Groundbreaking Research from Marsh McLennan Reveals Direct Link between Key Cybersecurity Controls and Reduced Cyber Risk - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
April 6, 2023 Newswires
Share
Share
Post
Email

Groundbreaking Research from Marsh McLennan Reveals Direct Link between Key Cybersecurity Controls and Reduced Cyber Risk

Business Wire

NEW YORK--(BUSINESS WIRE)-- Marsh McLennan (NYSE: MMC), the world’s leading professional services firm in the areas of risk, strategy and people, today released a report from its Cyber Risk Analytics Center that directly links key cybersecurity controls commonly required by cyber insurers to a reduced chance of a cyber incident. By assessing the relative effectiveness of each control, organizations are now able to allocate resources towards those that provide the best protection, better position their risk with insurers, and build their cyber resiliency more confidently.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230406005089/en/

According to a new Marsh McLennan report, these five controls, among the 12 key control categories commonly required by cyber insurers, were determined to have the greatest ability to decrease the likelihood of a successful cyberattack. (Graphic: Business Wire)

According to a new Marsh McLennan report, these five controls, among the 12 key control categories commonly required by cyber insurers, were determined to have the greatest ability to decrease the likelihood of a successful cyberattack. (Graphic: Business Wire)

According to the report, Using data to prioritize cybersecurity investments, automated hardening techniques were found, by a wide margin, to have the greatest ability of any control studied to decrease the likelihood of a successful cyberattack. Organizations with such techniques in place, which apply baseline security configurations to system components like servers and operating systems, are nearly six times less likely to have a cyber incident than those that do not.

The finding is surprising, the report notes, given that until now, the three controls most frequently recommended by insurers have been endpoint detection and response (EDR), multifactor authentication (MFA), and privileged access management (PAM).

The analysis also shows that MFA, long a staple among cybersecurity tools and recommendations, only works when it is in place for all critical and sensitive data, for all remote login access, and for administrator account access. Organizations with such broad implementation are 1.4 times less likely to experience a successful cyberattack than those that do not.

Additionally, patching high severity vulnerabilities across the enterprise within seven days of the patch’s release ties as the fourth most effective control – decreasing an organization’s probability of experiencing a cyber event by a factor of 2, yet it is has the lowest implementation rate among organizations studied, at only 24%, the report found.

“All of the key controls in our study are well-known best practices, commonly required by underwriters to obtain cyber insurance. However, many organizations are unsure which controls to adopt and rely on expert opinions rather than data to make decisions,” said Tom Reagan, US and Canada Cyber Practice Leader, Marsh. “Our research provides organizations the data they need to more effectively direct cybersecurity investments, which in turn, helps favorably position them during the cyber insurance underwriting process. It is another step toward building not only a more resilient cyber insurance market, but also a more cyber resilient economy.”

For the report, Marsh McLennan paired its extensive proprietary dataset of cyber claims with the results from Marsh Cybersecurity Self-Assessment (CSA) questionnaires, which are composed of hundreds of questions and responses from individual organizations. Based on the correlation, data scientists calculated and assigned a “signal strength” to each control. The higher the signal strength, the greater the impact the control has on decreasing the likelihood of an event.

Among the hundreds of cyber capabilities, tools, and implementation techniques analyzed and measured, the report focuses only on those falling within the 12 key control categories commonly required by cyber insurers. Among those, the top five controls determined most effective are:

Key control category

Signal strength

Hardening techniques

System configuration management tools, such as active directory group policy, which enforce and redeploy configuration settings to systems

5.58

Privileged access management

Managing desktop or local administrator privileges via endpoint privilege management (EPM)

2.92

Endpoint detection and response

Operating advanced endpoint security

2.23

Logging and monitoring

Operating a security operations center (SOC) and/or having an outsourced managed security service provider (MSSP) with the following capabilities at a minimum:

a. Established incident alert thresholds

b. Security incident and event management (SIEM) monitoring and alerting for unauthorized access connections, devices and software

2.19

Patched systems

Patching common vulnerability scoring system (CVSS) v3 high severity 7.0-8.9 vulnerabilities across the enterprise within 7 calendar days of release

2.19

Additional insights from the research will be used as part of a forthcoming cyber event attritional loss model from Marsh McLennan that will inform insureds of potential losses they could suffer, and the potential savings benefit from increasing their cybersecurity posture.

“Marsh McLennan launched the Cyber Risk Analytics Center in late 2021 with the goal of helping organizations make smarter investments in the ways they identify, prepare for, and recover from cyber risk,” said Scott Stransky, who leads the Marsh McLennan enterprise-wide resource. “This groundbreaking report will be indispensable to Marsh McLennan clients as we work together to build society’s resilience to this critical and costly risk.”

About Marsh McLennan

Marsh McLennan (NYSE: MMC) is the world’s leading professional services firm in the areas of risk, strategy and people. The Company’s more than 85,000 colleagues advise clients in 130 countries. With annual revenue of over $20 billion, Marsh McLennan helps clients navigate an increasingly dynamic and complex environment through four market-leading businesses. Marsh provides data-driven risk advisory services and insurance solutions to commercial and consumer clients. Guy Carpenter develops advanced risk, reinsurance and capital strategies that help clients grow profitably and pursue emerging opportunities. Mercer delivers advice and technology-driven solutions that help organizations redefine the world of work, reshape retirement and investment outcomes, and unlock health and wellbeing for a changing workforce. Oliver Wyman serves as a critical strategic, economic and brand advisor to private sector and governmental clients. For more information, visit marshmclennan.com and follow us on LinkedIn and Twitter.

src="https://cts.businesswire.com/ct/CT?id=bwnewssty=20230406005089r1sid=acqr8distro=nxlang=en" style="width:0;height:0" />

View source version on businesswire.com: https://www.businesswire.com/news/home/20230406005089/en/

Media:
Amelia Woltering Marsh McLennan
+1 347 703 5358

[email protected]

Source: Marsh McLennan

Older

To Better Support Medicare and Medicaid Beneficiaries, Zocdoc Launches Search and Booking for Federally Qualified Health Centers (FQHCs) on its Marketplace

Newer

Verisk Names Chris Sawford Managing Director of Claims for the UK

Advisor News

  • IRS CEO FRANK J. BISIGNANO VISITS OHIO TO TOUT WORKING FAMILIES TAX CUTS PROVISIONS ON NO TAX ON CAR LOAN INTEREST, NO TAX ON OVERTIME, ENHANCED DEDUCTION FOR SENIOR CITIZENS
  • The hidden flaw in insurance AI adoption for advisors and carriers
  • Rising healthcare costs impact 401(k) accounts
  • What advisors think about pooled employer plans, alternative investments
  • AI, stablecoins and private market expansion may reshape financial services by 2030
More Advisor News

Annuity News

  • How annuities can help protect retirees from financial scams
  • MetLife Inc. (NYSE: MET) Climbs to New 52-Week High
  • The Standard and Pacific Guardian Life Announce Entry into Agreement to Transition Individual Annuities Business
  • AuguStar Retirement launches StarStream Variable Annuity
  • Prismic Life Announces Completion of Oversubscribed Capital Raise
More Annuity News

Health/Employee Benefits News

  • Bay Area braces for Trump’s tougher CalFresh rules
  • Mom blames Florida Blue, Broward Health dispute for daughter’s $11,500 ER bill
  • ASHLEY HINSON FAILS TO FOOL IOWANS WITH HER MISLEADING SENATE CAMPAIGN TV AD
  • NEW: "ASHLEY HINSON AD MISLEADS VOTERS ABOUT HER RECORD"
  • Idaho farmers can band together to buy cheaper health insurance through Farm Bureau deal
More Health/Employee Benefits News

Life Insurance News

  • Kansas official running for governor received $300K in donations before key decision
  • Investigators say C.R. man's life insurance claims for 3 children were fraudulent
  • Shocking death of Kyle Busch renews debate over IUL plan
  • WoodmenLife launches final expense life insurance offering
  • The Standard and Pacific Guardian Life Announce Entry into Agreement to Transition Individual Annuities Business
More Life Insurance News

- Presented By -

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Why Blend in When You Can Make a Splash?
Pacific Life’s registered index-linked annuity offers what many love about RILAs—plus more!

Life moves fast. Your BGA should, too.
Stay ahead with Modern Life's AI-powered tech and expert support.

Bring a Real FIA Case. Leave Ready to Close.
A practical working session for agents who want a clearer, repeatable sales process.

Discipline Over Headline Rates
Discover a disciplined strategy built for consistency, transparency, and long-term value.

You Could Be Losing Up to 20% of Your Commissions
GreenWave helps you find, fix, and prevent commission errors.

Press Releases

  • Rockwood Programs Appoints Kerry Ladouceur as Vice President, Financial Lines
  • JP Insurance Group Launches Commercial Property & Casualty Division; Appoints Joe Webster as Managing Director
  • Sequent Planning Recognized on USA TODAY’s Best Financial Advisory Firms 2026 List
  • Highland Capital Brokerage Acquires Premier Financial, Inc.
  • ePIC Services Company Joins wealth.com on Featured Panel at PEAK Brokerage Services’ SPARK! Event, Signaling a Shift in How Advisors Deliver Estate and Legacy Planning
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet