Business Wire

NY-SECURITYSCORECARD

Share
SecurityScorecard Research Finds 48% of Global Critical Manufacturing At Significant Risk of Breach

SecurityScorecard, the global leader in cybersecurity ratings, today announced the results of its new report, Addressing the Trust Deficit In Critical Infrastructure, which revealed 48% of critical manufacturing organizations ranked “C,” “D,” or “F” on SecurityScorecard’s security ratings platform. Published during the World Economic Forum (WEF) Annual Meeting, the report analyzed the current state of cyber resilience in the critical infrastructure sectors such as Energy, Chemical, Healthcare, and others, as designated by the Cybersecurity and Infrastructure Security Agency (CISA). Organizations with an “A” security rating are 7.7 times less likely to sustain a breach than those with an “F” rating.

“Security ratings are a trusted barometer of cyber resilience and the time is now for policymakers and organizations to make cyber risk measurement mandatory,” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Cyberattacks in the last 10 years have gotten much worse, more complex, and increasingly have targeted critical infrastructure, thereby undermining the public’s trust in the cyber resilience of our global economy.”

SecurityScorecard provides comprehensive security ratings, automated assessments, and guidance from industry experts, providing a patented and easy-to-understand A-F graded scorecards for improved communication, effective compliance reporting, and more informed decision-making.

According to the World Economic Forum, only 19% of cyber leaders feel confident that their organizations are cyber resilient. SecurityScorecard recently joined the World Economic Forum Global Innovators Community, contributing to WEF’s Centre for Cybersecurity’s initiative to address systemic challenges, improve trust, and build cyber resilience. Yampolskiy is attending the WEF Annual Meeting in Davos to engage with the world’s foremost public- and private-sector leaders on mitigating global cyber risk, including within critical infrastructure.

Critical Manufacturing Patching Cadence Falls Amid Escalating Attack Cadence

Cyber incidents affecting critical infrastructure, once comparatively rare, have become far more frequent in recent years as nation-states and their proxies escalate their pursuit of geopolitical objectives. Data from the Federal Bureau of Investigation showed that 14 of the 16 sectors considered critical infrastructure by the U.S. government experienced at least one ransomware attack in 2021.

SecurityScorecard assessed these industries to measure their current state of cyber resilience. It found that critical manufacturing is highly vulnerable based on analysis of all organizations under that category in The Forbes Global 2000 list. SecurityScorecard considers 10 factors when developing an organization’s security rating. Of those 10, the patching cadence ‘factor’ for critical manufacturing experienced a significant drop from 2021 to 2022, moving from 88 (B) to 76 (C).

High and Medium-Severity CVEs Strain Resources

The decline in patching is likely due to an increased volume of vulnerabilities. Critical manufacturing experienced a 38% year-over-year increase in high severity vulnerabilities. In 2022 alone, 76% of critical manufacturing organizations have high and medium-severity CVEs.

These CVEs may, in some cases, facilitate ransomware groups’ targeting of organizations in the sector. Manufacturers experienced an increase in malware infections from 2021 to 2022. In 2022, 37% of critical manufacturing organizations had malware infections.

“While investing in more technology might seem burdensome to resource-constrained critical infrastructure operators, the reality is that cybersecurity ratings technology is extremely cost-effective, especially when you consider the catastrophic cost of a breach is $9.44 million on average for U.S. organizations,” continued Yampolskiy. “By leveraging security ratings, these organizations have a simple way to build resilience and make more informed decisions to strengthen their cyber defenses by confidently measuring risk and quantifying the trustworthiness of their partners, contractors, third-and fourth-party vendors, and supply chains.”

To view the full research paper, please visit: https://resources.securityscorecard.com/davos-2023/addressing-the-trust-deficit

About SecurityScorecard

Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20230117005416/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

“All Genetic Diseases Could be Cured within a Decade”, Hears Dubai Future Forum20.11.2025 14:15:00 CET | Press release

All known genetic diseases could be cured within the next decade thanks to major advances in gene editing, a leading scientist told the Dubai Future Forum 2025. Discussing his company’s research, Dr. Trevor Martin, Co-founder and CEO of Mammoth Biosciences, described “a one-time cure that will reshape the healthcare system as we know it.” This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251120548681/en/ Dubai Future Forum 2025 (Photo: AETOSWire) Opening the forum, Khalfan Belhoul, CEO of Dubai Future Foundation, introduced the concept of “national cognitive potential”, arguing that countries in the future will gain a competitive edge in fields like AI by leveraging the collective cognitive strength of their societies. In another session, Dr. Nikku Madhusudhan, Professor of Astrophysics at the University of Cambridge, said there is a “good chance” humanity will discover life on another planet—possibly in the next decade. He exp

12 Major Verification Trends in 2026: Regula on the Birth of a New Digital Identity20.11.2025 14:00:00 CET | Press release

How we verify is changing — and so is who and what we verify. Are we dealing with real people, fraudsters, or machines acting on their behalf? A new Regula report on 12 identity verification trendsexamines how these shifts are forcing businesses to rebuild their verification processes to stay ahead of fraud, comply with regulations, and regain eroding customer confidence. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251120373343/en/ Identity is leaving the human domain: Regula’s forecast illustrates the emerging need to verify systems, autonomous agents, and machine customers. The new face of fraud The identity threat landscape has entered a new industrial phase, defined by three structural shifts: Machine identity. Identity verification (IDV) is no longer limited to people. It now extends to autonomous systems acting on their behalf — AI agents that can open accounts, submit documents, and bypass checks on their own. Frau

Cassidy Bio Launches with the Goal to Develop Safer, More Scalable Gene Editing Therapies20.11.2025 14:00:00 CET | Press release

AI-driven genomic foundation model integrates wet-lab validation, population-scale genomics, and advanced machine learning to improve gene editing design at scale Founding team unites CRISPR pioneers and AI leaders, supported by a world-class Scientific Advisory Board including Dr. Vic Myer (former CTO, Editas Medicine) and Dr. Saar Gill (UPenn) Cassidy Bio, a biotechnology company developing the first AI-driven genomic foundation model to enhance the design of gene editing therapies, today announced its launch and the closing of an $8 million seed financing round. The company will use the funding to advance its platform, built as a holistic solution designed to bring precision, speed, and clinical confidence to the rapidly growing field of gene therapies. Cassidy Bio’s AI-driven genomic foundation model combines proprietary wet-lab data, population-scale genomic insights, and advanced machine learning to predict the best pairings of guides, enzymes, and delivery modalities, matching t

Scientist.com Completes Acquisition by GHO Capital Partners to Accelerate Global R&D Orchestration20.11.2025 13:55:00 CET | Press release

Strategic partnership finalized, unlocking expanded AI-driven platform capabilities and international growth Scientist.com, the life sciences industry’s leading AI-enabled R&D orchestration platform, and GHO Capital Partners LLP (“GHO”), the specialist private equity investor in global healthcare, today announced the successful closing of GHO’s acquisition of Scientist.com. The transaction marks the beginning of an accelerated expansion phase, strengthening Scientist.com’s mission to transform pharmaceutical R&D by streamlining the entire outsourced research lifecycle. “This is a pivotal moment for Scientist.com and for the global research community we support,” said Kevin Lustig, CEO and Chris Petersen, CTO, the founders of Scientist.com. “Partnering with GHO, a team that shares our vision and brings deep expertise in scaling healthcare technology companies, enables us to invest aggressively in our AI-powered orchestration platform and expand our global footprint. Together, we are bet

SimpliStor™ Solid State Data Recorder Delivers High-Speed, Radiation-Tolerant Storage for Next-Generation Space Missions20.11.2025 13:00:00 CET | Press release

Frontgrade™ Technologies, a leading provider of high-reliability electronic solutions for space and national security missions, today announced the release of the SimpliStor™ Solid State Data Recorder (SSDR), a next-generation, radiation-tolerant data recorder that gives satellite operators, system integrators, and spacecraft designers a faster, smarter, and more resilient way to capture and protect mission-critical information in orbit. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251120514203/en/ Frontgrade's SimpiStor™ 2.5TB Solid-State Data Recorder High-Throughput Performance SimpliStor delivers 2.5 terabytes of storage and 10Gbps throughput in a compact 3U SpaceVPX package, combining exceptional performance with low power consumption. Users can record more data in less time, with latency under 100 microseconds and continuous “store-to-full” recording, ensuring no data loss during peak operations. A 33-minute continuo

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye