Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Average Global Cost of a Data Breach Now $3.6M, IBM Reports

    Written by

    Sean Michael Kerner
    Published June 20, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      For years, the Ponemon Cost of a Data Breach Study has reported a steady increase in breach costs, but surprisingly that’s not the case in the 2017 edition of the report, sponsored by IBM.

      “Overall when you look at the report, the good news is that the overall cost of a data breach is down,” Wendi Whitmore, global lead of IBM X-Force IRIS (Incident Response & Intelligence Services), told eWEEK.

      Globally the study reported that the average cost of a data breach is $3.62 million, which is a 10 percent year-over-year decrease from the 2016 report. The average cost of a lost or stolen record globally now stands at $141. Health care industry breaches were once again reported to be the most costly globally, at $380 per record.

      While breach-related costs declined as a global average, not every region of the world experienced a cost decline. In the United States, breach costs actually rose 5 percent year-over-year to $7.35 million. 

      As to why costs in the U.S, are higher than in other parts of the world, there are multiple reasons. Whitmore more said there is an impact that U.S. regulations are having on breach costs, though with the General Data Protection Rule (GDRP) set to debut in Europe in 2018, it’s unclear if European costs will rise next year as well.

      The 2017 study reported that the mean time to identify (MTTI) a breach globally was 191 days, with the mean time to contain (MTTC) a breach coming in at 66 days. The time it takes to both identify and contain a breach are highest for malicious criminal attacks, extending the time to detect to 214 days and time to contain to 74 days. In contrast, the time to detect decreased to 168 days for human error, with the mean time to contain declining to 54 days.

      Globally, 47 percent of breaches analyzed in the 2017 report were attributed to malicious or criminal attacks.

      Reducing Costs

      As was the case in 2016, the 2017 report found that having an incident response team in place lowers the cost of a breach by improving breach response speed.

      “Having an incident response team can also help an organization to detect breaches,” Whitmore said. “When we talk to our clients, we talk about putting in place a layered defensive approach to detect potential hacker activities.”

      Whitmore added that by reducing the time an attacker has to operate in an environment, the potential impact can also be reduced. 

      Looking at the root cause vulnerabilities that trigger breaches, the 2017 Ponemon Cost of Data Breach Study does not provide much visibility. That said, Whitmore noted that in her experience, zero-day vulnerabilities typically represent less than 2 percent of all data breaches.

      “That doesn’t mean the other 98 percent is bad hygiene,” Whitmore added. “It could mean that organizations are being breached by vulnerabilities that they have difficulty patching.”

      Whitmore added that breaches can also occur when attackers are able to exploit default configurations and install backdoor web shells. In many cases investigated by IBM X-Force IRIS, Whitmore said the root attack vector is some form of spear phishing attack or email compromise.

      In addition to having an incident response team to help reduce breach costs, Whitmore is also an advocate of endpoint detection and response (EDR) technology.

      “As long as there is money to be made from attacks, attackers will keep finding new ways to breach organizations, and EDR tools are not a silver bullet,” Whitmore said. “But as part of an overall balanced strategy, EDR does provide a very positive benefit to help organizations identify and protect themselves.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×