Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/15/2016
09:50 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Average Cost Of Data Breaches Rises Past $4 Million, Ponemon Says

Ponemon annual report shows benchmark index on the rise again, while Deloitte advises those tangible costs may be just the start to financial impact racked up by breached organizations.

When security executives design the slide decks for their board room presentation about the financial risks of data breaches, they'd better increase the numbers this year. In two separate studies out today by the Ponemon Institute and Deloitte Advisory, traditional data breach costs are on the rise and at the same time the hidden costs of data breaches are also proving to be far more expensive than experts initially anticipated.

The annual Ponemon Cost of Data Breach 2016 report established its yearly benchmark statistics once again, with evidence that breach costs are going up. Sponsored by IBM, the comprehensive study found that the average cost of breaches at organizations have jumped past $4 million per incident, a 29% increase since 2013 and 5% increase since last year. The study found that average dwell time for breaches stands at 201 days, with organizations requiring another 70 days to contain breaches once they'd been identified.

According to the study, when it comes to the impacts of breaches -- like cost per record lost -- the delta continues to widen between organizations that are unprepared and organizations that have instituted mitigating factors like incident response plans, encryption, and employee training. The average cost per record equaled about $158. Having an incident response plan and team in place reduced that figure drastically, by $16 per record. 

"That's huge," says Diana Kelly, executive security advisor for IBM. "It's basically a matter of either having your plan and running that playbook or at least calling someone in to help with response. The savings make sense because without that people start to do things after a breach that don't necessarily benefit the response effectiveness or efficiency and could hurt it."

Other measures that tangibly affected cost-per-record savings included extensive use of encryption, which reduced the cost by $13 per record, use of threat sharing, which lowered it by $9, and having a CISO appointed, which sent it down by $7.

Meanwhile, Deloitte Advisory services says the damages could actually be much higher than those outlined by Ponemon and present themselves many years after the breach. Deloitte's new report, "Beneath the surface of a cyberattack," showed that in addition to the well-known costs like breach notification, post-breach protection and technical investigations, hidden costs also present themselves -- in the way of insurance premium increases, increased cost to raise debt, and devaluation of trade name. Deloitte estimates that the known costs may actually only account for less than 5% of total business impact. 

“Many executives have difficulty gauging potential impact, partly because they are not typically privy to what other industry participants struggle with as they work to get their businesses back on their feet after a cyber incident," says Emily Mossburg, principal for Deloitte & Touche LLP, and resilient practice leader for Deloitte Advisory cyber risk services. "An accurate picture of cyberattack impact has been lacking, and therefore many companies are not developing the cyber risk postures that they need.”

In one composite model put together by Deloitte for the report, it showed that the cost to a healthcare company it worked with actually lost $1.6 billion due to a significant breach of patient records, with only 3.5% of those costs coming in the form of "above the surface" costs. The costs under the surface included lost contract revenue and premiums and lost customer relationships.

It's a stark warning to organizations that the effects of a breach ripple outward much farther than they initially calculated. 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PeterMerkulov
50%
50%
PeterMerkulov,
User Rank: Author
6/17/2016 | 7:51:13 AM
If You Think Security is Expensive...
"If you think security is expensive you should try the alternative" is a new take on an old saying, but the Ponemon report once again puts an eye-opening cost on the consequences of a security failure. Certainly no one is immune to a breach, but as the report points out, preparation and rapid, effective response goes a long way to mitigating the effects.
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31607
PUBLISHED: 2021-04-23
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function...
CVE-2021-31597
PUBLISHED: 2021-04-23
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
CVE-2021-2296
PUBLISHED: 2021-04-22
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromi...
CVE-2021-2297
PUBLISHED: 2021-04-22
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromi...
CVE-2021-2298
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attac...