Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Data-breach costs rising, study finds

By Ellen Messmer, Network World
February 02, 2009 12:17 AM ET
  • Share/Email
  • Tweet This
  • Comment
  • Print

In its study of 43 companies that suffered a data breach last year, the Ponemon Institute found the total cost of coping with the consequences rose to $6.6 million per breach, up from $6.3 million in 2007 and $4.7 million in 2006.

The cost per compromised record in 2008 rose 2.5% over the year before to $202 per record, according to the study being released today.

"Each company is like a case study," says Larry Ponemon, head of the research group, noting that these 43 companies volunteered to participate in the study, which doesn’t reveal their names.

But the study, which was sponsored by security vendor PGP, makes some findings about these companies struggling with the fallout of a data-breach incident, which often is publicly reported due to state regulations requiring notification of individuals if their confidential personal data has been lost, stolen or compromised.

"For the majority of our companies, it was not their first time," says Ponemon about the 43 U.S.-based companies in the 2008 data-breach study. "84% of the cases were repeat offenders, and only 16% were new."

He adds the first-timers found a data breach to be more expensive. According to the study, the first-timers found themselves coughing up $243 per record, while for experienced companies, costs were held down to $192 per victim record.

There are some distinct consequences of a data breach, especially in healthcare and financial services, Ponemon notes. In these two industries more than others, customers notified of a data breach are more likely to discontinue association with companies that failed to secure sensitive data about them.

Despite headlines about lost and stolen data, "What continues to amaze me is that you'd think that people would be indifferent to a data-breach notification, but people continue to care a lot," Ponemon said.

While the average customer "turnover" or "churn" due to a data breach was generally 3.6%, in healthcare it was a much higher 6.5% and in financial services 5.5%. And the cost of a healthcare breach, at $282 per record, was more than twice as high as that of the average retail breach at $131 per record.

In other findings, the Ponemon study said 88% of all the cases for 2008 were traced back to insider negligence. The survey also showed that 44% of data breaches occurred due to external causes involving third parties, an increase from 40% in 2007 and 29% in 2006, the Ponemon report states.

A third-party breach is defined as third-party professional services, outsourcers, vendors and business partners that were in possession of the data and responsible for holding it.

Costs for a data breach mount up because of lost business and legal defense, which grew in 2008, while costs of customer support, notification and free services such as credit monitoring decreased, according to the study.

The most-cited steps that companies took following a breach included training and awareness programs; more manual procedures and controls; expanded use of encryption; identity and access-management deployments; and data-loss prevention products.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (7)
Login
Forgot your account info?

So who's learning from this?By kermidge on February 2, 2009, 2:04 amWith 84% repeats, doesn't seem as though they've learned much, aina?

Reply | Read entire comment

there's a good article on this issue and malware and generalBy Anonymous on February 2, 2009, 12:17 pmWhy are viruses and malware still an issue? http://www.trueprotection.com/newsone.html

Reply | Read entire comment

Business "Security" Mostly a Matter of Luck - What to Do?By johnfranks999 on February 2, 2009, 12:39 pmMost companies enjoy “security” insofar as they haven’t been targeted, or had an employee make a human error with catastrophic exposure. Price Waterhouse Cooper...

Reply | Read entire comment

Self serving dataBy Anonymous on February 2, 2009, 7:50 pmSponsors get "3rd party data" for sales and marketing data. Ponemon gets to be the "expert" in this DLP study market and drum up more business..

Reply | Read entire comment

How many of those breaches were contractors that also work for tBy Anonymous on February 2, 2009, 10:43 pmHow many of those forty some breaches were Contractors like Accenture who do work for the government.

Reply | Read entire comment

Solidcore SurveyBy Anonymous on February 9, 2009, 1:40 pmHi, Solidcore had conducted a survey last year and reached a similar conclusion (http://www.solidcore.com/news_events/release79.html). Over the course of 2008,...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed