The Costs Of A Data Breach

The cost of a data breach is not only the monetary value of an incident, but also the implications regarding loss of respect, negative PR and commercial credibility loss of the business. 
 
A severe data breach can be hugely detrimental to a company, particularly where stakeholders are concerned. The statistic, per IBM and the Ponemon Institute's annual Cost of a Data Breach report aggregates costs reported by 507 organisations, from 17 industries, from 16 regions worlwide.
 
Through interviews with 3,211 individuals, IBM and Ponemon collected data points regarding the number of customer records lost or stolen in breaches, how the company responded to the breach, and how their business fared after the breach. 
 
After analysing data breaches that happened across the world between April 2018 and April 2019, researchers at IBM reported that the average, total cost of a data breach to a business is a phenomenal $3.92 million.  They also found that companies in the US had the highest average cost of all countries, at around $8.19 million. 
 
To reach these figures, the researchers considered the monetary losses that were incurred in the four areas involved in a data breach:
 
  • Detection and escalation – this refers to any costs resulting from detecting and reporting a cybersecurity incident, such as auditing and investigation.
  • Notification – this aspect includes the financial cost of having to notify people of the incident, such as time spent making calls or writing letters to customers.
  • Response – this relates to the costs involved with the company’s response to the breach. This could be anything from legal advice to free gifts and discounts for customers.
  • Business losses – when a breach occurs, it will usually cause disruption and even downtime to a business. This area relates to the loss of revenue experienced as a result.
The Cost of Losing Credibility 
 
Even if  a business survives the financial difficulties that are associated with a data breach,there are further problems to contend with. A major cyber security incident, this can often deter new and even existing customers, who feel that their personal information is not in safe hands with your company. 
 
For small businesses in particular, this damaged reputation can be extremely hard, or even impossible to recover from.
 
Rebuilding a business reputation is vital in order to attract new customers, and keep existing clients on the books. After a breach, these stakeholders need to know that the business has taken the incident seriously, and is doing as much as possible to guarantee the protection of sensitive information going forwards.
 
Damaged  Stakeholder Relationships
 
As customers lose faith in a business after a data breach, so may other stakeholders, including investors and employees. The cost of these damaged relationships can also be profound, as these individuals, who are imperative to the business’ existence, may seek to part ways. 
 
A data breach can lead to discontent or even the departure of key employees, particularly if it was their personal information that was leaked. 
 
Such an incident will certainly lead to doubt and anxiety, causing employees to be distrustful of the employer. The publicity of such a data leak is also likely to put off potential new recruits in the future.
 
Where investors are concerned, many are likely to lose faith in the company simply because a breach has been allowed to happen. This is because a data breach demonstrates that the business is vulnerable, and ill-prepared for cyber-attacks.
 
The Real Cost Of A Data Breach
 
Taking into account the financial, credibility, and relationship implications of a data breach, it’s clear that the cost of this kind of incident can be severely damaging. For SMEs in particular, that may have a small budget and therefore less of a defence against cyber-crime, the costs can even lead to bankruptcy. Sadly, cyber criminals are all too aware of this, and are often known to target smaller businesses.
 
The true cost of a data breach will entirely depend on the nature of the attack, and the damage it has caused. Cyber criminals want different thing and while the overall goal is usually financial, this cost may not always be crippling. Many companies find that the damage a breach causes to their reputation is actually more detrimental than the immediate monetary costs involved.
 
The best defence against a data breach is to put in place adequate shields against cyber-crime, before one happens. This should include the use of quality security software, data encryption, and educating your staff about staying protected online.
 
IBM:        CPO Magazine:        Data Insider:   
 
You Might Also Read:
 
Cyber Attacks Knock 7.2% Off The Average Company Share Price:
 
« Women In Cyber Security Are Paid Much Less Than Men
#BLM Targeted By Racist Cyber Attacks »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

BakerHostetler

BakerHostetler

BakerHostetler is one of the largest law firms in the USA We have five core practice groups including a specialty practice team in Privacy and Data Protection.

Black Duck Software

Black Duck Software

Black Duck Hub allows organizations to manage open source code security as well as license compliance risks.

Korea Internet & Security Agency (KISA)

Korea Internet & Security Agency (KISA)

KISA is committed to improving the competitiveness, reliability and security of Internet information and knowledge in Korea.

AFCON Control & Automation

AFCON Control & Automation

AFCON is a leading global provider of software solutions and services for the smart management of Control & Automation systems in the age of Digital Transformation.

DeuZert

DeuZert

DeuZert is an accredited German certification body in accordance with ISO/IEC 27001 (Information Security Management).

OCM Business Systems

OCM Business Systems

OCM are experts in the safe, secure and responsible disposal of IT & EPoS assets.

Privacyware

Privacyware

Privacyware's ThreatSentry combines a state-of-the-art Web Application Firewall and port-level firewall with advanced behavioral filtering to block unwanted IIS traffic and web application threats.

Meditology

Meditology

Meditology Services is a top-ranked provider of information risk management, cybersecurity, privacy, and regulatory compliance consulting services exclusively for healthcare organizations.

QuoIntelligence

QuoIntelligence

QuoIntelligence experts can help your team understand the evolving cyber threats and provide simple yet comprehensive recommendations so you can focus on what matters.

Cyberfort Group

Cyberfort Group

Cyberfort exists to provide our clients with the peace-of-mind about the security of their data and the compliance of their business.

Spinnaker Support

Spinnaker Support

Spinnaker Support is a premier global provider of on-premise and cloud-based enterprise software support services.

Sidcon International Consulting Company

Sidcon International Consulting Company

SIDCON International Consulting Company has been providing consulting services since 2002 for private and public organizations in Ukraine and other countries.

Blue Cloud Softech Solutions

Blue Cloud Softech Solutions

Blue Cloud Softech propels inspiring digital transformations. We provide AI products, cybersecurity, healthcare technology, and cloud solutions.

Invisily

Invisily

Invisily makes enterprise and cloud computing resources invisible to attackers with zero trust solutions, making them visible only when needed to only those who need them.

IntelliBridge

IntelliBridge

IntelliBridge supports our nation’s most critical missions by solving complex technology, intelligence, and mission support challenges.

CeTu

CeTu

CeTu - Data Orchestration for the Modern SOC. Strengthen security and optimize costs with the world's first AI-native platform for scaling and future-proofing your data stack.