Improving the cyber security of companies that allow distributed devices access to corporate networks to facilitate remote working resulting from the longer term COVID-19 response.
Improving the cyber security of companies that allow distributed devices access to corporate networks to facilitate remote working resulting from the longer term COVID-19 response.
批准号:
85374
负责人:
金额:
$10.75万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2020
资助国家:
英国
项目状态:
已结题
起止时间:
2020 至 --
中文摘要
根据加拉格尔的说法,2019年_:“140万英国中小企业遭受了一次网络攻击/重大安全事件。这给经济造成了88亿GB的损失,平均攻击成本为6500 GB\。17%的事件花费了10%的赔偿金GB 20k。23%的中小企业在事件发生后如果无法交易\>;一个月无法生存……57,000家中小企业可能面临倒闭的风险。_新冠肺炎极大地增加了这些风险。网络犯罪分子正在调整他们的战术,瞄准因在家工作激增而暴露出来的终端漏洞。在第二季度,英国企业报告的网络攻击(VMWare)增加了92%。ZNET发现,在过去三个月里,文件加密恶意软件增加了72%,并指出勒索软件攻击现在集中在窃取数据和加密数据上。作为最近的一个例子,7月17日,国家预防控制中心揭露了俄罗斯对新冠肺炎疫苗开发商的攻击。在后新冠病毒感染的环境中,这些风险不太可能降低。高德纳最近的一项民意调查显示,在新冠肺炎事件发生后,48%的员工可能会至少在部分时间远程工作,而在新冠肺炎事件之前这一比例为30%。中小企业尤其容易受到远程工作攻击,因为它们通常缺乏防范网络犯罪所需的资源。鉴于攻击数量的增加,超过100,000家英国中小企业现在可能面临倒闭的风险。Per Aon“_过去几年,随着组织旨在提高员工的移动性,自带设备(BYOD)计划越来越受欢迎。__2018年,45%的英国企业允许员工使用自己的设备。_CyberArk 2020年7月的一项调查显示,77%的远程员工现在使用无管理、不安全的自带设备访问公司系统。Per Aon_“理想情况下,公司和个人数据应该存在完全独立的设备。然而,在冠状病毒爆发之前没有遵循向员工发放单独的公司设备的政策的大多数组织,现在极不可能产生这样做的成本。__...**因此,数据泄露的风险增加,特别是在家庭成员之间共享个人设备或使用不安全的网络连接的情况下**。_”中小企业虽然是最脆弱的组织之一,但缺乏专业人员来帮助他们防御威胁。网络风险管理需要民主化,以允许非专业人员管理网络防御的基础。创新的重点是扩展InsurTechnix的现有软件并重新调整其用途,以满足怡安和其他许多人的需求:**1\。提供一种方法,使中小企业能够确保用于访问其网络的笔记本电脑和电话(包括自带设备)达到最低安全阈值,以防御/避免绝大多数威胁;**和**2\。表征、量化和报告分布式设备(包括自带设备)上保存的数据,以便通过减少高风险环境中保存的数据的性质和数量来最大限度地降低数据泄露的风险。**
英文摘要
According to Gallagher, in 2019_: "1.4m UK SMES suffered a cyber-attack/significant security incident. This cost the economy £8.8bn with the average attack costing £6,500\. 17% spent \>£10k to combat an incident with 10% paying out \>£20k. 23% of SMEs couldn't survive for \> a month if unable to trade following an incident ... 57,000 SMEs could be at risk of collapse."_COVID-19 has dramatically increased these risks. Cyber-criminals are adapting their tactics and targeting endpoint vulnerabilities exposed by the surge in home working. In Q2, UK businesses reported a 92% increase in cyber-attacks (VMWare). ZNET identifies a 72% increase in file-encrypted malware in the last three months and notes that ransomware attacks are now focused on stealing data as well as encrypting it. As a recent example, on 17 July, the NCSC exposed Russian attacks on Covid-19 vaccine developers.These risks are unlikely to reduce in a post-COVID environment. A recent Gartner poll shows that 48% of employees will likely work remotely at least part of the time after COVID-19 versus 30% before the pandemic.SMEs are particularly vulnerable to remote working attacks as they typically lack the resources required to protect against cybercrime. Given the increased number of attacks, over 100,000 UK SMEs could now be at risk of collapse.Per Aon "_Over the past few years, bring your own device ("BYOD") programs have increased in popularity as organizations aim to increase employee mobility._ _In 2018, 45% of UK businesses allowed employees to use their own devices."_ A July 2020 survey by CyberArk shows that 77% of remote employees are now using unmanaged, insecure BYOD to access corporate systems. Per Aon _"Ideally, entirely separate devices should exist for corporate and personal data. However,_ _most organizations that did not follow a policy of issuing employees separate corporate devices prior to the coronavirus outbreak are highly unlikely to incur the costs of doing so now._ _...**As a result, there is an increased risk of data leakage particularly if personal devices are shared between family members or insecure network connections are being used**._"SMEs, while among the most vulnerable organisations, lack the specialists to assist them defend against the threat. Cyber risk management needs to be democratised to allow non-specialists to manage the basics of cyber defence.The Innovation Focus is to extend and repurpose InsurTechnix's existing software to meet the needs that Aon and many others describe by:**1\. Providing a means by which SMEs can ensure that laptops and phones, including BYOD, being used to access their networks meet the minimum security thresholds to defend against/avoid the substantial majority of threats;** and,**2\. Characterising, quantifying and reporting the data held on distributed devices, including BYOD, so that the risk of a data breach can be minimised by reducing the nature and volume of data held in higher-risk environments.**
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
Cyber体系脆弱性仿真分析方法研究
-
批准号:61403400
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2014
-
负责人:许相莉
-
依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
-
批准号:61374179
-
项目类别:面上项目
-
资助金额:77.0万元
-
批准年份:2013
-
负责人:胡晓峰
-
依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
-
批准号:61300132
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王竹晓
-
依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
-
批准号:61174035
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2011
-
负责人:贺筱媛
-
依托单位:
基于Cyber空间的体系脆弱性仿真分析方法研究
-
批准号:61174156
-
项目类别:面上项目
-
资助金额:59.0万元
-
批准年份:2011
-
负责人:胡晓峰
-
依托单位: