Site navigation

Report: Zero-Trust Could Slash Cyber Insurance Costs

Tom Quinn

,

zero-trust
New research from Zscaler suggests that adopting zero-trust platforms could prevent billions in cyber losses, particularly for large enterprises and service firms.

Implementing zero-trust platforms could slash cyber insurance costs by nearly a third annually, according to new research from Zscaler.

The security provider’s special report, How Much Cyber Loss Can Be Prevented Using Zero-Trust Solutions?, examined the intricacies of cyber insurance claims and found that cyber losses could be reduced by up to 31% if organisations more widely deploy zero-trust security, saving potentially billions in annual losses.

Using the Marsh McLennan Cyber Risk Intelligence Centre’s proprietary cyber losses dataset from the past eight years, which collates cyber incidents from past claims, Zscaler’s researchers found that 41% of European incidents were potentially preventable through zero-trust architecture, as well as 31% of events in North America.

More than four in ten cyber incidents were found to be mitigatable when zero-trust was deployed, while around a quarter (23%) of those experienced by financial services and insurance companies could have been avoided.

Professional service firms have even more reason to adopt a zero-trust approach, with more than a third (36%) of cyber incidents impacting the sector deemed mitigatable.

The largest enterprises have the most to gain, with the study finding that companies with over $1 billion (£740m) in annual revenue could have avoided 60% of attacks by implementing zero-trust architecture.

Although the exact savings any company can make through deploying zero-trust varies depending on a variety of factors, the researchers calculated that up to $465 billion in global annual total economic losses could be saved through wider deployment.

According to Zscaler, zero-trust significantly increases the security of enterprise IT infrastructure and limits the ability for attackers to cause widespread, costly damage by requiring continuous verification of every user, application, and device accessing an enterprise.


Recommended reading


“This report underscores the importance of recognising zero-trust as a fundamental cybersecurity control that fortifies cyber hygiene,” said Stephen Singh, global vice president for cyber risk at Zscaler.

“With the external attack surface identified as a key predictor of potential breaches, adopting zero-trust and phasing out outdated, high-risk technologies such as firewalls and VPNs, shows a dramatic reduction in risk exposure.”

A zero-trust first approach is becoming more common under the relentless barrage of increasingly sophisticated cyber threats.

In April, another report from Zscaler’s ThreatLabz found that 81% of firms intended to implement a ‘zero-trust everywhere’ strategy within the next year, driven by fears over backdoor vulnerabilities from third-party VPN connections and ransomware risks, while a study from AlgoSec revealed that more than half of businesses are already either fully or partially implementing a zero-trust approach to govern multi-cloud environments.   

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data