Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Costs Of Data Breaches Much Higher In U.S. Than In Other Countries, Study Says

Legal requirements for disclosure, notification add high expense to data compromise, Ponemon research says

A data breach in the United States could cost enterprises twice as much as the same breach costs companies in other countries with less stringent disclosure and notification laws, according to a study published today.

The study, conducted by the Ponemon Institute and sponsored by security vendor PGP, is an extension of the companies' previous cost-of-breach research that examined regional differences in the costs inflicted by compromises of enterprise data. In a nutshell, the study finds breaches are much more expensive in countries that have stringent regulations than in countries that don't.

"The overarching conclusion from this study is the staggering impact that regulation has on escalating the cost of a data breach," says Larry Ponemon, chairman and founder of The Ponemon Institute. "The U.S. figures are testament to this, and it's clear that as breach notification laws are introduced across the rest of the world, other countries will follow the same pattern, and costs will rise."

The study examined breach costs in five countries: the United States, the United Kingdom, Germany, France, and Australia. In the U.S., where 46 states have introduced laws forcing organizations to publicly disclose the details of breach incidents, the cost per lost record was 43 percent higher than the global average. In Germany, where equivalent laws were passed July 2009, costs were second highest -- 25 percent above the worldwide average. In Australia, France, and the U.K., where data breach notification laws have not yet been introduced, costs were all below the average.

"It's perhaps no surprise that in the U.S., where data protection laws are both stringent and mature, the financial fallout of a breach is at its most severe," commented Jonathan Armstrong, technology lawyer at Duane Morris. "However, the relatively low levels of expense incurred by British firms may raise a few eyebrows. With the U.K. Information Commissioner's Office toughening its stance on data protection, imposing hefty fines, and scrutinizing more and more organizations, it will be interesting to see how steeply U.K. costs rise in the future."

The Ponemon study breaks breach costs into five components: detection, escalation, notification, post-breach response, and customer churn. Of the five components, customer churn -- the loss of customers and the scramble to replace them following a breach -- is typically the highest cost, accounting for 44 percent of breach costs worldwide, the study says. In the U.S., the cost of customer churn was highest, accounting for 66 percent of breach costs.

"A big reason for [the high cost of churn in the U.S.] is that U.S. companies are required to notify customers of their breaches, even if they only suspect that the customers' records might be affected," Ponemon says. "That sort of notification doesn't happen anywhere else in the world." Notification accounts for $500,000 of the $6.75 million that the average U.S. company spends on a breach, according to the study; the average French company spends only $120,000 on notification.

Ponemon suggested that the notification requirements -- combined with a relatively short deadline to deliver those notifications -- could be forcing some U.S. companies to disclose too much too soon.

"They find out they have a breach that definitely affects 300 customers, but there's a remote chance their other 4.5 million customers might be affected, so they notify all of them," he explains. "They might feel they're being altruistic for notifying everyone of a possible breach. But if they don't have any real evidence that those other customers' data is really at risk, then they're just being stupid."

In Germany, by contrast, companies spend longer in the detection and escalation phase, Ponemon says. German companies are generally scrupulous about finding the source of the leak and its exact implications, and therefore end up having to notify fewer potential victims. "It takes them longer to get to notification -- maybe 60 to 70 days vs. 50 in the U.S.," he says. "But in the end, they've got more information."

Globally, the average cost of a breach has risen to $3.43 million -- an average of $142 per lost record, according to the Ponemon study. As regulations become more stringent and the cost of data breaches increases, will more companies make a business decision not to disclose their security troubles?

"There are organizations where executives make it known down the line that they don't want to know if they have a breach," Ponemon says. "There are cases where that situation is so bad that the CEO didn't know about a breach until he read about it in the newspaper. In those situations, it's the lower-level security guy whose job is at risk. He's the one who's going to feel it if the news of the breach comes out."

On the corporate level, making a decision not to disclose a breach is "a dangerous game," says Tim Matthews, vice president of marketing at PGP. "The bottom line is it's against the law. If the government finds out that you had a breach and you knew about it and didn't tell anybody, then you're not only telling the public that you don't care about the law, you're also saying that you don't care about your customers. It could really backfire on you."

The question of fault will also become more evident over time, as other states follow the lead of Massachusetts and Nevada, which require companies to encrypt sensitive data, Matthews predicts.

"I think that what's happening with regulation in the U.S. is a bellwether for what's going to happen around the world," Matthews says. "Other countries can look at what's happening here as a warning about what they can expect as their regulations become tougher. The regulatory environment is becoming more stringent around the world, and as that happens, the cost of a breach is going to keep going up."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
US Counterintelligence Director & Fmr. Europol Leader Talk Election Security
Kelly Sheridan, Staff Editor, Dark Reading,  10/16/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-10-20
The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction...
PUBLISHED: 2020-10-20
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place a DLL in this directory that a privileged service is looking ...
PUBLISHED: 2020-10-20
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linked advisory.
PUBLISHED: 2020-10-20
DomainMOD before 4.14.0 uses MD5 without a salt for password storage.
PUBLISHED: 2020-10-20
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a ...