Cost of data breach down 10% globally, says study
Robust response systems and processes can mitigate the financial loss from cyberattacks
Singapore
WITH cyberattacks becoming more sophisticated, the threat of a data breach has become the new normal for businesses. Over the past few years, security specialists have been saying that while it may not be possible to make a network foolproof, robust response systems and processes can mitigate the financial loss from cyberattacks.
Now, there is empirical evidence that this is indeed the case. The highly regarded Ponemon Institute and IBM Security have released the annual 2017 Cost of a Data Breach report which shows that globally, the total cost of a data breach fell 10 per cent to US$3.62 million from the 2016 figure (US$4 million). Globally, the average cost per lost or stolen record (or data) stood at US$141. In the Asean region, the average total cost of a data breach was S$3.18 million and 40 per cent of the data breaches involved malicious or criminal attacks. The average cost per incident in the region was S$156.
According to the report, one of the major reasons for the lower cost was better incident response planning.
Gene Ng, IBM Singapore's Asean security lead, told The Business Times that incident response planning has been identified as a significant cost saving measure in reducing the cost of a data breach.
"For the third year in a row in this study, having an incident response team in place was the top factor reducing the cost of a breach," Mr Ng said.
He added that companies with a comprehensive incident response plan will certainly be better prepared to handle breaches quickly and effectively. "Quickly identifying what has happened, what the attacker has had access to, and how to contain and remove this access are more important than ever."
Mr Ng noted that the study found that companies that do well in managing data breaches are those that have the following in place:
"On the flip side, the companies that do not do well are those that are complacent about data breach preparedness," he added.
In all, 20 companies from four Asean countries took part in the survey - Singapore (nine companies), Indonesia (five), the Philippines (four) and Malaysia (two).
In the region, companies whose data breaches were caused by malicious attacks had a per capita data breach cost of S$169, above the S$156 average. In contrast, companies whose data breaches were caused by system glitches (S$150) or employee negligence (S$145) had per capita costs below the mean.
The report noted that the cost of a data breach was nearly US$1 million lower on average for organisations that were able to contain a data breach in fewer than 30 days, compared to those that took longer than a month.
On average, organisations took more than six months to identify a breach, and more than 66 additional days to contain a breach once discovered. The involvement of third parties in a data breach was the top contributing factor that led to an increase in the cost of a data breach, raising the cost by US$17 per record.
Another significant data point in the report is that for the seventh year in a row, healthcare topped the list as the most expensive industry for data breaches. Healthcare data breaches cost organisations US$380 per record, more than 2.5 times the global average across industries (US$141 per record.)
The Ponemon Institute noted that for the third year in a row, the study found that having an incident response team in place significantly reduced the cost of a data breach, saving US$19.30.
Other factors that reduce cost are:
Mr Ng, however, noted that while the overall cost of a data breach might have declined, not all countries saw a decrease. "For instance, the US and many other countries in the Middle East, Japan, South Africa and India reported an increased cost.
"Only countries like Germany, France, UK, Italy, Australia and Brazil reported a decline," he added.
Successfully responding to a breach is all about speed and limiting the window of access and damage to your environment, Mr Ng noted. "The more quickly you can identify what has happened, what the attacker has access to, and how to contain and remove their access, the more successful you will be."
He added: "Be prepared to access the data needed to answer investigative questions. This means host and network-based logging and tools that will allow incident responders to answer questions quickly as to what happened - that is, what did the attackers access and what did they copy or remove from the environment."
Plan with IT staff in advance to understand how to be effective and efficient in a crisis, he added. And even before an attack happens, the staff must be primed to execute an enterprise-wide password reset quickly and to reset enterprise service accounts, Mr Ng said.