BreachExchange mailing list archives

Costs of a Data Breach: Can You Afford $6.65 Million?


From: security curmudgeon <jericho () attrition org>
Date: Mon, 9 Feb 2009 09:16:52 +0000 (UTC)


http://www.cio.com/article/479101/Costs_of_a_Data_Breach_Can_You_Afford_._Million_?source=nlt_cioinsider

Costs of a Data Breach: Can You Afford $6.65 Million?

A data breach may cost your company $6.65 million dollars, so consider 
that when assigning an appropriate budget to your information security 
staff.

By Dr. Larry Ponemon, Ponemon Institute

February 04, 2009 - Affixing a dollar cost to a problem has immense 
benefit, and The Ponemon Institute goes to great lengths to arrive at the 
figures for its Annual Cost of a Data Breach Study.

We painstakingly analyzed the financial impact a data breach has on a 
company by examining 43 different companies from a cross section of 
industries, all of which experienced a significant data breach affecting a 
range of data records representative of the norm. And knowing that a data 
breach may cost your company $6.65 million dollars may be all the 
information that is needed for a company to assign an appropriate budget 
to those tasked with information security.

In 2008 the average total cost of a data breach was $6.65 million, up from 
$6.35 million last year and $4.54 in 2005. In 2008, the per-victim cost of 
a data breach was $202, up from $197 in 2007, and from $138 when the study 
was launched in 2005. Breaches involving a third party to which data had 
been outsourced bore a per-victim cost of $231, whereas self contained 
breaches bore a per-victim cost of $179. Breaches that were the result of 
a malicious act bore a per-victim cost of $225, whereas breaches that were 
the result of negligence bore a per-victim cost of $199. Breaches that 
were the result of a lost of stolen laptop computer bore a per-victim cost 
of $249, whereas breaches that did not involve a lost or stolen laptop 
computer bore a per-victim cost of $177. If the data breach was a 
first-time event for the company the per victim cost was $243, but if the 
company had experienced a breach previously the per victim cost was $192.

[..]
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently 
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss


Current thread: