Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

New report finds cybersecurity investment generates substantial ROI as large firms fend off rising cyberattacks

ESI ThoughtLab and group of cybersecurity advisors release findings from study of 1,009 of the world's largest firms.


News provided by

ESI ThoughtLab

Jun 18, 2020, 09:00 ET

Share this article

Share toX

Share this article

Share toX

Driving Cybersecurity Performance eBook cover
Driving Cybersecurity Performance eBook cover

PHILADELPHIA, June 18, 2020 /PRNewswire-PRWeb/ -- A comprehensive study conducted by ESI ThoughtLab reveals that increased investment in cybersecurity can generate a significant ROI of 179% and provide greater protection as companies cope with the fallout from COVID-19.

ESI ThoughtLab benchmarked the cybersecurity investments, practices, and performance metrics of 1,009 firms across 13 industries and 19 countries to identify the most effective approaches for mitigating cybersecurity risks and losses. This ground-breaking research was conducted in conjunction with an advisory group of cybersecurity, cyber insurance, and technology specialists, including Arceo.ai, Check Point Software, Cowbell Cyber, Edelman, Fiserv, KnowBe4, Optiv, and Verizon Business.

Companies across the board are improving their cybersecurity practices and reducing their losses thanks to smart investments in people, process, and technology

Post this

The analysis found that, last year, firms surveyed spent $9.6 million on average on cybersecurity ($515 per employee), and 97% of those expect to increase their spending by an average of 14% this year (pre-COVID-19 estimates). Companies are investing in three areas: people, process, and technology. While the average ROI is 179%, it ranges from 271% for investments in people, 156% for process, and 129% for technology. According to the research, on average, investments in people result in a 46% decline in the probability of a breach vs. 30% for process and 37% for technology.

"These cybersecurity investments can generate enormous ROI for companies, particularly for those in earlier stages of cybersecurity maturity," said Lou Celi, CEO of ESI ThoughtLab and the program director of the research. "The reliance on digital technology during the pandemic, together with the rise of remote working, shopping, and healthcare, have served as a stress test for corporate cybersecurity systems. Our CISO interviews have revealed that companies with advanced protection, detection, and response frameworks, backed up by strong cybersecurity hygiene and governance, have fared well during the crisis."

Companies still need to do more to combat rising threats

According to the surveyed companies, one in three attack attempts over the last year resulted in a successful breach. While most cybersecurity breaches are minor, affecting only a small number of people or machines, the average price tag per breach is around US$330,000. However, for firms that are in the top 10% in terms of breach costs, the average cost per breach is over $1.8 million. Adding to the complexity, companies may be underestimating their exposure to a potential breach and overestimating the protection offered by their cybersecurity systems. While the average company assigns a 45% probability to a moderate or material breach, the research shows that the probability is much higher, ranging from 62% to 86%.

The research shows that companies need to go well beyond compliance with cybersecurity frameworks, such as NIST or ISO, to be effective in reducing risks. For example, only 64 of 151 companies (42%) classified as leaders in NIST compliance are advanced in cybersecurity effectiveness, according to the study's rankings. Rather than applying the NIST framework as a box-ticking exercise, the most cyber-secure companies adapt this framework to their business goals, strategies, and individual risk profiles. Cybersecurity leaders also combine analysis from advanced quantitative tools and input from internal business partners and third-party experts to make the best decisions.

Even before COVID-19 hit, companies reported the largest losses from malware (66% of survey respondents), phishing (60%), and password reuse (49%), with cyber criminals cited as the biggest threat actors. As business goes digital over the next two years, executives also expect an increase in attacks through artificial intelligence (38%), denial of service (34%), and web applications (29%). With geopolitical and social unrest growing, and greater economic volatility ahead, CISOs in the financial, energy, automotive, retail, and telecom sectors are bracing for a jump in cyber terrorism and activism, along with greater risks from nation-states.

The most successful approaches of companies advanced in cybersecurity

The study identifies the practices of cybersecurity leaders that are most effective in mitigating cybersecurity risks and losses. Leaders commonly do six things that keep them well prepared for today's high-risk environment:

1. Invest more in cybersecurity. Leaders spend about 25% more than others on cybersecurity per employee, increase those investments each year more than the average, and invest more than others in recruiting specialists, working with external consultants, and training, such as end-user security awareness training with simulated phishing.

2. Make cybersecurity hygiene a top priority. Leaders have the lowest percentage of "critical" unpatched or "high" vulnerabilities based on CVSS scores (18% for leaders vs. 28% for others). They also do more frequent backup restoration drills (5.6 times a year vs. 4.3 for non-leaders), IT infrastructure scans (4.9 vs 3.4), and phishing tests (5.1 vs. 4.4).

3. Keep management teams focused and aligned. Cybersecurity heads typically report into the CEO, COO, or the Board in leader companies. CISOs at these firms focus more on security than IT (75% of leaders) and play a bigger role in managing data privacy (54%), digital transformation (57%), and operational resiliency (49%). Leaders are also more likely to make cybersecurity a shared responsibility of two executives, such as the CIO and CISO, or the CISO and CSO.

4. Rely heavily on advanced analytics and specialized teams. More than 8 out of 10 leaders conduct cyber-risk scenario analysis, assess the financial impact of risk events, and measure the effects of mechanisms to mitigate cyber risks. Leaders also outsource incident response, red team, risk management, and security ops more often than others.

5. Extract greater value from cybersecurity tools. Leaders invest more heavily in—and achieve greater effectiveness from—key cybersecurity technologies, including cloud workload security, endpoint detection, mobile device management, deception technology, email filtering, multi-factor authentication, and firewalls and web filtering.

6. Make more use of cybersecurity insurance. Since it is impossible to mitigate all risk, leaders rely more on insurance to transfer it: 57% of leaders have cyber insurance coverage over $10 million, compared with 30% of non-leaders. Overall, six out of 10 firms plan to spend more on cybersecurity insurance over the next two years.

"Companies across the board are improving their cybersecurity practices and reducing their losses thanks to smart investments in people, process, and technology," said Celi. "While these steps have helped contain cyberattacks during the pandemic, today's turbulent environment has underscored the value of business continuity and resilience, as well as using advanced analytics to assess cyber risks in an interconnected world."

The full findings of the study can be found at https://econsultsolutions.com/esi-thoughtlab/driving-cybersecurity-performance/

For media inquiries, please contact:

Lou Celi, Program Director
ESI ThoughtLab
917-459-4614
[email protected]

Mike Daly, Marketing Director
ESI ThoughtLab
215-717-2777
[email protected]

About ESI ThoughtLab: ESI ThoughtLab is the thought leadership arm of Econsult Solutions Inc., a leading economic consultancy. The innovative think tank offers fresh ideas and evidence-based analysis to help business and government leaders understand and respond to economic, industry and technological shifts around the world. Its team of top economists and thought leaders excel at creating valuable decision support that combines visionary thinking, analytical excellence, and multi-format content.

About Arceo.ai: Arceo.ai enables cyber resilience by combining smarter insurance products with dynamic security solutions. Headquartered in San Francisco, Arceo empowers insurers and brokers to better assess, underwrite, and manage cyber risks through a patented methodology called Cyber Meteorology. Arceo's holistic risk analytics and insurance platform enables enterprises to better identify, respond to, and recover from cyber risks using AI to drive advanced risk assessment and proactive security services. For more information, visit http://www.arceo.ai and stay up to date on our blog Twitter and LinkedIn.

About Cowbell™ Cyber: Cowbell Cyber maps insurable threats and risk exposures using artificial intelligence to determine the probability of threats and impact on coverage types. In its unique approach to risk selection and pricing, Cowbell compiles Cowbell Factors™, a set of risk-rating factors, that enable continuous underwriting and expedite quoting and binding for brokers. Cowbell Prime™, Cowbell's standalone, admitted, and individualized cyber coverage is available to small and mid-size businesses (SMBs) through a network of independent insurance agencies and brokers.

About Edelman: Edelman is a global communications firm that partners with businesses and organizations to evolve, promote and protect their brands and reputations. Our 6,000 people in more than 60 offices deliver communications strategies that give our clients the confidence to lead, act with certainty and earn the lasting trust of their stakeholders. We develop powerful ideas and tell magnetic stories that move at the speed of news, make an immediate impact, transform culture, and spark movements.

About Fiserv: Fiserv, Inc. (NASDAQ: FISV) aspires to move money and information in a way that moves the world. As a global leader in payments and financial technology, the company helps clients achieve best-in-class results through a commitment to innovation and excellence in areas including account processing and digital banking solutions; card issuer processing and network services; payments; e-commerce; merchant acquiring and processing; and the Clover® cloud-based point-of-sale solution. Fiserv is a member of the S&P 500® Index and the FORTUNE® 500 and is among FORTUNE World's Most Admired Companies®. Visit Fiserv.com and follow us on social media for more information and the latest company news.

About KnowBe4: KnowBe4 is the world's largest security awareness training and simulated phishing platform that helps you manage the ongoing problem of social engineering. The KnowBe4 platform is user-friendly and intuitive. It was built to scale for busy security leaders and IT pros that have 16 other fires to put out. Our goal was to design the most powerful, cost effective and easy-to-use platform available. 

About Optiv Security: Optiv is a security solutions integrator – a "one-stop" trusted partner with a singular focus on cybersecurity. Our end-to-end cybersecurity capabilities span risk management and transformation, cyber digital transformation, threat management, security operations, identity and data management, and integration and innovation, helping organizations realize stronger, simpler, more cost-efficient cybersecurity programs that support business requirements and outcomes. At Optiv, we are leading a completely new approach to cybersecurity that enables clients to innovate their consumption models, integrate infrastructure and technology to maximize value, achieve measurable outcomes, and realize complete solutions and business alignment. For more information about Optiv, please visit us at http://www.optiv.com

About Verizon: Verizon Communications Inc. was formed on June 30, 2000 and is celebrating its 20th year as one of the world's leading providers of technology, communications, information and entertainment products and services. Headquartered in New York City and with a presence around the world, Verizon generated revenues of $131.9 billion in 2019. The company offers voice, data and video services and solutions on its award-winning networks and platforms, delivering on customers' demand for mobility, reliable network connectivity, security, and control.

SOURCE ESI ThoughtLab

Modal title

Driving Cybersecurity Performance press release
View PDF
Driving Cybersecurity Performance press release
Driving Cybersecurity Performance press release

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.