In 2023, everything seems to cost more. Even, as it turns out, data breaches.
The 2023 IBM Cost of a Data Breach report was released yesterday, revealing that the average cost of a data breach has now reached an all-time high of $4.45 million. While costs of dealing with a breach are rising, the report found that only 51% of breached organizations are planning on increasing their security budgets to help reduce risk. The cloud is a big target with 39% of data breaches spanning multiple clouds and resulting in a higher average cost at $4.75 million. Overall the most expensive data breaches occur in health care with an average cost of $10.93 million.
The report also highlighted the fact that time is literally money when it comes to breach detection. Organizations incur a cost of $3.93 million for breaches with identification and containment times below 200 days. Breaches surpassing the 200-day threshold result in higher costs, reaching $4.95 million. One of the best ways to reduce the time to detection is with artificial intelligence (AI), according to IBM. The breach lifecycle for organizations that used AI automation lasted 214 days, whereas those that did not use AI automation endured a longer period of 322 days.
"There were a lot of new findings this year we found really interesting. And while many of the results reinforced what our team expected to see, a few of the findings might be more surprising to some than others," John Dwyer, head of research for IBM X-Force, told SDxCentral.
Don't just call your IT department, call the cops when you have a data breachAmong the surprising findings for Dwyer is the impact of involving law enforcement.
Dwyer noted that the report found that involving law enforcement actually saved ransomware victims $470K in breach costs. Additionally, involving law enforcement in a breach investigation helped shave more than 30 days off the overall breach timeline on average.
"We’re hopeful that this finding can help dispel the misperception held by some that involving law enforcement might make breach response more costly or complicated," he said. "Currently, almost 40% of ransomware victims in the report chose not to involve them, so there’s a lot of room for growth there. "
Data breaches aren't generally detected by an organization's own teamsAnother surprising detail from the report is that only one third of studied breaches were detected by an organization's own security team.
"When it comes to organizations that detected the breach themselves, we’d definitely like to see that number grow," Dwyer said.
However, he noted that it's also important to realize that the biggest portion of breaches were disclosed by a neutral third party, such as law enforcement, a security researcher or a business partner. Dwyer said that those organizations have a different vantage point from which they may have been better equipped to identify the attack; for example, 15% of the breaches studied actually originated with a business partner. That said the 27% of breaches that were disclosed by the attacker themselves were the most costly and difficult to contain, and the report findings show clearly that investments in the right security strategies and technologies have a big impact on detecting incidents sooner and reducing their costs.
"There is certainly a lot of room for improvement in terms of detection and response, but the good news is that there is a very practical approach organizations can take to increase their chances of detecting a breach or, even better, preventing one," Dwyer said.
While the threat landscape continues to increase in terms of number of attacks, Dwyer commented that the main goals and objectives of the attacker have not changed all that much.
"If organizations implement a detection and response strategy that is directly related to the goals and objectives of the attacker, they can significantly reduce the risk of a costly data breach," Dwyer said. "I believe it’s one of the reasons why we see in the report that working with an incident response team and testing an incident response plan is one of the top ways to reduce the cost of the breach."
Use the DevSecOps advantage to reduce data breach costsTaking a DevSecOps (development/security/operations) approach can lead to a reduction in the cost of a data breach, amounting to nearly $1.7 million less than those organizations that either had a low level or did not utilize the DevSecOps approach.
Dwyer explained that at its core DevSecOps is a development practice that ensures secure development practices are baked into the entire software development lifecycle (SDLC). Historically, security has been a bolt-on feature at the end of the process, which often results in costly vulnerabilities and delays into the SDLC. By incorporating security throughout, security becomes a stakeholder in the development process. This ensures that security does not inhibit efficient software development, and also that developers implement core security principles into their software, resulting in efficient and effective software development without compromising security.
"DevSecOps ensures that fundamental security concepts such as least privileged are incorporated into the entire enterprise, limiting the potential blast radius so that if a security incident occurs, the attacker is limited in their ability to access data across various systems, reducing the overall cost," Dwyer said.
No surprise, the future is about more AILooking forward, Dwyer expects to see more impact from AI in the future to help reduce the cost of data breaches.
AI is already one of the biggest cost and time saving factors in the report — shaving nearly $1.8 million off breach costs between high adopters and those who aren’t yet using it, and also cutting more than 100 days from the breach timeline. However, right now only 28% of organizations are reporting a high level of usage of these technologies, and IBM predicts that this will be an area of significant growth in the coming year.
"We’re reaching a tipping point in the adoption of AI for security, where many of the early use cases for AI in security operations are reaching a stronger state of maturity and a level of trust where automation can be applied with greater confidence," Dwyer said.
Comments