tfh
Volume 16, Number 48 -- December 10, 2007

The Costs of Data Breaches Continues to Rise, Says Ponemon

Published: December 10, 2007

by Dan Burger

There are 215 million stories in the naked city . . . and those are just the stories that have something to do with data breaches. That's the number, dating back to January 2005, established by the Privacy Rights Clearinghouse. If you find that surprising, wait until you hear about the financial loss attached to those breaches. According to the study released last week by the Ponemon Institute, data breach incidents cost companies $197 per compromised customer record in 2007. Here are some equally sobering statistics to think about:

  • The average per-incident costs were $6.3 million.
  • The cost of lost business increased by 30 percent to an average of $4.1 million.
  • Breaches by third-party organizations such as outsourcers, contractors, consultants, and business partners were reported by 40 percent of survey respondents.

Do you feel that knot in your stomach getting tighter?

As companies grapple with the challenge of protecting their customers' private data, the latest research by The Ponemon Institute shows the cost of failing to protect data do is on the rise. Lost business opportunity, including losses associated with customer churn and acquisition, represented the most significant component of the cost increase.

"The data from 2007 suggests that although companies are responding to data breaches more efficiently, consumers seem to be less forgiving when their personal information is compromised," said Larry Ponemon, chairman and founder of The Ponemon Institute. "The bigger problem, however, remains the persistent underlying issue of data security. Of course, the easiest way for companies to avoid the costs associated with a data breach would be to avoid a breach in the first place."

Ponemon's annual Cost of a Data Breach study tracks a wide range of cost factors, including legal, investigative, and administrative expenses as well as customer defections, opportunity loss, reputation management, and costs associated with customer support such as information hotlines and credit-monitoring subscriptions.

So what measures are being put in place by companies that were crippled by a breach? The report lists the following technologies ranked according to popularity:

  1. Expanded use of encryption
  2. Data loss prevention solutions
  3. Identity and access management solutions
  4. Endpoint security controls
  5. Security event management solutions
  6. Perimeter controls

"Compliance requirements, new notification laws, and the growing list of breaches have made organizations aware they need a different approach to data security," said Phillip Dunkelberger, president and chief executive officer of PGP Corporation, one of two corporate sponsors of the study. "The 2007 Ponemon study shows that erecting another firewall doesn't work anymore because confidential data isn't just inside the company. A single product and a bunch of tactics aren't enough, either."

"The fact that more than a third of breaches result from data being shared with third parties in the normal course of business is a clear signal that organizations should examine how they are sharing their customers' data with outsourcers, vendors, and partners," said Steve Roop, vice president of products and marketing at Vontu, the other corporate sponsor of this survey.

The Cost of a Data Breach report was derived from the analysis of 35 data breach incidents. Some of those incidents involved a few as 4,000 records while others exceeded 125,000 records. The companies analyzed were from 16 industries, including communications, consumer goods, education, entertainment, financial services, gaming, health care, hospitality, Internet, manufacturing, marketing, media, retail, services, technology, and transportation. Copies of the study are available through PGP, Vontu, and The Ponemon Institute.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
WORKSRIGHT SOFTWARE

Do you need area code information?
Do you need ZIP Code information?
Do you need ZIP+4 information?
Do you need city name information?
Do you need county information?
Do you need a nearest dealer locator system?

We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

Just call us and we'll arrange for 30 days FREE use of either
ZIP/CITY or PER/ZIP4.

WorksRight Software, Inc.
Phone: 601-856-8337
Fax: 601-856-9432
E-mail: software@worksright.com
Web site: www.worksright.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

looksoftware:  Present your core System i applications in Outlook, Google and Notes
COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Linux Beacon
Emerging Markets and Virtualization Drive Q3 Server Sales

Novell Swaps the Kernel Guts in Real-Time Linux

IBM Readies Power Management for Power Servers

As I See It: The Sick Guys in Your Wallet

Four Hundred Stuff
Profound Logic Gives Web Access to DB2/400 with iData

Sametime, But a Different Place; IBM Tries to Top Microsoft

Touchtone Boosts Communication in i5/OS CRM

NGS Delivers Prebuilt BI for Healthcare

Big Iron
Emerging Markets and Virtualization Drive Q3 Server Sales

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
System i Developers and .NET 2.0, Part 2: Web Development Using ASP.NET AJAX

ON vs. ON

Admin Alert: Basic Tools for the System i Admin Tool Chest

System i PTF Guide
December 1, 2007: Volume 9, Number 47

November 24, 2007: Volume 9, Number 46

November 17, 2007: Volume 9, Number 45

November 10, 2007: Volume 9, Number 45

November 3, 2007: Volume 9, Number 44

October 27, 2007: Volume 9, Number 43

The Windows Observer
Windows Anti-Piracy Program Gets Stronger, Weaker with Vista SP1

Exchange Server 2007 SP1 Goes RTM

SAP-Microsoft Mega-Merger Rumor Surfaces, Then Dies

Be My Guest

The Unix Guardian
Sine Nomine Shows Off Solaris on System z

Q&A with Jim Herring: The View from the Top

Sun to Release xVM Virtualization Under GPL v3 License

Be My Guest

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Aldon
Bytware
Maximum Availability
Computer Keyes
WorksRight Software


Printer Friendly Version


TABLE OF CONTENTS
Database Tool Maker Joins the System i Market

State of the System i: Other Software Makers Weigh In

IDC Says Server Buyers Weigh Economy and Power in Q3

As I See It: What's Past Is Prologue

But Wait, There's More:

Robert Half Says IT Hiring to Be Solid in Q1 2008 . . . VAI Partners with Mid-Range for Canadian Sales . . . Quest Software Buys PassGo for Access and Identity Management . . . The Costs of Data Breaches Continues to Rise, Says Ponemon . . . MKS Swings to a Profit on Revenue Growth in Fiscal 2008 Second Quarter . . . Asia/Pacific Region Bolsters Disk Array Sales in Q3 . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement