IBM-2021年数据泄露报告的成本(英)-73页_3mb
报告摘要
Cost of a Data Breach Report 2021 Summary
Core Content
The Cost of a Data Breach Report 2021 is a comprehensive analysis of data breach costs across 537 real breaches in 17 countries and 17 industries. It highlights the financial impact of data breaches, the factors contributing to their cost, and recommendations for mitigating these costs.
Key Findings
- Average Total Cost Increase: The average total cost of a data breach increased by 10% from $3.86 million (2020) to $4.24 million (2021), the largest single-year increase in the last seven years.
- Remote Work Impact: Breaches involving remote work cost $1.07 million more on average than those without. Organizations with over 50% of their workforce working remotely took 58 days longer to detect and contain breaches.
- Healthcare Industry: Healthcare had the highest average breach cost for 11 consecutive years, rising from $7.13 million (2020) to $9.23 million (2021), a 29.5% increase.
- Lost Business Share: Lost business accounted for 38% of the total breach cost, with an average of $1.59 million.
- Per Record Cost: The average cost per record was $161 in 2021, up from $146 in 2020, and $180 for customer PII, the costliest record type.
- Initial Attack Vectors:
- Compromised credentials were the most common initial attack vector, responsible for 20% of breaches.
- Phishing was the second most costly, with an average cost of $4.65 million.
- Business email compromise (BEC), though responsible for only 4% of breaches, had the highest average cost at $5.01 million.
- Breach Lifecycle: The average time to identify and contain a breach was 287 days, an increase of 7 days from the previous year. Breaches taking over 200 days to contain cost $4.87 million on average.
- Zero Trust Impact: Organizations with a mature zero trust approach had an average breach cost of $3.28 million, $1.76 million less than those without, representing a 2.3% difference.
- Security AI & Automation: Full deployment of security AI and automation reduced breach costs by $3.81 million on average, or 80%, compared to organizations without these technologies.
- Hybrid Cloud Breaches: Hybrid cloud breaches had the lowest average cost at $3.61 million, $1.19 million less than public cloud breaches.
- Mega Breaches: Breaches involving 50 million to 65 million records cost $401 million, 100 times more than breaches involving 1,000-100,000 records.
- Compliance Failures: High levels of compliance failures were associated with $2.30 million higher breach costs.
Cost Factors
- Detection and Escalation: Average cost was $1.24 million, or 29% of total breach cost.
- Notification: Average cost was $1.12 million, or 26% of total breach cost.
- Post-Breach Response: Average cost was $1.02 million, or 24% of total breach cost.
- Lost Business: Average cost was $1.59 million, or 38% of total breach cost.
Regional and Industry Insights
- Top Countries by Average Cost: U.S., Middle East, Canada, Germany, and Japan.
- Top Industries by Average Cost: Healthcare, Financial, Pharmaceuticals, Technology, and Energy.
- Country Cost Increases: Latin America (52.4%), South Africa (50%), Australia (30.2%), Canada (20%), UK (19.7%), and France (14%).
- Only Brazil saw a cost decrease, with a 3.6% reduction.
Recommendations
- Implement Zero Trust Architecture: To reduce breach costs by up to $1.76 million.
- Adopt Security AI and Automation: To reduce breach costs by $3.81 million on average.
- Improve Detection and Containment Processes: The longer it takes to detect and contain a breach, the higher the cost.
- Focus on Compliance and System Complexity: High compliance failures and system complexity significantly increase breach costs.
Research Methodology
- The report is based on nearly 3,500 interviews with organizations that experienced data breaches between May 2020 and March 2021.
- Activity-based costing was used to calculate the cost of breaches, focusing on four key cost centers: detection and escalation, notification, post-breach response, and lost business.
- The study excluded very small and very large breaches, focusing on those with 2,000 to 101,000 compromised records.
- Mega breaches (over 100,000 records) were analyzed separately.
Organizations Studied
- The study included organizations from 17 countries and regions and 17 industries.
- 65% of organizations had fully or partially deployed security AI and automation, up from 59% in 2020.
- 17.5% of breaches involved remote work as a contributing factor.
Take the Next Steps
- Review the complete findings and charts for deeper insights.
- Explore the risk quantification section to understand how to assess and manage data breach risks.
- Access the security recommendations to implement cost-effective measures.
- Learn about the research methodology and limitations of the study.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载