Business Wire

NY-SECURITYSCORECARD

Share
SecurityScorecard Research Finds 48% of Global Critical Manufacturing At Significant Risk of Breach

SecurityScorecard, the global leader in cybersecurity ratings, today announced the results of its new report, Addressing the Trust Deficit In Critical Infrastructure, which revealed 48% of critical manufacturing organizations ranked “C,” “D,” or “F” on SecurityScorecard’s security ratings platform. Published during the World Economic Forum (WEF) Annual Meeting, the report analyzed the current state of cyber resilience in the critical infrastructure sectors such as Energy, Chemical, Healthcare, and others, as designated by the Cybersecurity and Infrastructure Security Agency (CISA). Organizations with an “A” security rating are 7.7 times less likely to sustain a breach than those with an “F” rating.

“Security ratings are a trusted barometer of cyber resilience and the time is now for policymakers and organizations to make cyber risk measurement mandatory,” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Cyberattacks in the last 10 years have gotten much worse, more complex, and increasingly have targeted critical infrastructure, thereby undermining the public’s trust in the cyber resilience of our global economy.”

SecurityScorecard provides comprehensive security ratings, automated assessments, and guidance from industry experts, providing a patented and easy-to-understand A-F graded scorecards for improved communication, effective compliance reporting, and more informed decision-making.

According to the World Economic Forum, only 19% of cyber leaders feel confident that their organizations are cyber resilient. SecurityScorecard recently joined the World Economic Forum Global Innovators Community, contributing to WEF’s Centre for Cybersecurity’s initiative to address systemic challenges, improve trust, and build cyber resilience. Yampolskiy is attending the WEF Annual Meeting in Davos to engage with the world’s foremost public- and private-sector leaders on mitigating global cyber risk, including within critical infrastructure.

Critical Manufacturing Patching Cadence Falls Amid Escalating Attack Cadence

Cyber incidents affecting critical infrastructure, once comparatively rare, have become far more frequent in recent years as nation-states and their proxies escalate their pursuit of geopolitical objectives. Data from the Federal Bureau of Investigation showed that 14 of the 16 sectors considered critical infrastructure by the U.S. government experienced at least one ransomware attack in 2021.

SecurityScorecard assessed these industries to measure their current state of cyber resilience. It found that critical manufacturing is highly vulnerable based on analysis of all organizations under that category in The Forbes Global 2000 list. SecurityScorecard considers 10 factors when developing an organization’s security rating. Of those 10, the patching cadence ‘factor’ for critical manufacturing experienced a significant drop from 2021 to 2022, moving from 88 (B) to 76 (C).

High and Medium-Severity CVEs Strain Resources

The decline in patching is likely due to an increased volume of vulnerabilities. Critical manufacturing experienced a 38% year-over-year increase in high severity vulnerabilities. In 2022 alone, 76% of critical manufacturing organizations have high and medium-severity CVEs.

These CVEs may, in some cases, facilitate ransomware groups’ targeting of organizations in the sector. Manufacturers experienced an increase in malware infections from 2021 to 2022. In 2022, 37% of critical manufacturing organizations had malware infections.

“While investing in more technology might seem burdensome to resource-constrained critical infrastructure operators, the reality is that cybersecurity ratings technology is extremely cost-effective, especially when you consider the catastrophic cost of a breach is $9.44 million on average for U.S. organizations,” continued Yampolskiy. “By leveraging security ratings, these organizations have a simple way to build resilience and make more informed decisions to strengthen their cyber defenses by confidently measuring risk and quantifying the trustworthiness of their partners, contractors, third-and fourth-party vendors, and supply chains.”

To view the full research paper, please visit: https://resources.securityscorecard.com/davos-2023/addressing-the-trust-deficit

About SecurityScorecard

Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20230117005416/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

TOURISE Reframes Tourism Sector as Global Powerhouse on a Path to $16 Trillion During Davos24.1.2026 00:22:00 CET | Press release

TOURISE advanced tourism’s role as a vital sector connecting industries, economies, and regions to address shared global challenges at the World Economic Forum Annual Meeting in Davos. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260123950180/en/ His Excellency Ahmed Al‑Khateeb, Minister of Tourism of Saudi Arabia and Chairman of TOURISE, convenes executives from Trip.com, Visa, TikTok, PayPal, Salesforce, Forbes, Avolta, ByteDance, and more at Davos 2026 Often overlooked as a siloed industry, TOURISE pressed the importance of tourism being recognized as a strategic sector, contributing one in every $10 to global GDP and uplifting every industry it touches. His Excellency Ahmed Al Khateeb, Minister of Tourism of Saudi Arabia and Chairman of TOURISE said alliances and collaboration across sectors will see tourism continue to rise. “Tourism is more than a lifestyle sector, it functions as a strategic economic system. TOURISE

Zycus Named a Leader in the 2026 Gartner® Magic Quadrant™ for Source-to-Pay Suites23.1.2026 20:00:00 CET | Press release

This acknowledgment reflects Zycus’ momentum in Agentic AI, comprehensive S2P suite, brand trust and customer outcomes. Zycus, a global provider in Source-to-Pay (S2P) technology, today announced that it has been recognized as a Leaderin the 2026 Gartner® Magic Quadrant™ for Source-to-Pay Suites. We believe the report points to Zycus’ continued investment in Merlin Intake to streamline user experience and Agentic AI to support workflows such as tail-spend management via autonomous negotiation. This aligns with Zycus’ “Intake to Outcomes” (I2O) belief: simplify how work enters procurement, orchestrate execution with Agentic AI, and deliver outcomes with the right governance and control. “Being recognized as a Leader in the Gartner Magic Quadrant for Source-to-Pay Suites reflects our long-term commitment to innovation, customer outcomes, and responsible AI,” said Aatish Dedhia, Founder & CEO of Zycus. “Merlin Agentic AI is designed to move beyond task automation towards end-to-end outcom

Bureau Veritas to Acquire a Leading Sustainability Specialist for Consumer Products in Italy23.1.2026 18:13:00 CET | Press release

Bureau Veritas, a global leader in Testing, Inspection, and Certification services (TIC), announces the acquisition of SPIN360, a leading Italian consulting firm specialized in sustainable innovation and development across primary premium fashion and luxury brands. This acquisition aligns with Bureau Veritas’ LEAP | 28 strategy to create new strongholds in the Consumer Product Services (CPS) industry, and to accelerate its growth in key markets such as Italy. The transaction will deliver on value creation opportunities, by combining SPIN360's proprietary Life Cycle Assessment (LCA) tools and data-driven advisory services with Bureau Veritas' certification and supply chain auditing expertise. It will also help position Bureau Veritas as a global center of excellence for premium fashion and luxury. Created in 2009 and based in Milan, SPIN360 provides technical advisory services covering LCA, life cycle costing, environmental product declarations, carbon footprint, supply chain engagement

HCLTech to Acquire Singapore-based Finergic to Boost Digital Transformation Offerings for Wealth Management Industry23.1.2026 17:55:00 CET | Press release

HCLTech, a leading global technology company, today announced that it has signed a definitive agreement to acquire Finergic Solutions Pte Ltd, a boutique wealth consulting firm headquartered in Singapore. The transaction is expected to close by April 30, 2026. Founded in 2019, Finergic focuses on core banking and wealth management transformation and has a strong, well-established global presence. The addition of Finergic’s niche capabilities, combined with the scale of HCLTech, is expected to unlock stronger synergies and enhance service delivery across the financial services and wealth management industry. HCLTech brings 25+ years of global experience in serving leading financial institutions. By integrating Finergic’s specialized transformation strategy, consulting and wealth-architecture capabilities, HCLTech will accelerate the delivery of next-generation, platform-enabled wealth management solutions anchored by advanced AI-native workflows. These capabilities will complement HCLTe

Saudi Arabia to Host World Economic Forum Global Collaboration and Growth Meeting: Building Common Ground and Reviving Growth on 22-23 April 202623.1.2026 16:29:00 CET | Press release

Saudi Arabia will host the World Economic Forum (WEF) Global Collaboration and Growth Meeting: Building Common Ground and Reviving Growth in Jeddah on 22-23 April 2026, it was announced on the closing day of the 56th Annual Meeting of the Forum in Davos, Switzerland. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260123725881/en/ HE Faisal F. Alibrahim, Saudi Arabia’s Minister of Economy and Planning, announces that the Kingdom will host the World Economic Forum Global Collaboration and Growth Meeting in Jeddah in April 2026 (Photo: AETOSWire) His Excellency Faisal F. Alibrahim, Saudi Arabia’s Minister of Economy and Planning today confirmed the details for the regular high-level WEF meeting, which was announced at the 2025 WEF Annual Meeting. Calling for pragmatism and collaboration against a backdrop of geopolitical fragmentation, HE Alibrahim said “stability can’t be quickly built, and it can’t be bought”. “Stability need

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye