The consequential cost of a cyber incident begins with the immediate aftermath. Software, equipment, and databases may have been damaged, so there will be costs associated with the recovery effort. There may also be direct financial losses associated, such as business disruption, theft, ransom, loss of intellectual property or commercially sensitive information, and reputational damage to repair.
A survey conducted as part of this research found that respondents believe cyber attacks have cost their organisation more than US $550K over the last three years. This is a 200% increase from the results collected as part of our 2022 research.
The major factors contributing to the costs as a consequence of cyber crime were found to be:
- Business interruptions and delays.
- The cost of replacing or restoring systems.
The multi-industrial average cost of an enterprise data breach has risen 2.3% this year to US $4.45m according to a recent report by IBM. In the same report, researchers from the Ponemon Institute add that this cost has risen 15.3% since 2020.
It’s important to note that in addition to these quantifiable costs, there are reputational costs to consider. Cyber attacks often hit the headlines and the harm they can do to the reputation of a company can be hard to recover from. Social media enables news to spread like wildfire, damaging the reputation of an organisation in an instant before they have had a chance to commence damage control.
In 2017, Equifax lost four billion dollars in stock market value within a week of a cyber breach and by the end of the year, the breach totalled an additional US $439,000,000. According to Palo Alto Networks, Equifax offered 147,000,000 customers free credit monitoring services for one year and a waiver of the requirement that all disputes be settled through arbitration. Equifax was also ordered by a court to spend US $1,000,000,000 in enhancing cyber security measures.
This reputational damage is long-lasting. There is no quick fix. Today, people are still talking about the Suez Canal incident in 2021, in which the Ever Given vessel blocked the canal for six days, causing complete chaos along the supply chain until she was freed from her grounded position. She remained under arrest by the Suez Canal Authority until early July 2021.
While not the result of a cyber breach, the long-term reputational damage that has been done is clear. Shipping used to be invisible. But as a result of the Suez Canal blockage and the global pandemic, there is a new appreciation for the role shipping plays in our day-to-day lives. Almost 95% of all worldwide imports and exports are moved by containers. The Just-in-Time supply chain model means that, when things go wrong, the consumer feels and sees the consequences and is immediately reminded of the alarming yet intriguing events such as the Ever Given.
Not only is it hard to recover from reputational damage, but a company’s ability to trade with certain key customers will be affected. The Suez Canal incident also drew further attention to questions about negligence and culpability in cyber security.
To read further on the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


