Cyber Security: How We Protect Aon and Clients

Cyber Security: How We Protect Aon and Clients
Building Sustained Cyber Resilience with Full Spectrum Risk Management
Cyber Security

How We Protect Aon and Clients

Risk Management for Clients Begins with Us

At Aon, we prioritize security by guiding business leaders with a strategic risk governance process. Our Global Risk Leadership Committee, experts in the security risks across Aon’s business areas, ensures we mitigate risks and follow best practices to protect our interests while achieving our goals. Learn more about our approach below.

Cyber Risk Governance at Aon

Cyber threats are evolving rapidly, which makes cyber risk mitigation an ongoing challenge. This is why companies, including Aon, should embrace an always-on approach to risk reduction measures in the face of increasing attacks and adverse geopolitical activity. The decisions an organization makes in product development, threat intelligence, and embedding security as a growth driver will prove critical to any firm's cyber resilience.

Our Approach

At Aon, we have adopted strong cyber resilience practices that span the entire cyber risk life cycle. These practices help us identify, assess, mitigate, and transfer cyber risk and quickly recover from attacks. Aon is committed to protecting its people, property, and information. Our robust security program not only aligns with regulatory mandates, it also complies with laws safeguarding customer data and firm intellectual property. Our Information Security Program aims to protect our constituents, including Colleagues, Clients, and Shareholders. This mission is achieved through shared values and priorities.

Cyber Security - Our Approach
Shared Values

Shared Values

We focus on outcomes, continuously improving by empowering colleagues to protect our valued assets. We prioritize customers, by offering simplified products and services that integrate seamlessly with business processes, helping clients stay cyber resilient. We remain agile, rapidly delivering valuable products and services, while adapting to new cyber threats.

Security Imperatives

We prioritize fundamental controls, providing a strong global framework to protect our clients and their data. We embed security by empowering business leaders and colleagues to make informed risk decisions. We view security as a driver for business growth, maintaining guardrails that foster innovation and deliver results for our stakeholders.

Security Imperatives

Cyber Security Tips

As corporate boards and business leaders seek to manage cyber threats and risks, following foundational cyber security processes is critical. At Aon, we advise our colleagues to consider the following cyber security measures, among others:

  • Stay Safe Online
    • Manage identity
    • Authenticate requests independently to help prevent deepfake scams
    • Apply patch management
    • Continuously train your workforce
    • Build cyber culture
  • Password Protection
    • Use strong passwords
    • Use unique passwords
    • Use different passwords across systems
    • Never reveal your passwords to others
    • Use multi-factor authentication
  • System Security
    • Using a next generation firewall securing remote access and establishing critical system log management
    • Installing a good antivirus focusing on a real-time protection against cyberattacks such as malware, phishing and ransomware.
    • Beware of phishing and business email compromise attacks and execute cyber security awareness training with simulations
    • Keep your operating systems updated and prevent system configuration management drift
    • Identify security gaps
    • Conduct security monitoring to enable threat detection
    • Maintain Incident Response preparedness and test a major event playbook
  • Securing Confidential Information
    • Encrypt confidential and sensitive data
    • Monitor networks constantly for suspicious activity

Cyber Resilience Tips

Beyond the fundamentals of cyber security, we advise clients to build a more sustainable approach to cyber resilience. This includes:

  • Assess Cyber Resilience
    • Regularly assess your security posture
    • Know where your sensitive data is located
    • Benchmark against Industry Standards
  • Mitigate Cyber Threats
    • Strengthen access controls
    • Patch systems regularly
    • Educate employees
    • Employ strong detection and detection
  • Transfer Cyber Risk
    • Employ cyber insurance
    • Regularly review and update coverage
    • Understand policy terms
  • Respond to and Recover from Cyber Events
    • Regularly test incident response plan
    • Have well-defined communication plans
    • Ensure clear communication channels
    • Have regular backups
    • Learn from security incidents
    • Engage external experts post-incident
    • Communicate transparently with stakeholders

More About Aon

About Aon
  • Our story

    About Aon

    Our Story

    At Aon, we exist to shape decisions for the better - to protect and enrich the lives of people around the world.

    Learn More
  • People Women Diversity

    About Aon

    Our Values

    At Aon, our values define who we are as colleagues and are the foundation of all we do.

  • Our Impact

    About Aon

    Our Impact

    We see significant opportunity in both enhancing our own ESG impact and delivering innovative solutions to clients and the wider market.

    Learn More