Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • IT Management
    • Networking
    • Storage

    Average Data Breach Cost Rises to $7.2 Million Per Incident: Survey

    Written by

    Fahmida Y. Rashid
    Published March 8, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The average cost of a data breach for an organization went up for the fifth year in a row, to $7.2 million, Ponemon Institute found in its sixth annual data breach report.

      Total cost is not the only thing that went up, as the average cost per compromised record increased to $214, according to the 2010 data breach report released by Symantec and Ponemon Institute on March 8. The cost per compromised record was $204 and total organization cost per breach was $6.8 million in 2009. Total breach costs have gone up every year since 2006, and the Ponemon Institute did not expect the trend to dip downwards anytime soon, according to the report.

      “We continue to see an increase in the costs to businesses suffering a data breach,” said Larry Ponemon, chairman and founder of the Ponemon Institute.

      Ponemon Institute considers a number of factors when calculating costs, such as the process in which a data breach is detected and investigated, how the victims are notified and the cost of deploying new remedies to resolve the issue. There are also other associated costs, such as setting up a call center to enable victims to get more information, paying for credit protection services, lost sales and productivity because customers no longer trust the organization to keep data safe, Josh Shaul, CTO of Application Security, told eWEEK.

      There can be additional costs if regulators crack down with harsher penalties, such as the recent fines on health care organizations for violating HIPAA, he said.

      For the second year in a row, data breach costs went up because organizations responded rapidly to these incidents, the institute found. Fast-acting organizations wound up spending 54 percent more per record than companies that moved more slowly, the survey found.

      About 43 percent of companies notified victims within one month of discovering the breach and faced an average per-record cost of $268, the survey found. More companies, or 7 percent, responded faster in 2010 than 2009, but their costs went up 22 percent. Companies that took longer to notify users paid a mere $174 per record.

      Most regulations require organizations to notify affected customers within 60 to 120 days after discovering the breach.

      While the total cost of a data breach can vary by the organization’s size, industry, location and existing security practices, the Ponemon Institute found there was a positive correlation between the number of records lost and the cost of the incident.

      Malicious attacks, regardless of whether they originated internally or externally, were the most expensive and appear to be increasing in frequency, the report found. Nearly one-third, of 31 percent, of all cases involved a malicious or criminal act, up 7 percent from 2009. A malicious attack was likely to cost companies $318 per compromised record, up 43 percent from 2009.

      Despite the rise of malicious attacks, the most common threat still comes from negligent employees. The number of breaches caused by negligence, such as not securing data properly, increased slightly to 41 percent, and averaged $196 per record, the survey said.

      “Securing information continues to challenge organizations at all levels, but the vast majority of these breaches are preventable,” said Francis deSouza, senior vice president of Symantec’s enterprise security group. Organizations must create a “culture of security” that includes training, data security policy and technology, he said.

      After a data breach, organizations continue to rely primarily on training and awareness programs to emphasize information security. While 63 percent of the respondents mentioned training, implementing encyption mechanisms was the second most popular data-breach remedy, at 61 percent, the report found. Both encryption and data loss prevention implementations have increased 17 percent since 2008.

      Encrypting data minimizes the impact of lost or stolen data because thieves or unauthorized users can’t easily get access to the sensitive information. Symantec also recommended organizations integrate information protection practices into business processes so that security is not an afterthought.

      The 2010 Annual Study: U.S. Cost of a Data Breach is based on actual data breach experiences in 2010 of 51 companies from 15 different industry sectors including finance, health care, technology and transportation. The data breach cases ranged from 4,200 to 105,000 compromised records.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.