Deloitte identifies 14 business impacts of a cyberattack
Current market valuation of cyber incident impact is grossly underestimated
10 August, 2016 — While cybersecurity is one of the most prevalent issues of our time, the resulting impact of a cyber incident is still largely unproven. Recognizing the need of business leaders to have clarity around the enterprise-wide effect of such events, Deloitte the global leader in cyber risk advisory services, released: “Beneath the surface of a cyberattack: A deeper look at business impacts,” a risk-based report outlining the depth, and duration of cyber incidents in financial terms.
“Executives have difficulty gauging potential impact partly because they are not typically privy to what their peers struggle with as they work to get their businesses back on their feet. An accurate picture of cyberattack impact has been lacking, and therefore companies are not developing the cyber risk postures that they need,” said Fadi Mutlak, partner, Enterprise Risk Services, and cyber security leader at Deloitte in the Middle East.
“This report is an effort to help leaders broaden their thinking on the potential consequences of a cyber incident. This is particularly important in the Middle East, which we view as being on “High-Alert” given the additional dimensions of threat that include; geo-political instability, our perceived economic wealth making us a prime target for cyber criminals, and our above average malware infection rates. With a fuller picture of what may be at stake, they can better shape cyber risk programs to protect their organizations’ strategic interests, and ultimately improve the organization’s ability to thrive in the face of cyberattacks.”
The “Beneath the surface of a cyberattack” report was created by Deloitte’s Cyber Risk practice in tandem with the organization’s leading forensic and investigations, and business valuation services. Looking at two samples cyberattack scenarios, the report demonstrates a model to quantify potential damage, and identifies 14 business impacts of a cyber incident as they play out over a five-year incident response process. The scenarios illustrate some of the many ways a cyberattack can unfold and both clearly illustrate that the road to business recovery can be far more drawn out, more complex, and more costly than imagined.
14 business impacts of a cyber incident:
Above the surface: well-known cyber incident costs
1. Customer breach notifications
2. Post-breach customer protection
3. Regulatory compliance (fines)
4. Public relations/crisis communications
5. Attorney fees and litigation
6. Cybersecurity improvements
7. Technical investigations
Below the surface: hidden or less visible costs
8. Insurance premium increases
9. Increased cost to raise debt
10. Operational disruption or destruction
11. Lost value of customer relationships
12. Value of lost contract revenue
13. Devaluation of trade name
14. Loss of intellectual property (IP)
“Rarely brought into executive and board conversations around cyber risk are the costs and consequences of IP theft, cyber espionage, data destruction, or business disruption, which are much harder to quantify and can have a significant impact on an organization,” commented Mutlak. “Our intent is not to scare executives into thinking that all cyber incidents will be more costly than they think. It’s to give them a better understanding of their specific risks so they can make more informed decisions that are aligned with their business strategies.”
Deloitte’s study also reveals that:
- The direct costs commonly associated with data breaches are far less significant than the “hidden” costs. In Deloitte’s scenarios, these account for less than five percent of the total business impact.
- The time horizon over which impact is felt is far more protracted than is often anticipated. In Deloitte’s scenarios, costs incurred during the initial triage stage of incident response account for less than 10 percent of the rippling impacts extending over a five-year period.
- Over 90 percent of cyberattack impact is likely to accrue in categories that are intangible. Given that these are less studied and more difficult to quantify, organizations can be caught especially unprepared for these “costs” in areas such as operational disruption, impact to trade name and loss of intellectual property.
“The ability to quantify intangible damages is especially important in anticipating business impact. In many cases, an approach based on tallying actual recovery costs that hit the balance sheet would paint a significantly distorted picture of the cost to business performance,” added Mutlak.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. Please see www.deloitte.com/about for a more detailed description of DTTL and its member firms.
Deloitte provides audit, consulting, financial advisory, risk management, tax and related services to public and private clients spanning multiple industries. With a globally connected network of member firms in more than 150 countries and territories, Deloitte brings world-class capabilities and high-quality service to clients, delivering the insights they need to address their most complex business challenges. Deloitte’s more than 220,000 professionals are committed to making an impact that matters.
About Deloitte & Touche (M.E.):
Deloitte & Touche (M.E.) is a member firm of Deloitte Touche Tohmatsu Limited (DTTL) and is a leading professional services firm established in the Middle East region with uninterrupted presence since 1926.
Deloitte provides audit, tax, consulting, and financial advisory services through 26 offices in 15 countries with more than 3,300 partners, directors and staff. It is a Tier 1 Tax advisor in the GCC region since 2010 (according to the International Tax Review World Tax Rankings). It has also received numerous awards in the last few years which include best employer in the Middle East, best consulting firm, the Middle East Training & Development Excellence Award by the Institute of Chartered Accountants in England and Wales (ICAEW), as well as the best CSR integrated organization.