2016年-德勤全球_Beneath_the_surface_of_a_cyberattack_28页_5mb
报告摘要
Deloitte Cyberattack Business Impact Summary
Core Content
Deloitte's report Beneath the Surface of a Cyberattack: A Deeper Look at Business Impacts explores the broader business implications of cyber incidents beyond the commonly reported direct costs. It introduces a multidisciplinary approach to analyzing cyber risk, integrating insights from cyber risk, forensic, and valuation experts. The report outlines 14 impact factors that can affect an organization's financial and operational health in the aftermath of a cyberattack, emphasizing that many of these impacts are intangible and less visible.
Main Points
1. Cyber Risk Management is Evolving
- Cyberattacks are increasingly seen as a strategic risk, not just a technical threat.
- Organizations are adopting a Secure. Vigilant. Resilient. approach to balance cybersecurity investments with threat visibility and response preparedness.
- Business leaders must understand both the likelihood of cyber incidents and their potential business impacts.
2. Traditional Cyber Risk Estimation is Limited
- Most risk assessments focus on direct costs such as customer notification, credit monitoring, and regulatory fines.
- These are often based on visible and quantifiable impacts, but fail to account for long-term and intangible consequences.
- Deloitte highlights that many cyber incidents have hidden impacts that are critical to business recovery and reputation management.
3. The 14 Impact Factors
The report identifies 14 key impact factors that can affect an organization following a cyberattack. These include both visible (above the surface) and hidden (beneath the surface) impacts. The visible ones include:
- Customer breach notification
- Cybersecurity improvements
- Attorney fees and litigation
- Technical investigation
- Post-breach customer protection
- Regulatory compliance
- Public relations
The hidden ones include:
- Value of lost contract revenue
- Devaluation of trade name
- Loss of intellectual property
- Operational disruption
- Increased cost to raise debt
- Insurance premium increases
- Lost value of customer relationships
4. Scenario-Based Analysis
Deloitte presents two fictional scenarios to illustrate the range and depth of these impacts:
Scenario A: Major Health Insurer
Company Overview
- Annual revenue: US$60 billion
- 50,000 employees
- 23.5 million members (60% through employer contracts)
- Uses a patient care application for medical alerts and insurance coverage
- Plans to raise US$1 billion in debt capital
- Pays US$7 million annually for a US$100 million cyber insurance policy
Cyber Incident
- A laptop with 2.8 million PHI records was stolen.
- The breach was discovered when a client's employee data appeared on dark web sites.
- Unauthorized access to the patient care application was detected, leading to the shutdown of physician access for two weeks.
Aftermath and Business Impact
- Short-term disruption: Physicians and providers could not access critical data, increasing patient risk.
- Reputation damage: Loss of customer confidence led to a 3-year decline in members.
- Financial consequences:
- Lost contract revenue: US$830 million over 5 years
- Devaluation of trade name: US$230 million
- Lost customer relationships: US$430 million
- Other impacts:
- Increased cost to raise debt: US$60 million
- Insurance premium increases: US$40 million
- Operational disruption: US$30 million
Total Estimated Impact: US$1,679 million (100%)
- Above the surface: 3.5% of total impact (US$60 million)
- Beneath the surface: 96.5% of total impact (US$1,619 million)
- The most significant impacts were:
- Lost contract revenue (49.43%)
- Devaluation of trade name (13.70%)
- Lost customer relationships (25.61%)
Scenario B: Major Technology Manufacturer
Company Overview
- Annual revenue: US$40 billion
- 60,000 employees
- Growth strategy focused on IoT innovation
- Holds contracts with multinational clients
- Operating profit margin: 12.2% (prior to incident)
- Pays US$3.75 million annually for US$150 million in cyber insurance
Cyber Incident
- A foreign nation-state breached the company's infrastructure.
- IP from 15 of 30 device product lines was exfiltrated.
- The breach was revealed 30 days after discovery by a tech blog.
Aftermath and Business Impact
- Product disruption: Sales and shipments of affected products were suspended for 4 months.
- Government contract termination: Caused an additional 5% drop in revenue.
- Financial consequences:
- Lost contract revenue: US$1,600 million over 5 years
- Operational disruption: US$1,200 million over 2 years
- Devaluation of trade name: US$280 million
- Loss of intellectual property: US$151 million
- Other impacts:
- Insurance premium increases: US$1 million
- Increased cost to raise debt: Not applicable
- Lost value of customer relationships: Not applicable
Total Estimated Impact: US$3,258 million (100%)
- Above the surface: 0.38% of total impact (US$12 million)
- Beneath the surface: 99.62% of total impact (US$3,246 million)
- The most significant impacts were:
- Lost contract revenue (49.11%)
- Operational disruption (36.83%)
- Loss of intellectual property (4.63%)
Key Takeaways
- Cyberattacks have far-reaching implications beyond data theft.
- Intangible costs such as loss of customer trust, devaluation of trade names, and loss of intellectual property are often the most significant.
- Multidisciplinary analysis is essential for accurate estimation of cyber risk impacts.
- Financial modeling and valuation techniques can help quantify the hidden costs of cyber incidents.
- Recovery is a long-term process, with most impacts materializing over several years.
- Insurance and regulatory responses are important but represent only a small portion of the total financial impact.
Going Forward
- Organizations must move beyond the traditional "cost per record" model to consider a broader set of impact factors.
- Integrating cyber risk analysis with financial modeling can provide more accurate and comprehensive risk assessments.
- The report encourages a holistic approach to cyber risk management, emphasizing the need for better visibility, response capabilities, and strategic planning.
试读结束,高清完整版pdf/doc/ppt,请点下载