Home
News
Tech Grid
Data & Analytics
Data Processing Data Management Analytics Data Infrastructure Data Integration & ETL Data Governance & Quality Business Intelligence DataOps Data Lakes & Warehouses Data Quality Data Engineering Big Data
Enterprise Tech
Digital Transformation Enterprise Solutions Collaboration & Communication Low-Code/No-Code Automation IT Compliance & Governance Innovation Enterprise AI Data Management HR
Cybersecurity
Risk & Compliance Data Security Identity & Access Management Application Security Threat Detection & Incident Response Threat Intelligence AI Cloud Security Network Security Endpoint Security Edge AI
AI
Ethical AI Agentic AI Enterprise AI AI Assistants Innovation Generative AI Computer Vision Deep Learning Machine Learning Robotics & Automation LLMs Document Intelligence Business Intelligence Low-Code/No-Code Edge AI Automation NLP AI Cloud
Cloud
Cloud AI Cloud Migration Cloud Security Cloud Native Hybrid & Multicloud Cloud Architecture Edge Computing
IT & Networking
IT Automation Network Monitoring & Management IT Support & Service Management IT Infrastructure & Ops IT Compliance & Governance Hardware & Devices Virtualization End-User Computing Storage & Backup
Human Resource Technology Agentic AI Robotics & Automation Innovation Enterprise AI AI Assistants Enterprise Solutions Generative AI Regulatory & Compliance Network Security Collaboration & Communication Business Intelligence Leadership Artificial Intelligence Cloud
Finance
Insurance Investment Banking Financial Services Security Payments & Wallets Decentralized Finance Blockchain
HR
Talent Acquisition Workforce Management AI HCM HR Cloud Learning & Development Payroll & Benefits HR Analytics HR Automation Employee Experience Employee Wellness
Marketing
AI Customer Engagement Advertising Email Marketing CRM Customer Experience Data Management Sales Content Management Marketing Automation Digital Marketing Supply Chain Management Communications Business Intelligence Digital Experience SEO/SEM Digital Transformation Marketing Cloud Content Marketing E-commerce
Consumer Tech
Smart Home Technology Home Appliances Consumer Health AI
Interviews
Think Stack
Press Releases
Articles
Resources
  • Data Security

Marsh McLennan: Incident Response Cuts Cyber Risk 13%


Marsh McLennan: Incident Response Cuts Cyber Risk 13%
  • Source: Source Logo
  • |
  • August 28, 2025

The Marsh McLennan Cyber Risk Intelligence Center (CRIC) released its 2025 report, Cybersecurity Signals: Connecting Controls and Incident Outcomes, on August 27, 2025, highlighting incident response planning as a critical cybersecurity control. The report, based on data from Marsh’s Cyber Self-Assessment and cyber insurance claims, shows organizations with robust incident response plans are 13% less likely to experience a material cyber event.

Quick Intel

  • Report: Cybersecurity Signals: Connecting Controls and Incident Outcomes, released August 27, 2025.

  • Key Finding: Incident response planning reduces breach likelihood by 13% through tabletop exercises and drills.

  • Ranking: Fourth most effective control, behind EDR, logging/monitoring, and cybersecurity awareness/phishing testing.

  • Other Controls:

    • EDR: 10% breach reduction per 25% coverage increase.

    • Phishing-resistant MFA: 9% lower breach likelihood.

  • Source: Marsh McLennan Cyber Risk Intelligence Center, Business Wire.

  • Stock Context: Marsh McLennan (MMC) at $223.95, up 0.74% (see finance card above).

Key Findings

The report analyzes 12 cybersecurity controls tracked by the cyber insurance industry, correlating their implementation with claim likelihood. Incident response planning, focused on post-breach activities, emerged as the fourth most effective control, following:

  1. Endpoint Detection and Response (EDR): Each 25% increase in deployment reduces breach likelihood by 10%.

  2. Logging and Monitoring: Enhances real-time threat detection.

  3. Cybersecurity Awareness and Phishing Testing: Builds employee resilience.

“Marsh has long advocated proactive cyber incident response planning,” said Tom Reagan, Global Cyber Practice Leader. “Thoughtful planning drives positive security behaviors and strong control implementations, reducing breach incidents.”

The report also emphasizes proper management of controls. For example, phishing-resistant MFA reduces breach likelihood by 9% compared to standard MFA. “Simply deploying controls is no longer enough—they must be properly managed,” said Scott Stransky, Head of CRIC.

Strategic Impact

With cybercrime costs projected to reach $24 trillion by 2027, the report underscores the need for robust cybersecurity frameworks. Organizations conducting regular tabletop exercises and scenario-based drills see measurable risk reduction, aligning with findings from a 2025 Dragos report showing incident response planning cuts operational technology (OT) cyber risk by up to 18.5%.

Marsh McLennan’s insights, drawn from one of the largest cyber claims datasets, empower organizations to prioritize investments in controls like EDR and MFA, which are critical as 73% of companies reported cyberattacks in 2024, dominated by ransomware and phishing.

Industry Context

The report aligns with broader industry trends, as 60% of enterprises prioritize cyber resilience by 2026. Marsh McLennan’s stock (MMC) rose 0.74% to $223.95 post-announcement, reflecting investor confidence, though it’s 2.5% below its 52-week high of $229.63 (see finance card above).

 

About Marsh McLennan

Marsh McLennan is a global leader in risk, strategy and people, advising clients in 130 countries across four businesses: Marsh, Guy Carpenter, Mercer and Oliver Wyman. With annual revenue of over $24 billion and more than 90,000 colleagues, Marsh McLennan helps build the confidence to thrive through the power of perspective. 

  • Marsh Mc LennanCybersecurityIncident ResponseEDRMFA
News Disclaimer
  • Share