The costs of data breaches is on the rise across the world, but in the U.S. companies have managed to continue bringing breach costs down, according to the eighth annual Cost of Data Breach Study.

The research found mistakes and human errors accounted for the bulk of all breaches, but malicious or criminal attacks cost businesses more when they are at the root of breaches, according to the report by the Ponemon Institute on behalf of Symantec.

RELATED STORIES
Speeding Up System Forensics
Espionage Campaign Uncovered
Utility Blackouts as a Weapon
Synching Up a Reliable Power Grid

Examining breach experiences from 277 organizations in nine countries, the study found the average global cost of data breaches reached $136 per compromised record, while in the U.S. the cost was $188 per compromised record.

“It’s still not chump change, but it definitely seems to be trending down in the U.S. with two years of downward movement,” said Dr. Larry Ponemon, chairman and founder of the Ponemon Institute.

Schneider Bold

The downward pressure could likely be attributable to more mature breach prevention and response practices. According to the study, the factors most likely to push breach costs down were instituting incident response plans, establishing a strong security posture, and appointing a CISO. Meanwhile, factors most likely to raise costs included third-party error, rushed breach notification, and lost or stolen devices.

Delving into the root causes of breaches studied in this report, Ponemon found 64 percent of breaches were the result of negligence or system failures, while 37 percent were the result of malicious insiders or criminal hackers. Ponemon said this should be a wake-up call.

“Everyone wants to hear about cyber attacks, and everyone wants to hear about cyber attacks and exfiltration of data by the Chinese or the proverbial bad guy, and those things are happening, but in our data, since the beginning of time the majority of cases are involving people problems or system failures,” he said. “Both are the result of negligence in a way.”

The catch is, malicious insider or criminal attacks cost more compared to human error and system woes.

An attack costs $157 per breached record compared to the $122 per record for breaches caused by system glitches and $117 for those caused by human error. Ponemon and Symantec feel the study results generally point to a greater need to address malicious and negligent insider threats within the enterprise.

“Our conversations with customers and our research does point to the insider threat continuing to be the bigger cause behind data loss and data breach events,” said Linda Park, product marketing manager for Symantec. “While there is an uptick in the malicious attacks, companies really are still focused on insider threats overall and making sure that employees are trained, aware, and that they have the right enforcement in place to make sure people are doing the right things.”

Click here to download the entire eighth annual “Cost of Data Breach Study.”

ISSSource

Pin It on Pinterest

Share This