Cyberattacks Pose Rising Risk to Creditworthiness, Moody's Warns
Cyberattacks have surged globally, increasing the risk to creditworthiness of debt issuers, particularly in the healthcare and public sectors. Moody's credit rating agency reports that the number of organisations experiencing cyber incidents has climbed from 4-5% per year before 2019 to around 7% since 2020. These incidents are often driven by indirect attacks from third-party software providers, posing a risk to credit ratings. While direct impacts on credit ratings are limited to 14 organisations, the trend suggests a growing vulnerability.
Key Takeaways:
- Moody's survey of 9,600 rated debt issuers globally found a 2% increase in cyber incidents from 2019 to 2020, contrasting the pre-2019 annual rate of 4-5%.
- The surge in cyber incidents is primarily driven by indirect attacks from third-party software providers.
- Three prominent debt issuers, including Mount Sinai Hospital, Financiere Verdi I S.A.S. (Ethypharm), and Ascension Health Alliance, received lower revised ratings after facing cyberattacks.
- A past cyber incident correlates with an increased likelihood of future breaches, with one in three organisations examined experiencing at least one incident since 2015.
- Organisations experiencing a cyber incident in one year are four to five times more likely to face another in subsequent years compared to those previously unaffected.
- Sectoral hotspots for cyber incidents include not-for-profit hospitals, public-sector housing, education, and telecommunications, with 42% of not-for-profit hospitals experiencing at least one incident since 2022.
- Despite stronger cyber diligence and governance, banks display one of the highest recurrence rates relative to impact, suggesting targeted attacks or stringent disclosure requirements.
Statistics:
- 9,600 rated debt issuers were surveyed by Moody's globally.
- The number of organisations experiencing annual cyber incidents climbed from 4-5% pre-2019 to approximately 7% since 2020.
- Three prominent debt issuers received lower revised ratings after facing cyberattacks.
- One in three organisations examined had experienced at least one cyber incident since 2015.
- Organisations experiencing a cyber incident in one year are four to five times more likely to face another in subsequent years.
- Not-for-profit hospitals exhibited the highest rates of cyber incidents, with 42% experiencing at least one incident since 2022.
- 14% of public-sector housing entities faced multiple incidents within a year.
Sources:
- Moody's credit rating agency
- Survey of 9,600 rated debt issuers globally by Moody's
- Not-for-profit hospitals, public-sector housing, education, and telecommunications sectors