The true cost of corporate data breaches

happygeek 0 Tallied Votes 417 Views Share

According to a survey by the Ponemon Institute, sponsored by and , the true cost of data breaches in 2006 was $182 per compromised record on average, that is a 31% increase over the 2005 figures. Furthermore, the results of the report, published today, reveal that the total cost of each data breach ranged from less than $1 million to more than $22 million.

Cost of a Data Breach: The Financial Impact of Data Loss Incidents 2006 may not sound like ideal bedside reading material, but I would heartily recommend stuffing a copy under the pillow of every CEO, CTO and CFO in order to get them to wake up and smell the security coffee. The study examined all the financial consequences of data breaches involving consumers' personally identifiable information, although the Ponemon Institute only analyzed 31 different incidents from the 330 or so that have occurred since February 2005 according to the Privacy Rights Clearinghouse.

So what did the study actually study in those 31 incidents in order to come up with the bottom line figures? It tracked a wide range of cost factors, including legal, investigative, and administrative expenses, as well as stock performance, customer defections, opportunity loss, reputation management, and costs associated with customer support such as information hotlines and credit monitoring subscriptions.

The end result illustrating the high costs companies will incur for failing to protecting their customers' data, with 72% of respondents indicating that the cause of the data breach was fairly to properly protect digital information (well duh!) If you want to play the percentages, take a look at a recent report also from The Ponemon Institute and Vontu, ‘U.S. Survey: Confidential Data At Risk’ which saw 81 percent of respondents reporting that that their organizations had experienced one or more lost or missing laptop computers that contained sensitive or confidential business information in the previous 12-month period.

Mind you this does not surprise me in the least, considering yet another survey from recently revealed that that 40% of all mobile phones, PDAs and laptops left at airports over the summer will never be reclaimed by their owners – and that was just in the UK. The report went on to suggest that Heathrow Airport send 730 lost and unclaimed laptops and 1460 mobile phones off to auction every year. A figure made all the more worrying when the same survey suggested that 25% of these had no security in place to protect the data stored at all!

Dani AI

Generated

As noted, the thread highlights that a single breach is rarely just an IT event — it becomes a legal, customer-relations and business-continuity problem. The most useful takeaway for practitioners is not the historic dollar figure but which controls and habits actually reduce exposure and shorten recovery time.

Start with practical prevention and hardening: map and classify where sensitive data lives; remove or redact unnecessary data; enforce least-privilege access and multi-factor authentication; deploy full-disk encryption and device management on mobile/laptop endpoints; keep an accurate asset inventory and a prioritized patching program; use endpoint detection/response to reduce dwell time; and bake security requirements into vendor contracts and development lifecycles. Each item above reduces either the likelihood a breach occurs or the number of records exposed — both of which materially lower downstream costs.

Immediate, pragmatic 72-hour checklist:

  • Activate the incident response plan and call the pre‑selected forensic firm and legal counsel.
  • Isolate and contain affected systems; preserve volatile logs and images for chain‑of‑custody.
  • Triage data exposure: what types of data and how many records.
  • Notify internal stakeholders (executive, legal, compliance, PR, ops) and assemble a single communications lead.
  • Begin remediation (patch, revoke credentials, rotate keys) and restore integrity of critical services.
  • Document all actions and expenses for insurance, regulator, and potential litigation follow-up.

Measure what matters: time‑to‑contain, percentage of sensitive records encrypted, mean‑time‑to‑recover, and results of regular tabletop exercises. Those metrics let you cost‑justify controls and insurance limits. This thread is a useful wake‑up call; the practical work is in reducing exposure and rehearsing the response.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.