[1/2] Cost of a Data Breach Report 2024 (Category Security)
I studied interesting. report 2024 The report was prepared by IBM in collaboration with the Ponemon Institute. IBM knows everyone, but the Ponemon Institute is an independent research organization specializing in privacy, data protection and information security. To create the report, the researchers studied 604 organizations affected by data breaches since March 2023 February 2024 years. The study included companies from 17 industries 16 countries and regions. The extent of the incidents examined varied from 2 100 before 113 000 compromised records. To get first-hand information, Ponemon Institute analysts conducted interviews with 3 556 Security specialists and C-level managers who were directly involved in the incidents.
This report can be trusted for several reasons:
- That's it 19An annual report of this kind, indicating a well-established methodology and the ability to track long-term trends.
- Studied. 604 organization of different sizes and industries, which ensures representativeness of the sample. IBM and the Ponemon Institute use a clear methodology to calculate the cost of a data breach, taking into account various factors, including the cost of detecting a leak, notifying victims, response measures and lost profits. Although the report is sponsored by IBM, the study itself is conducted independently by the Ponemon Institute, which reduces the likelihood of bias. The report includes a detailed look at various aspects of data breaches, including initial attack vectors, detection time, technology impact, and more.
Main results of the study 1) Rising cost of data breaches Average cost of data breach in 2024 The year reached a record high in 4,88 a million dollars, which 10% higher than last year’s figure in 4,45 A million dollars. This is the largest increase since the pandemic. The increase in value is due to several factors: Increased costs of eliminating operational downtime Increased financial losses due to customer outflow Increased costs of customer support services Increase in regulatory fines 2) Impact of AI and automation Two-thirds of the organizations surveyed reported implementing artificial intelligence and automation technologies in their operational security centers. 10% higher compared to the previous year. Organizations that widely use AI in threat prevention processes save on average 2,2 One million dollars in costs associated with leaks, compared to organizations that do not use AI in these processes. 3) Life cycle of incidents Leaks related to stolen credentials take the most time to detect and fix - on average 292 day. Phishing attacks are on average 261 day, and attacks using social engineering 257 days. 4) Types of compromised data
- Nearly half of all leaks. (46%) affected personal data of customers, including tax identifiers, email addresses, telephone numbers and residential addresses. In second place were intellectual property records. (43percent of leaks). At the same time, the cost of one compromised intellectual property record increased to 173 dollars from last year 156 dollars. 5) The problem of “shadow data” More than a third (35%) The leaks affected "shadow data" - information stored in unmanaged data sources. Theft of “shadow data” correlates with an increase in the cost of leakage 16%. 6) Business implications More 70Percentage of organizations reported significant or very significant failures following data breaches. More than half of organizations pass on the increased costs of leaks to their customers through higher prices for goods and services.
The conclusions of the report will be in next post.
#Security #Software #AI #SRE #Architecture #Management