Bypassing EDR through Retrosigned Drivers and System Time Manipulation
The Retrosigned Driver EDR Bypass is a novel modification of a technique employed by multiple ransomware groups to bypass EDR and limit visibility into malicious actions by abusing expired code signing certificates to load malicious kernel drivers.
Summary
Aon's Stroz Friedberg Incident Response Services ("Stroz Friedberg") has observed ransomware actors utilizing an Endpoint Detection and Response (“EDR”) solution bypass technique dubbed “Retrosigned Driver EDR Bypass” to terminate EDR and to limit visibility of EDR telemetry. This technique involves loading a malicious driver signed with an out-of-date code signing certificate and then manipulating the system time on the target system during the loading process. Once loaded, the driver is utilized to terminate running processes.
Background
Drivers are essential pieces of software that allow the operating system to communicate with hardware devices. They serve as a bridge between the system and the hardware, ensuring that peripheral devices like printers, graphics cards, and network adapters function correctly. Given their critical role, drivers operate with high privileges within the system, making them a prime target for malicious exploitation.
To mitigate the risks associated with driver installation, Microsoft Windows enforces a driver signing process. Driver signing involves the use of cryptographic certificates issued by trusted authorities to verify that the driver code has not been tampered with and originates from a legitimate source. This process ensures that only authorized drivers can be installed, adding a layer of security. However, when attackers find ways to bypass these protections, it opens the door for malicious drivers to be loaded, posing significant threats to system integrity.
Due to the privileged nature of kernel drivers and their potential for abuse, starting in Windows Vista, Microsoft implemented restrictions that required drivers to be signed by trusted software developers, preventing the loading of unsigned drivers. This required developers to obtain code signing certificates from a certificate authority to cryptographically attest that they were the authors of the driver being loaded. Beginning in Windows 10 1607 Microsoft tightened these requirements to only allow drivers that were signed by Microsoft to be loaded. However, to ensure backwards compatibility, Microsoft still allowed for kernel mode drivers to be loaded under certain circumstances, including if the driver was signed with “an end-entity certificate issued prior to July 29th 2015 that chains to a supported cross-signed CA.”1
These restrictions, combined with the increasing deployment of EDR across the industry lead threat actors to explore an alternate class of attack termed “Bring Your Own Vulnerable Driver” or “BYOVD” in which a threat actor would use a vulnerability in a legitimately signed driver to gain kernel level access. This access can then be used to kill processes such as EDR. Stroz Friedberg has previously written about this technique here. Microsoft addressed this technique through the creation of the vulnerable driver blocklist which prevented known vulnerable drivers from being loaded.
Cisco Talos previously documented a technique in which threat actors forged certificate validity dates in order to make expired cross-signing code certificates appear valid during the signing process. The Retrosigned Driver technique Stroz Friedberg observed employs a distinct methodology and relies on manipulating the certificate validity time checks on targeted systems as opposed to manipulating the signing process. However, both techniques leverage on the same architectural decision in Windows to trust cross-signed code from third party certificates prior to 2015 and result in similar impact.
Retrosigned Driver EDR Bypass
Retrosigned Drivers extends previous techniques by altering the system clock on the target system to load malicious kernel drivers that were signed by historically compromised expired cross-signing certificates. The following Retrosigned Driver attack pattern was observed by Stroz Friedberg:
- Stop the Windows Time Service to prevent time synchronization through Active Directory Domain Services.
- net stop w32time & w32tm /unregister
- Set the date during the validity period of the certificate
- Example: powershell -command Set-Date -Date "6/23/2015"
- Execute malware which loads a driver signed by a certificate valid prior to July 29th, 2015.
- Kill the EDR processes using the newly loaded driver.
Stroz Friedberg analyzed the recovered sample and confirmed that it was able to successfully load the driver and kill the targeted EDR, but only when the system time was changed to a period within the validity date of the driver. Stroz Friedberg observed similar samples across several engagements involving threat actors which deployed the Medusa and Abysslocker ransomware variants.
The recovered samples had code overlaps with previously known malware samples tracked as POORTRY and STONESTOP. When these malware families were previously identified, they were signed using a Microsoft Hardware Compatibility Program certificate as opposed to an out-of-date signing certificate.
Stroz Friedberg reported their findings to the targeted EDR vendor and provided Microsoft the malicious drivers and associated certificates, along with a description of the technique. Stroz Friedberg held publication of this post for a 60-day period after the disclosure.
Detection Mechanisms
- Time changes
- Kernel-General Event ID 1: Time Changed.
- Security Event ID 4616: Time Changed.
- Out of sequence MFT records.
- System Event 7034 – EDR service terminated unexpectedly.
- System Event 7045 – Service install of malicious driver.
- System Registry Key update ROOT\ControlSet001\Services\[Malicious Driver].
- Sysmon Event ID 11 – Creation of malicious .sys driver file.
- PowerShell command execution: Date change.
- PowerShell command execution: Stopping time service.
Contact
If you suspect you are compromised or need assistance in assessing compromise, please call our Incident Response hotline. If you are from a Law Enforcement Agency or Endpoint Detection and Response vendor and wish for more details, please contact Aon Cyber Solutions.
-
John AilesDFIR
-
Zachary ReichertDFIR
-
Partha AlwarDirector, Incident Response at Stroz Friedberg, an Aon company
About Cyber Solutions:
Aon’s Cyber Solutions offers holistic cyber risk management, unsurpassed investigative skills, and proprietary technologies to help clients uncover and quantify cyber risks, protect critical assets, and recover from cyber incidents.
General Disclaimer
This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document. While care has been taken in the preparation of this material and some of the information contained within it has been obtained from sources that Stroz Friedberg believes to be reliable (including third-party sources), Stroz Friedberg does not warrant, represent, or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the article and accepts no liability for any loss incurred in any way whatsoever by any person or organization who may rely upon it. It is for informational purposes only. You should consult with your own professional advisors or IT specialists before implementing any recommendation or following the guidance provided herein. Further, we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. Further, this article has been compiled using information available to us up to 9/13/2024.
Terms of Use
The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.
Aon's Better Being Podcast
Our Better Being podcast series, hosted by Aon Chief Wellbeing Officer Rachel Fellowes, explores wellbeing strategies and resilience. This season we cover human sustainability, kindness in the workplace, how to measure wellbeing, managing grief and more.
-
Podcast 23 mins
Better Being Series: Understanding Burnout in the Workplace -
Podcast 14 mins
Better Being Series: Why Nutrition Matters -
Podcast 10 mins
Better Being Series: Discover the ‘Blue Zones’ Where People Live Longer -
Podcast 20 mins
Better Being Series: Improving Your Financial Wellbeing -
Podcast 17 mins
Better Being Series: Are You Taking Care of Your Digital Wellbeing? -
Podcast 19 mins
On Aon Podcast: Better Being Series Dives into Women’s Health -
Podcast 29 mins
On Aon’s Better Being Series: The World Wellbeing Movement -
Podcast 28 mins
On Aon’s Better Being Series: Mental Health and Creating Kinder Cultures -
Podcast 25 mins
On Aon’s Better Being Series: Managing Loss and Grief -
Podcast 24 mins
On Aon’s Better Being Series: Measuring Wellbeing -
Podcast 25 mins
On Aon’s Better Being Series: Physical Wellbeing and Resilience -
Podcast 23 mins
On Aon’s Better Being Series: Human Sustainability
Aon Insights Series Asia
Expert Views on Today's Risk Capital and Human Capital Issues
-
Article 8 mins
Thriving in an interconnected world: How the C-Suite embraces uncertainty -
Article 6 mins
Powering progress: Collaborating to build a sustainable future in emerging markets -
Article 5 mins
Building Business Resilience: Key Steps to Effectively Integrate Risk Management Across Your Organisation -
Article 7 mins
Why humans are the essential factor in the success of Artificial Intelligence (AI) -
Article 5 mins
Leveraging Research and Expertise to Strengthen Your HR Strategy for 2025 and Beyond
Aon Insights Series Pacific
Expert Views on Today's Risk Capital and Human Capital Issues
Aon Insights Series UK
Expert Views on Today's Risk Capital and Human Capital Issues
-
Article 2 mins
Introduction: Clarity and Confidence to Make Better Decisions -
Article 2 mins
The Age of Rising Resilience – An Economic Outlook -
Article 3 mins
Building Resilience Against the Constant Cyber Threat -
Article 2 mins
Making Better Decisions – A Treasurer’s Perspective -
Article 2 mins
How to Balance the Conflicting Forces of Efficiency, Performance and Wellbeing -
Article 3 mins
Seizing the Opportunity: Building a Comprehensive Approach to Risk Transfer -
Article 2 mins
Tapping New Markets to Unlock Deal Value -
Article 5 mins
The Rise of the Skills-Based Organisation -
Article 2 mins
Creating a Fair and Equitable Workforce for Everyone -
Article 3 mins
The Year of the Vote: How Geopolitical Volatility Will Impact Businesses -
Article 2 mins
The Aon Difference
Construction and Infrastructure
The construction industry is under pressure from interconnected risks and notable macroeconomic developments. Learn how your organization can benefit from construction insurance and risk management.
-
Article 8 mins
How North American Construction Contractors Can Mitigate Emerging Risks -
Article 7 mins
Managing Construction Risks: 7 Risk Advisory Steps -
Article 7 mins
Unlocking Capacity and Capital in a Challenging Construction Risk Market -
Article 7 mins
Protecting North American Contractors from Extreme Heat Risks with Parametric -
Article 5 mins
How Climate Modeling Can Mitigate Risks and Improve Resilience in the Construction Industry -
Report 1 mins
Construction Risk Management Europe Report 2023 -
Article 8 mins
Parametric Can Help Mitigate Extreme Heat Risks for Contractors in EMEA -
Article 9 mins
How the Construction Industry is Navigating Climate Change -
Article 11 mins
Top Risks Facing Construction and Real Estate Organizations
Cyber Labs
Stay in the loop on today's most pressing cyber security matters.
-
Cyber Labs 9 mins
Mounted Guest EDR Bypass -
Cyber Labs 6 mins
Optimizing Your Cyber Resilience Strategy Through CISO and CRO Connectivity -
Cyber Labs 9 mins
Bypassing EDR through Retrosigned Drivers and System Time Manipulation -
Cyber Labs 10 mins
DNSForge – Responding with Force -
Cyber Labs 7 mins
Unveiling "sedexp": A Stealthy Linux Malware Exploiting udev Rules -
Cyber Labs 3 mins
Command Injection and Path Traversal in StoneFly Storage Concentrator -
Cyber Labs 7 mins
Adopt an AI Approach with Confidence, for CISOs and CIOs -
Cyber Labs 3 mins
Responding to the CrowdStrike Outage: Implications for Cyber and Technology Professionals -
Cyber Labs 10 mins
DUALITY Part II - Initial Access and Tradecraft Improvements -
Cyber Labs 17 mins
Cracking Into Password Requirements -
Cyber Labs 57 mins
DUALITY: Advanced Red Team Persistence through Self-Reinfecting DLL Backdoors for Unyielding Control -
Cyber Labs 7 mins
Restricted Admin Mode – Circumventing MFA On RDP Logons -
Cyber Labs 9 mins
Detecting “Effluence”, An Unauthenticated Confluence Web Shell -
Cyber Labs 10 mins
Flash Loan Attacks: A Case Study -
Cyber Labs 7 mins
Financially Motivated Criminal Group Targets Telecom, Technology & Manufacturing -
Cyber Labs 16 mins
New Burp Suite Extension: BlazorTrafficProcessor -
Cyber Labs 3 mins
Command Injection and Buffer Overflow in Multiple Sharp NEC Displays -
Cyber Labs 3 mins
Command Injection in Multiple Snap One Araknis Networks Products -
Cyber Labs 6 mins
Introducing D-Modem: A software SIP modem -
Cyber Labs 10 mins
CVE-2021-1825: Inadequate Input Encoding in WebKit
Cyber Resilience
Our Cyber Resilience collection gives you access to Aon’s latest insights on the evolving landscape of cyber threats and risk mitigation measures. Reach out to our experts to discuss how to make the right decisions to strengthen your organization’s cyber resilience.
-
Article 9 mins
Building Resilience in a Buyer-Friendly Cyber and E&O Market -
Article 11 mins
A Middle Market Roadmap for Cyber Resilience -
Article 8 mins
Lessons Learned from the CrowdStrike Outage: 5 Strategies to Build Cyber Resilience -
Article 8 mins
Responding to Cyber Attacks: How Directors and Officers and Cyber Policies Differ -
Article 7 mins
Why Now is the Right Time to Customize Cyber and E&O Contracts -
Article 6 mins
8 Steps Toward Building Better Resilience Against Rising Ransomware Attacks -
Article 7 mins
Mitigating Insider Threats: Managing Cyber Perils While Traveling Globally -
Article 5 mins
Managing Cyber Risk through Return on Security Investment -
Article 10 mins
Mitigating Insider Threats: Your Worst Cyber Threats Could be Coming from Inside -
Article 9 mins
Why HR Leaders Must Help Drive Cyber Security Agenda -
Article 10 mins
Escalating Cyber Security Risks Mean Businesses Need to Build Resilience
Employee Wellbeing
Our Employee Wellbeing collection gives you access to the latest insights from Aon's human capital team. You can also reach out to the team at any time for assistance with your employee wellbeing needs.
-
Article 9 mins
The Next Evolution of Wellbeing is About Performance -
Article 6 mins
Three Ways Collective Retirement Plans Support HR Priorities -
Article 9 mins
How the Right Employee Wellbeing Strategy Impacts Microstress and Burnout at Work -
Podcast 19 mins
On Aon Podcast: Better Being Series Dives into Women’s Health -
Article 7 mins
Making Wellbeing Part of a Company’s DNA -
Podcast 24 mins
On Aon’s Better Being Series: Measuring Wellbeing -
Podcast 25 mins
On Aon’s Better Being Series: Physical Wellbeing and Resilience -
Article 7 mins
Why Workforce Wellbeing is Vital to Company Performance -
Article 7 mins
COVID-19 has Permanently Changed the Way We Think About Wellbeing
Environmental, Social and Governance Insights
Explore Aon's latest environmental social and governance (ESG) insights.
-
Article 8 mins
Why ESG Is Even More Important In A Crisis Like COVID-19 -
Podcast 16 mins
On Aon Podcast: Approach to DE&I in the Workplace
Q4 2023 Global Insurance Market Insights
Our Global Insurance Market Insights highlight insurance market trends across pricing, capacity, underwriting, limits, deductibles and coverages.
-
Article 12 mins
Q4 2023: Global Insurance Market Overview -
Article 13 mins
Top Risk Trends to Watch in 2024
Regional Results
How do the top risks on business leaders’ minds differ by region and how can these risks be mitigated? Explore the regional results to learn more.
-
Article 12 mins
Top Risks Facing Organizations in Asia Pacific -
Article 12 mins
Top Risks Facing Organizations in North America -
Article 10 mins
Top Risks Facing Organizations in Europe -
Article 8 mins
Top Risks Facing Organizations in Latin America -
Article 8 mins
Top Risks Facing Organizations in the Middle East and Africa -
Article 9 mins
Top Risks Facing Organizations in the United Kingdom
Human Capital Analytics
Our Human Capital Analytics collection gives you access to the latest insights from Aon's human capital team. Contact us to learn how Aon’s analytics capabilities helps organizations make better workforce decisions.
-
Article 14 mins
How Technology Will Transform Employee Benefits in the Next Five Years -
Podcast 18 mins
On Aon Podcast: Technology Impacting the Future of Health and Benefits -
Article 8 mins
Integrating Workforce Data to Uncover Hidden Insights -
Article 9 mins
How Employers Can Use Data to Improve Their Health Plans -
Podcast 24 mins
On Aon’s Better Being Series: Measuring Wellbeing -
Article 11 mins
Designing Tomorrow: Personalizing EVP, Benefits and Total Rewards -
Article 9 mins
How to Balance Cost with Growth in a Shifting Talent Market -
Article 8 mins
How Companies are Mitigating Rising Medical Costs -
Article 10 mins
How Data and Analytics Can Optimize HR Programs
Insights for HR
Explore our hand-picked insights for human resources professionals.
-
Article 7 mins
COVID-19 has Permanently Changed the Way We Think About Wellbeing -
Article 7 mins
DE&I in Benefits Plans: A Global Perspective -
Article 10 mins
How Data and Analytics Can Optimize HR Programs -
Article 9 mins
Why HR Leaders Must Help Drive Cyber Security Agenda -
Article 7 mins
Case Study: The LPGA Unlocks Talent Potential with Data -
Article 11 mins
Navigating the New EU Directive on Pay Transparency -
Article 4 mins
How to Design Better Talent Assessment to Promote DE&I -
Article 6 mins
Training and Transforming Managers for the Future of Work -
Article 7 mins
Rethinking Your Total Rewards Programs During Mergers and Acquisitions -
Article 14 mins
Building a Resilient Workforce That Steers Organizational Success | An Outlook Across Industries
Workforce
Our Workforce Collection provides access to the latest insights from Aon’s Human Capital team on topics ranging from health and benefits, retirement and talent practices. You can reach out to our team at any time to learn how we can help address emerging workforce challenges.
-
Report 14 mins
A Workforce in Transition Prepares to Meet a Host of Challenges -
Article 17 mins
3 Strategies to Improve Career Outcomes for Older Employees -
Article 7 mins
Companies Need a Global Benefits Identity in an Era of Cost Containment -
Article 8 mins
Driving Inclusion and Diversity with Employee Benefits -
Article 17 mins
Five Big Human Resources Trends to Watch in 2024 -
Article 8 mins
How Companies are Mitigating Rising Medical Costs -
Report 1 mins
The Global Medical Trend Rates Report 2025 -
Podcast 25 mins
On Aon’s Better Being Series: Physical Wellbeing and Resilience -
Article 9 mins
How the Right Employee Wellbeing Strategy Impacts Microstress and Burnout at Work -
Article 11 mins
Advancing Women’s Health and Equity Through Benefits and Support -
Podcast 18 mins
On Aon Podcast: Technology Impacting the Future of Health and Benefits -
Article 7 mins
How Collective Retirement Plans Help Support Financial Sustainability
Mergers and Acquisitions
Our Mergers and Acquisitions (M&A) collection gives you access to the latest insights from Aon's thought leaders to help dealmakers make better decisions. Explore our latest insights and reach out to the team at any time for assistance with transaction challenges and opportunities.
-
Article 8 mins
Exit Strategy Value Creation Opportunities Exist as Economic Pressures Persist -
Article 5 mins
Future Trends for Financial Sponsors: Secondary Transactions -
Article 7 mins
3 Ways to Unlock M&A Value in a Challenging Credit Environment -
Article 7 mins
Rethinking Your Total Rewards Programs During Mergers and Acquisitions -
Article 9 mins
Organizational Design and Talent Planning are Key to M&A Success -
Article 7 mins
An Ever-Complex Global Tax Environment Requires Strong M&A Risk Solutions -
Article 6 mins
Project Management for HR: The Secret Behind a Successful M&A Deal -
Article 9 mins
Cultural Alignment Planning Drives M&A Success -
Report 1 mins
A Guide to Maximizing Value in Post-Merger Integrations -
Report 2 mins
The ABC's of Private Equity M&A: Deal Flow Impacts of Al, Big Tech and Climate Change -
Article 11 mins
The Silver Lining on M&A Deal Clouds: M&A Insurance Insights from 2023
Navigating Volatility
How do businesses navigate their way through new forms of volatility and make decisions that protect and grow their organizations?
Parametric Insurance
Our Parametric Insurance Collection provides ways your organization can benefit from this simple, straightforward and fast-paying risk transfer solution. Reach out to learn how we can help you make better decisions to manage your catastrophe exposures and near-term volatility.
-
Article 10 mins
How Public Entities and Businesses Can Use Parametric for Emergency Funding -
Article 6 mins
Parametric Insurance: A Complement to Traditional Property Coverage -
Article 8 mins
Using Parametric Insurance to Match Capital to Climate Risk -
Article 6 mins
Using Parametric Insurance to Close the Earthquake Protection Gap -
Article 5 mins
How Technology Enhancements are Boosting Parametric
Pay Transparency and Equity
Our Pay Transparency and Equity collection gives you access to the latest insights from Aon's human capital team on topics ranging from pay equity to diversity, equity and inclusion. Contact us to learn how we can help your organization address these issues.
-
Article 10 mins
How Financial Institutions can Prepare for Pay Transparency Legislation -
Article 8 mins
Pay Transparency Can Lead to Better Equity Across Benefits -
Article 12 mins
Understanding and Preparing for the Rise in Pay Transparency -
Podcast 14 mins
On Aon Podcast: Understanding Pay Transparency Regulations -
Article 11 mins
Navigating the New EU Directive on Pay Transparency -
Article 7 mins
To Disclose Pay or Not? How Companies are Approaching the Pay Transparency Movement -
Podcast 19 mins
On Aon Podcast: Better Being Series Dives into Women’s Health -
Article 11 mins
Advancing Women’s Health and Equity Through Benefits and Support -
Article 8 mins
Driving Inclusion and Diversity with Employee Benefits -
Article 7 mins
Belonging at Work: How Employers can Strengthen DE&I -
Article 7 mins
DE&I in Benefits Plans: A Global Perspective -
Podcast 16 mins
On Aon Podcast: Approach to DE&I in the Workplace
Property Risk Management
Forecasters are predicting an extremely active 2024 Atlantic hurricane season. Take measures to build resilience to mitigate risk for hurricane-prone properties.
-
Article 8 mins
Florida Hurricanes Not Expected to Adversely Affect Property Market -
Article 10 mins
Build Resilience for an Extremely Active Atlantic Hurricane Season -
Article 6 mins
Four Steps to Develop Strong Property Risk Coverage in a Hardening Market -
Podcast 16 mins
On Aon Podcast: Navigating and Preparing for Catastrophes -
Article 6 mins
Parametric Insurance: A Complement to Traditional Property Coverage -
Article 6 mins
Navigating Climate Risk Using Multiple Models and Data Sets -
Article 5 mins
Rising Losses From Severe Convection Storms Mostly Explained by Exposure Growth -
Article 6 mins
Using Parametric Insurance to Close the Earthquake Protection Gap
Technology
Our Technology Collection provides access to the latest insights from Aon's thought leaders on navigating the evolving risks and opportunities of technology. Reach out to the team to learn how we can help you use technology to make better decisions for the future.
-
Article 15 mins
How Artificial Intelligence is Transforming Human Resources and the Workforce -
Report 18 mins
Evolving Technologies Are Driving Firms to Harness Opportunities and Defend Against Threats -
Alert 3 mins
Better Decisions Brief: Perspectives on the CrowdStrike Outage -
Article 12 mins
5 Ways Artificial Intelligence can Boost Claims Management -
Article 6 mins
Artificial Intelligence and the Next Frontier for Financial Institutions -
Article 10 mins
Mitigating Insider Threats: Your Worst Cyber Threats Could be Coming from Inside -
Article 6 mins
8 Steps Toward Building Better Resilience Against Rising Ransomware Attacks -
Article 9 mins
Overcoming the Reputational Cost of Cyber Attacks: The 10-Day Plan -
Article 9 mins
Why HR Leaders Must Help Drive Cyber Security Agenda -
Article 5 mins
How Technology Enhancements are Boosting Parametric -
Article 9 mins
How to Futureproof Data and Analytics Capabilities for Reinsurers
Top 10 Global Risks
Trade, technology, weather and workforce stability are the central forces in today’s risk landscape.
-
Article 7 mins
Cyber Attack or Data Breach -
Article 4 mins
Business Interruption -
Article 4 mins
Economic Slowdown or Slow Recovery -
Article 5 mins
Failure to Attract or Retain Top Talent -
Article 5 mins
Regulatory or Legislative Changes -
Article 4 mins
Supply Chain or Distribution Failure -
Article 6 mins
Commodity Price Risk or Scarcity of Materials -
Article 4 mins
Damage to Brand or Reputation -
Article 5 mins
Failure to Innovate or Meet Customer Needs -
Article 4 mins
Increasing Competition -
Report 3 mins
Business Decision Maker Survey
Trade
Our Trade Collection gives you access to the latest insights from Aon's thought leaders on navigating the evolving risks and opportunities for international business. Reach out to our team to understand how to make better decisions around macro trends and why they matter to businesses.
-
Article 8 mins
The Evolving Threat of Cargo Theft: 5 Key Mitigation Strategies -
Report 3 mins
Global Risk Management Survey -
Report 15 mins
Wide-Ranging Trade Issues Confront Global Businesses on Multiple Fronts -
Article 6 mins
Four Steps to Develop Strong Property Risk Coverage in a Hardening Market -
Article 14 mins
Cutting Supply Chains: How to Achieve More Reward with Less Risk -
Article 9 mins
Driving Private Equity Value Creation Through Credit Solutions -
Article 7 mins
4 Steps to Help Take Advantage of a Buyer-Friendly Directors' & Officers' Market -
Article 9 mins
Managing Reputational Risks in Global Supply Chains -
Article 6 mins
How an Outsourced Chief Investment Officer Can Help Improve Governance and Manage Complexity -
Article 8 mins
Decarbonizing Your Business: Finding the Right Insurance and Strategy -
Article 8 mins
Reputation Analytics as a Leading Indicator of ESG Risk
Weather
With a changing climate, organizations in all sectors will need to protect their people and physical assets, reduce their carbon footprint, and invest in new solutions to thrive. Our Weather Collection provides you with critical insights to be prepared.
-
Article 8 mins
Florida Hurricanes Not Expected to Adversely Affect Property Market -
Report 16 mins
Climate Analytics Unlock Capital to Protect People and Property -
Report 3 mins
Climate and Catastrophe Insight -
Article 10 mins
How Public Entities and Businesses Can Use Parametric for Emergency Funding -
Podcast 12 mins
On Aon Podcast: Tackling Climate Risk to Build Economic Resilience -
Article 8 mins
Understanding Freeze Risk in a Changing Climate -
Podcast 9 mins
On Aon Podcast: Climate Science Through Academic Collaboration -
Article 6 mins
How Companies Are Using Climate Modeling to Improve Risk Decisions -
Podcast 7 mins
On Aon Insights: Climate and Supply Chain -
Article 8 mins
Using Parametric Insurance to Match Capital to Climate Risk -
Article 9 mins
How the Construction Industry is Navigating Climate Change -
Article 9 mins
Record Heatwaves: Protecting Employee Health and Safety
Workforce Resilience
Our Workforce Resilience collection gives you access to the latest insights from Aon's Human Capital team. You can reach out to the team at any time for questions about how we can assess gaps and help build a more resilience workforce.
-
Article 4 mins
Using Data to Close Workforce Gaps in Financial Institutions -
Article 5 mins
Using Data to Close Workforce Gaps in Retail Companies -
Article 7 mins
Using Data to Close Workforce Gaps in Technology Companies -
Article 5 mins
Using Data to Close Workforce Gaps in Manufacturing Companies -
Article 6 mins
Using Data to Close Workforce Gaps in Life Sciences Companies -
Report 4 mins
Measure Workforce Resilience for Better Business Outcomes -
Podcast 18 mins
On Aon Podcast: Methodology to Predict Employee Performance for the LPGA -
Article 6 mins
Training and Transforming Managers for the Future of Work -
Article 14 mins
Building a Resilient Workforce That Steers Organizational Success | An Outlook Across Industries
More Like This
View All-
Cyber Labs 3 mins
Responding to the CrowdStrike Outage: Implications for Cyber and Technology Professionals
This client alert provides an overview of the current global IT outage that is related to a CrowdStrike update. We provide an overview of CrowdStrike's response and guidance, and Aon Cyber Solutions' recommendations for affected clients.
-
Cyber Labs 8 mins
A SIMple Attack: A Look Into Recent SIM Swap Attack Trends
Stroz Friedberg Digital Forensics and Incident Response has observed an uptick in SIM swapping across multiple industries, with several recent incidents targeting crypto and crypto-adjacent companies.
Ready to Explore Further?
Subscribe to Aon
Sign up to receive updates on the latest events, insights, news and more from our team.