Global losses from cybercrime have now topped $1 trillion, according to a new report released yesterday by McAfee in partnership with the Center for Strategic and International Studies (CSIS). The report puts the cost of cybercrime to the global economy at more than 1% of global GDP. A 2018 study found that global losses were more than 50% lower, at around $600 billion.
As Infosecurity Magazine reports, McAfee commissioned independent technology market research specialist Vanson Bourne to conduct the research on which the report is based. From April to June 2020, the researchers interviewed 1,500 IT and business decision-makers. Respondents were located in countries around the world including Australia (200), Canada (200), France (200), Germany (200), Japan (200), the United Kingdom (200), and the United States (300) .

The report focuses not only on the significant financial cost that cybercrime imposes on the global community, but also on its broader impact on areas such as a company’s performance and reputation. 92% of companies surveyed reported experiencing significant impacts from cybercrime, resulting in significant financial losses.
Additionally, over 33% of respondents said that downtime caused by IT incidents cost them between $100,000 and $500,000. The average cost to organizations from their longest downtime in 2019 was $762,231. Also, 26% said that downtime caused by cybercrime to their systems and services damaged their reputation. Downtime also reduced productivity, with organizations losing an average of nine hours of work per week.

Steve Grobman, SVP and CTO at McAfee, said the severity and frequency of cyberattacks on businesses continues to increase as techniques evolve , new technologies broaden the threat landscape, and the nature of work expands to home and remote environments. He added that while industry and governments are aware of the economic and national impacts of cyberattacks, the unplanned downtime , breach investigation costs , and productivity disruption cannot be underestimated.
Grobman identified the need for a greater understanding of the overall impact of cyber-risk, noting that effective plans must be put in place to respond to and prevent cyberattacks.
