On the eve of World Privacy Day (Jan. 28), findings from Cisco's 2020 data privacy study show that privacy is, in fact, a very good investment.
Where companies used to prioritize things like function and scalability over data privacy and security, consumer backlash to privacy leaks in recent years has elicited a global response for new legislation. Regulatory data privacy laws like the EU’s General Data Protection Regulation (GDPR) paved the way for countries from China to Brazil and even individual states — like California and its new California Consumer Privacy Act (CCPA) — to follow suit. In fact, U.S. legislators are also considering an updated federal privacy law.
For the report, Cisco researchers spoke with 2,800 security professionals in 13 countries about privacy and data security practices within their organization. A key finding quantified the return on investment (ROI) on privacy, which averaged a 270% ROI.
Organizations with an increased focus on privacy saw shorter sales delays, better security, and fewer data breaches. And more than 40% of the companies surveyed saw at least double the return on their privacy investment.
“I think companies are beginning to recognize that this privacy thing is important, not just as a compliance issue or a boardroom issue, but because it matters to the customers, building loyalty and trust in the company,” explained Robert Waitman, Cisco's director of privacy insights and innovation, in an interview with SDxCentral.
Privacy Pays Profits70% organizations said they found significant business benefits from privacy, and 74% of respondents believed that going above and beyond privacy regulation compliance helped them build loyalty and trust with their customers.
“This is about doing the right thing so that your customers believe that you're taking good care of their data, and want you to continue to do that,” Waitman said. “Because, again, at the end of the day, privacy is about protecting people. And those people are your customers.”
The survey reported 82% of companies had a breach in the past year.
Companies with higher accountability scores — as assessed using the Centre for Information Policy Leadership's Accountability Wheel, which is a framework for managing and assessing organizational maturity — experienced shorter sales delays and higher financial returns.
In fact, of the companies with advanced privacy efforts, 28% went breach-free compared to the 13% of those with minimal privacy efforts. The more advanced organizations had 90% less downtime from records exfiltrated, which translates to cost.
Get Your Data House in OrderData privacy and security converge in what Waitman called the "data house," and he used the analogy of preparing for a home invasion. He explained how you might prepare for a home invasion if you knew someone was going to break into your house sometime this year — even with no knowledge of when or where the break in would occur.
“You would probably take the most sensitive assets that you have, your most valuable things, and you would do something further to either protect them, encrypt them, store them somewhere else,” Waitman said. “You might make them even harder to get access, because at some point an intruder is going to come in.”
Legislative processes such as GDPR have pressured businesses to get their data houses in order — protecting valuable assets and throwing out old ones to minimize the loss that might occur when and if that break in does happen.
Although some businesses might see privacy regulations as another hurdle to clear, Cicso's findings position legislative processes as a worthy ally in driving net benefits for businesses. Furthermore, the findings also reaffirm Cisco's 2019 privacy report, which found GDPR-ready firms had fewer data breaches.
While the study proves the positive benefits of regulation, Waitman stressed the need to proceed with caution. He said Cisco supports federal legislation that would allow companies to pursue one standard to establish consistency across all 50 states.
"I think the idea of having a federal legislation would be to avoid 50 different state regulations, but not to change, or perhaps hamper some of the valuable protections that are in place for some of the industries today," Waitman said.
Comments