cloud to aggregate and filter security alerts, while Steelcase leverages cloud-based managed services for advanced authentication, threat monitoring, and network analysis.
4. Big Data and Cybersecurity
- Big Data analytics is being used to model and monitor threats, detect anomalies, and improve response times.
- It allows organizations to shift from perimeter-based security to a more data-driven approach, offering better visibility into both external and internal threats.
- CIBC is testing a new analytics-based threat detection system to enhance its SIEM capabilities.
- Steelcase found that Big Data also helps in identifying non-security-related issues, such as network performance problems.
5. Advanced Authentication
- Passwords are increasingly seen as inadequate, leading to the adoption of advanced authentication methods.
- 91% of survey respondents have implemented advanced authentication, including two-factor authentication, biometrics, and hardware tokens.
- USAA uses facial, voice, and fingerprint recognition to enhance customer access security.
- Google has developed a USB-based Security Key using the FIDO Alliance's U2F standard for secure two-factor authentication.
- Mobile payment systems are also leveraging tokenization to protect customer data, with 57% of respondents adopting mobile payment systems.
6. The Internet of Things (IoT)
- The IoT ecosystem is expanding rapidly, with 30 billion connected devices expected by 2020.
- This growth brings new security challenges, especially with embedded systems, consumer technologies, and operational systems.
- 34% of organizations have a security strategy for IoT, emphasizing the need for privacy and cybersecurity standards.
- Steelcase is working with start-ups and universities to understand IoT security and privacy requirements, aiming to "design in" security into its platforms.
- Smart city projects, such as those involving GE Lighting, highlight both the benefits and privacy concerns of IoT integration.
7. Mobile Payments and Cybersecurity
- 57% of organizations have adopted mobile payment systems, which introduce new cybersecurity risks.
- Risks include malware/malicious apps (57%), hardware/device platform issues (45%), and verification processes (45%).
- Uber is cited as a game-changer in mobile payments due to its seamless, token-based payment process.
- The document emphasizes the need to balance security with user experience.
8. Collaboration and Cybersecurity Intelligence
- External collaboration is becoming more common, with 57% of organizations engaging in information sharing with peers and ISACs.
- Information sharing improves threat awareness and intelligence, but challenges include lack of framework standards, incompatible data formats, and slow communication.
- The US government has introduced ISAOs (Information Sharing and Analysis Organizations) to enhance inter-industry and cross-sector collaboration.
- The European Parliament has also approved a Network and Information Security Directive to promote cooperation and information sharing.
9. Cybersecurity Insurance
- Cybersecurity insurance is becoming a critical tool for mitigating financial risks from cyberattacks.
- The global cyberinsurance market is expected to grow from $2.5 billion to $7.5 billion by 2020.
- Insurance covers data destruction, denial of service attacks, theft, and extortion, as well as incident response and remediation.
Conclusion
The document underscores the need for a comprehensive, integrated approach to cybersecurity that includes risk-based frameworks, cloud computing, Big Data analytics, advanced authentication, and collaboration. It highlights the growing complexity of the threat landscape and the importance of innovation and proactive measures to ensure resilience, trust, and compliance in an increasingly connected world.
试读结束,高清完整版pdf/doc/ppt,请点下载