2015年-普华永道全球__Key_findings_from_the_2015_US_State_of_Cybercrime_Survey_16页_667kb
报告摘要
2015 US State of Cybercrime Survey Summary
Core Content
The 2015 US State of Cybercrime Survey highlights the growing concerns and challenges surrounding cybersecurity in the United States. Conducted by PwC, CSO, the CERT® Division of the Software Engineering Institute at Carnegie Mellon University, and the United States Secret Service, the survey gathered insights from over 500 executives across various sectors, including businesses, law enforcement, and government agencies. The report also draws on previous PwC research to provide a comprehensive overview of current cybersecurity trends and risks.
Main Findings
Cybercrime Concerns Rise
- 76% of respondents reported increased concern about cyberthreats in 2015 compared to the previous year, up from 59% in 2014.
- Cybersecurity incidents are becoming more frequent, destructive, and widespread, with 79% of respondents detecting at least one incident in the past 12 months.
- Larger organizations are better at detecting incidents, with large businesses detecting 31 times more incidents than small ones.
Increasing Cyber Threats
- Cyberattacks are becoming more public and damaging, with DDoS attacks cited as one of the most frequent types, affecting 18% of respondents.
- Phishing remains a significant threat, with 31% of respondents reporting attacks in 2014.
- Ransomware is on the rise, with 13% of respondents affected in 2014, and expected to increase further.
Industry-Specific Spending Trends
- The retail and consumer products industry significantly increased information security spending due to high-profile attacks.
- 38% of retail and consumer companies increased their security budgets by 20% or more, far exceeding other industries.
- Large companies are more likely to boost cybersecurity spending, with 20% increasing budgets by 20% or more in 2014.
- Healthcare organizations are expected to increase spending due to new types of attacks and regulatory pressures.
Board Engagement in Cybersecurity
- 49% of Boards still view cybersecurity as an IT matter rather than an enterprise-wide risk.
- 26% of respondents said their CISO or CSO presented to the Board only once a year.
- 30% of respondents said no Board members were engaged in cyber-risk discussions.
- The NACD recommends that the full Board, not just a committee, should oversee cybersecurity risks.
Importance of Proactive Board Involvement
- Cybersecurity should be treated as a strategic and cross-functional risk, not just an IT issue.
- 7 reasons are provided for why cybersecurity is a Board oversight issue:
- Cybersecurity impacts are systemic.
- Financial implications can be severe.
- Compliance with evolving regulations is becoming more complex.
- The Internet of Things introduces new risks.
- Cybersecurity insurance is essential.
- Adversaries are increasingly coordinated and sophisticated.
- Cyberattacks can disrupt strategic objectives and brand reputation.
Information Sharing and Cybersecurity Frameworks
- Information sharing is critical for threat awareness and response.
- ISAOs (Information Sharing and Analysis Organizations) are expected to offer more flexibility than current ISACs (Information Sharing and Analysis Centers).
- 75% of cyberattacks spread within 24 hours, highlighting the need for real-time threat intelligence.
- Standardized formats like TAXII, STIX, and CybOX are being promoted to enhance information sharing.
Third-Party Risk Management
- 62% of respondents evaluate third-party security risks, while only 42% consider supplier risks.
- 19% of C-suite executives are not concerned about third-party cyber risks.
- Only 16% of respondents evaluate third-party cybersecurity more than once a year.
- Regulators in the financial services industry are taking a more active role in enforcing due diligence of third-party suppliers.
Strategic Role of the CISO
- The CISO or CSO is increasingly seen as a strategic leader, not just an IT function.
- In small organizations, the CISO typically reports to the CEO.
- In medium-sized companies, the CISO reports to the CIO.
- In large companies, the CISO often reports to the CIO or the Board.
- The role of the CISO is evolving to include risk management, corporate governance, and communications.
Key Takeaways
- Cybersecurity is a growing concern across all sectors, with increased frequency and impact of incidents.
- Larger organizations are better equipped to detect and respond to threats due to greater resources and maturity.
- The CISO's role is expanding, requiring a broader skill set and higher visibility within the organization.
- Boards must take a more active role in cybersecurity oversight, treating it as an enterprise-wide risk.
- Information sharing and third-party risk management are becoming critical components of a robust cybersecurity strategy.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载