2018年网络安全预测报告(英文版)_26页-1mb
报告摘要
2018 Cybersecurity Predictions Summary
Core Content
This document outlines key cybersecurity predictions for 2018, emphasizing the shift from treating cybersecurity as an IT issue to managing it as an enterprise risk. It highlights the growing sophistication and impact of cyber threats, the role of regulatory pressures, the rise of cyber insurance, and the need for integrated risk management across departments.
Main Predictions
1. Businesses adopt standalone cyber insurance policies
- Key Point: As cyber attacks cause significant financial and operational damage, companies will increasingly seek standalone cyber insurance policies.
- Trends:
- Boards and executives will become more aware of their liability for cyber incidents.
- Cyber insurance will expand beyond traditional policies, offering broader coverage for cyber-related exposures.
- The insurance industry will focus on developing specialized policies and limiting "silent" coverage in other policies.
- Data:
- 24% of risk management professionals had cyber insurance in 2017.
- 87% viewed cyber liability as a top business risk.
- GDPR violations could lead to fines of up to 4% of global annual revenue or €20 million.
2. Managing cyber as an enterprise risk
- Key Point: Cyber risk will be integrated into enterprise-wide risk management, with CROs and CISOs working together.
- Trends:
- C-suites will recognize the broader impact of cyber risk on operations, compliance, finance, and HR.
- Siloed approaches to cybersecurity will give way to a more coordinated and holistic risk management strategy.
- Companies will break down organizational silos and incorporate cybersecurity into all areas of business risk.
- Data:
- $86.4B was spent on cybersecurity in 2017, a 7% increase.
- CROs will play a central role in articulating the financial and operational consequences of cyber risk.
3. Regulatory spotlight widens
- Key Point: Regulatory scrutiny will increase, with new and stricter rules being introduced globally.
- Trends:
- GDPR will be strictly enforced, with major consequences for non-compliance.
- The EU will hold global companies accountable for GDPR violations.
- New regulations will affect sectors beyond finance, healthcare, and retail, including education.
- Data:
- 4% of global annual revenue or €20 million is the maximum fine for GDPR non-compliance.
4. Criminals attack businesses embracing IoT
- Key Point: IoT adoption will create new vulnerabilities, particularly in third-party relationships.
- Trends:
- Large companies may be brought down by attacks on smaller vendors or contractors with insecure IoT systems.
- SMBs will face increased pressure to improve IoT security to remain competitive.
- Data:
- 55% of small businesses reported breaches between 2015 and 2016.
- Only 25% of respondents said boards of directors assessed IoT risks in third parties.
5. Multi-factor authentication (MFA) becomes standard practice
- Key Point: As passwords and biometrics become easier targets, MFA will be widely adopted.
- Trends:
- MFA will move from being a niche requirement to a mainstream security measure.
- Financial institutions will implement MFA across all customer service interactions.
- Attackers will develop new techniques to bypass MFA, such as malware targeting mobile devices.
- Data:
- 81% of hacking-related breaches used stolen or weak passwords.
6. Bug bounty programs go mainstream
- Key Point: Companies will increasingly use bug bounty programs to identify and fix security vulnerabilities.
- Trends:
- Bug bounty programs will become a standard practice for a broader range of companies.
- These programs will help organizations improve their cybersecurity posture through external collaboration.
- Major cloud providers will encourage the use of MFA and bug bounty programs.
Key Information
- Cyber Liability Awareness: Boards and executives will face greater liability for cyber incidents, leading to increased legal and financial consequences.
- Regulatory Compliance: GDPR and other regulations will drive stricter enforcement and new compliance requirements across industries.
- Third-Party Risks: The integration of IoT into business operations will create new vulnerabilities through third-party vendors.
- Security Evolution: Passwords and biometrics will be supplemented with MFA to enhance security, though they remain vulnerable to attack.
- Insurance Market Shift: Cyber insurance will become more specialized, with increased scrutiny and modeling of potential cyber perils.
Conclusion
2018 will mark a turning point in how businesses approach cybersecurity. The convergence of physical and digital risks, regulatory pressure, and the rise of new attack vectors will push organizations to adopt a more integrated and enterprise-wide approach to managing cyber risk. This shift will involve greater collaboration between CROs and CISOs, the mainstream adoption of MFA and bug bounty programs, and the development of specialized cyber insurance policies.
试读结束,高清完整版pdf/doc/ppt,请点下载