Across the board, 2020 has been a year marred by economic, social, political, and environmental decline – but sadly, the same can’t be said for the average total cost of a data breach, according to the latest IBM data breach report.
The 2020 Cost of a Data Breach Report from IBM Security and Ponemon Institute interviewed more than 3,200 security professionals from 524 organizations that suffered a data breach between August 2019 and April 2020 to better understand the financial consequences of a data breach and how companies can reduce the impact.
Despite a 1.5% decline from $3.92 million in the 2019 data breach report to $3.86 million in the 2020 study, costs actually increased for many organizations. Charles DeBeck, senior cyber threat intelligence strategic analyst with IBM X-Force Incident Response and Intelligence Services (IRIS), called this “more of a stratification” than an overall decline.
Mature enterprises with fully developed security technologies that included automation lost about $2.45 million in a breach, while those who did not doubled their losses beyond $6 million.
Increased disparity between organizations that are well prepared with strong security steps and organizations that were less prepared and hadn't taken significant security steps ultimately led to a “relatively flat rate,” he explained. “That sort of disparity, to me, suggests that cybersecurity is valuable. By using security automation within an organization, we're finding that organizations are better able to protect themselves against not only threats of today but also the threats of tomorrow by speeding the time up by which they can respond to instant events.”
To that end, organizations are better able to protect themselves in real time rather than being more reactive.
Securing Employee VulnerabilitiesData breaches that originated from a malicious cyber attack were responsible for 52% of breaches in the 2020 study, which is a slight increase from 51% in 2019. The IBM data breach report found these to be the most expensive, averaging $4.77 million.
Perhaps the most alarming discovery to emerge from the study: one in five malicious attacks (19%) resulted from stolen or compromised credentials. IBM found 80% of breached organizations said customers’ personally identifiable information (PII) was the most frequently compromised type of record.
According to findings from the report, a lost or stolen record containing a customer’s PII was also the most expensive across all data breaches, costing businesses $150 per compromised record. That price increased to $175 in breaches caused by a malicious attack.
With no end in sight to remote work, companies will require continued access sensitive data via cloud-based business operations. Findings from IBM's data beach report indicate that organizations with a remote workforce saw an increased average total cost of a data breach of $3.86 million by nearly $137,000 for an adjusted average total cost of $4 million.
“Any organization that doesn't have multi factor authentication enabled needs to have multi-factor authentication enabled,” DeBeck said. “It's one of the easiest, most cost efficient ways to protect your organization.
Cost ComplexityThe pandemic has complicated a number of different things in a number of different ways, and “security is just one of the many facets that have been touched by the pandemic,” he said.
Along with lost and stolen credentials, the report found that misconfigured cloud servers tied for the most frequent initial threat vector in breaches caused by malicious attacks. Breaches involving cloud misconfigurations led to the average cost of a breach increasing by more than half a million dollars to $4.41 million.
When it comes to data breaches, time is money. Although security automation was found to significantly reduce the average time and cost to identify and respond to a breach, companies with incident response (IR) teams that extensively test their incident response plans spend an average of $3.29 million, compared to $5.29 million for companies with neither an IR team nor tests of the IR plan. That’s a difference of $2 million, which increased from $1.23 million in the 2019 study.
According to the report, from a list of 25 cost factors, complexity of security systems was the number one factor contributing to higher average data breach costs. Figuring out how to effectively detect and respond from a disparate environment is going to be very important for organizations moving forward, DeBeck explained.
“Organizations are going to have to start thinking about how they can best protect themselves when they don't necessarily have complete control over the network with multiple endpoints coming in from different geographies, and how they can sort of capture all the data to detect and respond to incidents quickly,” he added. “Because again, detection and response time are ultimately correlative to overall cost.”
Comments