Prioritise automated hardening over traditional cyber controls, says report

Vasily Merkushev – stock.adobe.c

A report from strategic risk specialist Marsh McLennan advises security buyers to funnel their budgets towards automated cyber security hardening techniques, saying they have a much better chance of reducing risk in a meaningful way

Alex Scroxton

By

Published: 06 Apr 2023 13:39

Endpoint detection and response (EDR), multifactor authentication (MFA) and privileged access management (PAM) have long been the three tools most commonly required by cyber insurers when issuing policies, but a report compiled by the Cyber Risk Analytics Centre at professional services firm Marsh McLennan suggests that automated hardening techniques are more effective than traditional tools by some margin.

The report directly links the key cyber controls that insurers demand are put in place prior to issuing a policy to a reduced chance of a cyber incident, and by assessing the relative effectiveness of each, Marsh McLennan’s analysts believe organisations can better allocate their scarce resources to the most effective tools, better position their risk with insurers and ultimately improve their overall resilience.

“All of the key controls in our study are well-known best practices, commonly required by underwriters to obtain cyber insurance. However, many organisations are unsure which controls to adopt and rely on expert opinions rather than data to make decisions,” said Tom Reagan, US and Canada cyber practice leader at Marsh McLennan.

“Our research provides organisations the data they need to more effectively direct cyber security investments, which in turn helps favourably position them during the cyber insurance underwriting process. It is another step toward building not only a more resilient cyber insurance market, but also a more cyber resilient economy.”

The report data comprises Marsh McLennan’s own cyber claims dataset, and the results of a series of cyber security self-assessment questionnaires completed by its US and Canadian customers.

Based on the correlation between the two datasets, it was able to assign a “signal strength” metric to each control method – the higher the metric, the greater impact the control method has on decreasing the likelihood of an incident.

It found that organisations that used automated hardening techniques that apply baseline security configurations to system components such as servers and operating systems were six times less likely to experience a cyber incident than those that did not. Such techniques include, for example, implementing Active Directory (AD) group policies to enforce and redeploy configuration settings to systems.

Marsh McLennan said this was something of a surprise given the emphasis put on EDR, MFA and PAM, and while such tools remain important and useful, the report also revealed some insight into how they stack up in reality.

MFA, for example, only really works when in place for all critical and sensitive data, across all possible remote login accesses, and all possible admin account accesses, and even so, organisations that implement it this broadly (which not all do) are only 1.4 times less likely to experience a successful cyber attack. The report authors said this clearly showed the benefits of a defence-in-depth approach to cyber security, rather than haphazardly implementing tools in some instances but not others.

Prompt patching: a path to protection

Conversely, patching high-severity vulnerabilities – those with a high CVSS score of between seven and 8.9 – within a seven-day window was markedly more effective than expected, decreasing the probability of experiencing a cyber incident by a factor of two, and yet only 24% of organisations that responded to the questionnaires were doing this.

It said organisations that implement improved patching policies stood a good chance of not only increasing their own resilience, but in comparing favourably against others, could make themselves a much more attractive risk to cyber insurers.

Note, however, that prompt patching of vulnerabilities with severe CVSS scores of nine and up were less effective at reducing the likelihood of a successful incident – likely because threat actors are much quicker to exploit them.

The most effective controls out of the 12 studied were:

  • Hardening techniques, which reduced the likelihood of a successful cyber incident 5.58 times;
  • PAM, which reduced the likelihood 2.92 times;
  • EDR, which reduced the likelihood 2.23 times;
  • Logging and monitoring through a security operations centre (SOC) or managed services provider (MSP), which reduced the likelihood 2.19 times;
  • Patching high-severity vulnerabilities, which reduced the likelihood 2.19 times.

Some of the less impactful controls, besides MFA, included cyber security training initiatives and email filtering.

Marsh McLennan’s full report can be downloaded here.

Read more on IT risk management

Read More
Lawanda Mayoral

Latest

Everything you need to know about Greek yogurt and how it can meet your nutrition needs

Recipes Two-ingredient cheesecake. Turkish-style pasta. Baked yogurt toast. Bagels....

Cook This: 3 recipes from Istanbul, including one of Turkey’s favourite breakfasts

Recipes Özlem Warren shines a light on the culinary...

Green Sauce Tofu and More Recipes We Made This Week

Recipes It’s no secret that Bon Appétit editors cook...

Newsletter

Don't miss

Everything you need to know about Greek yogurt and how it can meet your nutrition needs

Recipes Two-ingredient cheesecake. Turkish-style pasta. Baked yogurt toast. Bagels....

Cook This: 3 recipes from Istanbul, including one of Turkey’s favourite breakfasts

Recipes Özlem Warren shines a light on the culinary...

Green Sauce Tofu and More Recipes We Made This Week

Recipes It’s no secret that Bon Appétit editors cook...

Marshmallow Creme vs. Fluff: The Sweet and Sticky Showdown

Recipes Skip to main content Taste of Home Taste of Home Do...

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250