2015-11-17-奥纬咨询-Why_hackers_could_cause_the_next_global_crisis_5页_162kb
报告摘要
CYBER-RISK MANAGEMENT SUMMARY
Core Content
The document highlights the escalating global threat of cyberattacks and the urgent need for comprehensive cyber-risk management across industries. It underscores that cyber risks are no longer isolated IT issues but are becoming a critical operational concern that affects the entire enterprise. As the world becomes more reliant on digital systems, the potential for cyber incidents to disrupt essential services and cause global crises is increasing.
Main Points
-
Cyberattacks on Critical Infrastructure: Recent incidents include the access of 21.5 million American public service employees' records, infiltration of the German parliament's network, and the blocking of 11 French television channels. In 2014, a malware attack compromised operations at over 1,000 energy companies, affecting power plants, gas pipelines, and wind turbines in 84 countries.
-
Global Cybersecurity Initiatives: More than 30 countries, including Germany, the United States, and the United Kingdom, have developed cybersecurity strategies. The European Union is working on a unified cybersecurity directive to protect critical infrastructure.
-
Cyber Risks as Operational Risks: Cyber risks are often misclassified as lower priority and managed by IT departments alone. This oversight leads to a lack of integration with broader risk management frameworks and underestimates the financial and reputational impact of breaches.
-
Rising Cyber Insurance Coverage: Companies with revenues over $1 billion have increased their cyber insurance limits by 42% since 2012. Healthcare firms have seen a 178% increase, and power and utilities firms have expanded their coverage by 98%.
-
Need for Integrated Cyber Risk Management: Cyber risk should be treated as a core operational risk, with clear targets and prioritization based on the company's risk appetite. Controls and processes should be designed to address mission-critical vulnerabilities first.
-
Importance of a Cyber-Risk Culture: Top management must embed cyber-risk management into organizational culture, including performance metrics, incentives, and executive discussions. Cyber incidents involving industrial control systems should be prioritized in risk assessments.
-
Cost of Cyber Breaches: In the UK, 81% of large businesses experienced a cybersecurity breach in the past year, and the average cost of breaches has nearly doubled since 2013.
Key Information
-
Cyber Risk Exposure: Companies are increasingly exposed to cyber risks due to their reliance on digital systems. These risks can have significant financial and operational consequences.
-
Cyber Insurance Trends: The growth in cyber insurance coverage reflects the rising awareness of cyber threats and the need for financial protection against them.
-
Strategic Response: Organizations must adopt a proactive, integrated approach to cyber-risk management, aligning it with their overall risk strategy and involving all departments, not just IT.
-
Global Collaboration: There is a growing recognition of the need for international cooperation to address cyber threats, especially in critical sectors like energy and healthcare.
Conclusion
Cyber risk is a pressing global issue that requires a strategic, integrated, and culturally embedded approach to management. As the frequency and impact of cyberattacks increase, companies must treat them as operational risks, prioritize them in their risk appetite framework, and invest in robust cybersecurity measures to prevent potential crises. The trend of rising cyber insurance coverage indicates that businesses are beginning to recognize the importance of preparing for these threats, but much more needs to be done to ensure long-term resilience.
试读结束,高清完整版pdf/doc/ppt,请点下载