KPMG study: "Internet of Things increases the risk of cybercrime in Switzerland"
Swiss companies underestimate the cyber risks associated with the Internet of Things. They still do not collaborate enough in the area of digital security and have an inadequate understanding of the threat landscape.
A significant number of Swiss companies are at risk of being left behind in this area and risk jeopardizing the continuation of their business activities. This is shown by the current KPMG study "Clarity on Cyber Security".
Digitalization continues to advance at a tremendous pace. In addition to business opportunities, this development also harbors major risks for the Swiss economy: over half (54%) of all companies surveyed have been the victim of a cyberattack in the last 12 months. For 44% of the companies affected, the attacks caused serious disruption to business processes and a quarter feared that they had suffered reputational damage as a result of the attacks. The most common methods used by cyber criminals were malware, phishing emails and social engineering. Victims are manipulated by means of false identities, by pretending to be social networks or by supposed authorities.
"The survey of 60 Swiss companies from various sectors shows that the topic of cyber security is still approached very differently in Switzerland: Some companies have an up-to-date approach and are trying to adapt to the constantly changing threat situation. Others are in danger of completely losing touch and thus jeopardizing the basis of their business activities in the medium term," says Matthias Bossardt, Head of Cyber Security at KPMG Switzerland, summarizing the results.
Little experience with the Internet of Things
The fourth industrial revolution and the ever-increasing networking of different devices also brings with it an immense security risk. This is because networked technology landscapes offer significantly more attack surfaces: Through the Internet of Things, cyberattacks can cause tangible damage in the offline world. However, the survey shows that many Swiss companies are paying far too little attention to the security aspects of Industry 4.0. More than half of the respondents (53%) stated that they had no overview of their risk situation in connection with the Internet of Things, which makes effective protection against cyberattacks impossible.
Internal risks and the human factor
It is not only external attacks that can cause serious damage; internal sources of danger should not be underestimated either. However, a large majority of the company representatives surveyed (80%) are dissatisfied with the company's internal handling of these insider threats: 60 percent do not have sufficient monitoring of suspicious internal activities, 51 percent lack appropriate data evaluation and 49 percent complain about a lack of multidisciplinary coordination. However, a multidisciplinary approach is essential when it comes to cyber security, as limiting internal and external security measures to technology alone is not enough: "Many cyber criminals take advantage of the human factor to circumvent technical defense barriers. For this reason, companies will increasingly have to place softer factors, such as corporate culture, at the center of their security considerations in the future and not just consider the technology component," says Gerben Schreurs, Partner Forensics at KPMG Switzerland.
Intensified cooperation is necessary
The desire for increased collaboration was expressed by 95% of all companies in last year's survey. In the current survey, 66% stated that they had actually increased their cooperation in the area of cyber security in the last 12 months. These alliances most frequently involve sharing relevant information on the threat situation (88%), exchanging experiences (83%) or joint prevention (78%). "In an increasingly networked and complex world, it makes no sense for companies to isolate themselves in the fight against cybercrime. Meaningful cooperation should be expanded wherever possible," comments Matthias Bossardt on the results of the study.
Progress in dealing with third parties
While 59% of companies were still unsure in 2015 whether and how their business partners, service providers and suppliers defend themselves against cyber attacks, 72% of respondents now explicitly require minimum security standards in their third-party contracts. The proportion of companies that fear an increased cyber risk from IT outsourcing also fell from 15% to 8 percent. However, the financial sector is more skeptical when it comes to the security risks associated with outsourcing and collaboration with partners. Many companies are questioning whether the trust they place in third parties is really justified. In the financial sector, for example, the proportion of respondents who fear less transparency with regard to cyber risks as a result of outsourcing increased from 25% to 33%.
Methodology
The "Clarity on Cyber Security" study by KPMG Switzerland is based on a combination of qualitative individual interviews and an online survey and covers around 60 companies. The individual interviews were conducted with C-level partners (CEO, COO, CIO, CMO) from various industries.
