UK Home >  OUT-LAW News >  News Archive >  2009 >  February 2009 >  Data breach costs rise to £60 per record, say researchers

Data breach costs rise to £60 per record, say researchers

OUT-LAW News, 05/02/2009

The biggest cost to companies that lose data is the business that it loses those firms, according to industry research. The total cost of losing a piece of data has risen by 28% in the last year, the research found.

advert: Data Protection Update Sessions by Amberhawk and Pinsent Masons. London, Manchester, Edinburgh. £95+VAT

The average cost of a single lost record is £60, research conducted by privacy research firm The Ponemon Institute on behalf of encryption company PGP Corporation. Last year's research results showed that the cost per record was £47.

The research examined the circumstances of 30 UK data breaches, examining both the causes and the costs of incidents. It found that 53% of the costs that companies reported were due to lost business. "[This suggests] that the UK public cares deeply about the loss or theft of their personal information," said a PGP statement.

"The total cost of a data breach ranged from £160k to £4.8 million, with an average cost of £60 per customer record," it said.

The research found that just 30% of breaches were down to acts of malice, but the fact that the other 70% of incidents were down to insider negligence should encourage companies to take action, it found. "More needs to be done to educate staff on the importance of safeguarding information," said PGP.

The most expensive data breaches are those resulting from action by third parties to whom data processing has been outsourced. These cost organisations £67 per record rather £56 per record when no third party was involved. The range of the cost of a data breach was £160,000 to £4.8 million, the research found.

"2008 saw no slow down to the stream of data breaches started in 2007 – if anything they’ve gotten bigger and more costly,” said Phil Dunkelberger, chief executive of PGP. “In this current climate, organisations are taking desperate measures to preserve their reputation and retain customers; this study shows they simply cannot afford to lose out to competitors as a result of poor data security.”

The Ponemon survey found that breaches were less costly in the UK than in the US, where they cost $202 per lost record. It found that the average total cost of a breach in the US is $6.65 million.

Other evidence has emerged that the frequency, as well as the cost, of data breaches is on the increase. Research company Enterprise Strategy Group analyst Jon Oltsik wrote at technology site CNET News that his firm has said that the number of firms reporting breaches has jumped from 30% in previous years to 56% for 2008.

"Armed with data from several years of surveys, I think it is safe to assume that things are getting worse, not better," he wrote. "Sensitive data continues to flow throughout the enterprise, ending up in e-mails and IMs, laptops, and thumb drives, and into the hands of malicious or careless employees--an uphill battle indeed."

 

Disclaimer: We hope you find OUT-LAW’s content useful. It’s prepared by the lawyers at Pinsent Masons. Please remember, though, that it’s intended as general information only. It’s not legal advice. If that’s what you’re seeking, please contact us. See also: our full disclaimer

 

OUT-LAW Recommends

This week's podcast
Football snap spat


Advert: How can I manage the costs of my litigation? Our forensic accountants can help

UK Home | 
2010 | 
2009
2008 | 
2007 | 
2006 | 
2005 | 
2004 | 
2003 | 
2002 | 
2001 | 
2000 | 
Fun | 

 

Pinsent Masons named Legal Firm of the Year 2009 at Finance Directors' Excellence Awards

OUT-LAW star: link to the home page
Disclaimer: This was printed from OUT-LAW.COM, a service of international law firm Pinsent Masons. We hope you find this content useful. However, please note that nothing in this document constitutes specific legal advice. You should consult a suitably qualified lawyer on any specific legal problem or matter. Any questions, please email info@out-law.com.