The Rising Importance of Cyber Incident Response Planning: A New Report from Marsh McLennan
In today’s escalating threat landscape,a robust cyber security posture is no longer a ‘nice-to-have’ but a critical necessity.Increasingly, cyber incident response plans are emerging as a cornerstone of effective risk reduction, particularly when it comes to navigating the complexities of cyber insurance. This conclusion is powerfully supported by new research from Marsh McLennan’s Cyber Risk Intelligence Centre (CRIC).
the report,titled Cybersecurity signals: Connecting controls and incident outcomes,reveals a compelling correlation: organizations that proactively prepare for cyberattacks through regular tabletop wargame exercises and scenario-based breach response drills are 13% less likely to experience a significant cyber incident compared to those who don’t.
“Marsh McLennan has consistently championed proactive cyber incident response planning as a vital tool for organizations to effectively manage and recover from cyberattacks,” explains Tom Reagan, Global cyber Practice Leader at Marsh McLennan. “Our latest research validates this approach, demonstrating that thoughtful planning not only streamlines response efforts but also fosters positive security behaviors and strengthens overall control implementations, ultimately building greater organizational resilience and reducing the likelihood of a breach.”
From Correlation to Causation: Understanding the Impact of Preparedness
For two years, the CRIC has meticulously tracked the relationship between core security controls – those scrutinized by cyber insurers – and the frequency of insurance claims. This analysis leverages data from thousands of organizations utilizing Marsh McLennan’s Cyber Self Assessment service, allowing for a detailed examination of risk profiles and preparation levels, cross-referenced with actual claims histories.This data-driven approach provides valuable insights into which security practices demonstrably reduce risk.
While direct year-over-year comparisons are challenging due to the rapidly evolving threat landscape, the findings clearly position incident response planning as a top-tier security control. Currently ranked as the fourth most effective control, it trails only endpoint detection and response (EDR), robust logging and monitoring, and complete security awareness training coupled with phishing simulations.
Interestingly, Marsh McLennan suggests that effective incident response planning may be driving a positive ripple effect. The process of developing and refining these plans often uncovers vulnerabilities in other areas of an organization’s security program, prompting further investment and strengthening the overall security posture.
A Broader Look at Security Posture Improvements
the 2023 report also highlights encouraging trends across other key cyber security controls. Organizations are demonstrably improving their defenses:
Endpoint Detection and Response (EDR): Implementation has increased by 9%, rising from 82% to 91% of respondents. Email Security: Evaluation and quarantine of inbound email attachments are now practiced by 83% of respondents, an 8% increase.
Vulnerability Management: Significant gains have been made in patching critical vulnerabilities. Organizations setting target windows for patching high-severity vulnerabilities have soared from 24% to 89%, and for critical-severity vulnerabilities, from 53% to 89%.
However, the report also identifies areas requiring attention. The use of endpoint privilege management – a crucial control for limiting the impact of compromised accounts – decreased from 35% to 27%, a concerning trend.”Our findings underscore a critical point: simply deploying security tools isn’t enough,” emphasizes Scott Stransky, Head of CRIC. “These tools must be actively managed and comprehensively utilized to deliver maximum value. By leveraging these insights, organizations can make informed decisions to fortify their security frameworks and minimize their exposure to cyber risks.”
Key Takeaways & Implications for Organizations
This report from Marsh McLennan provides a clear message: proactive preparation is paramount. Investing in comprehensive cyber incident response planning isn’t just about satisfying insurance requirements; it’s about building a resilient organization capable of weathering the unavoidable storm of cyberattacks.
Here’s what organizations should prioritize:
Regular Tabletop Exercises: Simulate real-world attack scenarios to identify weaknesses in yoru response plan and train your team.
Scenario-Based Breach Drills: Go beyond tabletop exercises with practical drills that test your technical capabilities and interaction protocols.
Continuous Improvement: Incident response planning is not a one-time event. Regularly review and update your plan based on evolving threats and lessons learned.
Holistic Security Approach: Don’t focus solely on incident response. Invest in foundational controls like EDR, logging & monitoring, and security awareness training.
Prioritize Vulnerability Management: Establish and enforce strict patching policies to address known vulnerabilities promptly.
By embracing a proactive and comprehensive approach to cyber security, organizations
Keep reading