埃森哲-网络弹性创新(英文)-2020.5-48页_2mb
报告摘要
Third Annual State of Cyber Resilience Summary
Core Content
This report, Third Annual State of Cyber Resilience, explores the current state of cybersecurity and cyber resilience across organizations, focusing on how leaders are outperforming non-leaders in key areas. It highlights the growing complexity of the cyber threat landscape, the challenges of cost sustainability, and the need for strategic innovation in cybersecurity practices.
Main Findings
Where Are We Now?
-
Investment in innovation grows:
- Leaders are doubling their investment in advanced technology, with 82% spending more than 20% of their cybersecurity budgets on AI, ML, and RPA.
- Overall, 84% of organizations now spend more than 20% of their cybersecurity budgets on these technologies, up from 67% three years ago.
-
The basics seem better:
- Direct attacks have dropped by 11% over the last year.
- Security breaches have decreased by 27%, indicating improved basic cybersecurity hygiene.
-
Progress masks hidden threats:
- Indirect attacks, such as those targeting third-party vendors, now account for 40% of all security breaches.
- The true scale of cyber threats is being obscured due to this shift.
-
Unsustainable cost increases:
- 69% of respondents say staying ahead of attackers is a constant battle with unsustainable costs.
- The top cost drivers include network security, threat detection, and security monitoring.
-
Security investments are failing:
- Non-leaders have significantly lower performance in breach detection and remediation.
- Non-leaders experience a 93% breach impact lasting more than 24 hours, compared to 55% for leaders.
- 44% of non-leaders had over 500,000 customer records exposed, versus 15% of leaders.
Why Leaders Are More Cyber Resilient
Leaders outperform non-leaders in four key areas:
-
Stop more attacks:
- Leaders stop 4x more attacks than non-leaders, with only 9% of attacks resulting in breaches, compared to 22% for non-leaders.
-
Find breaches faster:
- 88% of leaders detect breaches in less than one day, while only 22% of non-leaders achieve this.
-
Fix breaches faster:
- 96% of leaders fix breaches in 15 days or less, versus 36% for non-leaders.
-
Reduce breach impact:
- 83% of breaches for leaders result in no or minor impact, compared to 50% for non-leaders.
Key Strategies for Cyber Resilience
Invest for Operational Speed
- Leaders prioritize speed in their cybersecurity strategies.
- They focus on technologies that enable rapid detection, response, and recovery.
Drive Value from New Investments
- Leaders scale their efforts, train more effectively, and collaborate across departments and ecosystems.
- These actions increase the return on investment and enhance overall resilience.
Sustain What They Have
- Leaders maintain existing investments and perform better at the basics of cybersecurity.
- This includes consistent compliance, effective monitoring, and robust incident response.
What is Cyber Resilience?
- Cyber resilience combines cybersecurity, business continuity, and enterprise resilience.
- It enables organizations to respond quickly to threats, minimize damage, and continue operations under attack.
- It supports innovation and customer trust while allowing for confident growth.
Take Action for Non-Leaders
- Reduce breach frequency: Aim to lower the rate of attacks resulting in breaches from 1-in-8 to 1-in-27 or better.
- Improve detection speed: Reduce average detection time from up to seven days to less than one day.
- Accelerate remediation: Target a 15-day or less response time for breaches.
- Minimize breach impact: Ensure at least three out of five breaches result in no or minor impact.
Key Technologies for Leaders
| Technology | Benefits |
|---|---|
| SOAR | #1 (Fewer attacks, more precise detection, faster response) |
| AI | #1 (Reduced breach impact, more precise detection) |
| NGF | #1 (Fewer successful attacks) |
| PAM | #3 (Fewer attacks, reduced breach impact) |
| RPA | #4 (More precise detection, cost reduction) |
| RBA | #2 (Reduced inherent risk) |
Conclusion
The report emphasizes that while many organizations are improving their cybersecurity basics, the threat landscape is evolving rapidly. Leaders are leveraging innovation and advanced technologies to enhance their cyber resilience, but even they have room for improvement. Non-leaders must shift their focus toward strategic investments, operational speed, and collaboration to close performance gaps and achieve better outcomes in cybersecurity execution.
试读结束,高清完整版pdf/doc/ppt,请点下载