Informe de ciberresiliencia 2023
Este artículo 13 es parte 16 de este informe.
October 11, 2023 / 7 minuto(s) de lectura
North America: Investment Leads to Enhanced Cyber Resiliency
Organizations across North America show improvements in critical areas of cyber resiliency. But there remain opportunities for improvement in key areas such as backup strategy and use of MFA — particularly for small and medium-sized enterprises.
- The average number of critical cyber resilience controls failed by clients declined in 2022 compared to 2021.
- Cyber insurance pricing for all industries is expected to continue to decrease in 2023 following improvements to cyber resiliency, drops in claims frequency and lowered insurer loss ratios.*
- While global trends indicate that ransomware attacks are on the rise**, companies and insurers appear to be focused on how AI can change attack patterns and privacy too.
* “Buyer-Friendly Cyber and E&O Market: How to Take Advantage | Aon.” Report. Aon. May 2023.
** “Buyer-Friendly Cyber and E&O Market: How to Take Advantage | Aon.” Report. Aon. May 2023.
Business leaders in North America (NA) continue to address cyber attacks through investment in tools, technologies, and procedures. Data pulled from Aon highlights this trend. On average, Aon data revealed that10 out of 33 critical controls in 2022 were failed — down from 12 out of 33 in 2021. We’ve also seen marked improvement in the areas of Access Management (7.19 percent decrease in failure rate), Multi Factor Authentication (MFA) (11.29 percent decrease in failure rate), and business resilience (6.08 percent decrease in failure rate). Claims frequency reduced in 2022 and loss ratio’s improved as a result. When paired with reduction in claims frequency and improvement in insurer loss ratios, these investments are expected to help push cyber premiums lower in 2023 while simultaneously enhancing the organization’s overall cyber resiliency.
Percent of lack of critical IT controls U.S. (‘red flags’)
Despite the average improvements for all companies in the NA region, there remain key areas where additional investment could be targeted and there’s a marked difference in resilience between Enterprise and Global clients from mid-market and small and medium-sized clients. Ransomware Supplemental application data shows that on average backup security controls improved by 6 percent across all industries. However, 90 percent of companies reported that they did not store backups in the cloud, and backups are neither stored offsite nor immutable for 70 percent of companies. Overall 2022 data shows that mid-market and small and medium-sized clients’ control deficiencies in business resilience were 10 percent higher than that of enterprise and global clients. Organizations under $2 billion in revenue continue to report greater deficiencies around MFA than other organizations, which remains a top concern for cyber insurance underwriters.
Following several quarters of decreased activity, there has been an uptick in the frequency of global ransomware attacks in Q1 and 20231, reminding organizations why ransomware remains a top concern with respect to cyber resiliency. In addition, the use of AI tools to create and refine attack patterns is a growing concern both for businesses and the cyber insurance underwriting community. The power and ease of use of these AI tools means we can expect an increase in phishing and spear phishing. Privacy is also coming back into focus in a big way, particularly in the healthcare space2. Lawsuits alleging privacy violations (such as California Invasion of Privacy Act(CIPA) and Video Privacy Protection Act (VPPA)) resulting from the use of pixel tracking technology became a popular tool of the plaintiffs’ bar at the end of 2022 and that trend continues in 2023.
Industries in Perspective
This year, we examined three industries in more depth: manufacturing, healthcare and finance and insurance. While companies across all three sectors generally tracked with the average improvements seen across all industries, nuances specific to each industry’s needs and operations show departures from the averages in key areas.
Manufacturing clients made significant improvements in the areas of MFA and access management. However, backup security, business resilience and data security showed the highest percentage of average deficiencies3 and so remain the top areas of concern. The prevalence of legacy tools and increased mergers and acquisitions activity in this sector are both factors in the increasing exposure related to information technology (IT) and operational technology (OT) vulnerabilities. Companies in this industry continue to show an average failure rate of 40 percent specific to OT controls4. We see these results being driven by a lack of ransomware coverage in tabletop exercises, not having current or tested business continuity plans and/or deficient monitoring and patching capabilities in the OT environment.
Percent of lack of critical IT controls for Manufacturing in U.S. (‘red flags’)
Percent of lack of critical OT controls’ for Manufacturing in U.S. (‘red flags’)
Healthcare clients appear to have made significant improvements in 2022 when compared to 2021 in the domains of MFA and business resilience5. This is partly driven by the insurers focus on key controls that help limit the probability and severity of a ransomware event. However, data security, software management and endpoint security saw a reported increase in deficiencies over this same time period. Due to increased digitization and the push within the healthcare industry to automate certain processes, data shows many companies outsourced IT operations in 2022 or hired mature security talent. However, this increase in deficiencies may not reflect an actual regression of cyber resiliency but instead an improvement in the accuracy of reporting.
Percent of lack of critical IT controls for Healthcare in U.S. (‘red flags’)
Finance and insurance clients made significant improvements in MFA, access management and business resilience6. Claims and cyber intelligence trends indicate that bad actors are still able to bypass MFA and use remote desktop controls to compromise the network environment in this industry. Aon’s ransomware supplemental application data suggests that finance and insurance clients are increasing their focus on stricter MFA rules and patch management capabilities to combat these trends. Data security and endpoint security domains remain particularly relevant for the finance and insurance industry given the higher nature of third party and insider risk facing these organizations. Finally, new SEC rules regarding reporting on tabletop exercises as a part of business continuity and disaster recovery planning is likely to see a rise in penetrating testing and proactive remediation controls7.
Percent of lack of critical IT controls for Finance and Insurance in U.S. (‘red flags’)
Now What? Some suggested actions for North American Leaders
- Update and strengthen governance frameworks and risk management strategies concerning cyber risk. Privacy regulations across the region continue to go beyond data breach notification laws and contemplate new types of information (e.g. biometrics) as well as the concepts of informed consent at the time of data capture. As such, it is paramount that senior business leaders properly record and disclose their adoption of good governance and risk management of cyber threats per best practices and regulatory requirements. This action will not only improve the business’s risk profile but will mitigate potential regulatory and shareholder actions in the event of a cyber or privacy event.
- Keep vigilant on ransomware threats. While companies in the region have performed well in combating ransomware threats, global trends indicate that ransomware attacks are on the increase (up 38 percent Q1 2023 over Q4 2022)8. Continue to focus on security controls that mitigate ransomware attacks, particularly those controls that are a critical part of the insurance underwriting process.
- Continue to be forward-looking with respect to cyber risk mitigation and resilience strategies. Reviewing the tools, technologies, and procedures necessary to combat cyber threats as they are influenced by geopolitical tensions and emerging attack vectors is critical for all organizations. Ensuring business continuity and disaster recovery plans are updated and tested based on changes to tools, technologies and procedures as well as current business operations is a critical aspect of a crisis management strategy. Testing insurance limits and coverage through periodic risk quantification and risk-based heat mapping will ensure that any insurance purchase remains a valuable aspect of a company’s overall cyber risk mitigation strategy.
1 “Buyer-Friendly Cyber and E&O Market: How to Take Advantage | Aon.” Report. Aon. May 2023.
8 “Buyer-Friendly Cyber and E&O Market: How to Take Advantage | Aon” Report. Aon. May 2023.
Aon Risk Insurance Services West, Inc., Aon Risk Services Central, Inc., Aon Risk Services Northeast, Inc., Aon Risk Services Southwest, Inc. y Aon Risk Services, Inc. de Florida, y sus filiales autorizadas ofrecen los productos y servicios de seguros.
La información aquí contenida y las afirmaciones expresadas son de carácter general, no pretenden abordar las circunstancias de ninguna persona o entidad en particular y se facilitan únicamente con fines informativos. Esta información no sustituye el asesoramiento de un asesor jurídico o de un profesional de seguros cibernéticos y no debe utilizarse para tal fin. Si bien nos esforzamos por proporcionar información exacta y oportuna y utilizamos fuentes que consideramos fiables, no puede garantizarse que dicha información sea exacta en la fecha en que se recibe o que siga siéndolo en el futuro.
Madurez Cibernética por Región
La madurez cibernética general de las empresas puede diferir según la región. Obtenga más información sobre las brechas, los desafíos y las oportunidades, incluidas las medidas sugeridas que los líderes pueden tomar para desarrollar la resiliencia cibernética y empresarial.
América Latina: Tres áreas críticas en riesgo
En general, la madurez cibernética de las empresas de América Latina es similar a las de la región de EMEA y el Reino Unido, aunque se evidencian tres problemas significativos: administración de terceros, resiliencia empresarial y seguridad de las aplicaciones.
Asia-Pacific: Shifting Threat Landscape
For the first time, cyber earns a place in Asia Pacific’s top five list of business risk rankings. Companies report improvement in cyber maturity levels with a focus on governance, data protection and supply chain controls
Europe, the Middle East and Africa: Forward Movement Demonstrates Shifting Mindset
EMEA companies focused on improving data security and safeguarding organizational data in 2022, partly driven by the Ukraine-Russia conflict.
UK: Los cambios en el escenario de amenazas
Tener conciencia del riesgo no estar preparado para enfrentarlo. La madurez general de la seguridad cibernética entre las organizaciones del Reino Unido cayó marginalmente entre 2020 y 2022, aunque algunos dominios de seguridad tuvieron un desempeño excepcional, mientras que otros experimentaron un retroceso.