Related Links

  • PGP Corporation
  • Elsevier Ltd is not responsible for the content of external websites.

Related Stories

  • Data breaches: Who has been named and shamed in the last year?: Find out more on 24 September!
    Infosecurity Magazine’s 2009 Virtual Conference on Information Security will look at recent data breaches in both public and private sectors in a session headed by Bloor Research, CheckPoint and the Open Security Foundation.
  • Most UK organisations hit by data breach
    Seventy percent of UK organisations have been hit by one data breach or more in the last year compared to 60% the year before, according to a Ponemon Institute survey on encryption and information security commissioned by enterprise data protection firm PGP Corporation.
  • UK government agencies changing approach to data security
    Amidst all the reports of data breaches and intrusions in recent months comes a spot of good news, namely that a report from BeCrypt claims to show that UK government agencies are adopting a positive attitude to data security.
  • PGP research highlights crippling data breach losses
    Research just released by crypto specialist PGP Corporation claims to show that the average cost of a data breach soared by 28% during 2008, with typical costs weighing in at an astonishing £1.7 million per incident.
  • Loyalty cards: The security risks and the rewards
    Loyalty cards – with their numerous security risks and few rewards – have really taken off. Can we trust that the commercial organisations that store our data will take good care of it? Cath Everett investigates and finds there’s no such thing as a free lunch...

News

Third annual UK Ponemon study shows costs of data breaches

29 January 2010

The third annual UK report into data breaches – sponsored by PGP and carried out by the Ponemon Institute – claims to show that each lost customer record cost organisations an average of £64 in 2009.

Breaking down the numbers reveals that the cost for data breaches came in at £69 per lost record for private organisations, and £59 for the public sector. The figures, says the Institute, were a 7% hike on 2008's average of £60 per customer record. And back in 2007 the cost per lost record stood at just £47.

Interestingly, the data breach report shows that lost business – due to reduced consumer trust – was the main contributor to this expense, making up £29 per record.

Whilst the financial impact of lost business is substantially lower for public bodies than for commercial firms, the study says that costs associated with detecting and escalating a breach – with notifying citizens and dealing with subsequent enquiries – are all substantially higher in the public sector, and are the principle contributors to the overall costs.

"This third annual study shows that the financial impact of data breaches is hitting UK organisations harder and harder each year", said Larry Ponemon, chairman and founder of The Ponemon Institute.

"In the commercial sector the costs associated with customer churn and attracting new customers are particularly acute, but our research suggests these firms are getting better at detection, remediation and customer communications", he added.

"However, these efficiencies aren't shared in the public sector, where the direct costs of a data breach are significantly higher. For example, the cost of notifying users that their records might have been compromised is more than four times higher for public organisations than for private firms."

The report, which focuses on the cost of activities resulting from real life data loss incidents occurring between May 2009 and January 2010, took in responses from 33 UK organisations.

Researchers found that data breach events involved between 5,200 and 60,000 personally identifiable information records, costing between £365 000 and £3.92m pounds to manage, at an average of £1.68m.

 

This article is featured in:
Data Loss Encryption Public Sector

 

Comment on this article

You must be registered and logged in to leave a comment about this article.