2018-网络风险不断演变_亚太企业增强网络风险应变能力势在必行(英文版)-3mb
报告摘要
Summary of CYBER EVOLUTION: En Route to Strengthening Resilience in Asia-Pacific
Core Content
This white paper explores the evolving cyber threat landscape in the Asia-Pacific (APAC) region, emphasizing the need for stronger cyber resilience among businesses. It highlights the increasing sophistication of cyber threats, the lack of preparedness in many APAC countries, and the urgent call for improved cybersecurity measures and regulatory frameworks.
Main Points
-
Cyber Threat Landscape: Cyber threats are becoming more complex and frequent, with attackers leveraging both digital and physical interconnections to expand their attack surface. The region remains highly vulnerable due to limited cybersecurity investments and long dwell times.
-
Cyber Resilience Importance: Cyber risks are now a top concern for businesses in APAC, particularly in financial services, energy and utilities, and telecommunications. These sectors are frequently targeted, indicating the need for higher awareness, stronger mitigation, and improved cybersecurity postures.
-
Dwell Time: APAC companies have significantly longer dwell times (the time between network intrusion and threat detection) compared to global averages. In 2016, the median dwell time in APAC was 172 days, which is almost double the global average of 99 days. This highlights the region's poor detection capabilities.
-
Cyber Risk Perception: According to the Marsh/Microsoft Global Cyber Risk Perception Survey 2017, over half (58%) of global respondents from major industries rank cyber as one of the top five risks. However, only 50% of companies in the Pacific estimate the financial impact of a cyber incident, indicating a lack of preparedness.
-
Cyber Threats: Financially motivated cyber attacks are the most common threat in APAC, followed by insider threats. The WannaCry ransomware attack in 2017, which affected over 29,000 Chinese institutions, is a notable example of the scale and impact of cyber incidents.
-
Key Drivers of Cyber Challenges:
- Geopolitical Tensions: These create an environment conducive to cyber espionage and other intelligence activities.
- Exposed Critical Infrastructure: Many APAC countries have not adequately secured their critical information infrastructure (CII), making them vulnerable to attacks that could disrupt essential services.
- Cybersecurity Talent Shortage: A significant lack of skilled cybersecurity professionals hampers the region's ability to defend against and respond to cyber threats effectively.
-
Regulatory Climate: Most APAC countries do not have mandatory breach notification laws, contributing to a lack of transparency and underreporting of cyber incidents. However, countries like Singapore and Australia are moving toward implementing such laws.
-
Call to Action: The paper urges businesses and governments to recognize cyber risks as a critical enterprise concern and to take proactive steps to build resilience. This includes investing in cybersecurity, improving threat detection, and aligning with evolving regulatory requirements.
Key Information
-
Financial Services: 31% of FireEye clients in APAC were targeted in cyber attacks, with threats including client-side exploitation, payment card data breaches, and bypassing multi-factor authentication.
-
Energy and Utilities: 10% of FireEye clients in APAC were targeted, with attacks focusing on operational technology (OT) systems that control essential services such as energy and water supply.
-
Telecommunications: 9% of FireEye clients in APAC were targeted, often due to the sector's critical role in both civilian and military operations, and its exposure through the Internet of Things (IoT) and new technologies.
-
Dwell Time Statistics:
- APAC median dwell time: 172 days (2016)
- Global median dwell time: 99 days (2016)
- Dwell time is primarily due to low investment in cybersecurity measures and poor preparedness.
-
Regulatory Developments:
- Singapore and Australia are planning to implement mandatory breach notification laws by 2018.
- The US and EU have stricter breach notification laws, with the EU requiring 72-hour reporting.
-
Cyber Insurance Challenges: Many APAC companies face over-priced cyber insurance with limited effectiveness in mitigating actual risks, due to a lack of good quality actuarial data.
Recommendations
- Invest in Cybersecurity: Companies should allocate resources to examine and enhance their information security programs.
- Understand Cyber Risk Exposure: Conduct industry benchmarking, risk quantification, and threat profiling to better assess vulnerabilities.
- Strengthen Internal Capabilities: Develop robust detection, response, and prevention mechanisms to protect against both insider and external threats.
- Improve Cyber Awareness: Companies must raise awareness among employees and invest in training to reduce human error and improve security hygiene.
- Collaborate with Legal Counsel: Ensure compliance with current and emerging data privacy and security regulations.
Conclusion
The Asia-Pacific region is facing a rapidly evolving and increasingly sophisticated cyber threat landscape. Despite the growing awareness of cyber risks, many APAC countries still lack the necessary preparedness, regulatory frameworks, and cybersecurity talent to effectively counter these threats. The paper calls for a unified and proactive approach to cyber resilience, emphasizing the importance of investment, awareness, and collaboration between businesses and governments.
试读结束,高清完整版pdf/doc/ppt,请点下载