Security News

Malicious Insider Attacks are Expensive & Lengthy to Resolve: Accenture

According to a report from Accenture and  Ponemon Institute, the cost to address and contain cyber-attacks is greater for financial services firms than for companies in any other industry.

The report, “Unlocking the Value of Improved Cybersecurity Protection,” examines the costs that organizations incur when responding to cybercrime incidents and applies a costing methodology that allows year-over-year comparisons.

It found that the average annualized cost of cybercrime for financial services companies globally has increased to US$18.5 million, the highest of all industries included in the study and more than 40% higher than the average cost of US$13 million per firm across all industries. The analysis focuses on the direct costs of incidents and does not include the longer-term costs of remediation.

Malicious insider attacks are the most expensive type of attack for financial services firms to resolve, at US$243,000 per attack, and also take the longest time for the firms to resolve, at 55.1 days on average — significantly higher than the time to contend with ransomware (33.8 days) or web-based attacks (25.9 days).

“More prudent “More “More prudent technology investments at the right spending levels would actually reduce costs while improving banks’ and insurers’ overall cybersecurity resilience. These cost savings are crucial for financial services executives trying to decide how much to spend on security versus other key areas, such as their overall digital transformation” said Chris Thompson, global security and resilience lead for financial services at Accenture Security.

Financial Services Firms Should Reconsider Security Investments
The report notes that only one-third (34%) of firms are deploying automation, artificial intelligence (AI) and machine learning to help combat cyber threats. The study found that, when fully deployed, these technologies deliver the largest cost savings for an organization’s security efforts.

Similarly, only 24% of firms are making extensive use of cyber analytics and user behavior analytics, despite similarly high cost savings for these technologies.

According to the report, financial services firms are not prioritizing security investments that can actually help reduce the cost of cybercrime. Investments in security intelligence and threat sharing technologies, for example, have an estimated annual return on investment of 22.5%, second only to advanced identity and access management.

Yet, when examining the rank of security technologies by percentage spending, security intelligence and threat sharing is in the bottom three among financial services firms. A similar value gap exists for automation, AI and machine learning, as well as cyber analytics.

(Image Courtesy:

Leave a Comment

Your email address will not be published.

You may also like