Cybercrime costs the world economy over $1 trillion, or just more than 1% of global gross domestic product, according to a McAfee report.
The security vendor says the cost nearly doubled in two years. Its 2019 study put global losses at close to $600 billion.
The report also found that two-thirds of surveyed companies reported some kind of cyber incident in 2019, with the average interruption to operations at 18 hours, and the average attack cost companies more than half a million dollars per incident.
Beyond the global figure, the report found 92% of companies felt effects beyond direct monetary losses including downtime, brand reputation, and reduced efficiency. And despite the half-a-million-dollar price tag per incident, just over half (56%) of organizations said they do not have a plan to both prevent and respond to a cyber incident.
Does this mean that organizations — and the security sector as a whole — are losing the war against cybercriminals? We’re not losing the way, McAfee CTO Steve Grobman said. But cybercrime is a reality that all organizations need to face, and the first step in doing better at defending IT environments is recognizing that reality, he added.
“Organizations of all forms are finding new levels of efficiency and productivity by using modern technology,” he said. “The cost of doing that is they’re being impacted by cybercrime at much greater levels. It’s not unlike our global pandemic that we’re going through on the health side where it’s not that we want or we don’t want it, it’s here, and we have to deal with it.”
Cybercrime Gets More LethalThe report found that it takes, on average, 19 hours for most organizations to move from discovering a security incident to remediation. This usually involved restoring IT services, removing the threat from the system, and retrieving lost data. It also costs businesses an average of eight people to detect and respond to an IT security incident.
“Things are moving away from simple, malware-based attacks where there can be a high level of confidence that an attack is just on the machine where the attack was executed,” Grobman said. In this scenario, the organization can quarantine the infected machine and safely assume that will contain the attack and stop it from spreading. But this isn’t the case anymore, he added.
Instead, McAfee and other security officials see more “lethal” attacks, where the criminals spend more time in a company’s environment and move around more freely, infecting multiple systems and stealing data.
“What we’re seeing more and more is things such as credential theft, where there’s an adversary using human-machine teaming capabilities, and the organization that is impacted isn’t necessarily sure exactly what the scope of the breach is,” Grobman said. “And because the scope of the breach is unclear. It drives the organization to have a much more expensive and much more in depth investigation to gain the confidence that they’ve successfully remediated it. When an organization knows that there’s a human on the other end of the wire, they don’t know all the possible places that the human might have gone, so they have to look almost everywhere within their organization.”
The COVID-19 pandemic spurred a couple other major changes since 2018, Grobman added. Employees are much more likely to work remotely these days, and as a result companies rely on cloud services. “This means that the threat surface that cyber attackers have to work with is much bigger than it was in traditional business environments,” Grobman said.
In fact, COVID-themed attacks represent the highest amount of reported activity in 2020, the report found. In the U.S. alone, the FBI reported cybercrime complaints increased from 1,000 to 4,000 daily during the pandemic.
Cybercrime Costs Other Than CashThe report also dives into costs other than cash, finding that 92% of businesses said there were other negative effects on their business beyond financial costs and lost work hours after an incident. This includes things like system downtime, which was a common experience for about two-thirds of respondents’ organizations. The average cost to organizations from their longest amount of downtime in 2019 was $762,231. Additionally, 33% of respondents said IT security incidents resulting in system downtime cost them between $100,000 and $500,000.
Brand and reputation damage is another big one, and this encompasses the cost of rehabilitating the external image of the brand, working with outside consultancies to mitigate brand damage, and hiring new employees to prevent against future incidents is part of the cost of cybercrime. The survey found 26% of respondents identified damage to brand from the downtime experienced because of a cyberattack.
“There are the recoverable elements of a cyberattack and the non-recoverable elements of a cyberattack,” Grobman said. The recoverable elements include restoring data and bringing systems back online.
On the other hand, intellectual property theft represents a non-recoverable element, he explained. “Once somebody steals the secret sauce for a company’s IP, that allows the duplication of their technology in another country that could even end up becoming a leader in that industry and competing with them,” Grobman said. “That is a very profound, very high-impact, long-term cost. So when organizations are thinking about defending their environments, it’s not only important to think about the information related to running their business, but what are the things that if stolen would be a permanent or long-term impact with intellectual property or trade secrets being key examples.”
Lack of Cyber Risk UnderstandingMcAfee also calls out a lack of organizational understanding of cyber risk. In addition to 56% saying they do not have a plan to both prevent and respond to a cyberattack, only 32% of the 951 organizations that did have a response plan said it was effective.
However, there are steps companies can take to help prevent attacks or reduce the harm that they inflict to the business and its brand and reputation. The report includes five best practices for organizations to protect themselves. These include uniform implementation of basic security measures, increased transparency, standardization and coordination of security requirements, security awareness training for employees, and prevention and response plans.
“Cybersecurity is not only the responsibility of the CISO, IT, and the security organization, it’s the responsibility of all employees,” Grobman said. “When we look at how many of these attacks are bootstrapped, it’s because individuals outside of the security organization made a human error. They clicked on a spear phishing email. They used a BYOD device in a way that wasn’t appropriate. And therefore, having strong training, across the organization above and beyond the IT and security teams is critically important.”
‘Cybercrime Is a Business’Looking ahead to 2021, Grobman doesn’t expect to see cybercrime stop, but businesses can take steps to improve their security hygiene and deter criminals from going after their networks and data.
“Cybercrime is a business, and it’s a good business,” he said. “We’d expect is to see cybercriminals continue to run their criminal enterprises to generate significant monetary benefit for their cybercrime organizations or nation states. But just like consumers, having strong technology for their homes or their cars can make a car thief move on to the next car versus trying to steal a well-defended one. Clearly we want to, on a global scale, build better global defense, but on an individual organization basis, having a strong cyber defense solution is as much about giving the cybercriminals an incentive to focus on an easier target as being absolutely imperative impenetrable at all costs.”
Comments