Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • IT Management
    • Small Business

    Enterprise Compliance Costs Hit $3.5 Million, Study Finds

    Written by

    Brian Prince
    Published January 31, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The penalties for being out of step with compliance mandates are not going away, and neither is the cost of keeping up with regulations.

      However, a new report from the Ponemon Institute revealed that more compliance audits can actually have the effect of lowering the price tag.

      According to the study (PDF), which included responses from 160 business leaders spanning 46 multinational companies, the average cost of compliance is more than $3.5 million. Twenty-eight percent of those surveyed said they do not conduct internal compliance audits, while 22 percent responded they conduct between three and five a year.

      Those in the latter group had a lower per capita compliance cost than those in the former. Organizations with three to five internal compliance audits each year averaged a cost of $154 per capita. In contrast, those that did not perform internal audits had a compliance cost of $341 per capita, and their noncompliance cost-the cost of the consequences of compliance failure-stands at $1,275 per capita.

      “I believe that the reason why internal audits reduce compliance cost is that they help prioritize the organization’s overall compliance efforts,” explained Larry Ponemon, chairman of the Ponemon Institute. “This leads to greater efficiency in managing the total compliance burden. In other words, companies that do not conduct audits appear to be less efficient in their ongoing program management of data protection and privacy efforts.”

      If companies spent more on compliance in areas such as audits, enabling technologies, training and expert staffing, they could recoup their expenditures and possibly more by reducing the cost of the consequences of being out of compliance, the report asserts.

      The total cost of compliance varies significantly between industries, ranging from $6.8 million for education and research to more than $24 million for the energy sector. In terms of budget allocation, the areas of considerable cost include complying with laws and regulations ($1,588,900), addressing internal policies and procedures ($1,190,005), and funding contractual agreements with partners, vendors and data protection authorities ($564,230), according to the report.

      A consistent theme in the institute’s studies on data breach and compliance issues has been the role of strong management in maintaining and reaching regulatory compliance, Ponemon said.

      “Executive leadership or sponsorship of data protection, privacy and information security initiatives almost always leads to a more favorable program effort and outcome,” he said. “One reason for this finding is that executive support translates into a larger program budget, which results in the purchase of cutting-edge technologies, professional staff and more.”

      Unfortunately, compliance regulations have become a necessity because very few organizations have voluntarily created a secure environment for sensitive data, opined Rekha Shenoy, vice president of strategy at Tripwire, which commissioned the study.

      “I believe that executive leadership involvement is imperative to be able to create a culture of not only compliance, but also of security,” she said, adding that no industry or public sector is really improving in this area.

      “The difference between companies that are improving and those that have a wider gap is likely executive leadership,” she said. “We see the common thread being the number of internal audits occurring-which happens with executive support. So when the compliance dollars go toward investing in automated compliance and good security practices, the business reaps the benefits. We are excited that we have good economic data to prove what the industry has been debating for some time.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.