Data breaches are on the rise in the business world. According to the Privacy Rights Clearinghouse, more than 330 data loss incidents involving more than 93 million individual records have occurred since February 2005.
As these incidents increase in number, so too do the associated expenses that companies end up paying for their negligence.
Data breaches have cost companies an average total of $4.7 million, or $182 per compromised record, in 2006, according the "2006 Cost of Data Breach Study" from Ponemon Institute. That's up from $138 per record last year.
Among the 31 companies that participated in the study, all of which suffered data security breaches, total costs per incident ranged from under $226,000 to over $22 million.
"The burden companies must bear as a result of a data breach are significant, making a strong case for more strategic investments in preventative measures such as encryption and data loss prevention," said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute, in a written statement. "Tough laws and intense public scrutiny mean the consequences of poor security are steep - and growing steeper for companies entrusted with managing stores of consumer data."
The report, slated for release on Monday, Sept. 23 at Infosecurity NY 2006, was co-sponsored by PGP, an enterprise data security and encryption provider, and Vontu, the data-loss prevention solutions vendor. (Notice a common thread between Ponemon's recommendation and the companies sponsoring the report? Still, I wouldn't discount these findings outright.)
About 70% of the costs per incident were "indirect," stemming from loss of existing and future customers, according to the report. Not surprisingly, people don't want to stick around after you've made them a target for identity theft.
The report breaks down the direct costs by various activities. Detection, discovery and escalation expenses, i.e. "activities necessary to discover and report the breach to appropriate personnel in a specified time period", averaged $295,475.
Notification costs, referring to the process of alerting "data subjects with a letter, outbound telephone call, e-mail or general notice, averaged $662,269.
Ex-post responses, the process of helping victims with information, recommendations, credit-report monitoring, or reissuing a new account or credit card, cost an average of $1,245,845.
What was to blame for these breaches?
- Fourteen of them (45%) were a result of lost or stolen laptops, desktops, PDAs, or thumb drives.