Skip the navigation
News

IT pros say data breach assessment is more valuable than notification, study says

The study was published as the EU proposed 24-hour data breach disclosure deadlines

By Lucian Constantin
January 25, 2012 12:27 PM ET

IDG News Service - IT professionals believe that assessing the potential harm caused by data breaches is more useful to mitigating the effects of such incidents than notifying affected individuals, according to a survey published on the day the European Union's proposed a 24-hour deadline for data breach disclosures.

Entitled "Aftermath of a Data Breach," the study was sponsored by information services company Experian and was conducted by the Ponemon Institute, which surveyed 584 experienced IT professionals working for companies that suffered a data breach involving consumer records during the past 24 months.

The questions asked by the Ponemon Institute tried to establish the circumstances leading to the data breach, the company's response and the incident's impact on the affected organization's data protection practices.

One of the study's most interesting conclusions was that while notifying victims and regulators are the most common steps taken by companies in the aftermath of a data breach, IT professionals don't view them as the most important actions for reducing the negative consequences of such incidents.

Only 6 percent of survey participants said that victim notification is helpful for reducing the impact of a breach, a significant change of opinion compared to 2007 when 54 percent of IT professionals chose it as an important mitigation step.

Retaining outside legal counsel, carefully assessing the harm to victims and hiring forensic experts to investigate the breach were viewed as the most valuable actions a company can take in the aftermath of a breach by approximately half of respondents.

By comparison, contracting computer forensic experts was considered important by only 5 percent of survey participants in 2007. This suggests that IT professionals today are much more interested in learning how a breach happened before taking action.

Legislators in both the U.S. and the European Union are pushing for legislation that would require companies to alert victims about data breaches in a more timely and uniform manner.

The European Commission proposed significant changes to the E.U.'s data protection laws Wednesday that include a 24-hour deadline for companies to report data breaches. While the proposal was largely welcomed by consumer protection groups, it attracted criticism from the U.S. Department of Commerce and business associations, which described the deadline as too short.

The Aftermath of a Data Breach survey also revealed that, despite making improvements to their data breach response practices, companies still have a long way to go as far as prevention is concerned. Only half of respondents believed that their companies made the best possible effort to protect customer and consumer information in advance of a data breach.

Negligent staff, disgruntled employees and third-party contractors remain the primary source of data breaches. Despite the large wave of cyberattacks that targeted companies last year, only 7 percent of respondents named such attacks as the cause for a data breach in their organization.

According to the study, companies continue to avoid offering free credit monitoring or identity protection services to data breach victims, and when such services do get offered, they rarely exceed periods of one year.

Nearly half of respondents said that their companies suffered data breaches that involved log-in credentials and credit card or bank payment information. Sixty percent of them said that the data was not encrypted, while 16 percent were unsure.

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Cybercrime and Hacking White Papers
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
Protecting Point of Sale Systems from Targeted Attack
If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
From the Frontline - Preventing APT
Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
Stop Hackers Before They Attack
Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
The four rules of complete web protection
As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time...
All Cybercrime and Hacking White Papers
Cybercrime and Hacking Webcasts
WikiLeaks: How am I Affected?
The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard
Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
Banish Poor Application Performance
End User Experience, 30-Min Webinar
Wed. March 21st ~ 11 AM ET

Are you ready to gain the proactive ability to rapidly respond...
Virtualization KnowledgeVault
Virtualization initiatives are underway at most small and midsize businesses, but some unexpected challenges have prevented many organizations from achieving original goals. This...
Mobility KnowledgeVault
How "mobile ready" is your infrastructure? This Mobility Knowledge Vault provides a wide variety of expert advice on how to strike a balance...
All Cybercrime and Hacking Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs