Cyber resilience in 2025 and beyond: What pharmaceutical companies need to know

Share now

Every business knows about the recent devastating cyberattacks on Marks & Spencer and Co-op, and every C-suite will be breathing a sigh of relief that their operations aren’t the ones being deluged with negative publicity. It’s human nature to take reassurance from this situation —optimism bias encourages us to underestimate the likelihood of adverse events. However, this is dangerous thinking for pharmaceutical companies that must be turned around.

Keep it real

You know bad actors are drawn to the pharmaceutical sector, attracted by the glitter of your ultra-valuable and highly sought-after intellectual property. But did you know that every time a compromised business in any industry pays up, the value of your pharmaceutical data and intellectual property increases further, and the target on your company’s back gets bigger? In 2024, the global average data breach cost increased by 10%, with your sector’s average data breach cost hitting $5.1 million.

However, other knock-on effects could have even more devastating impacts on your company’s future. If the attacker’s aim is data piracy, your intellectual property could end up as a copycat drug in another regulatory market, permanently devaluing it. Or if you had to go public with a data loss of medical records used for research purposes, public willingness to consent to data sharing would likely plummet, making future research collaborations extremely challenging.

As the phrase goes, this is a situation to keep you up at night, and it’s why you have detailed cybersecurity resilience plans in place as part of your overall business continuity strategy. But how confident are you that they’ll deliver? It’s time to face the fear of cyberattacks head-on and find out.

Five actions to make 2025 the year of no fear

In our experience, many companies see cyber resilience as a purely IT responsibility, categorising the issue as something “the IT team has got covered”.

However, this view underplays the complexity of resilience and overlooks the number of teams involved in managing a cyberattack’s impact and the level of inter-coordination involved. If asked, would your teams responsible for data storage, cybersecurity, data backup, crisis management and more definitively agree that their resilience plans would work as a unified, integrated response strategy to ensure nothing falls between the gaps?

We have conversations like this with companies in your sector (and others) every day, and the first thing we tackle is the fear factor. Enabling operational resilience is what we do, and because we deal with every aspect of data security daily, we have the knowledge and skills to guide you to a position of justified optimism.

Taking the fear out of being a high-value cyberattack target starts with a clear-eyed delve into your current state of resilience and preparedness, before exploring how best to enhance these five areas in your business:

1. Keep data as private as possible

Make your goal to keep as much of your data off the public internet and minimise the amount exposed to potential vulnerabilities. Explore various options to build a secure and private infrastructure to connect and host your data, compute and storage, and include robust private connectivity paths to your broader ecosystem.

2. Clamp down on access to valuable data

When data is your business’s lifeblood, it must be readily available to all who have the right to access it whenever they need it — whether that’s your employees or the many parties that make up your research ecosystems and supply chains. However, in 2024, using compromised credentials benefited attackers in 16% of breaches globally, accounting for an average of $4.81 million per breach. So, it’s crucial to implement advanced identity access management protocols that grant users only the access level required and only for the task’s duration.

3. Ramp up data observability

Should a cyberattack succeed in exfiltrating some of your data, your compliance obligations to regulations such as GDPR mean you must identify what data has been lost and where it may have gone to understand any potential consequences. The more private you can keep your data, the greater the visibility you can achieve, and the lower the likelihood that regulatory bodies will make an example of your business regarding fines and publicity.

4. Capture the hearts and minds on your frontline

Endpoint users are notoriously the weakest link in the cybersecurity chain. In 2024, the global average data breach cost increased by 10%, with your sector’s average data breach cost hitting $5.1 million.

However, in 2024, using compromised credentials benefited attackers in 16% of breaches globally, accounting for an average of $4.81 million per breach. In 2024, 22% of breaches globally were due to human error.
IBM’s Cost of a Data Breach Report 2024

Whether it’s deliberate activism, using shadow IT to work around restrictive practices or clicking on a phishing email, endpoint users can open your data vault, leaving your crown jewels vulnerable. Mitigate this risk by including endpoint users in your resilience strategy. Educate them on why cybersecurity processes are essential and sometimes cause inconvenience to build tolerance and compliance. Establish a culture where admitting errors is praiseworthy rather than something to fear and allocate specific tasks to help tackle a breach.

5. Game out your minutes-to-meltdown scenarios</h3

It’s so much easier to map out, assign and rehearse essential resilience actions when you’re not in the middle of a cyberattack. Identifying red flags and gaming out potential scenarios now means that, should you be attacked, muscle memory will kick in and teams can act promptly and confidently. As well as boosting your resilience, this supports compliance with ever-tightening data and security regulations. And investing time and effort in growing resilience now means any additional or remedial activities can be run at a pace that suits your business and its resources.

Harness the power of together

As a future-focused pharmaceutical company, you want to forge ahead into new research areas, patents and markets without hesitation about security and data protection. This is where we come in, working at your side to enable you to thrive without restraint.

We know how essential it is that your data environment and storage are secure and compliant, yet flexible enough to support your innovation and growth. Drawing on our three decades of experience, our technology-agnostic, consultancy-led services are ready to design, implement, monitor, manage and secure your operations to protect your business-critical data. Throughout every engagement, we focus on developing tailored solutions that reduce complexity and optimise workloads to deliver a cost-effective and collaborative ecosystem.

Together with our partner, Equinix, we can design and deliver a private infrastructure to maximise your defences. Equinix’s global network of 190+ secure data centres can host your equipment, compute, storage and data and provide direct private connectivity to all major cloud platforms so that you can build out your digital ecosystem as you need to. And should you need to move to quantum key distribution networks in preparation for quantum computing, you can access them at Equinix data centres today.

Whatever direction you take, we’ll have your back, keeping your security resilient as you move through mergers and acquisitions or add new partners and third parties to your ecosystem. We’ll help you navigate the NIS2 requirement that all private data must be stored away from public domains, as well as evolving data sovereignty complexities, so your work can roam securely wherever it needs to go.

And as regulations develop and expand, we’ll be ready to guide you because we’ve already been through the auditing process ourselves, and everything we advise comes from that practical experience. For example, we hold ISO 27001, one of the most widely used security frameworks worldwide. Our journey to this risk-driven standard that focuses on data confidentiality, integrity and availability means we can break down each step for you to streamline your pathway..

Ready to learn more? Get in touch.

For more details on how we support businesses like yours, or to get in touch with one of our experts email: pharma@proact.co.uk or visit our dedicated webpage: Pharmaceuticals & Life Sciences – Proact UK

Sources sited in this report can be found here: link