- Securing SSLVPN with client certificates
- Toshiba propels DVD quality to near HD
- 16 hot roles for IT pros
- Torvalds: Fed up with the 'security circus'
- The dos and don'ts of IT job seeking
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
For many companies, the question is not will they experience a data breach, it's when and how often, according to survey results released this week.
Some 85% of 700 C-level executives, managers and IT security officers revealed they had experienced a data breach event, and about half of those admitted they had no incident response plan in place. Among the most common causes for the breach incidents were lost or stolen equipment such as laptops, PDAs and memory sticks. The secondlargest contributing factor involved negligent employees, temporary employees or contractors.
The survey, titled "The Business Impact of Data Breach," revealed the "pervasive problem" plaguing IT security officers in midsize to large U.S. businesses in all industries, researchers say. Scott & Scott, a law and technology services firm, commissioned the survey conducted by independent research firm Ponemon Institute and released the findings today.
"Our findings show that data breaches are a pervasive problem for most organizations in the United States today. We also show that despite negative repercussions in terms of cost outlays and reputation diminishment, many companies that experience a breach do not take appropriate steps to prevent future incidents," said Larry Ponemon, founder and chairman of the Ponemon Institute, in a press release.
The survey also shows that most companies are required to report the incident to subjects whose information was lost or stolen. Nearly 100% were required to give such notifications under state statutes, and some 60% were required to notify victims under federal privacy acts such as the Health Insurance Portability and Accountability Act and the Gramm-Leach-Bliley Act. About 37% of respondents said they sent blanket notifications to potential victims, rather than precise details.
Of those organizations suffering a data loss, about three-fourths reported loss of customers, nearly 60% said they faced potential litigation, and one-third faced potential fines. Another 32% said they saw a decline in their share value.
Yet most respondents reported little or no monetary harm to data subjects. Researchers say the findings highlight the need to reform notification requirements, "which can be detrimental to businesses especially when weighed against the perceived lack of real benefit to consumers."
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment