S&P Global Inc. (SPGI) Earnings Call Transcript & Summary
February 2, 2023
Earnings Call Speaker Segments
Alexander Gombach
executiveHello, everyone. Welcome to our first Cyber Risk Insights webinar of the year. Last year, we began this series of monthly webinars to discuss how cyber risks are affecting credit ratings. Today, we kick off with our views on cyber trends and credit risk for 2023. My name is Alexander Gombach, Director of Structured Finance, and I'll be moderating today's call. With me today for our first portion: Scott Crawford, Research Director of Information Security, 451 Research, S&P Global Market Intelligence; Sudeep Kesh, Chief Innovation Officer at S&P Global; and Tiffany Tribbitt, Senior Director, U.S. Public Finance and Lead for Global Cyber Security Research. So before we begin, we have a few housekeeping issues. We know some of you have pre-submitted questions. And during the presentation, you'll have an opportunity to ask questions by typing them into the QA box on the left side of your screen. Immediately following our discussion, we will take as many questions as time permits. Please send your questions at any time during the webinar. You don't have to wait until the end of the presentation. You can find a copy of today's presentation and links to publications we mentioned at the bottom of your screen in the red resource list, which is also on the left side of your screen. We'd like to let everyone know that a replay of this webinar will be available in 24 hours, and that can be found on our website at s&pglobal.com/ratings. The replay is valid for 1 year. And please complete our post-webinar survey by filling out the form on the right side of your screen. It will remain present throughout the duration of the live event. It will also pop up automatically at the conclusion, so you may save your responses until then. I cannot stress this enough. Your feedback is truly important to us, as you will likely see today. We carefully consider all comments and suggestions for improvement. So about a year ago, Ukraine's governmental systems were attacked and users were met with a message on their screens: "Be afraid and expect the worst. This is your past, present and future." This seemed an ominous sign of things to come in the area of cybersecurity. And since then, we saw a wide range of attacks and incidents through the year unleashed not only by the war but by other actors and in other theaters, such as the MFA-related attack on Uber, the Optus breach in Australia. A recent world economic cybersecurity study noted that 91% of respondents stated that they believe a "catastrophic cyber event" is possible within the next 3 years. So how to make sense of all of this? And how might it impact credit risk and ratings? Well, our panel today have attempted to shed light and bring much needed insight and detail to this topic in their recently published piece, Cyber Trends and Credit Risks.
Alexander Gombach
executiveSo to begin, Tiffany, can you start us off with key takeaways from that research?
Tiffany Tribbitt
executiveSure, Alex, and thank you for having us all on here today to give us an opportunity to kind of dig into this research. I'll start with the kind of our key takeaways. We've put them on a slide for you so that I don't have to read them all out. But really, the headline here is that last one. The overall takeaway here is that we really view cyber risks as something that should be embedded into overall risk management policies for our issuers. It's not something anymore that's only banks and governments should be thinking about. It's really everyone because this is an evolving risk. Sudeep and Scott are going to talk more about that later in this presentation. But we really do expect our issuers to kind of stay on top of the trends, adapt as new technologies emerge or as best practices evolve. Some of the notable trends that I'll cover here are kind of going back to what you were saying, Alex. We've seen this really come to a head with the Russia-Ukraine conflict. We're living in an age of hybrid warfare. Cyberspace is simply another battlefield. This can really cause collateral damage in terms of third-party vendor risks and spill-outs from attacks. We saw those back with the NotPetya attack. And I know that Scott later is going to kind of talk about how some of these systemic risks can really amplify the impact of an attack. Another one of the areas that we've been monitoring is disclosure. We're seeing some of the regulators really got interested in what folks are writing about cyber and what are they doing to protect against attacks? Are they disclosing when they do have attacks? And as a ratings agency, we always love disclosure, but we're also looking at as increased disclosure, does this increase reputational damage for companies? Could this become a regulatory risk if you're not complying with the disclosure regulations? And so that's something we've been monitoring. And then I'm going to flip to another slide with some eye-popping numbers just about some of these trends. And I think all of these numbers really get at what we've been saying for a while now. This is a threat that's not going away. It's only going to continue to increase in importance and credit relevance. We've seen insurance premiums rising. I know we got a lot of questions about insurance, so we're going to dig into that in a little bit. The cost of attacks, the number of attacks, the cost of IT budgets, all these things are trending upward as we're entering into a downward cycle in the economy. So it's going to be a very pressured situation for issuers, making really tough choices in how they're allocating budgets. Finally, this brings me back to where I started. Cyber risks aren't going away. We really need to evolve our understanding of the threats, and we expect to see our issuers embedding cybersecurity preparedness and response planning into their enterprise risk management strategy. There are a lot of interesting takeaways when you dig into the attack trends and things like how much time does an attacker have in the network. And my co-author, Sudeep, did a lot of research on that for our piece. And so I'll hand it back to you, Alex, to go to him for some takeaways there.
Alexander Gombach
executiveYes. Thanks, Tiffany. That already is a key theme developing, right? This constant evolving nature of this risk that we really saw last year. So Sudeep, can you give us some perspective on how that threat landscape has evolved and what you're thinking about for 2023?
Sudeep Kesh
executiveSure. Thanks, Alex, and thanks to the audience for their attendance as well as all of -- we've gotten a lot of great comments in terms of the research, and I'd really encourage everyone to read the research that's sort of attached to this. But I think when we talk about evolution, a lot of times, I think cyber's a scary topic, right? So we just have to sort of acknowledge that. And -- but I don't want to give the impression that it's perpetually sort of accumulating to something that's worse and worse and worse things. Some things get better, some things get worse, but it's really important to just kind of call it how it is. And as Tiffany alluded to, it's a big problem, right? So it's $10.5 trillion is the projected cost of global cyber crime by 2025, so just 2 years from now. Just to keep that in perspective, I mean that's nearly 3/4 of the GDP of the second largest economy in the world, China. So that's a huge problem. It's also a people problem, largely. So Scott, my colleague, will be talking about some of the research in terms of user behavior. But what we've found is -- and digging through a lot of the data that's on the next slide, actually. And by the way, on the web version of this article, all of these graphics are interactive, so you could actually kind of play around and see what's happening. But really, 82% of the cybersecurity breaches that were investigated and some of the data behind the scenes is coming from Verizon has a report called the Data Breach Investigations Report, and they have a community database. It's an open source database. We were able to then pull that and mine it and be able to come up with some of these statistics. And we found that about 82% of the cybersecurity breaches investigated involve a human element. And some of these can be, in terms of how to rectify them, it's often something where staff training can do a great part of it. But also what -- piggybacking on what Tiffany was saying is that if you think about risk management more generally, it's a team sport. And you really have to have this level of sort of connectedness between the IT community, the security community within IT, the risk managers within an organization, the general management, the employees, human resources, training. All of these other things is -- they all facilitate a team, which is really the secret sauce to be able to defeat these things while also kind of recognizing that some things receive, for example, a DDOS attack that distributed service. So there's a lot of technology that has become ubiquitous that has reduced sort of the severity and sort of the widespreadness of certain attacks and then you have an increase in things like ransomware. And most recently, I know everybody's heard of ChatGPT and these different sort of AI-based technologies. Those are starting to become weaponized as well. So it's one of these things that we have to be hyper vigilant on development and technology in general and how they're actually -- can be weaponized in the sense of cyber crime, but also how we can use sort of the social constructs behind teamwork and really having sort of a cyber community, a risk management community, general management community, business community, user community all integrated, which is really part of the problem. One of the other things I just want to point out, and if it just kind of underscores the point, is on the next slide. This is what I call sort of a sleeping problem. Organizations typically discover a cyber attack months after a compromise. So it's particularly important to not rest on your laurels because the -- given the network effects of cyber attacks or the network nature of cyber attacks, these things can metastasize very, very quickly because you haven't seen them, like you don't know where the seeds are. So that's why it's really important that if you have this level of sort of comprehension in terms of your cyber strategy and it's actually holistic in nature, then you at least have more eyes to be able to kind of discover these kinds of things. And in the case of phishing attacks and things like that, then at least you have a community that's at least kind of blocking the entry for some of those seeds of destruction. So with that, let me just conclude. The cybersecurity industry, it's not nascent. There's been -- it's been an industry for quite a while, but it's still really in the early days. And there's a couple of people issues there as well in terms of a talent deficit. So roughly 40% of companies still don't have a CISO, a Chief Information Security Officer. For those that do, 25% are on the job for less than 1 year. And government institutions especially, I think it's this budgetary problem where things are constrained in terms of resourcing. So you may have to outsource a lot of these kinds of things, if at all. Sometimes it's just they don't even have the funds to even outsource things. But then it becomes kind of the providence of a third party, which has another spring of risks. And one thing I could say about the CISO because, for better or for worse, I've personally been contributing some of this deficit by hiring 1 or 2 CISOs from the industry, one of whom actually is Scott. So let me pivot there. So Scott can give some remarks. He's a former CISO with quite a lot of [indiscernible].
Scott Crawford
executiveGreat, everybody. And thank you again. Can you guys hear me okay?
Alexander Gombach
executiveYes. Sounds good, Scott.
Scott Crawford
executiveVery good. All right. Again, let me have my thanks to everyone for joining today. This is a very interesting topic, particularly for cybersecurity practitioners. The intersections of business and financial impact and cybersecurity is something we, as professionals have been following with great interest over many years. And what we're seeing now is actually a lot of that expectation begin to bear fruit in terms of what is actually the impact of cybersecurity on the business and how is that becoming manifest. And there are a few places where it's becoming manifest more than in an assessment of credit risk as well as other aspects of financial risk. We'll talk about risk mitigation as transfer here a little bit when we talk in more depth about cyber insurance, for which we have someone who's very well versed in that. But before we begin, let me just step back a little bit. So I've been in the industry as a cybersecurity practitioner for a few years now. And those of you who are on the call who are familiar with the field, who are cybersecurity practitioners yourselves, you know the evolution that we see in our field in terms of the broad overall trends. We went 20 years ago from focusing primarily on things like viruses to, roughly towards the end of the 2000s, we began to see evidence of the more focused adversary, meaning the adversary with the capability and the tools and the resources to pursue very specific strategic attacks. And a lot of these were low-frequency but high-impact incidents. And a lot of them began to become known as the advanced persistent threat, advanced in terms of the ability to field some bleeding edge, if you will, technology in terms of applying malware and attacker tools to an opportunity, persistent in terms of finding ways to embed themselves in an environment, avoid detection and discovery, and continue to have a presence in the target environment, sometimes for a while before they would have an impact or moving laterally around the environment to see what was possible to compromise as part of their strategy. Now that was the very focused, the low frequency but high-impact issue, but APTs, as they're so-called, began to become very commonly discussed in the market. Threat intelligence began to take off because organizations wanted insight into that level of threat. At the same time, however, we saw this evolution of what we had at the time called the industrialized threat, which meant much broader, perhaps lower impact per incident, but the ability to be very systematic about discovering common exposures and vulnerabilities, the ability to exploit those fairly routinely, and a market emerging around that very field, sometimes called the dark web depending on which side of it you may work on. But just as an example, these underground exchanges, aside from the legitimate economy that were -- they're businesses, and they were run very much like businesses. And in fact, they had a lot more latitude than regular businesses did because they weren't obliged to adhere to things like regulatory rules, compliance, standards and specifications. They could do basically whatever they wanted as long as they were effective, made a profit, were good business partners for their partners. And as we saw this mature, we began to see it become manifest, and [ Aversar ] is becoming very specific about these are the types of exposures that we can routinely exploit. And add to that, we can turn this into an even more of a good business if we quite literally hold the targets and the victims hostage. What we began to see coming out of that, if we can move to the next slide is, of course, what we have all become familiar with as the rise of ransomware. And this data point comes from our research at 451 Research within the Market Intelligence division here in S&P Global. And it's going to be no secret, I think, probably to most anyone on this call, we've seen a substantial rise in the incidence of malware, particularly as the pandemic began to become more prevalent, as the increased movement to working from anywhere began to take hold, as networks began to become even more interconnected and the enterprise had to reach out to wherever their personnel happened to be. That was a trend that was already in motion. But its prevalence and the dependence of businesses on that connectivity every day became much more pronounced. So much more widely connected points within any given network. But it also began to reveal what some of the consistent issues were in terms of cybersecurity strategy and practice within organizations. There's a saying among practitioners that everyone gets a penetration test, but you don't always get the results. If you have an incident or an attack, you most definitely get the results in ways that you don't want. And the consistency and pervasiveness with which we began to see ransomware take hold began to show up some of these issues. If we can advance to the next slide, we see how that's had an impact on the perceptions of security practitioners in responding to these incidents. This again is from a survey we conduct as part of our voice of the enterprise here at 451 Research. We asked organizations about their plans and expectations in terms of what they would anticipate in a ransomware attack. We asked them -- they told us that they thought that their endpoint security tool would interrupt the attack. They figured that their network defenses would. They figured that they would be able to successfully restore from a backup. The projected responses you see in the light aqua there, I guess, would be the color. Their actual responses though, check out -- click that slide just once if you would, please, to highlight the one thing that really does stand out. They anticipated -- only 7% anticipated before the fact that they would actually pay the requested amount of the ransom in order to get control of their systems and their data back. In reality, among those that we surveyed who actually had sustained a ransomware attack, nearly 1/4 of them, 22% said, yes, we did pay. So this, in turn, has had an impact on risk mitigation and risk transfer. We can advance to the next slide. We'll see that organizations have increasingly looked to cyber coverage, which has grown in its own right as a dedicated form of insurance, partly because of some of the outcomes and precedents that have occurred in terms of attempting to claim it under terms such as general liability and so on, the rise of cyber insurance coverage over the last several years. In fact, when we ask our survey respondents, do they currently have cybersecurity insurance, 71% of them said yes. Only 29% said no, but of that 29%, another 38% of them -- and this survey was taken last year, another 38% of them said that they, yes, were planning to purchase cybersecurity insurance in the next 12 months. But what has happened, as you might imagine, is that given the rise of claims, particularly around issues such as ransomware, the cost of that insurance has risen, largely because the loss ratio sustained by insurers has risen as well. I'm going to pause there because we do have some depth of expertise on insurance per se and the impact of cyber on the insurance industry. So Alex, let me at this point, hand it back to you for moving forward.
Alexander Gombach
executiveGreat. Thank you, Scott. Right. So as we heard, we received a lot of questions ahead of time. And by far, the biggest topic in those questions was cyber insurance. So since we know this was a topic that's so important to many, to better help us answer these questions, we've tapped none other than S&P Global Ratings Chief Analytical Officer for Insurance Ratings, Simon Ashworth. Simon, thank you for jumping in here at the last minute to help field some of these questions.
Simon Ashworth
executiveSure. No problem.
Alexander Gombach
executiveAppreciate that. So first up, we have a bunch of questions around the theme of recent trends in cyber insurance coverage, terms and premiums. Can we talk a little bit about that?
Simon Ashworth
executiveSure. Yes. Thank you. Pleasure to be here. I've actually waited 20 years for this moment for insurance to be so fashionable. So I'm going to make the most of this opportunity. I think I'm going to back up a little bit just to start and just talk about how important the cyber insurance market is for insurers and reinsurers. It is one of the key growth element within the market. But it's important to say that it is still very much in its infancy. Insurers and reinsurers are actually grappling with questions about how and even if they want to play in this space. So I think we've all heard about the topic of silent cyber, which Scott alluded to before, because often cyber coverage can sometimes be implicitly covered unbeknownst to insurers themselves and reinsurers within existing insurance coverage. And we really think that for a sustainable market to develop that, as Scott said, that actually needs to be segmented and really clearly attributable. Maybe just 1 or 2 more bits of background. So if we look at the economic costs from cyber, they dwarf any comparable other economic cost, economic loss information even compared to perils such as natural catastrophes. So the potential for this market is huge. And actually, in terms of insurance coverage of cyber economic losses, we're talking about 1% of economic losses that are currently covered. So a huge insurance protection gap at the moment. If we just briefly rewind to pre-COVID, this was a segment that was one of the most profitable for any insurer or reinsurer that played in this space. They were really getting extreme levels of profitability, partly because there weren't too many insurers or reinsurers willing to supply and partly because of the absence of larger or more frequent loss events with respect to cyber. But as we all know, excess profits don't last for too long. So Scott and Alex, as you mentioned, we've seen cyber insurance premiums really ramp up over the last couple of years, up almost 200% in some cases in aggregate. And in many ways, that is attributable to underlying loss and risk experience. Obviously, insurers and reinsurers themselves need to make some return on capital. But I think it's important to say that to the extent that corporates and other entities who are purchasing cyber insurance can really highlight that they are good risks or better risks. there's clearly refined pricing levels, just as would be the case if you're a good risk from an auto perspective, you'll get a more beneficial auto premium. So I think it's really also incumbent on corporates and entities themselves to demonstrate to their cyber insurers the depth of their risk management processes to really reduce premium quotes. Alex, back to you.
Alexander Gombach
executiveYes. Thank you, Simon. Let's stick on insurance for a little bit. Can we talk about some of the metrics that these insurers are using to assess the effectiveness of the cyber risk mitigation? And Scott, I'm hoping you can jump in on this one.
Scott Crawford
executiveIt'd probably be better if I jump in with my microphone on. Yes, we have taken a look at that. We did actually ask organizations as far as their -- what are insurers asking them to do. In fact, that actually in itself highlights the evolution that we're seeing in the security technology marketplace. There's this growing group of companies that are working in, if you will, the interface between enterprises and businesses and their cybersecurity teams and their deployment, cybersecurity deployments, and the insurance industry. On the one hand, the insurance industry does need subject matter expertise to help advise them, guide them on what does actually constitute an insurable security posture. And for the practitioners and the enterprises, they need to know what will be considered acceptable and insurable with our insurers. And that is still rather nascent in terms of that segment that's growing up now, which means that the consensus on what those criteria are or should be is still growing. But what we see insurers are asking for is maybe not so much metrics per se as implementation of specific types of controls. And in particular, this could be interpreted as reflective of the nature of what they're seeing in claims, the issues that contribute to claims that they have to sustain. So they're asking organizations, are you implementing anti-phishing initiatives? There is a metric there that we do see occasionally that's something like there will be some sort of standard of -- not standard, but to criterion of, say, 15% or less of personnel successfully phished, if you will, in an anti-phishing exercise. E-mail filtration, not just for malware, but for suspicious domains, sandboxing a combination for remote connectivity, et cetera. Multi-factor authentication comes up quite often. And one of the reasons that ransomware has been so prevalent is the exploit of identity and access, privilege and controls. There are often a lot of overlaps in terms of the provisioning of access. There could be things like intergroup overlaps and memberships. So a member of one group can be a member of another that has overlapping privileges, which may not -- probably not the best way to deploy those. So identity governance administration, identity verification, these are areas that are growing up around these areas. Endpoint security, the nature of what's in place, antivirus, heuristic behavioral detection and so on, network security, including controls and lateral movement. Security operations, metrics there might include time to triage and contain incidents. Security monitoring response functionality, vulnerability and controls assessment and testing, compliance with an organization to find patching standards. Backup and recovery, obviously, a big one for ransomware in particular. In fact, the notion of immutable backups, which are and should be beyond the reach of compromise in order to support a good and reliable recovery, known return to operations time, testing and demonstrations of resilience. Ransomware specific measures such as a documented response plan, has this plan actually been exercised and tested to see how the organization would perform under these situations. So these are the types of criteria that we see insurers asking their insureds for in order to demonstrate their cybersecurity posture. For the insurers' sake, they do have to see these to get a handle on their loss ratios and continue to capitalize on the opportunity that cyber insurance presents, as Simon has so well described.
Alexander Gombach
executiveGreat. Thank you. See, we've got continuing on this theme of insurance, let's think about cyber insurance and government. Tiffany, I think you're well positioned to answer this one. What levels of cyber insurance are carried by governments currently? What do we know about that?
Tiffany Tribbitt
executiveSure, Alex. And I'll say this one really varies. And I'll also use this question as an opportunity to talk about the fact that we don't really assess a proper level of insurance. What we're really looking at is how does this fit into your overall credit story? How does this fit into your overall profile? It's not really any different than how we look at other event risks. I know Scott mentioned earlier, we see these low-frequency, high-impact events. In my sector, we're looking at hurricanes and wildfires and things like that which our issuers are going to cover insurance for. And really when we're looking at this, it's not just do you have insurance or how much insurance do you have? It's also, well, how high is the risk here? What are you doing to mitigate those risks? What is your liquidity position? Do you have reserves, something we really look at for our local governments? Are you going to be able to float until you get reimbursements from the insurance policies that you carry? But a notable trend that we are seeing here in the U.S. at least is that in the government space, we're seeing some insurers start to get priced out as these premiums rise, which is something we've been talking about. And we're seeing this movement toward these shared risk pools or kind of shared service type agreements at the county or state level. And so that's something we're really monitoring here in the U.S. So I'll turn it back over to you.
Alexander Gombach
executiveGreat. Thank you. So I think we're going to move on from some insurance questions and to some more broader topics here. So Sudeep, I'll turn this one to you. With the world becoming more interconnected than it was 10 years ago, what are the risks of a major cyber event in one part of the world negatively impacting companies from other parts?
Sudeep Kesh
executiveYes, they're huge, and it's a little bit scary because once you sort of transcend between this physical realm to the digital realm, there are no jurisdictions, right? So it's basically you have, what do they call them. They call them QQ maps in terms of you can see a sort of a map and seeing where all the -- some of the cyberattacks are basically emanating from and where they're attacking. But largely because of sort of the digital nature of the -- of cyber in general as well as the sort of increasing digitized nature of companies in general, you're seeing that all of these sort of cross-jurisdictional issues are starting to pop up. So I think it's one of these things that it's -- it would be rare that you would only have one country impacted in terms of a cyber attack these days and certainly in the future. Now there are -- I guess the benefit is that the technology has managed to kind of keep up in some respect with a lot of advances in network science. So network science is basically -- it's a computer science development which really looks at how relationships kind of work. So there's these sort of nodal relationships, meaning that if you have a company or an entity and then who their suppliers are, who their customers are and things like that, those can be mapped. And then the suppliers and the customers of those companies can be mapped. And a lot of third-party risk management providers now are basically using the sort of these network effects, these nodal relationships to assess where the risks are to essentially identify the probability of an attack vis-a-vis some vector and some of the things that Scott was just talking about with multi-factor authentication. And just different elements of network security and things like that are helping to kind of at least identify what's the area that's most probable and then you can kind of increase some of your defenses there. But it's one of these things that because of the sort of the nature and sort of the silent nature of this, it's often difficult to manage. So it's one of these things that it's sort of a layering of the technology, the people, governance strategy. And as Tiffany just alluded to, it's looking at this holistic picture of how this relates to, in the case of the credit story for us of how we're evaluating for the business, being really, really intentional about how does this disrupt your business, making sure your backups are there, and they're actually kind of salient to the business continuity that you need to have as an organization.
Alexander Gombach
executiveThanks, Sudeep. I really want to underscore that point you keep making about bringing it back to people and how the importance of that kind of frontline defense, that really is comes down to our human behavior. You don't expect that. You don't often think of that. We always are thinking of things in terms of these technological solutions, but you're really reminding us that people's choices really make a big difference here. We've got plenty more questions here. I just want to remind our audience, keep submitting questions as we go here. We're -- we can see them in real time as you enter them, and we're trying to actually incorporate them as we go here. But I want to stick with Sudeep for a minute here. Let's get a little bit technical here. So how about firms that are already implementing the NIST protocols? And that is the National Institute of Standards and Technology Cybersecurity Framework, the 853 protocols. This is a set of standardized controls that companies can implement. So we have a company that's reached a certain maturity level in that. What should they be thinking about in terms of expanding or better understanding the threat landscape?
Sudeep Kesh
executiveYes. I think the important thing, so NIST 853, the title of the article. So the NIST, it's basically a standard organization, right? So it's really secured and privacy controls for information systems and organizations. That's the actual 853. And it's -- the good thing is it's really establishing a lexicon or basically a common language of security management across the organization. So I think it's one of these things that these -- again, I mean sort of perseverate on the human element of this, but it's one of these things that having a common language is really a first step to be able to really identify, triage and then solve an issue. So I think we're organizations that are adopting standards and encouraging kind of their suppliers to adopt similar standards and things like that. Allows the organizations to speak with one voice and be able to really triage these problems more effectively, recognizing that NIST standards actually, they evolve as well. NIST, in general, it started as more of a U.S. phenomenon. It's starting to become a little more ubiquitous in other jurisdictions as well. But again, it's starting, but that's actually an incredible advancement because it's layering this layer of a standardized lexicon across these organizations. Once they're speaking with the same voice, then you can kind of evolve therein. So I think that the industries, the companies within those industries that were more advanced are continuing to be kind of on the cutting edge of adopting new security technologies and so on because they're actually -- they're having this foundation of this common lexicon, these being really intentional about what the strategy is. But you can't sit on your laurels. You kind of have to adapt those things. And really, I can't stress this enough, is the security -- there is no best security. It's really -- it can't be divorced from the business line you're in and the assets you're trying to protect, the continuity thresholds you're comfortable with, things around trust. So like once you break trust with your customers, you can't gain that back. So if you have -- if you're operating in a space that's really, really elastic, then your customer demand is completely a function of how much they trust you. So then that's something that needs to be higher in the order of magnitude of some of the assets you're trying to protect there.
Alexander Gombach
executiveAll right. Thanks, Sudeep. Yes, just this theme of the interconnectedness of our world in the digital space is just really important for us to remember, and I want to still build on this a little bit. So I'm going to turn to Scott here. So in this growing interconnected world, what do we think about systemic risks that could follow an attack?
Scott Crawford
executiveWell, it's interesting to connect that with what Sudeep was discussing around things like cybersecurity frameworks and standards and practices that an organization adheres to for itself. And the subtext of that is that we're talking about an organization focusing on itself and its own cybersecurity posture. But as Sudeep has also alluded, we have this increasing emphasis on interconnectedness and how that's become -- there are various ways in which that's become manifest among practitioners. And one of them is what type of risk do third parties and those to whom I am connected, how do they influence my risk posture, how do they influence my exposure. We've seen ample evidence of this in attacks that had unintended consequences and if you will, collateral damage. And one of the most visible aspects of that was the NotPetya attack from -- well, the incident from -- that grew out of Ukraine a few years ago, about 5 years ago, that affected -- had an impact on logistics organizations around the world, in fact, brought one of the largest in the world to its knees in terms of shutting down its entire logistics operation. That was simply collateral damage. They simply had a system that was part of the target space for this particular attack. It just happened to be inter-networked and interconnected with other business systems throughout its environment. So that was a very big attention-getter a few years ago. Just in the last couple of years in terms of the SolarWinds breach. And it wasn't just SolarWinds, there was other organizations, some major companies who were affected by that same method of attack, where the theme in that case was infiltration of the supply chain for a commercial product. In other words, effectively insinuating a threat into the products of a supplier -- of an IT supplier, software technology and services. So these issues with respect to supply chain exploits have become very much front and center for security practitioners in the last few years, and it's a challenge. As Sudeep alluded, it is possible now to begin to understand the network relationships between interconnected points within any technological environment. The challenge is that they are all so interconnected, it can be very, very difficult to tease out what the priorities are, what to mitigate first and foremost. And again, this gets back to -- has an impact on things like insurance when you're trying to establish what those priorities should be. It's interesting to note, since Sudeep brought up the cybersecurity framework, the NIST cybersecurity framework, and you did as well, Alex, in his discussions that, that framework is right now undergoing a major revision to version 2.0. And as part of the discussion of that provision, one of the things that has really come to the fore is the importance of cybersecurity supply chain risk management, which abbreviated by the working group C-SCRM, which will very likely become incorporated, at least the level of discussion now around CSF 2.0 indicates that will very likely become incorporated in Version 2.0 of the cybersecurity framework. The importance of cybersecurity governance also and the introduction of a governance function for organizations, how the CSF can support the measurement and assessment of cybersecurity programs. So these are some of the things that are having an impact on the nature of cybersecurity deployment, security posture and which indicate that, that is always changing. The nature of security is very much like a military conflict. I hesitate to say an arms race, but it does have some resemblance to really any field of conflict. In other aspects of technology, your course may be determined by what your customers require and demand, the competitive landscape and so on. This is true in the cybersecurity industry. But you have the added dimension of an intelligent adversary who is looking to exploit gaps in your defense, and you, on the other hand, must be able to shore up those gaps. It's also an asymmetric sort of conflict as well because, while on the one hand, a defender must use limited resources and prioritize those as best they can across the entire exposed landscape, the adversary can choose the opportunities and that it wants to exploit, that things can do it the most focused benefit, can deliver the most focused benefit for the level of effort. So there's that asymmetric aspect of it as well. So getting a handle on these exposures and keeping up with the nature of the threat landscape and the nature of defense as well, too, means that this is an ongoing issue and will be. Technology is pervasive. We had a question come up about the nature of survey respondents in our survey study. And I looked this up while we were discussing these topics. Roughly 30% of the respondents to that survey said that they were in software and IT services, another 21% in business services. But if you peel the covers back a little bit on those indications of what their industry vertical is, you'll find that software and IT services is pervasive in things like manufacturing, is pervasive in things like health care. It's pervasive in so many industries, it's becoming difficult to tease apart what is technology and what is the underlying nature of that industry. So the pervasiveness of technology does pose some real challenges for identifying cyber risk as a realm of its own in terms of being able to mitigate that risk and address it through risk management.
Alexander Gombach
executiveYes, the constantly evolving complexity here is really an interesting issue to tackle. And it's interesting to think about insurance again. I actually want to pivot back to a question that came in. Thinking about this complexity and constant changing complexity, have premiums increased because insurers don't understand how to price this risk?
Simon Ashworth
executiveYes. No, that's a good question. I think there is an element of risk premium within the premiums themselves and the charges based on uncertainty. But I think that's not been the overriding factor with respect to cyber insurance premium increases. It's really been a view to some of the huge underlying spikes in risk, some of which Scott showed earlier with respect to ransomware and others that we've moved to a more digital world. So no, I don't think it's really linked to insurers not being able to price the risk itself. Insurers are well used to attempting to price very niche and bespoke risks on a very daily basis. So they -- it is fair that their models are evolving with respect to cyber all the time, but the underlying chunk of the premium risk -- premium increases has been due to underlying risk increases. And we've seen those premiums go up maybe 30% to 50% compound each year for the last few years. So clearly, that's a big pill for buyers of cyber insurance to swallow. As mentioned before, obviously attempting to highlight that your relatively good risk will limit that, and trying to squeeze your cyber insurers to understand what additional services they can help you with on that derisking journey with respect to cyber. So it's not always just all about the cost of insurance.
Alexander Gombach
executiveGreat. So let's shift gears a little bit. Let's talk a little bit about cybersecurity and ESG factors. We've got a variety of questions in on that topic. I'll keep the question broad and turn to Tiffany to give us some insight on those 2 topics and their interconnectedness.
Tiffany Tribbitt
executiveSure. And I'll also use the opportunity, Alex, I know we've had a lot of questions kind of coming in about how do we assess this in our ratings and this is the interconnectivity. So I'll see if I can address about 6 questions in one go here. So bear with me. So starting with how does cyber fit into ESG. So we evaluate cyber risk as a governance factor, specifically as a risk management culture and oversight factor. And we've gotten a question in, would we ever take a rating action because of weak cyber governance? And the answer is, potentially. However, what we typically see is that where cyber risk management is weak, there are other weaknesses in risk management. And that really makes it challenging to pull out that a specific rating action is tied just to weak cyber risk management. I mean I, personally speaking, I've never seen an issuer that just has slam dunk overall risk management and then just is doing nothing for cybersecurity. That's just not been our experience. And that's kind of one of the challenges is that it gets intermingled in that, which also brings us into answer another question, which is what number of rating actions have we seen? And that's also kind of challenging to kind of pinpoint because it does get kind of caught in some of that noise with overall risk management challenges that are being evaluated in cyber profiles. What we did, and I'll harken back, Alex, to a great panel that you moderated back in October, we do have the replay available for folks who are interested. There's also kind of a summary on it, if you want to read. But we did highlight some rating actions where we've seen cyber attacks drive rating actions and had the analysts on from around the world to kind of walk through those case studies. A lot of the times, the ones that we can really pinpoint specifically to cyber are the ones that follow an attack. And, well, a lot of the times, what we've seen is slow responses. As Sudeep noted, folks can be in the system for a really long time without detection, and that does tend to drive up the likelihood that there could be a larger business impact. On poor recovery, we've seen that with other credits like Baltimore water sewer, where the lingering effects of a cyberattack just took years, and there's a long kind of tail at the event that can linger and affect the ratings even years later. And we do see those. Those are typically governance-driven rating actions. I'll pivot now to we've had a bunch of questions come in about how specifically we're looking at cyber risk within certain entities like corporate entities and bank entities. I'm going to remind everyone, we have some great related research and resources. We've actually put out a series of pieces kind of looking at each of our practices and sectors and how do we assess these cyber risks and the criteria. We have a digital book that's going to bundle those together coming out in the coming weeks. So if you're on this webinar, you'll be receiving a copy of that [indiscernible] so check your e-mail. I'm pretty excited about it. But in the meantime, I will refer you to some of those links below. We have a corporates piece that's going to dig in kind of how we assess the reputational risks falling from a cyber attack, how that can impact liquidity, how it can impact your management in the U.S. public finance space. We've got some pieces out for our various sectors where these risks attack. I think I saw somebody asking about water utilities and power utilities. I actually cover power utilities. That's kind of in our operational management assessment. So within every criteria out there, there's a place where we're looking at these risks. I would say, high level, it's going to be management, it's going to be liquidity. It's going to be kind of how are you positioned to absorb if there's an attack. So I think I answered about 6 questions that have come in there. So Alex, if I missed one, let me know.
Alexander Gombach
executiveYou did an amazing job there, Tiffany, keeping that all straight. We have time for, I think, one more big question. And this is a fantastic question. I'm actually going to read it just as it was written in here, and let's do a little bit of a lightning round maybe. We'll start with Sudeep, but then the entire panel can jump in here if you've got different points of view on this. So the question is, with the interconnectedness convergence, do you see the structure of the C-suite changing or the responsibilities of the CIO? How should we think organizationally about fusing third-party physical and cyber risk? So Sudeep, kick us off and then, panel, jump in.
Sudeep Kesh
executiveYes, I think that I love this question. And I think it's one of these things, I don't want to give any illusion that there's sort of a magic pill or there's one organizational structure that is better than all others. I think the most important thing to think about is, and this really should be something that a lot of corporate boards are thinking about is, is our organization, however it is structured, is it done so with intent to basically maximizing what our goals are and minimizing -- you can't minimize risk, but you can maximize sort of your management of it. And I think, again, it's really to me, it's 2 things. It's the intentionality is one thing and the inclusivity of the right voices in the room. And what I mean by that is that the cybersecurity posture is not just the providence of your IT department. That really has to be embedded within your risk management culture. And one of the things that I think are part of that sort of secret sauce, so to speak, is your learning organization embedded in that, meaning that your employee training and so on, that's kind of your first line of defense from sort of that standpoint is your marketing department and your customer relations department. Is that integrated in that strategy to maintain customer trust that you basically have sort of inside out and outside in? And then in terms of how you're organized, making sure that, that risk management culture and cybersecurity is part of that risk management framework is really embedded in your executive functions, in your operating functions, in your actual product and all those sort of development activities. Because I think it's one of these things that if you incorporate these elements of security and risk management into the design of how you actually do business, you're much better placed to really be able to deliver on your mission as an organization and do so with managing that risk, including cybersecurity risk.
Scott Crawford
executiveI'm going to jump in here if I may. Having worn one of those hats in the past, there's a couple of things. So one of them is, Sudeep mentions the right voice, having the right voices participate. And yes, there is a necessity to have people with domain expertise, subject matter expertise about cybersecurity per se, regardless of the aspect of the business. Where the tension comes in, in a lot of businesses is when cybersecurity, in a larger sense, risk management, risk mitigation begins to pose a conflict to business objectives in some, I don't know if I'd say material way, but certainly in a meaningful way. And I'll give you an example of what I mean by that. If you really want to know what your peers are up against, it really behooves you to share information about the types of security activity, threat activity that organizations have seen and share that among anyone who might be affected. And we have actually seen the rise of information sharing organizations. They tend to be vertically specific, focused on a given industry. They may or may not share information outside that industry. There's reasons to not do that given -- in certain types of industries, but there are reasons that organizations do resist that. They don't want their competitors, they don't want the adversary to know what their exposures might be or what they're sustaining successfully or unsuccessfully. Also with insurers as well, too. It's been kind of strange because you think of any body of data that could really be reflective of the nature of cybersecurity incidents, it would be those who against whom claims are filed for compensation for those incidents. And in the early days of the evolution -- Simon, you can speak to this more specifically, of course, but in the early days, the evolution of cybersecurity insurance, the insurers sometimes were reluctant to share with each other because they didn't want to disclose what they're seeing. They didn't want to disclose anything that they might consider intellectual property in that. So there's resistance to like, yes, we think it's a great idea, but we want to play it somewhat close to the vest. Well, as the world becomes increasingly interconnected, that's going to be more and more difficult and, frankly, more and more impractical. Events shaped cybersecurity more than virtually anything else. We've seen that over and over again. And as a CISO, as a Chief Information Security Officer, you learn very quickly, never waste a good incident, use it to your advantage. And as we see more of those, we'll see more pressure to become more, not just interconnected, but better interconnected in terms of information and what we need to do to respond as organizations. Keep in mind that governance is a primary aspect of the discussion revolving around what the NIST Cybersecurity Framework 2.0 will evolve to be.
Alexander Gombach
executiveGreat. Simon, any last thoughts on this topic.?
Simon Ashworth
executiveMaybe just one. Over the last decade or so, the insurance industries had a lot of focus, particularly at the Chief Risk Officer level, to look for the upside of risk management, in particular, looking at ways to allocate capital to the most profitable insurance products. And I think there's really a parallel there with the cyber sphere because the extent to which CISOs, CROs, other C-suite members can pitch these, frame these things, perhaps it's to Scott's point, never wasting a good crisis. But to the extent that those members are able to frame elements to ensure that the C-suite can understand the upside from a profitability perspective of appropriate cyber risk management, then I think that is the key challenge and key focus.
Alexander Gombach
executiveNice. Tiffany, we're going to give you the last word today.
Tiffany Tribbitt
executiveYes. And I'll bring it back to the ratings perspective. And I'll say, these have all been such valuable insight, but I'm going to harken back to what an analyst said to me one time is, we are looking for folks, when we talk about embedding this in your overall risk management strategy, we expect everyone in the C-suite to have that pulse. We say here at S&P, cybersecurity is everyone's responsibility, no more so than your CEO and your CFO and the folks who are sitting in those rooms and are going to be the ones who need to respond to these attacks. And so I had an analyst say to me, you can tell when they don't have that embedded in their policy because you get the homina homina homina when you're asking the cyber questions. And I think that's really, as this threat evolves, that's really what we're looking for when we talk about it being an embedded part of risk management. We want to have everybody kind of knowing the high-level details, what are you going to do the day that, that happens, because we like to say it's not an if, it's a when. And that's why we're really focused on what you're doing to prepare yourself for that. So Alex, on that delightful, happy note...
Alexander Gombach
executiveNot to leave everybody on a scary note, it is when, not if, but -- no, thank you, and thank you to the panel today. This was an incredible wealth of fantastic information. And just seeing the interaction on questions, I think the audience, I hope, is getting a lot out of this today. So again, to our audience, thank you for attending today. As another reminder, the replay will be available in 24 hours on s&pratings.com. The articles and the slide deck that you saw today are also going to be available in the platform as well. And my last pitch, if you haven't done so already, please take the survey. We truly do listen to your feedback as, hopefully, you saw today by the way we brought on Simon here at the last minute. So again, thank you. Stay vigilant, my friends, stay aware. All right. Take care. Thanks, everybody.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete S&P Global Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to S&P Global Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.