<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; research</title>
	<atom:link href="http://www.endpoint-security.info/tag/research/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Thu, 02 Feb 2012 10:58:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Healthcare data breaches on the rise and costing billions</title>
		<link>http://www.endpoint-security.info/2011/12/02/healthcare-data-breaches-on-the-rise-and-costing-billions/</link>
		<comments>http://www.endpoint-security.info/2011/12/02/healthcare-data-breaches-on-the-rise-and-costing-billions/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 21:09:13 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[hospitals]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=814</guid>
		<description><![CDATA[Based on the many stories about data breaches reported by organizations in the healthcare industry, from hospitals to insurance companies and other third-party companies that deal with healthcare data, we could have guessed this is not even close to being a top sector when it comes to data security. A new report released by the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F12%2F02%2Fhealthcare-data-breaches-on-the-rise-and-costing-billions%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F12%2F02%2Fhealthcare-data-breaches-on-the-rise-and-costing-billions%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img style="float: left; margin-right: 10px" title="hospital" src="http://www.endpoint-security.info/wp-content/uploads/2011/12/hospital.jpg" alt="" width="240" height="158" />Based on the many stories about data breaches reported by organizations in the healthcare industry, from hospitals to insurance companies and other third-party companies that deal with healthcare data, we could have guessed this is not even close to being a top sector when it comes to data security. <a href="http://www.darkreading.com/insider-threat/167801100/security/attacks-breaches/232200606/healthcare-data-in-critical-condition.html" target="_blank">A new report released by the Ponemon Institute</a> now brings even further insight into the state of the healthcare industry, showing a spike in data breaches of over 30% and average annual costs of 6.5 billion US dollars.</p>
<p>The &#8220;2011 Benchmark Study on Patient Privacy and Data Security,&#8221; commissioned by IDExperts, idendified employee error to be one of the main cause for data breaches in hospitals and healthcare providers. These types of organizations in the healthcare industry suffered an average of four data breaches in the past year. Nearly 30 percent of healthcare companies said the breaches they suffered resulted in medical identity theft – an over 25 percent increase over 2010.<span id="more-814"></span></p>
<p>The jump is not entirely determined by a larger number of breaches happening in the past year compared to the previous one. It&#8217;s actually the effect of better detection capabilities by healthcare organizations, <a href="http://www.darkreading.com/insider-threat/167801100/security/attacks-breaches/232200606/healthcare-data-in-critical-condition.html" target="_blank">according to Larry Ponemon, chairman and founder of the Ponemon Institute. </a></p>
<blockquote><p>&#8220;It was not too surprising that the rate of data loss increased … [But] we think that finding may not be as negative as it appears, and could be a discovery-rate increase with more control and governance practices and use of enabling technologies.&#8221;</p></blockquote>
<p>The strong increase of mobile device usage in the healthcare segment is also a high-impact factor. About 80% use such devices to gather, transmit and store patient data, and a troubling 50% don&#8217;t secure their mobile devices. The help they provide in patient care is overshadowed by the major risks to data security the patients are exposed to.</p>
<p>Nearly half of the healthcare industry breached were caused by stolen or lost computing or data devices and another 46% were caused by errors by third-party providers. Moreover, the healthcare organizations are just unaware of where patient data is stored &#8211; 61% don&#8217;t really know where all their patient data is kept. If that&#8217;s not enough, over half of them aren&#8217;t sure they actually can detect incidents where patient data is exposed.</p>
<p>Hospitals don&#8217;t lack written policies when it comes to data breach reporting &#8211; about 80% have them. Too bad about 60% consider them ineffective.</p>
<p>A full copy of the report <a href="http://www2.idexpertscorp.com/ponemon-study-2011" target="_blank">is available here for download</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/08/29/new-data-breaches-reported-by-healthcare-companies/" rel="bookmark" class="crp_title">New Data Breaches Reported by Healthcare Companies</a></li><li><a href="http://www.endpoint-security.info/2010/07/27/security-breach-costs/" rel="bookmark" class="crp_title">The real cost of a security breach: 1 to 53 million USD per year</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li><li><a href="http://www.endpoint-security.info/2008/05/20/hospitals-a-danger-to-your-personal-data/" rel="bookmark" class="crp_title">Hospitals, a Danger to Your Personal Data</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/12/02/healthcare-data-breaches-on-the-rise-and-costing-billions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Database administrators lack proper understanding of security</title>
		<link>http://www.endpoint-security.info/2011/05/22/database-administrators-lack-proper-understanding-of-security/</link>
		<comments>http://www.endpoint-security.info/2011/05/22/database-administrators-lack-proper-understanding-of-security/#comments</comments>
		<pubDate>Sun, 22 May 2011 07:25:35 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[IT professionals]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security breaches]]></category>
		<category><![CDATA[survey]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=660</guid>
		<description><![CDATA[A recently published study shows that database administrators don’t fully understand security. According to these fresh findings, database administrators and IT decision-makers in general admit to knowing very little about security issues like change control, patch management, auditing etc. This survey was conducted on 214 Sybase administrators belonging to the International Sybase User Group. &#8220;A [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F05%2F22%2Fdatabase-administrators-lack-proper-understanding-of-security%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F05%2F22%2Fdatabase-administrators-lack-proper-understanding-of-security%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A recently published study shows that database administrators don’t fully understand security. According to these fresh findings, <a href="http://www.darkreading.com/database-security/167901020/security/application-security/229502495/survey-database-administrators-it-security-still-not-on-the-same-page.html" target="_blank">database administrators and IT decision-makers in general admit to knowing very little about security</a> issues like change control, patch management, auditing etc. This survey was conducted on 214 Sybase administrators belonging to the International Sybase User Group.</p>
<blockquote><p>&#8220;A majority of respondents admit that there are multiple copies of their production data, but many do not have direct control over the security of this information,&#8221; the survey report stated. &#8220;Only one out of five take proactive measures to mask or shield this data from prying eyes.&#8221;</p></blockquote>
<p>According to the report&#8217;s author, Unisphere Research analyst Joe McKendrick, the ISUG survey is the first released of a series of similar database security surveys being conducted across various database user groups, including those running other platforms such as Oracle and SQL Server.<span id="more-660"></span></p>
<blockquote><p>&#8220;This [ISUG survey] pretty much follows the same script [as the survey responses in the other database environments,&#8221; McKendrick said. &#8220;It&#8217;s very consistent &#8212; with a very common theme across all of these different user groups and technology bases &#8212; that there is a disconnect between management and security.&#8221;</p></blockquote>
<p>The biggest problem seems to be the understanding of change management and patch management, as 37of th% e respondents did not know how to correct unauthorised changes to the database or how long this would take.</p>
<p>Another 35% stated that they rarely apply security patches or did not know how frequently these patches were applied. Almost two thirds of database manipulation have no automated software for database setup or patching.</p>
<p>Surprisingly, <strong>almost 50% of the respondents do not believe they will experience security breaches in the next year.</strong></p>
<p>These results are not at all surprising according to Rich Mogull the founder Securosis analysys firm.</p>
<blockquote><p>&#8220;We still see very much a split between the database and security worlds &#8212; and not nearly the level of communication between the two of them that we&#8217;d like,&#8221; Mogull says.</p></blockquote>
<p>Security experts strongly state organizations need to do a better job in increasing access to data assets for both DBAs and IT professionals.</p>
<p><a href="http://www.endpointprotector.com/lp/endpoint_protector_general_EN.php"><img title="Endpoint Security and Device Control Solutions with low TCO and great ROI." src="/wp-content/uploads/banners/banner-galactic-red-epp.jpg" border="0" alt="Endpoint Security and Device Control Solutions with low TCO and great ROI." width="500" height="100" align="middle" /></a></p>
<blockquote><p>&#8220;We need to ask ourselves, &#8216;Where are these pieces of classified information and bank account numbers and sensitive organizational data being stored in the databases? Can we identify all the databases they&#8217;re in?&#8217;&#8221; Hutton explains. &#8220;And then we can figure out how to create a control structure that prevents, detects, and responds to incidents against that database.&#8221;</p></blockquote>
<p>Experts have also pointed out many organizations fail to properly audit their data to ensure that the policies and controls put in place are actually working. According to McKendrick, the recent survey found that only 16% of organizations perform regular database audits once a month. Another 32% either say they don&#8217;t know how often audits are performed or never perform them at all.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/11/14/steam-hit-by-hackers-are-all-their-35-million-user-accounts-breached/" rel="bookmark" class="crp_title">Steam hit by hackers. Are all their 35 million user accounts breached?</a></li><li><a href="http://www.endpoint-security.info/2008/07/28/potential-breach-affects-128000-saint-mary-patients-and-clients/" rel="bookmark" class="crp_title">Potential Breach Affects 128,000 Saint Mary Patients and Clients</a></li><li><a href="http://www.endpoint-security.info/2010/06/28/smbs-start-taking-security-seriously/" rel="bookmark" class="crp_title">SMBs start taking security seriously</a></li><li><a href="http://www.endpoint-security.info/2011/10/24/israeli-ministry-falls-pray-to-insider-theft-of-9-million-records/" rel="bookmark" class="crp_title">Israeli Ministry Falls Pray to Insider Theft of 9 Million Records</a></li><li><a href="http://www.endpoint-security.info/2009/11/25/employees-would-still-data-companies-worry-but-do-nothing/" rel="bookmark" class="crp_title">Most employees would steal data. Companies worry, but do nothing</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/05/22/database-administrators-lack-proper-understanding-of-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Employees Couldn&#8217;t Care Less about Data Security</title>
		<link>http://www.endpoint-security.info/2009/06/16/employees-couldnt-care-less-about-data-security/</link>
		<comments>http://www.endpoint-security.info/2009/06/16/employees-couldnt-care-less-about-data-security/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 08:54:39 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security policy]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=219</guid>
		<description><![CDATA[More and more employees chose to overlook data security policies put in place by the companies they work for and engage in activities that could easily lead to data breaches, according to the findings of a new Ponemon Institute survey. The risky activities include taking private records with them on unsecured storage devices, downloading personal [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F06%2F16%2Femployees-couldnt-care-less-about-data-security%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F06%2F16%2Femployees-couldnt-care-less-about-data-security%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>More and more employees chose to overlook data security policies put in place by the companies they work for and engage in activities that could easily lead to data breaches, according to the findings of a new Ponemon Institute survey. The risky activities include taking private records with them on unsecured storage devices, downloading personal software on company systems, turning off security settings and networking on social media sites.</p>
<p>Most members of a company&#8217;s staff copy classified data to USB drives or turn off security settings on their work laptops. Compared to the Institute&#8217;s 2007 findings, the numbers of those ignoring company policies has increased.</p>
<p>Here are some highlights of the survey findings, as <a title="Employees Ignore Data Security" href="http://www.pcworld.com/businesscenter/article/166478/more_employees_neglecting_data_security_survey_says.html" target="_blank">presented by PC World</a>:</p>
<ul>
<li> 69 percent of the 967 IT professionals surveyed copied confidential company data to USB sticks</li>
<li>those who lost said USB sticks with confidential corporate data on them failed to report it immediately</li>
<li>almost 31 percent of respondents engaged in social-networking practices on the Web from work PCs</li>
<li>around 53 percent said they downloaded personal software on corporate PCs</li>
</ul>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/04/12/stolen-hardware-most-common-cause-for-data-breaches/" rel="bookmark" class="crp_title">Stolen Hardware &#8211; Most Common Cause for Data Breaches</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li><li><a href="http://www.endpoint-security.info/2009/03/09/you-fire-them-they-take-your-confidential-data/" rel="bookmark" class="crp_title">You fire them, they take your confidential data!</a></li><li><a href="http://www.endpoint-security.info/2008/10/28/employees-dodge-security-to-increase-their-productivity/" rel="bookmark" class="crp_title">Employees Dodge Security to Increase their Productivity</a></li><li><a href="http://www.endpoint-security.info/2009/08/11/how-to-prevent-social-networking-threats-on-private-data/" rel="bookmark" class="crp_title">How to Prevent Social Networking Threats on Private Data?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/06/16/employees-couldnt-care-less-about-data-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Laptop Facial Recognition Takes Hard Blow</title>
		<link>http://www.endpoint-security.info/2009/03/01/laptop-facial-recognition-takes-hard-blow/</link>
		<comments>http://www.endpoint-security.info/2009/03/01/laptop-facial-recognition-takes-hard-blow/#comments</comments>
		<pubDate>Sun, 01 Mar 2009 10:29:26 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Asus]]></category>
		<category><![CDATA[biometric security]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[facial recognition system]]></category>
		<category><![CDATA[laptop security]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[Lenovo]]></category>
		<category><![CDATA[R&D]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Toshiba]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=190</guid>
		<description><![CDATA[Facial recognition is one of the very well known methods employed by biometric security systems. It&#8217;s used in different complicated security systems, but also on more day-to-day devices, such as laptops. A group of white hat security researchers have recently managed to bypass the facial recognition systems employed by several laptops. According to the Register, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F03%2F01%2Flaptop-facial-recognition-takes-hard-blow%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F03%2F01%2Flaptop-facial-recognition-takes-hard-blow%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Facial recognition is one of the very well known methods employed by <a title="Biometrics" href="http://en.wikipedia.org/wiki/Biometrics" target="_blank">biometric security systems</a>. It&#8217;s used in different complicated security systems, but also on more day-to-day devices, such as laptops.</p>
<p>A group of white hat security researchers have recently managed to bypass the facial recognition systems employed by several laptops. According to <a title="Facial recognition fail" href="http://www.theregister.co.uk/2009/02/19/facial_recognition_fail/" target="_blank">the Register,</a> the laptops that have had their biometric security breached are developed by Lenovo, Asus and Toshiba. The researchers&#8217; team includes and they have also detailed their findings in a presentation called <a title="Hacked Biometric Security Systems" href="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Nguyen" target="_blank">Your Face is NOT your Password</a> during the Blackhat security conference in Washington.</p>
<p>You might wonder if it was hard to breach the facial recognition systems. The team responsible for this breaches used images of laptop owners or photoshopped images:</p>
<blockquote><p>Nguyen and his team created a large number of images to run what they described a &#8220;fake face bruteforce&#8221; attack to fool the systems, which in fairness are still in their infancy, into allowing a log-on. The approach can be compared to trying out a huge number of possible text passwords until the right combination is stumbled upon as part of a conventional brute-force dictionary attack.</p></blockquote>
<p>While trying to find a practical security use for biometric traits, the developers at Lenovo, Asus and Toshiba should reconsider the efficiency of their facial recognition software. We admire the fact that they lead research and implementation in the field, but we&#8217;d appreciate safer systems more <img src='http://www.endpoint-security.info/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/10/29/a-critical-look-at-biometrics-security/" rel="bookmark" class="crp_title">A Critical Look at Biometrics Security</a></li><li><a href="http://www.endpoint-security.info/2008/02/19/is-biometric-authentication-a-must-for-usb-sticks/" rel="bookmark" class="crp_title">Is Biometric Authentication a Must for USB Sticks?</a></li><li><a href="http://www.endpoint-security.info/2009/04/26/the-fco-has-its-eye-on-biometric-security/" rel="bookmark" class="crp_title">The FCO has its eye on Biometric Security</a></li><li><a href="http://www.endpoint-security.info/2008/03/05/builders-of-london-olympics-site-biometricaly-authenticated/" rel="bookmark" class="crp_title">Builders of London Olympics Site &#8211; Biometricaly Authenticated</a></li><li><a href="http://www.endpoint-security.info/2009/02/13/new-in-biometrics-tapping-vains/" rel="bookmark" class="crp_title">The Latest Trick in Biometrics: Finger Vein Authentication</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/03/01/laptop-facial-recognition-takes-hard-blow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Data Breach Cost Up, Response Cost Down</title>
		<link>http://www.endpoint-security.info/2009/02/09/us-data-breach-cost-up-response-cost-down/</link>
		<comments>http://www.endpoint-security.info/2009/02/09/us-data-breach-cost-up-response-cost-down/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 10:26:08 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[breach costs]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[findings]]></category>
		<category><![CDATA[legal costs]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[response costs]]></category>
		<category><![CDATA[studie]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=184</guid>
		<description><![CDATA[According to a  recent Ponemon Institute study, the costs of data breaches rose in the USA to $6.6 million per incident in 2008, although companies put increased efforts in better handling such incidents. The study, funded by data security firm PGP Corp. and quoted by Security Focus, analyzed data breaches experienced by 43 US-based companies [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F02%2F09%2Fus-data-breach-cost-up-response-cost-down%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F02%2F09%2Fus-data-breach-cost-up-response-cost-down%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>According to a  recent Ponemon Institute study, the costs of data breaches rose in the USA to $6.6 million per incident in 2008, although companies put increased efforts in better handling such incidents.</p>
<p>The study, funded by data security firm PGP Corp. and <a title="US Data Breaches cost more" href="http://www.securityfocus.com/brief/900?ref=rss" target="_blank">quoted by Security Focus</a>, analyzed data breaches experienced by 43 US-based companies from 17 different industry sectors. The breaches involved a number of records ranging from about 4,200 to more than 113,000. The findings showed the average costs of data breaches are about 2.5 percent higher in 2008, amounting to $202 per record, up from $197 per record in 2007 and $182 per record in 2006. An average breach would require a company to spend $6.6 million in 2008, up from $6.3 million in 2007 and $4.7 million in 20006.</p>
<p>To calculate the total cost of a data breach, the institute added the costs of detecting and responding to the loss of data, legal and administrative expenses, customer defections and opportunity loss. The response costs decrease was a result of businesses learning how to cost effectively handle such incidents:</p>
<blockquote><p><span class="body">While legal fees and customer losses moved breach costs higher, companies reduced the costs of dealing with breaches, signaling that firms and their third-party providers are becoming more cost effective in responding to data breaches, the Ponemon Institute stated in the report.</span></p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/04/29/data-breaches-cost-more-in-the-us/" rel="bookmark" class="crp_title">Data breaches cost more in the US</a></li><li><a href="http://www.endpoint-security.info/2010/07/27/security-breach-costs/" rel="bookmark" class="crp_title">The real cost of a security breach: 1 to 53 million USD per year</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li><li><a href="http://www.endpoint-security.info/2008/02/25/uk-companies-pay-47-for-every-private-record-lost/" rel="bookmark" class="crp_title">UK Companies Pay £47 for Every Lost Private Record</a></li><li><a href="http://www.endpoint-security.info/2011/03/22/data-breach-costs-blamed-on-system-failures/" rel="bookmark" class="crp_title">Data breach costs blamed on system failures</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/02/09/us-data-breach-cost-up-response-cost-down/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

