in

This Blog

Syndication

Tags

AlertBoot Endpoint Security

Cost Of Data Security Breaches? How High Can It Go?

One of the reasons why people do not sign up for data security programs like drive encryption software from AlertBoot cites cost as an issue.  They claim that their IT budget is fixed.  That encryption does not produce revenue.  That they don't need encryption because they didn't lose any records last year (highly doubtful).

An analysis, however, may open some eyes, as well as raise some brows.

Let's Do An Analysis: How Much Of A Loss Are You Facing?

  • 2007 - $197 per customer record compromised
  • 2006 - $182
  • 2005 - $138

The figures come from The Ponemon Institute's annual surveys.  The dollar figures you see above are totals, including costs for notifications, lost employee productivity, cost of lost business from angered customers, legal fees, etc.  As far as I can tell, it doesn't include legal settlements or penalties.

So, depending on how many customers you have, you can expect an impact of about $197 x (number of customers in your database).  The more customers you have, the higher the chances of approaching, and going beyond, this figure.

For example, if I lost the information for 10 customers, chances are the cost will be much less than $1970 since I don't need to set up a call center to deal with inquiries.

Other Factors - Civil Penalties

However, there is something in 2009 that companies have to take into consideration that they didn't back in 2007 or 2008.  Massachusetts passed a new law that, beginning from May 2009, will start assessing civil penalties for data breaches involving unencrypted data.  And if history is any guide, it means other states will start exploring civil penalties as well (these things just tend to spread once one state has taken the initiative).

Supposedly, the fine will be up to $5000 per violation (not sure whether "per violation" means per person involved or per law that is broken--everyone seems to have a different interpretation, and I can't contribute since I'm not a lawyer).

Can you imagine, though?  Up to $5000 per customer record compromised?  Even if the state decides to fine you 1/10th of the amount, that'll add more than double to your cost of data security breach, since it's separate from the other costs!

HDD encryption software is beginning to look cheap, I'd say.

In fact, when you consider that a company probably has more customers than computers, the odds are it makes sense to really begin looking into encryption products to secure sensitive data.

Related Articles:
http://www.informationweek.com/news/security/showArticle.jhtml?articleID=199000222
http://www.pgp.com/insight/newsroom/press_releases/2007/ponemon-us.html
http://www.computerworld.com/pdfs/PGP_Annual_Study_PDF.pdf
http://www.cio.com/article/print/466817

 
<Previous Next>

Drive Encryption Software Missing: UO Laptop for Youth Transition Program

Massachusetts Encryption Law: It's Not Just About Encryption

Comments

AlertBoot Endpoint Security said:

The US Department of Veteran Affairs has decided to settle a class-action suite that was filed in response

January 31, 2009 4:38 PM
 

About sang_lee

Sang Lee is a Senior Account Manager and Security Analyst with AlertBoot, Inc., the leading provider of managed endpoint security services, based in Las Vegas, NV. Mr. Lee helps with the deployment and ongoing support of the AlertBoot disk encryption managed service. Prior to working at AlertBoot, Mr. Lee served in the South Korean Navy. He holds both a B.S. and an M.S. from Tufts University in Medford, Massachusetts, U.S.A.