Close X
Log In
If you are not a member,
register now
Email
Password
Forgot Your Password?
New User? Register now
to gain member-only access to all of IT World Canada's premium content & community portals.
Log in for Full Access |
Log In
|
Subscribe Now!
Follow
IT World Canada
Knowledge Centres
Community
Publications
Events
Services
Media
Communications Infrastructure
•
Carriers and Cellular
•
Networking
•
Voice, Data, and IP
Security
•
Alerts, Patches and Fixes
•
Disaster Recovery
•
Hacking and Viruses
Enterprise Business Applications
•
Business Intelligence
•
Enterprise Resource Planning
•
Open Source and Linux
Enterprise Infrastructure
•
Data Centre
•
Servers and Mainframes
•
Virtualization
Government
•
Case Studies and Best Practices
•
Collaboration
•
Policy
Leadership
•
Budgeting / IT Alignment
•
Industry News
•
Issues for CIOs
Information Architecture
•
Data Warehousing
•
Databases
•
Messaging and Collaboration
Integrating IT
•
Development Environments
•
Middleware - Utilities
•
Project Management
Green IT
•
E-Waste and Recycling
•
Green thinking
IT Workplace
•
Careers and the Job Market
•
Consulting and Contracting
•
Human Resources Issues
•
Women in IT
Departmental and End User Computing
•
Future Technology
•
Help Desk and End-User Support
•
Mobile Applications
All IT World Blogs
Featured Blogs
•
All things Android
•
Career Corner
•
Enterprise Insights
•
Security
ComputerWorld Canada Blogs
•
Shane Schick's Computerworld
•
World Wide Webb
•
Blogosphere
•
Techbuzz
CIO Canada Blogs
•
CIO Canada
•
Candid CIO
NetworkWorld Canada Blogs
•
Network World
•
Industry Watch
Guest Blogs
•
Stuff IT Managers Like
•
CDN Varbose
•
Making IT Work
Wikis
•
IT job Descriptions
•
CWC In Conversation
Groups
•
Finance
CIO Canada
ComputerWorld Canada
Network World Canada
Computer Dealer News
Direction Informatique
IT Business.ca
Click Here to Subscribe Now!
ComputerWorld Canada Events
•
Computerworld Interactive
•
Computerworld IT Leadership Awards
•
Computerworld Technology Insights
Feature Events
•
Visability - Social Media
•
Technicity
Events for Government
•
GovSym Symposium
•
Lac Carling
Computer Dealer News Events
•
CDN Channel Elite Awards
•
CDN Top 100
•
Computer Golf
Events for CIOs
•
CIO Exchange
•
CIO Frankly Speaking Breakfasts
•
CIO Frankly Speaking @ Your Desk
More Information on
IT World Canada Events
IT World Canada Curated
Job and Career Resources
•
Canadian IT Jobs
•
IT Sales Jobs
•
Salary Calculator
•
Tech Learning Space
Knowledge Services
•
CDN ProFIT - Turnkey Marketing solutions
•
Visability
•
Knowledge Store
Subscribe Now- Register
Slide Shows
Videos
White Papers
Webinars
Hot Topics:
cloud services
•
big data analytics
•
Oracle
•
operating systems
•
DDoS Protection
•
databases
•
Microsoft
•
videoconferencing
•
Search
SHARE
Home
>>
Security
Why data breach costs are really going down
By:
Rafael Ruffolo
On:
09 Nov 2010
For:
ComputerWorld Canada
Telus says reported data breaches are on the rise in 2010, while the financial impact of the average breach is steadily decreasing. Rotman School of Business professor Walid Hejazi helps explain the peculiar trend
A new study by
Telus Corp.
reveals that while Canadian organizations reported 29 per cent more data breaches in 2010 versus the previous year, the annual cost of these security issues has dropped substantially.
The telecom giant’s report, which polled 500 business and IT professionals, was part of a joint study with the
University of Toronto’s Rotman School of Management
. The report found that breaches were up almost 30 per cent year-over-year, largely because of a doubling in reported incidents at government agencies.
Yogen Appalraju, vice-president of Telus’ security solutions division, said better detection and protection technologies have not only led to more reporting across the board, but also to better containment techniques. This, he said, starts to explain why reported breaches have jumped 30 per cent in 2010, while
breach costs
dropped from an average of $834,000 in 2009 to $179,508 in 2010.
Appalraju added, however, that targeted attacks have been on the rise during the same period, which might be contributing to the underreporting of data breach losses at some firms.
“In a lot of cases, organizations might not know that they’ve been breached for a long time,” he said.
For Walid Hejazi, professor of business economics at Rotman, the massive 78 per cent decrease in breach costs underscores a drastic change in the way hackers and cyber criminals are going about their trade.
“They’re not trying to bring down the network anymore,” he said.
Increasingly, criminals are targeting organizations and employees that can give them sensitive data that can be sold or repurposed for financial gain.
Hejazi said enterprises often felt a huge financial hit anytime their network and IT infrastructure was attacked. But when attackers target credit card data instead, the data breach costs are being felt amongst customers.
In cases where attackers are targeting intellectual property or sales leads, he added, an organization often is unaware that they’ve lost their competitive advantage and fail to report any data breach costs.
As for the state of IT security teams, the
Telus
survey found that organizations decreased the size of security staff in 2010 much more than the previous year. In 2010, 50 per cent of responding organizations reported security teams of one to five staff members compared with 12 per cent reporting teams of six to 10 staff members.
One of the biggest issues these smaller security teams have been tasked with, Telus said, is the job of controlling
social networking
access. But the study found that even though one in four responding Canadian organizations actively blocked access to social networking sites for security reasons, these companies do not experience any improvement in security.
According to Hejazi, some organizations that block access to social networking sites actually bring productivity and security issues upon themselves as employees spend valuable time trying to circumvent the block or surf the sites through their mobile devices.
He said organizations should ideally allow social networking access and put into place extensive education programs to ensure that employees know how to use the sites responsibly. And that doesn’t mean just telling your employees to “go on Facebook and be careful,” Hejazi said.
He added that employees should be advised that even a few unrelated Facebook or Twitter messages at the wrong time may lead to negative consequences.
“Especially in the financial sector, the fact that you’re talking on Facebook about nothing can send a signal to a lot of signals to your competitors,” Hejazi said.
Sign up for our
Newsletters
Tags:
security
,
networking
,
data breach
Close X
Your Name:
Your E-mail:
Friend's Name:
Friend's E-mail:
Close X
|
Views:
4211 |
Rating:
(0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.
Close X
Page
1
Quick Access
Video Conferencing
Cloud Computing Resource Centre
CIO Canada's Brainstorm Centre
CIO Canada Debate
Rafael Ruffolo
was a senior writer for ComputerWorld Canada from 2006 to 2011. He was the winner of a Kenneth R. Wilson award for business journalism in 2009.
Related Content
One in five Canuck firms report security violations
According to a new survey by CA Canada, enterprise data breaches caused by security attacks have doubled since 2006. Info-Tech’s James Quin notes not all breaches necessarily cause harm but the feds should mandate encryption.
Security survey reveals data breaches are on the rise
Poll shows that one in five companies have experienced a data breach
Threat landscape changing
The Internet security threat landscape is changing, according to security firm Symantec. Attackers are moving away from large, multipurpose attacks on network perimeters and towards smaller, more focused attacks on client-side targets.
Obama, the security threat
much hay was made in the now-mercifully-ended u.s. election campaign (next one starts in january!) about whether the democrats were soft on homeland security. regardless of opinion, the president-elect -- congratulations, sen. obama -- has predictably become an it security threat.websense, symantec and sophos labs reported today on pusa-related security issues. websense says its threats
Please enable JavaScript to view the
comments powered by Disqus.
blog comments powered by
Disqus
Related Videos
Building an Enterprise IT Security Training Program
Building an Enterprise IT Security Training Program
-
Over 50% of security breaches are a result of end-user error, oversight, and ignorance. IT security training is an effective method of reducing end-user related security breaches.
Cloud Computing: Extending the Network (3 of 3)
Cloud Computing: Extending the Network (3 of 3)
-
The end goals of private cloud computing are to; Enable efficient delivery of IT resources and services; Give the enterprise complete control over data; Enable choice in technologies and service providers
Cloud Computing: Getting to One Network (1 of 3)
Cloud Computing: Getting to One Network (1 of 3)
-
In this first video of the series, the team will take you through how to consolidate the different types of traffic onto a single, general-purpose, high-performance, highly available network that greatly simplifies the network infrastructure and redu
Cloud Computing: The Unified Compute Model (2 of 3)
Cloud Computing: The Unified Compute Model (2 of 3)
-
In this second video, the team will look at how to unite computing, networking, storage access, and virtualization into a single cohesive system. The Unified Compute model prepares you for cloud computing. This will be discussed in the next and fin
Professors warn of arms race in cyberspace
Professors warn of arms race in cyberspace
-
At a panel discussion organized by Osgoode Hall, professors Ronald Deibert and Stephane Leman-Langlois discussed the attacks on Google Inc. and the challenges of working in countries such as China.
more from the:
Video Library
Take Our Poll
Most Popular
Articles
Most Viewed
Most Emailed
Top Rated
Most Viewed
Most Emailed
Top Rated
Shaw wins Internet deal with city of Winnipeg
By: Howard Solomon (16 May 2012)
Shaw Communications has scored a big win in its campaign to extend its services to municipalities. The Calgary-based cableco won a bidding contest to ...
The cost of open data: A Canadian lawyer's analysis
By: Lou Milrad (14 May 2012)
We’ve started hearing a lot over the last year or so about “open data”, particularly in the municipal sector. It’s all ab ...
Rogers offers lure to M2M developers
By: Howard Solomon (11 May 2012)
Network operators are always looking for ways to expand the way organizations can use their networks beyond voice and data centre traffic. To encour ...
Canadian employee survey indicates dark view of cloud
By: Shane Schick (16 May 2012)
If Canadian enterprises are using cloud computing, their employees may be the last to know. A recent research bulletin from Toronto-based Pollara of ...
Researcher runs IP network over xylophones
By: Joab Jackson (14 May 2012)
NEW YORK -- Vint Cerf once wore a shirt that read "IP on Everything," a wry comment on the universatility of the Internet Protocol he helped invent, a ...
Cisco kills off Cius development
By: Paolo Del Nibletto (5/25/2012 11:56:00 AM)
In a surprise move, Cisco Systems Inc. has confirmed it will no longer invest in developing the Cius tablet device running Android.The Cius tablet was ...
Microsoft's new server and tool upgrades and CIOs
By: Juan Carlos Perez and Chris Kanaracus (5/25/2012 10:21:00 AM)
MIAMI -- CIOs and IT directors tracking the barrage of major upgrades for Windows and Office also need to stay tuned to the refresh cycle for Microsof ...
Microsoft clarifies tremendous Windows 8 claims
By: Gregg Keizer (5/25/2012 9:21:00 AM)
FRAMINGHAM, Mass. -- Reports earlier this week that Microsoft CEO Steve Ballmer predicted unprecedented sales of Windows 8 were wrong on multiple ...
How to make PHP apps scale
By: Andrew Oliver (5/25/2012 9:14:00 AM)
SAN FRANCISCO -- The power of PHP and an RDBMS is the ability to nail the major features of an application with cheaply paid developers in a reco ...
Funding rural broadband: Whatever it takes
By: Howard Solomon (5/25/2012 7:11:00 AM)
For rural communities looking to get ultra-fast broadband speeds increasingly seen in cities, there’s only one obstacle: Money. Getting it is ...
VIDEO: Why IT pros need 'soft skills'
By: Brian Bloom (23 May 2012)
Unemployment in the high-tech sector is low. But are IT pros getting the jobs they want? Stafflink CEO Tim Collins explains why having impressive ...
Why integrate Wi-Fi radios into small cellular cells
By: Ajay Kumar Gupta (15 May 2012)
FRAMINGHAM, Mass -- (Gupta is team lead at Wesley Clover Communications Solutions, which develops solutions from Canadian companies -- including Mitel ...
CEOs demand CIOs prepare for growth and mobility
By: Mark Chillingworth (15 May 2012)
CEOs have shifted their position and are releasing funds to CIOs that have innovations for mobile users and revenue generation ideas, finds the CIO Su ...
EMC mega-launch targets hybrid cloud, big data
By: Jeff Jedras (22 May 2012)
LAS VEGAS – With nearly 15,000 attendees making this its biggest user conference, IT infrastructure vendor EMC Corp. has made its largest ...
Why Eugene Kaspersky has big problems with big data
By: Jeff Jedras (22 May 2012)
NASSAU, BAHAMAS – The big data drumbeat is becoming deafening in the technology sector as vendors and analysts rush aboard the latest trend. But ...
Related White Papers
The Value of Smarter Datacenter Services
-
Efficient future IT operations require smarter datacenters. Learn more about the evolution of datacenter environments, key factors to consider, and challenges and opportunities here.
Three Steps to Progress BPM from Project to Program
-
As businesses move from smaller scale Business Process Management (BPM) projects to broad BPM programs, a new degree of "know-how" is required. "Three Steps to Progress BPM from Project to Program" provides the steps needed to make the most of BPM across an organization.
A Journey to Adaptive MDM
-
Adaptive master data management (MDM) solutions can increase revenue, reduce costs, enhance business agility and streamline compliance.
Load Balancing 101: Firewall Sandwiches
-
Learn how to recover from firewall failure – Click here to read
Role of 3rd party archiving in Exchange 2010
-
Where is Data Management Today? Manage your deletion and retention policies with this new whitepaper.
more:
White Papers
Close X