Study: Data losses proving more costly for businesses

By Jeremy Kirk, IDG News Service |  Security, data breach 2 comments

Data breaches are costing companies more than ever as consumers shun those that have lost information, according to a new study.

Data breaches have proven to be a downside of the information age as personal and financial information face threats from hackers, careless employees and thieves.

The study is based on a survey of 43 U.S. companies that lost data in 2008, ranging from 4,200 records to 113,000 records across 17 industry sectors, according to the Ponemon Institute, which studies privacy practices at companies and government organizations.

It cost companies on average US$202 for every data record lost in 2008. That's compared with $197 in 2007, $182 in 2006 and $138 in 2005, the first year the study was conducted.

Factored into those figures are how much companies spend on detecting data losses, costs incurred notifying victims and hiring forensic experts and paying for free credit checks for affected consumers, among others.

The most costly factor, however, was loss of business. Of the $202, $139 represented the cost of lost business, up 69 percent over 2007.

"The growth in lost business costs demonstrates consumers do not take a breach of their trust and privacy lightly and have not become desensitized to the issue," the study said.

Health-care and financial-services companies that lost data suffered the worst backlash from consumers. The churn rate -- or the rate at which people change their provider -- was 6.5 percent for health care and 5.5 percent for financial services, the study found. Health-care organizations also face a higher-than-average cost per record lost, at $282.

So far about 44 U.S. states have data loss notification laws, but the laws can vary widely. For example, some companies do not have to tell customers if data is scrambled with 128-bit encryption or if the breach was stopped before information was wrongly acquired.

Last month, the Identity Theft Resource Center (ITRC) found that more than 35 million data records were breached in 2008 in the U.S., a record number. The majority of the lost data was neither encrypted nor protected by a password, the ITRC's report found.

ITRC counted 656 breaches in 2008 from a range of well-known U.S. companies and government entities. That was than 47 percent more incidents than the 446 breaches in 2007.

Information about the breaches was collected by tracking media reports and the disclosures companies are required to make by law. But the ITRC said it is likely many more than 35 million records were lost since some companies do not reveal how many records were compromised.

2 comments

    Anonymous 2 years ago
    大阪でバッテリー販売。 セルモーターリビルト。 オルタネーターリビルト。リビルト在庫多数。大阪で電装品販売。リンク品在庫多数。大阪でウイング車モーター修理・販売・在庫多数。大阪でパワーゲート車モーター修理・販売・在庫多数。
    Anonymous 3 years ago
    Perhaps some useful statsistics - together or by themselves - i.e the cost of a lost piece of data at $202 - that is only one piece of data or call it record. What would the cost be to i.e. a bank, to a retailer who's File Server is down for 4+ hours and over 50,000 customer records sit idle not generating revenue - if the cost per record is only 50 cents (that's out of comission), unable to use file server data just cost the company a starting $25,000 and growing when you add... however an inservice record generating revenue may be worth a $1.00 per record - then the file server down problem (users can't access the data) has become a $50,000 starting problem and growing...:)Spread the gospel...

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question