Global cyber attack may cause average of US$53b in losses
A major, global cyber attack could trigger an average of US$53 billion of economic losses, a figure on par with a catastrophic natural disaster such as US Superstorm Sandy in 2012, Lloyd’s of London said in a report yesterday.
The report, co-written with risk-modeling firm Cyence, examined potential economic losses from the hypothetical hacking of a cloud service provider and cyber attacks on computer operating systems run by businesses worldwide.
Insurers are struggling to estimate their potential exposure to cyber-related losses amid mounting cyber risks and interest in cyber insurance. A lack of historical data on which insurers can base assumptions is a key challenge.
“Because cyber is virtual, it is such a difficult task to understand how it will accumulate in a big event,” Lloyd’s of London CEO Inga Beale said.
Economic costs in the hypothetical cloud provider attack dwarf the US$8 billion global cost of the “WannaCry” ransomware attack in May, which spread to more than 100 countries, according to Cyence.
Economic costs typically include business interruptions and computer repairs.
The Lloyd’s report follows a US government warning to industrial firms about a hacking campaign targeting the nuclear and energy sectors.
In June, an attack of a virus dubbed “NotPetya” spread from infections in Ukraine to businesses around the globe. It encrypted data on infected machines, rendering them inoperable and disrupted activity at ports, law firms and factories.
“NotPetya” caused US$850 million in economic costs, Cyence said.
In the hypothetical cloud service attack in the Lloyd’s-Cyence scenario, hackers inserted malicious code into a cloud provider’s software that was designed to trigger system crashes among users a year later.
By then, the malware would have spread among the provider's customers, from financial services companies to hotels, causing all to lose income and incur other expenses.
Average economic losses caused by such a disruption could range from US$4.6 billion to US$53 billion for large to extreme events. But actual losses could be as high as US$121 billion, the report said.
As much as US$45 billion of that sum may not be covered by cyber policies due to firms underinsuring, the report said.
- About Us
- |
- Terms of Use
- |
- RSS
- |
- Privacy Policy
- |
- Contact Us
- |
- Shanghai Call Center: 962288
- |
- Tip-off hotline: 52920043
- 沪ICP证:沪ICP备05050403号-1
- |
- 互联网新闻信息服务许可证:31120180004
- |
- 网络视听许可证:0909346
- |
- 广播电视节目制作许可证:沪字第354号
- |
- 增值电信业务经营许可证:沪B2-20120012
Copyright © 1999- Shanghai Daily. All rights reserved.Preferably viewed with Internet Explorer 8 or newer browsers.