A study released Wednesday shows the cost of a data breach is becoming increasingly expensive for firms—not so much because of the technological steps needed to fix the problem—but because the increasingly savvy public bails on the victim of the breach and takes their business with them.
The study was conducted by privacy and information management research firm Ponemon Institute along with Vontu, the data loss prevention software developer recently acquired by Symantec, and PGP, makers of the Pretty Good Privacy security software.
The study found that data breach incidents cost companies $197 per compromised customer record in 2007, compared to $182 in 2006. For a financial services firm, the cost was even more expensive at $239 per lost record. Most of the cost, $128 out of the $197, is from lost business and having to acquire new customers.
This data, according to the study and some security experts, is starting to affect how companies operate.
“A few years ago, you wouldn’t have a marketing officer concerned with a data breach. That was an IT problem. Nowadays all the execs around a boardroom table are concerned about it,” John Dasher, director of product management for PGP told InternetNews.com. “If I’m a marketing officer, the last thing I want to do is spend marketing money doing brand damage repair because of a breach.”
The report, called “The 2007 Annual Study: Cost of a Data Breach,” comes from a detailed analysis of 35 data breach incidents involving fewer than 4,000 records to more than 125,000 records.
The TJX breach, initially believed to be a small deal, has grown enormously expensive for the retailer. TJX in August announced it would take a $118 million charge related to the costs and potential liability resulting from the theft of more than 45 million credit and debit accounts. “This is one of the first widely publicized examples of how a data breach can affect you, your shareholders, and your stock price,” said Dasher.
But Peter Firstbrook, security research analyst for Gartner, disputes this scale of impact. “How do they know how much revenue would have accrued before the breach? Our research shows that most consumers do not actually change business after a breach. Check out TJMax’s sales before and after their incident,” he said in an e-mail to InternetNews.com.
Firstbrook appears to make a valid point. TJX may have gotten a black eye but sales rose 8 percent in the third quarter of 2007 compared to the same quarter last year, and the company plans to add more than 1,000 new stores in the next few years.
The report also claims that the average total per-incident costs in 2007 were $6.3 million, a 31 percent increase from the 2006 average per-incident cost of $4.8 million. On the bright side, if there is such a thing, the cost of notification fell 40 percent because firms got better at notifying their customers when a breach occurred.
One of the biggest vulnerabilities is found when data is stored, disseminated and shared with third parties. Outsourcers, contractors, consultants and business partners accounted for 40 percent of breaches, up from 29 percent in 2006. External breaches also cost more, averaging $231 compared to $171 per record.
The Real Point Of Vulnerability?
While outsourcing and third parties are a weakness, the notion of the nefarious hacker sniffing traffic coming into Amazon and Overstock may be overblown. Instead, it’s brick-and-mortar retail outlets like TJX stores that are the weak link.
This past Sunday, the TV news magazine 60 Minutes showed how many retail outlets don’t secure the wireless networks of their stores. Sitting in a car with some computer experts with a laptop, correspondent Leslie Stahl showed how easy it was to pick up on wireless transmissions in the stores.
“It makes sense because companies like Amazon that are born and bred of technology have a good security model from the beginning,” said Dasher. “A lot of brick-and-mortar companies don’t have this. They have conflicting setups. Some of them are still using a DOS-based point-of-sale system.”
This article was first published on InternetNews.com. To read the full article, click here.
Huawei’s AI Update: Things Are Moving Faster Than We Think
FEATURE | By Rob Enderle,
December 04, 2020
Keeping Machine Learning Algorithms Honest in the ‘Ethics-First’ Era
ARTIFICIAL INTELLIGENCE | By Guest Author,
November 18, 2020
Key Trends in Chatbots and RPA
FEATURE | By Guest Author,
November 10, 2020
FEATURE | By Samuel Greengard,
November 05, 2020
ARTIFICIAL INTELLIGENCE | By Guest Author,
November 02, 2020
How Intel’s Work With Autonomous Cars Could Redefine General Purpose AI
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
October 29, 2020
Dell Technologies World: Weaving Together Human And Machine Interaction For AI And Robotics
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
October 23, 2020
The Super Moderator, or How IBM Project Debater Could Save Social Media
FEATURE | By Rob Enderle,
October 16, 2020
FEATURE | By Cynthia Harvey,
October 07, 2020
ARTIFICIAL INTELLIGENCE | By Guest Author,
October 05, 2020
CIOs Discuss the Promise of AI and Data Science
FEATURE | By Guest Author,
September 25, 2020
Microsoft Is Building An AI Product That Could Predict The Future
FEATURE | By Rob Enderle,
September 25, 2020
Top 10 Machine Learning Companies 2020
FEATURE | By Cynthia Harvey,
September 22, 2020
NVIDIA and ARM: Massively Changing The AI Landscape
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
September 18, 2020
Continuous Intelligence: Expert Discussion [Video and Podcast]
ARTIFICIAL INTELLIGENCE | By James Maguire,
September 14, 2020
Artificial Intelligence: Governance and Ethics [Video]
ARTIFICIAL INTELLIGENCE | By James Maguire,
September 13, 2020
IBM Watson At The US Open: Showcasing The Power Of A Mature Enterprise-Class AI
FEATURE | By Rob Enderle,
September 11, 2020
Artificial Intelligence: Perception vs. Reality
FEATURE | By James Maguire,
September 09, 2020
Anticipating The Coming Wave Of AI Enhanced PCs
FEATURE | By Rob Enderle,
September 05, 2020
The Critical Nature Of IBM’s NLP (Natural Language Processing) Effort
ARTIFICIAL INTELLIGENCE | By Rob Enderle,
August 14, 2020
Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.
Advertise with TechnologyAdvice on Datamation and our other data and technology-focused platforms.
Advertise with Us
Property of TechnologyAdvice.
© 2025 TechnologyAdvice. All Rights Reserved
Advertiser Disclosure: Some of the products that appear on this
site are from companies from which TechnologyAdvice receives
compensation. This compensation may impact how and where products
appear on this site including, for example, the order in which
they appear. TechnologyAdvice does not include all companies
or all types of products available in the marketplace.