Candor about cybersecurity incidents can save money as well as trust, says survey

There’s an old adage that says, “Honesty is the best policy.” A new survey from security vendor Kaspersky suggests it might also pay.

The survey, released Monday, says that on average, small and medium-sized businesses that tell stakeholders and the public about a data breach are likely to lose 40 per cent less than their peers that saw the incident leaked to the media. Data suggest the same tendency has also been found to be the case in enterprises.

“Proactive disclosure can help turn things around in a company’s favour, and it goes beyond just the financial impact,” said Yana Shevchenko, senior product marketing manager at Kaspersky. “If customers know what happened firsthand, they are more likely to maintain their trust in the brand. In addition, the company can give its clients recommendations on what to do next so that they can keep their assets protected. The company can also tell their side of the story by sharing reliable and correct information with the media, instead of publications relying on third-party sources that may depict the situation incorrectly.”

The conclusions are based on a global survey of more than 5,200 IT and cybersecurity practitioners in June. Costs for SMBs (firms with up to 999 employees) that disclose a breach are estimated at $93,000 (all figures in U.S. funds), while their peers that had an incident leaked to the media suffered $155,000 in damage.

The same is the case for enterprises. Those that voluntarily inform their audiences about a breach experienced less financial damage (28 per cent) than those whose incidents were leaked to the press – $1.134 million compared to $1.583 million.

In North America, around half (48 per cent) of businesses that responded to the survey revealed a breach proactively. In contrast, 27 per cent of organizations that had experienced a data breach preferred not to disclose it. A quarter (25 per cent) of companies tried to hide the incident but saw it leaked to the media.

Kaspersky also said that identifying a breach early gives businesses a much better chance of avoiding unexpected public disclosure. For example, 29 per cent of SMBs that took over a week to discover a breach said they saw it exposed in the press, compared to nearly half of that (15 per cent) if the breach is detected almost immediately. It’s a similar case for enterprises, with these figures standing at 32 per cent and 19 per cent respectively. “The pressure on speed when it comes to data breach discovery and reaction, therefore impacts both costs and reputational damage caused by public disclosure,” says the report.

In the U.S. and Canada, 39 per cent of those who proactively disclosed a breach said they reported the breach almost immediately, while 48 per cent said it took up to a week, and 50 per cent said it took over a week to disclose.

Note that the survey covers the public acknowledgment of a breach. In some jurisdictions, companies may have an obligation to report a breach of security controls to a regulator, but not to the public.


Here’s a link to the full report. Registration required.

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

Howard Solomon
Howard Solomon
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times. I can be reached at hsolomon [@] soloreporter.com

Featured Articles

Cybersecurity in 2024: Priorities and challenges for Canadian organizations 

By Derek Manky As predictions for 2024 point to the continued expansion...

Survey shows generative AI is a top priority for Canadian corporate leaders.

Leaders are devoting significant budget to generative AI for 2024 Canadian corporate...

Related Tech News

Tech Jobs

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

Tech Companies Hiring Right Now