Prioritise automated hardening over traditional cyber controls, says report

Vasily Merkushev – stock.adobe.c

A report from strategic risk specialist Marsh McLennan advises security buyers to funnel their budgets towards automated cyber security hardening techniques, saying they have a much better chance of reducing risk in a meaningful way

Alex Scroxton

By

Published: 06 Apr 2023 13:39

Endpoint detection and response (EDR), multifactor authentication (MFA) and privileged access management (PAM) have long been the three tools most commonly required by cyber insurers when issuing policies, but a report compiled by the Cyber Risk Analytics Centre at professional services firm Marsh McLennan suggests that automated hardening techniques are more effective than traditional tools by some margin.

The report directly links the key cyber controls that insurers demand are put in place prior to issuing a policy to a reduced chance of a cyber incident, and by assessing the relative effectiveness of each, Marsh McLennan’s analysts believe organisations can better allocate their scarce resources to the most effective tools, better position their risk with insurers and ultimately improve their overall resilience.

“All of the key controls in our study are well-known best practices, commonly required by underwriters to obtain cyber insurance. However, many organisations are unsure which controls to adopt and rely on expert opinions rather than data to make decisions,” said Tom Reagan, US and Canada cyber practice leader at Marsh McLennan.

“Our research provides organisations the data they need to more effectively direct cyber security investments, which in turn helps favourably position them during the cyber insurance underwriting process. It is another step toward building not only a more resilient cyber insurance market, but also a more cyber resilient economy.”

The report data comprises Marsh McLennan’s own cyber claims dataset, and the results of a series of cyber security self-assessment questionnaires completed by its US and Canadian customers.

Based on the correlation between the two datasets, it was able to assign a “signal strength” metric to each control method – the higher the metric, the greater impact the control method has on decreasing the likelihood of an incident.

It found that organisations that used automated hardening techniques that apply baseline security configurations to system components such as servers and operating systems were six times less likely to experience a cyber incident than those that did not. Such techniques include, for example, implementing Active Directory (AD) group policies to enforce and redeploy configuration settings to systems.

Marsh McLennan said this was something of a surprise given the emphasis put on EDR, MFA and PAM, and while such tools remain important and useful, the report also revealed some insight into how they stack up in reality.

MFA, for example, only really works when in place for all critical and sensitive data, across all possible remote login accesses, and all possible admin account accesses, and even so, organisations that implement it this broadly (which not all do) are only 1.4 times less likely to experience a successful cyber attack. The report authors said this clearly showed the benefits of a defence-in-depth approach to cyber security, rather than haphazardly implementing tools in some instances but not others.

Prompt patching: a path to protection

Conversely, patching high-severity vulnerabilities – those with a high CVSS score of between seven and 8.9 – within a seven-day window was markedly more effective than expected, decreasing the probability of experiencing a cyber incident by a factor of two, and yet only 24% of organisations that responded to the questionnaires were doing this.

It said organisations that implement improved patching policies stood a good chance of not only increasing their own resilience, but in comparing favourably against others, could make themselves a much more attractive risk to cyber insurers.

Note, however, that prompt patching of vulnerabilities with severe CVSS scores of nine and up were less effective at reducing the likelihood of a successful incident – likely because threat actors are much quicker to exploit them.

The most effective controls out of the 12 studied were:

  • Hardening techniques, which reduced the likelihood of a successful cyber incident 5.58 times;
  • PAM, which reduced the likelihood 2.92 times;
  • EDR, which reduced the likelihood 2.23 times;
  • Logging and monitoring through a security operations centre (SOC) or managed services provider (MSP), which reduced the likelihood 2.19 times;
  • Patching high-severity vulnerabilities, which reduced the likelihood 2.19 times.

Some of the less impactful controls, besides MFA, included cyber security training initiatives and email filtering.

Marsh McLennan’s full report can be downloaded here.

Read more on IT risk management

Read More
Lawanda Mayoral

Latest

Eagles lose key front office executive to the Falcons

NFL teams continue to poach Philadelphia’s front office. Apr 27, 2026, 9:19 PM UTC Philadelphia Eagles senior vice president/tertiary football executive Bryce Johnston is leaving Philly to join the Atlanta Falcons as their new senior vice president of football administration/senior personnel executive, according to a report from NFL insider Mike Garafolo. In Atlanta, Johnston is

Iowa State Football in Great Spot With Class of 2027 TE

New Iowa State Cyclones head football coach Jimmy Rogers has been hard at work since taking over the job from Matt Campbell, who departed for the Penn State Nittany Lions. Extra attention has been put on the recruiting front in recent weeks, with Iowa State’s staff looking to make up for lost time. Because of

Liz Kendall talks up work with ‘middle power nations’ on sovereign tech

The technology secretary speaks about the importance of forging alliances to make UK tech more resilient to geopolitical pressure By Cliff Saran, Managing Editor Published: 28 Apr 2026 16:00 In a speech at the Royal United Services Institute, UK technology secretary Liz Kendall discussed technological disruption and Britain’s role in the tech economy. “Technology is

Take-Two CEO Addresses Grand Theft Auto 6 Price, and the Possibility for More L.A. Noire

How much would "the most spectacular piece of entertainment on Earth" cost? Updated : Apr 29, 2026 12:11am UTC Speaking at iicon today, a new conference for video game executives , Take-Two CEO Strauss Zelnick addressed the much-debated question of how much Grand Theft Auto 6 will cost. He declined to confirm the game’s price

Newsletter

Don't miss

Eagles lose key front office executive to the Falcons

NFL teams continue to poach Philadelphia’s front office. Apr 27, 2026, 9:19 PM UTC Philadelphia Eagles senior vice president/tertiary football executive Bryce Johnston is leaving Philly to join the Atlanta Falcons as their new senior vice president of football administration/senior personnel executive, according to a report from NFL insider Mike Garafolo. In Atlanta, Johnston is

Iowa State Football in Great Spot With Class of 2027 TE

New Iowa State Cyclones head football coach Jimmy Rogers has been hard at work since taking over the job from Matt Campbell, who departed for the Penn State Nittany Lions. Extra attention has been put on the recruiting front in recent weeks, with Iowa State’s staff looking to make up for lost time. Because of

Liz Kendall talks up work with ‘middle power nations’ on sovereign tech

The technology secretary speaks about the importance of forging alliances to make UK tech more resilient to geopolitical pressure By Cliff Saran, Managing Editor Published: 28 Apr 2026 16:00 In a speech at the Royal United Services Institute, UK technology secretary Liz Kendall discussed technological disruption and Britain’s role in the tech economy. “Technology is

Take-Two CEO Addresses Grand Theft Auto 6 Price, and the Possibility for More L.A. Noire

How much would "the most spectacular piece of entertainment on Earth" cost? Updated : Apr 29, 2026 12:11am UTC Speaking at iicon today, a new conference for video game executives , Take-Two CEO Strauss Zelnick addressed the much-debated question of how much Grand Theft Auto 6 will cost. He declined to confirm the game’s price

Roundup: Here’s What The Reviews Are Saying About ‘Aphelion’ On Xbox Game Pass

The latest title from Don't Nod! by Ben Kerry Yesterday, 2pm Sci-fi adventure Aphelion is rolling out now on Xbox Game Pass as the next game from Life is Strange maker DON'T NOD Entertainment - and that means early reviews for the title are now hitting the web too. We're going to gather some of

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day