2017数据泄露成本研究(英文版)_35页-2mb
报告摘要
2017 Cost of Data Breach Study Summary
Core Content
The 2017 Cost of Data Breach Study: Global Overview by IBM Security and Ponemon Institute analyzed data breaches across 419 organizations in 13 countries and two regions, revealing key trends and insights into the financial impact of data breaches.
Key Findings
- Average Total Cost: The average total cost of a data breach decreased from $4.00 million in 2016 to $3.62 million in 2017, a 10% decrease.
- Per Capita Cost: The average cost per lost or stolen record dropped from $158 to $141, a 2.9% decrease.
- Breach Size: Despite the overall cost reduction, the average size of data breaches increased by 1.8%, indicating more records were affected.
- Churn Rate: The abnormal churn rate (unexpected customer loss) remained unchanged, but organizations with strong incident response (IR) capabilities and customer trust programs saw reduced churn and breach costs.
- Regional Variations:
- The United States had the highest per capita cost at $225 and the highest total organizational cost at $7.35 million.
- Canada had the lowest per capita cost at $190 and the second-lowest total organizational cost.
- Brazil and India had the lowest total organizational costs at $1.52 million and $1.68 million, respectively.
- South Africa had the highest probability of experiencing a data breach in the next 24 months at 41%.
- Germany had the largest decrease in average total cost at -.91.
- Industry Differences:
- Healthcare had the highest cost per record at $380.
- Financial services had an average cost of $245 per record.
- Media, research, and public sector had the lowest costs at $119, $101, and $71, respectively.
Main Factors Influencing Costs
- Breach Size: Larger breaches result in higher costs. The average total cost ranged from $1.9 million for breaches with fewer than 10,000 records to $6.3 million for breaches with over 50,000 records.
- Time to Detect and Contain: Faster detection and containment reduce costs. The mean time to identify (MTTI) was 191 days, and the mean time to contain (MTTC) was 66 days.
- Malicious or criminal attacks took the longest to detect and contain (214 and 77 days).
- Human error resulted in faster detection and containment (168 and 54 days).
- Root Causes:
- Malicious or criminal attacks were the most common cause (47% of all breaches).
- System glitches and human error accounted for 34% and 35% of breaches, respectively.
- Malicious attacks had the highest cost per record at $156, compared to $128 for system glitches and $126 for human error.
- Cost Components:
- Direct costs: Forensic investigations, legal fees, notification, identity protection services, etc.
- Indirect costs: Employee time, communication, loss of goodwill, and customer churn.
- Cost Reduction Factors:
- Having an incident response (IR) team reduced the cost by $19 per record.
- Extensive encryption reduced costs by $16 per record.
- Appointment of a Chief Privacy Officer (CPO) reduced costs by $3 per record.
- Security analytics reduced costs by $7 per record.
- Cost Increase Factors:
- Third-party involvement increased the cost by $17 per record.
- Cloud migration increased the cost by $14 per record.
- Extensive use of mobile platforms and compliance failures increased the cost by $9 and $11 per record, respectively.
Trends and Implications
- Global Trends:
- The cost of data breaches decreased, but the size of breaches increased.
- United States and Middle East had the highest notification and post-breach response costs.
- India and Brazil had the lowest total organizational costs.
- Organizational Strategies:
- Investing in security technologies (e.g., encryption, security analytics) and governance programs (e.g., GRC, CPO appointment) significantly reduces breach costs.
- Customer trust initiatives and effective incident response teams help reduce churn and overall financial impact.
- Churn and Financial Impact:
- Organizations that lost less than 1% of their customer base had an average total cost of $2.6 million.
- Those that lost 4% or more had an average cost of $5.1 million.
- Japan, Italy, and France had the highest customer churn, while South Africa, Brazil, and ASEAN were better at retaining customers.
Frequently Asked Questions
- What is a data breach? A breach is defined as an event where personal information (e.g., names, medical, or financial records) is potentially exposed.
- What is a compromised record? A record is any information that identifies an individual, such as credit card details or medical records.
- How is data collected? Through 1,900 interviews with IT, compliance, and information security professionals over a 10-month period.
- How is the cost calculated? It includes both direct and indirect costs such as forensic investigations, legal fees, and customer churn.
- Benchmark vs. Survey Research: Benchmark research focuses on organizations, while survey research focuses on individuals.
- Can average cost be used for mega breaches? No, as the study excludes breaches with more than 100,000 compromised records.
Conclusion
The 2017 study highlights the importance of proactive security measures, incident response teams, and customer trust initiatives in reducing the financial impact of data breaches. While global costs decreased, the size of breaches increased, and regional and industry differences in breach costs and likelihood remain significant. The study also underscores the role of currency fluctuations, security complexity, and technological adoption in influencing breach costs.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载