2016年-德勤全球_Global_Cyber_Executive_Briefing_41页_3mb
报告摘要
Global Cyber Executive Briefing Summary
Core Content
This executive briefing explores the critical importance of cyber-threat management in today's digital world. It emphasizes that cybersecurity is not just a strategic concern but a fundamental part of doing business. The report highlights that breaches are inevitable, and no industry or organization is immune. It provides real-world examples and insights to help executives and board members better understand and manage cyber-risks.
Key Industry Sectors
The report focuses on seven key industry sectors that are prime targets for cyberattacks:
- High Technology
- Insurance
- Online Media
- Manufacturing
- Telecommunications
- Retail
- E-Commerce & Online Payments
Each sector is analyzed for the types of cyber-threats, attackers, techniques, and business impacts.
Main Points
- Cybersecurity is essential: In a world driven by digital technologies, cyber-threat management is crucial for business continuity and reputation.
- Breaches are inevitable: Every organization is at risk, and the threat landscape is evolving rapidly.
- Cyber threats are diverse: They include both external and internal actors, ranging from state-sponsored hackers to hacktivists and organized crime groups.
- Cybersecurity is a shared responsibility: Organizations must work together to build a resilient cyber-space and protect against threats that can impact multiple sectors.
- Three key characteristics of a well-balanced cyber-defense:
- Secure: Focus on protecting critical assets.
- Vigilant: Establish threat awareness and detection capabilities.
- Resilient: Develop the ability to contain damage and minimize impact.
Key Threats and Impacts
High Technology
- Who: State actors, insiders, hacktivists, competitors
- What: Intellectual property, personal identifiable information (PII), backdoors in critical products
- Business Impact: Loss of competitive advantage, financial losses, reputational damage, and legal consequences
- Case Examples:
- Fraudulent certificates: Led to bankruptcy and national security breaches
- Stolen customer data and source code: Caused reputational damage and financial losses
- Hacktivist attacks: Resulted in service shutdowns and reputation damage
Online Media
- Who: Cybercriminals, hacktivists, script kiddies
- What: Email addresses, news content, trusted information resources
- Business Impact: Reputational damage, spread of propaganda, manipulation of public opinion
- Case Examples:
- Email addresses stolen: Resulted in customer compensation costs of $200 million
- Banking malware outbreak: Caused trust issues in online advertising
- Fake news redirection: Tarnished reputation and credibility
Telecommunications
- Who: Cybercriminals, script kiddies, state actors
- What: Customer data, communications data, leased infrastructure
- Business Impact: Loss of customer trust, confidential information, reputational damage
- Case Examples:
- False claims of attacks: Forced shutdowns of critical services
- Stolen laptop with customer data: Highlighted the risk of sensitive data loss in call centers
- State-sponsored surveillance: Used APT attacks to target communication channels
Key Takeaways
- Cybersecurity is not just a technical issue but a strategic and reputational concern.
- Threats are becoming more sophisticated and persistent, and organizations must be prepared to handle them.
- Awareness at the C-suite and board level is essential for building a resilient cyber-defense.
- Collaboration across sectors is necessary to create a secure digital ecosystem.
- The report references real-world data breaches and attack patterns from the Verizon 2014 Data Breach Investigations Report, showing that web app attacks are the most frequent (35%) and cyber-espionage is a growing concern (22%).
Conclusion
This briefing serves as a starting point for organizations to assess their cyber threat profiles and develop strategic and practical approaches to enhance their cybersecurity posture. It underscores the importance of resilience in the face of inevitable cyberattacks and encourages collaboration and information sharing to improve overall cyber defenses.
试读结束,高清完整版pdf/doc/ppt,请点下载