Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Post-Breach Costs And Impact Can Last Years
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
andrew_hay
100%
0%
andrew_hay,
User Rank: Author
1/26/2016 | 10:56:30 PM
Too small a sample size

"The survey sample began with 10 telephone interviews, which were followed by a 30-question survey taken by 59 participants involved in quantifying losses and responding to breaches of sensitive information. Of those, 26 experienced true breaches and finished the survey questions."

So the n value is 26? That is far too small a sample to draw any conclusions from. For example:

"Well over half of the survey respondents (64%) reported that the breach they described did not receive media attention."

The percentage sounds significant but it's really only 16 or 17 people.

RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/27/2016 | 8:22:47 AM
Re: Too small a sample size
That's a very good point. A study is further validated by the quantity of results. A more accurate percentage can be drawn and metrics extracted from a myriad of results.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/27/2016 | 8:25:27 AM
Brand Reputation
Brand Reputation can be a killer when it comes to costs from a breach, even more so than the up front cost of that breach. If you lose the confidence of your customer/client, your competitor may get the jump on you.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/28/2016 | 10:25:56 AM
Prestige
Main impact is on prestige of the company, that is basically long lasting situation, people would not forget for long period of time. At the same time while we will never forget Target for example we will continue to shop there. :--))
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/28/2016 | 10:28:01 AM
Re: Too small a sample size
I agree. Numbers may not be so reliable but it is still a number that was not randomly chosen. :--))
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/28/2016 | 10:30:49 AM
Re: Brand Reputation
Survey responders are generally not high in any surveys. This is the case in the other surveys results we have been seeing or hearing. Including political parties.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/28/2016 | 10:32:54 AM
Re: Brand Reputation
"Brand Reputation can be a killer ..."

Completely agree. Unless you do PR well enough that may simply be end of the brand.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/28/2016 | 10:33:07 AM
Re: Brand Reputation
Could you elaborate on your statement? Do you mean not high in count? I fail to see if this is the case how one could create accurate assumptions.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
1/28/2016 | 10:33:36 AM
Cyber insurance?
 

When we start insure our inability to secure ourselves that simply means everting will be unnecessarily expensive. Insurance industry is never a good thing for everyday individuals.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/28/2016 | 10:36:54 AM
Re: Brand Reputation
@Dr. T (10:32:54). Precisely, its amazing how an event such as a breach can tank sales. But very understandable...once you discover the logistics behind some breaches occur simply because of a lack of security best practices such as updating software that may be EOL, patching consistently, or overlooking other simple principles.
Page 1 / 2   >   >>


How Attackers Could Use Azure Apps to Sneak into Microsoft 365
Kelly Sheridan, Staff Editor, Dark Reading,  3/24/2020
Malicious USB Drive Hides Behind Gift Card Lure
Dark Reading Staff 3/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5527
PUBLISHED: 2020-03-30
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource co...
CVE-2020-5551
PUBLISHED: 2020-03-30
Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA manufactured in the re...
CVE-2020-10940
PUBLISHED: 2020-03-27
Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.
CVE-2020-10939
PUBLISHED: 2020-03-27
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.
CVE-2020-6095
PUBLISHED: 2020-03-27
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.