Cyber Security Insurance

Casurance.com a Farmers Insurance Agency Provides New Cyber Liability and Data Breach Coverage Program for Main Street Businesses.



The biggest threat to your company's most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions.


Malicious or criminal attacks are the most expensive cause of data breaches and are on the rise. In 2011, 37 percent of data breach cases involved malicious attacks and averaged $222 per record. Negligence accounted for 39 percent of reported breaches.



Historically speaking, these 2011 data breaches rate among the biggest or most significant data-loss incidents to date.

A new report from the Privacy Rights Clearinghouse (PRC) notes 535 breaches during 2011, involving 30.4 million sensitive records. But that's just a conservative estimate, since not all data breaches see the light of day. "Because many states do not require companies to report data breaches to a central clearinghouse, data breaches occur that we never hear about," said PRC director Beth Givens in the report.

[ From Sony to Nasdaq, read about some of the most significant corporate data breaches in 2011. See 6 Worst Data Breaches Of 2011. ]

But in an era in which the number of breaches--and often their severity--seems to be increasing, the overall decrease in customer churn resulting from breaches suggests that the average consumer may be facing data breach notification burnout. "Maybe people are numb to data breaches," said Ponemon. "There are still many people who care deeply about it, but maybe there are more people worried about the economy, their job security, or the state of gas prices."

The study also found that the number of data breaches that were caused by malicious attacks increased from 31% in 2010 to 37% in 2011. The leading cause (in 50% of cases) was malware, followed by malicious insiders (33%), device theft (28%), SQL injection (28%), and phishing attacks (22%). Interestingly, 17% of all data breaches also involved social engineering attacks. "We think about the evil hacker, which is pretty serious stuff, but in our study, we find that it's really the malicious insider--someone who's nefarious or angry at the organization--that presents the real danger to the company," said Ponemon.

Beyond malicious attacks, meanwhile, 39% of data breaches in 2011 were caused by negligent insiders, and 24% by system glitches.

Another factor behind the decreased cost of data breaches is that businesses' detection costs decreased by 6% from 2010, to an average of $428,330 per incident in 2011. "We think that companies are more efficient in investigating the data breach and organizing themselves around their incident response plan," said Ponemon. In the same time period, however, notification costs did increase by 10%, to $561,495 per incident, which he ascribed to businesses wanting to ensure that they remained compliant with states' more stringent notification rules.

The report found that there are a number of ways that organizations can better control their data breach costs. Notably, companies that have a CISO who is responsible for data protection and outside consultants to assist with the response saw reduced costs, in large part because these companies had the right policies and procedures in place, including a data breach response plan. "It helps the organization manage their team and not do extraneous things, like having two or three different parts of the organization hiring different forensic teams to conduct the investigation," said Ponemon.

But breach costs went up when the data was exposed by a third party or a lost or stolen device. This increase is due to the difficulty of conducting a forensic examination, especially for businesses that failed to keep up-to-date backups.

Another cost hit came from organizations that responded rapidly to breaches and quickly notified affected customers. "A lot of companies, believe it or not, over-report their data breach because they just want to get rid of it," said Ponemon. But in numerous cases, he said, businesses ended up over-reporting the scope of their breach--sometimes by a factor of five or 10. The lesson: sometimes it's prudent to let breach investigators finish their job before alerting customers.

The biggest threat to your company's most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions.