News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Network Security
Average Rating:
Rate this article:  
Data Breaches Cost U.S. Companies $6.65 Million Data Breaches Cost U.S. Companies $6.65 Million
By Jennifer LeClaire
February 2, 2009 9:46AM

    Bookmark and Share
The latest Ponemon Institute survey shows the cost of data breaches rising. The Ponemon report says data breaches in 2008 cost U.S. companies $6.65 million, up from $6.3 million in 2007. The largest cost increase was lost business, with the churn rate up 40 percent since 2005. Phillip Dunkelberger of PGP warned that breaches can damage a company.
 



The Heartland data Relevant Products/Services breach made headlines in January, exposing 250,000 companies to hackers. But Heartland is hardly the only company that suffered a data breach in 2008.

According to a new survey from the Ponemon Institute, a privacy research firm, data breaches cost U.S. companies $6.65 million last year. That's up from $6.3 million in 2007.

The firm's fourth annual U.S. Cost of Data Breach Study examined 43 organizations across 17 industry sectors to break down data-breach costs. The costs are rising, with incidents costing U.S. companies $202 per compromised customer Relevant Products/Services record in 2008, compared to $197 in 2007.

The largest cost increase in 2008 was due to lost business created by customer turnover. Since 2005, the first year for the study, the churn rate cost has grown by more than $64, or 40 percent, on a per-victim basis.

"After four years of conducting this study, one thing remains constant: U.S. businesses continue to pay dearly for having a data breach," said Dr. Larry Ponemon, chairman and founder of the Ponemon Institute. "As costs only continue to rise, companies must remain on guard or face losing valuable customers in this unpredictable economy."

Breaking Down the Numbers

The average churn rate was 3.5 percent, but health-care companies experienced 6.5 percent and financial-services companies 5.5 percent. According to Ponemon, that indicates the sensitivity of the data collected and customer expectations that the information will be protected.

Slicing the data another way reveals third-party organizations accounted for more than 44 percent of all cases in the 2008 study and cost the most due to additional investigation and consulting fees. More than 84 percent of 2008 cases involved organizations that had more than one data breach. Noteworthy is the fact that more than 88 percent of all cases involved insider negligence.

On the positive side, more than half the respondents believe training and awareness programs help prevent breaches and 44 percent have expanded the use of encryption. And the most significant cost decrease was seen in activities relating to post-breach response, which indicates that organizations are becoming more cost-effective in managing breaches.

"In this current economic climate, U.S. businesses can't afford to give their customers any reason to go elsewhere," said Phillip Dunkelberger, president and CEO of PGP, which owns the Pretty Good Privacy code. "This study continues to show that the results of a data breach can seriously wound a company's bottom line and reputation. This begs the question: When are organizations going to get proactive about protecting their critical data?"

Closing the Gap

According to Michael Argast, a security analyst at Sophos, recent legislation requiring disclosure has driven up the costs of data breaches for companies as consumers become more aware of the risks to their data and the importance of security at the companies which hold that data.

Financial organizations and health-care organizations are especially at risk, he added, due to the potential financial and privacy risks associated with their data.

"Hopefully the extreme costs associated with these losses will cause organizations which were previously lax to take a more aggressive approach to safeguarding their data," Argast said. "Increasing the scope of encryption technology, combined with enforcement mechanisms to ensure its use, will help. Users continue to be a weak link -- policy-enforcement mechanisms combined with improved user education will help close that gap."
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.