Cost and Frequency of Cyber Attacks on the Rise, yet Companies are Less Prepared to Combat Attacks, According to Hiscox Cyber Readiness Report
To determine the respondents' preparedness to handle cyber attacks, Hiscox evaluated the firms' strategy (oversight and resourcing) and execution (technology and process) and ranked them as a 'cyber novice,' 'cyber intermediate' or 'cyber expert.'
Key findings specific to the more than 1,000 US companies surveyed include:
- Leaky bucket budgets: Seventy-two percent of firms plan to increase spending on cyber security in the coming year. However, increased spend without proper infrastructure and training is the equivalent of pouring water into a leaky bucket. Only 11% of respondents cited increased spending on employee training and culture changes as a result of a cyber security incident, both of which are crucial components of a company's defense against cyber risks.
- Attacks are on the rise: Fifty-three percent of respondents reported an attack in the past 12 months, compared to 38% last year. Many companies do not take proper action following an attack, with 45% of companies reporting experiencing three or more attacks in the past year. Cyber incidents come with a large price tag. The mean cost of cyber incidents in the US was
$119,000 .
- Fewer large companies are 'cyber experts:' While it would seem they have the resources to be prepared, only 11% of large and enterprise firms ranked as 'cyber experts,' compared to 26% of large and enterprise firms last year.
- Unexpected risks in the supply chain: Fifty-six percent of firms experienced cyber-related issues in their supply chain in the past year. However, only 7% of respondents cited increased evaluation of the supply chain as a result of a cyber security incident occurring in the past 12 months.
- Lack of insurance heightens the stakes: Twenty-seven percent of respondents have no plans to purchase cyber insurance, and 5% are unsure of what cyber insurance is.
"The message that cyber risk is a real threat to businesses of all sizes is sinking in. Companies are increasingly aware of the risks and pouring more resources into cyber protection, and yet, there is still a tremendous gap between awareness of the issue and actually having an effective defense," said
Creating a Line of Defense: Cybersecurity Best Practices
Based off Hiscox's proprietary module, companies in the seven countries surveyed had to achieve a minimum score of 4.0/5 in strategy and execution to qualify as a 'cyber expert.' The study identified 'cyber expert' best practices that 'cyber novices' lack, and, based on the global findings, these include:
- Securing executive buy-in: Only 54% of 'cyber novices' globally believe cybersecurity is a top priority for their firm's executive management/board as compared to 85% percent of 'cyber experts.'
- Creating a well-defined strategy with input from multiple stakeholders and determining a formal and adequate cyber budget: On average, 'cyber experts' globally devote 14.7% of their IT budget to cybersecurity, but 'cyber novices'' cybersecurity spending accounts for just 8.7% of their overall IT budget.
- Dedicating a cyber head tasked with overseeing the strategy, supported by a team if necessary: Globally, 51% of 'cyber experts' have a dedicated leader who oversees cybersecurity, compared to just 39% of 'cyber novices.'
- Regularly evaluating the supply chain: Only 18% of 'cyber novices' strongly feel that they have good visibility into their suppliers' security arrangements, compared to 34% of 'cyber experts' globally.
- Defining a process that spans from when a cyber incident is detected to when it has been mitigated, and making sure employees are ready to learn, respond and make changes to this process if an incident occurs: Eighty-five percent of all 'cyber experts' have a clearly defined cybersecurity strategy, compared to just 53% of 'cyber novices.'
- Conducting proactive testing through simulated attacks and regular phishing experiments: Forty-one percent of 'cyber novices' globally have conducted phishing experiments to understand employee behavior and readiness for attacks, compared to 69% of 'cyber experts.'
- Insuring your business with a cyber policy: Globally, 59% of 'cyber experts' currently have already adopted cyber insurance, compared to only 37% of 'cyber novices.'
Hiscox offers an online interactive suite of cyber security training modules included as part of its Cyber and data insurance policies that helps customers prepare their employees and reduce the risk of a cyber incident occurring.
In the US, Hiscox has offices in
Related Materials:
The Hiscox Cyber Readiness Report 2019™
About the Study
Hiscox commissioned
About
Hiscox is a global specialist insurer, headquartered in
Our values define our business, with a focus on people, quality, courage and excellence in execution. We pride ourselves on being true to our word and our award-winning claims service is testament to that. For more information, visit www.hiscoxgroup.com.
The content provided above is provided for general informational purposes, but is not intended, nor shall it be deemed, to be business, legal or insurance advice for any particular or specific person or entity.
Media Contacts
+1 646 442 8341
[email protected]
Gyawu Mahama
+1 678 781 6003
[email protected]
View original content:http://www.prnewswire.com/news-releases/cost-and-frequency-of-cyber-attacks-on-the-rise-yet-companies-are-less-prepared-to-combat-attacks-according-to-hiscox-cyber-readiness-report-300836008.html
SOURCE Hiscox



World Insurance Associates LLC Completes 40th Acquisition with Lampe-Batkin Associates LLC of Greenwich, CT
HCAP Partners Announces New Investment in Mission Healthcare
Advisor News
- Most Americans optimistic about a financial ‘resolution rebound’ in 2026
- Mitigating recession-based client anxiety
- Terri Kallsen begins board chair role at CFP Board
- Advisors underestimate demand for steady, guaranteed income, survey shows
- D.C. Digest: 'One Big Beautiful Bill' rebranded 'Working Families Tax Cut'
More Advisor NewsAnnuity News
- Integrity adds further scale with blockbuster acquisition of AIMCOR
- MetLife Declares First Quarter 2026 Common Stock Dividend
- Using annuities as a legacy tool: The ROP feature
- Jackson Financial Inc. and TPG Inc. Announce Long-Term Strategic Partnership
- An Application for the Trademark “EMPOWER PERSONAL WEALTH” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
More Annuity NewsHealth/Employee Benefits News
- As class-action lawsuit continues, advocates say Johnstown stuck in 'pharmacy desert'
- Mass. will spend $250M to lower health insurance bills after federal subsidies expired
- MURPHY ON TRUMP'S PLAN TO RUN VENEZUELA: NOBODY ASKED FOR THIS
- Sorensen and Miller-Meeks disagree on ACA health insurance subsidies, prepare for shutdown
- Pittsburgh Post-Gazette to publish final edition and cease operations on May 3
More Health/Employee Benefits NewsLife Insurance News