Sunday, January 31, 2010

Data Breaches Are More Expensive And Serious Than Ever

The Ponemon Institute has released its annual study of data breaches at US companies entitled the “U.S. Cost of a Data Breach". According to the study, the average cost of a data breach increased almost 2 percent, from $6.65 million per organization in 2008 to $6.75 million in 2009.

Other key findings in the study:
  • Organized crime is now going after corporate data.
  • Data breaches are now being caused by malware.
  • Increased use of mobile devices is leading to increasing data security issues.
  • Third-party mistakes with outsourced data were involved in 42% of the breaches.

So, what should you be thinking about in your business to prevent data breaches?

  • Make sure that all of your computers have anti-virus and anti-malware software installed and keep this software updated regularly with the latest virus/malware definitions.
  • Make sure all of your laptops have encrypted hard drives.
  • Create a policy about how you want your employees to handle sensitive company information and then train them on the policy. Do not allow sensitive information to be stored on mobile devices or on unencrypted laptops.
  • Do not use email or ftp to share sensitive data. Use a secure file sharing system instead.
  • Be very careful about outsourcing your sensitive data storage to third-party providers. Use reputable firms offering iron-clad service level agreements or store the data in-house under your complete control.

As always, feel free to contact me if you have any questions.