{"id":36004,"date":"2018-08-09T14:00:49","date_gmt":"2018-08-09T14:00:49","guid":{"rendered":"https:\/\/www.cloudcomputing-news.net\/news\/2018\/aug\/09\/ibms-2018-data-breach-study-shows-why-were-zero-trust-world-now\/"},"modified":"2018-08-09T14:00:49","modified_gmt":"2018-08-09T14:00:49","slug":"ibms-2018-data-breach-study-shows-why-were-in-a-zero-trust-world-now","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/ibms-2018-data-breach-study-shows-why-were-in-a-zero-trust-world-now\/","title":{"rendered":"IBM\u2019s 2018 data breach study shows why we\u2019re in a Zero Trust world now"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/www.cloudcomputing-news.net\/media\/iStock-458622753_2.jpg\"><\/p>\n<ul>\n<li>Digital businesses that lost less than 1% of their customers due to a data breach incurred a cost of $2.8M, and if 4% or more were lost the cost soared to $6M.<\/li>\n<li>U.S. based breaches are the most expensive globally, costing on average $7.91M with the highest global notification cost as well, $740,000.<\/li>\n<li>A typical data breach costs a company $3.86M, up 6.4% from $3.62M last year.<\/li>\n<li>Digital businesses that have security automation can minimize the costs of breaches by $1.55M versus those businesses who are not ($2.88M versus $4.43M).<\/li>\n<li>48% of all breaches are initiated by malicious or criminal attacks.<\/li>\n<li>Mean-time-to-identify (MTTI) a breach is 197 days, and the mean-time-to-contain (MTTC) is 69 days.<\/li>\n<\/ul>\n<p>These and many other insights into the escalating costs of security breaches are from the&nbsp;<a href=\"https:\/\/www.ibm.com\/security\/data-breach\" rel=\"noopener noreferrer\" >2018 Cost of a Data Breach Study<\/a>&nbsp;sponsored by IBM Security with research independently conducted by Ponemon Institute LLC.&nbsp;<a href=\"https:\/\/www.pbwt.com\/content\/uploads\/2018\/07\/2018-Cost-of-Data-Breach-Study.pdf\" rel=\"noopener noreferrer\" >The report is downloadable here<\/a>&nbsp;(PDF, 47 pp. no opt-in).<\/p>\n<p>The study is based on interviews with more than 2,200 compliance, data protection and IT professionals from 477 companies located in 15 countries and regions globally who have experienced a data breach in the last 12 months. This is the first year the use of&nbsp;Internet&nbsp;of Things (IoT) technologies and security automation are included in the study. The study also defines mega breaches as those involving over 1 million records and costing $40M or more. Please see pages 5, 6 and 7 of the study for specifics on the methodology.<\/p>\n<p>The report is a quick read and the data provided is fascinating. One can&rsquo;t help but reflect on how legacy security technologies designed to protect digital businesses decades ago isn&rsquo;t keeping up with the scale, speed and sophistication of today&rsquo;s breach attempts. The most common threat surface attacked is compromised privileged credential access. 81% of all breaches exploit identity according to an excellent study from&nbsp;<a href=\"https:\/\/www.centrify.com\/\" rel=\"noopener noreferrer\" >Centrify<\/a>&nbsp;and Dow Jones Customer Intelligence,&nbsp;<a href=\"https:\/\/www.centrify.com\/resources\/ceo-disconnect-weakening-cybersecurity\/\" rel=\"noopener noreferrer\" >CEO Disconnect is Weakening Cybersecurity<\/a>&nbsp;(31 pp, PDF, opt-in).<\/p>\n<p>The bottom line from the IBM, Centrify and many other studies is that we&rsquo;re in a&nbsp;<a href=\"https:\/\/www.centrify.com\/education\/what-is-zero-trust\/\" rel=\"noopener noreferrer\" >Zero Trust Security (ZTS)<\/a>&nbsp;world now and the sooner a digital business can excel at it, the more protected they will be from security threats. ZTS begins with&nbsp;<a href=\"https:\/\/www.centrify.com\/education\/what-is-next-gen-access\/\" rel=\"noopener noreferrer\" >Next-Gen Access (NGA)<\/a>&nbsp;by recognizing that every employee&rsquo;s identity is the new security perimeter for any digital business.<\/p>\n<p>Key takeaways from the study include the following:<\/p>\n<h3><strong>US-based breaches are the most expensive globally, costing on average $7.91m, more than double the global average of $3.86m<\/strong><\/h3>\n<p>Nations in the Middle East have the second-most expensive breaches globally, averaging $5.31M, followed by Canada, where the average breach costs a digital business $4.74M. Globally a breach costs a digital business $3.86M this year, up from $3.62M last year. With the costs of breaches escalating so quickly and the cost of a breach in the U.S. leading all nations and outdistancing the global average 2X, it&rsquo;s time for more digital businesses to consider a Zero Trust Security strategy. See Forrester Principal Analyst Chase Cunningham&rsquo;s recent blog post&nbsp;<a href=\"https:\/\/go.forrester.com\/blogs\/what-ztx-means-for-vendors-and-users\/\" rel=\"noopener noreferrer\" >What ZTX Means For Vendors And Users<\/a>, from the Forrester Research blog for where to get started.<\/p>\n<p><a href=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Avg-total-cost-of-a-breach-by-region.jpg\"><img decoding=\"async\" alt=\"\" class=\"aligncenter size-full wp-image-14433\" src=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Avg-total-cost-of-a-breach-by-region.jpg\" style=\"height:100%; object-fit:contain; width:100%\" \/><\/a><\/p>\n<h3><strong>The number of breached records is soaring in the US, the third&nbsp;leading nation of breached records, 6,850 records above the global average<\/strong><\/h3>\n<p>The Ponemon Institute found that the average size of a data breach increased 2.2% this year, with the U.S. leading all nations in breached records. It now takes an average of 266 days to identify and contain a breach&nbsp;<em>(Mean-time-to-identify (MTTI) a breach is 197 days and the mean-time-to-contain (MTTC) is 69 days)<\/em>, so more digital businesses in the Middle East, India, and the U.S. should consider reorienting their security strategies to a&nbsp;<a href=\"https:\/\/www.centrify.com\/zero-trust-security\/\" rel=\"noopener noreferrer\" >Zero Trust Security Model<\/a>.<\/p>\n<p><a href=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Avg-number-of-breached-record-by-region.jpg\"><img decoding=\"async\" alt=\"\" class=\"aligncenter size-full wp-image-14434\" src=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Avg-number-of-breached-record-by-region.jpg\" style=\"height:100%; object-fit:contain; width:100%\" \/><\/a><\/p>\n<h3><strong>French and US&nbsp;digital businesses pay a heavy price in customer churn when a breach happens, among the highest in the world<\/strong>&nbsp;<\/h3>\n<p>The following graphic compares abnormally high customer churn rates, the size of the data breach, average total cost, and per capita costs by country.<\/p>\n<p><a href=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Figure-6.jpg\"><img decoding=\"async\" alt=\"\" class=\"aligncenter size-full wp-image-14435\" src=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Figure-6.jpg\" style=\"height:100%; object-fit:contain; width:100%\" \/><\/a><\/p>\n<h3><strong>US&nbsp;companies lead the world in lost business caused by a security breach with $4.2m&nbsp;lost per incident, over $2m&nbsp;more than digital businesses from the Middle East<\/strong><\/h3>\n<p>Ponemon found that U.S. digitally-based businesses pay an exceptionally high cost for customer churn caused by a data breaches. Factors contributing to the high cost of lost business include abnormally high turnover of customers, the high costs of acquiring new customers in the U.S., loss of brand reputation and goodwill. U.S. customers also have a myriad of competitive options and their loyalty is more difficult to preserve. The study finds that thanks to current notification laws, customers have a greater awareness of data breaches and have higher expectations regarding how the companies they are loyal to will protect customer records and data.<\/p>\n<p><a href=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Figure-20.jpg\"><img decoding=\"async\" alt=\"\" class=\"aligncenter size-full wp-image-14436\" src=\"https:\/\/blogs.forbes.com\/louiscolumbus\/files\/2018\/07\/Figure-20.jpg\" style=\"height:100%; object-fit:contain; width:100%\" \/><\/a><\/p>\n<h3><strong>Conclusion<\/strong><\/h3>\n<p>The IBM study foreshadows an increasing level of speed, scale, and sophistication when it comes to how breaches are orchestrated. With the average breach globally costing $4.36M and breach costs and lost customer revenue soaring in the U.S,. it&rsquo;s clear we&rsquo;re living in a world where Zero Trust should be the new mandate.<\/p>\n<p><a href=\"https:\/\/www.centrify.com\/education\/what-is-zero-trust\/\" rel=\"noopener noreferrer\" >Zero Trust Security<\/a>&nbsp;starts with&nbsp;<a href=\"https:\/\/www.centrify.com\/education\/what-is-next-gen-access\/\" rel=\"noopener noreferrer\" >Next-Gen Access<\/a>&nbsp;to secure every endpoint and attack surface a digital business relies on for daily operations, and limit access and privilege to protect the &ldquo;keys to the kingdom,&rdquo; which gives hackers the most leverage. Security software providers including&nbsp;<a href=\"https:\/\/www.centrify.com\/\" rel=\"noopener noreferrer\" >Centrify<\/a>&nbsp;are applying&nbsp;<a href=\"https:\/\/www.forbes.com\/sites\/louiscolumbus\/2018\/06\/24\/analytics-are-empowering-next-gen-access-and-zero-trust-security\/#70ba24ec2996\" rel=\"noopener noreferrer\" >advanced analytics and machine learning<\/a>&nbsp;to thwart breaches and many other forms of attacks that seek to exploit weak credentials and too much privilege. Zero Trust is a proven way to stay at parity or ahead of escalating threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital businesses that lost less than 1% of their customers due to a data breach incurred a cost of $2.8M, and if 4% or more were lost the cost soared to $6M.<br \/>\nU.S. based breaches are the most expensive globally, costing on average $7.91M with the hig&#8230;<\/p>\n","protected":false},"author":56,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-36004","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/36004","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/56"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=36004"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/36004\/revisions"}],"predecessor-version":[{"id":36005,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/36004\/revisions\/36005"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=36004"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=36004"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=36004"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}