<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; Data Breach</title>
	<atom:link href="http://blog.kraasecurity.com/tag/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>What is the value of a Data Breach?</title>
		<link>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/</link>
		<comments>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 02:33:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Citibank]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=174</guid>
		<description><![CDATA[Image by Getty Images via Daylife SC magazine just reported that the Ponemon Institute has determined the cost of a data breach is $204 per record. &#8220;Data breaches last year cost organizations $204 per exposed record on average, which represents an almost two percent increase over 2008, according to the fifth annual &#8220;Cost of  Data [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 160px;">
<dt class="wp-caption-dt"><a href="http://www.daylife.com/image/0fcc5b451yfWd?utm_source=zemanta&amp;utm_medium=p&amp;utm_content=0fcc5b451yfWd&amp;utm_campaign=z1"><img title="NEW YORK - MAY 20:  In this photo illustration..." src="http://cache.daylife.com/imageserve/0fcc5b451yfWd/150x100.jpg" alt="NEW YORK - MAY 20:  In this photo illustration..." width="150" height="100" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image by <a href="http://www.daylife.com/source/Getty_Images">Getty Images</a> via <a href="http://www.daylife.com/">Daylife</a></dd>
</dl>
</div>
</div>
<p>SC magazine just reported that the <a class="zem_slink" title="Ponemon Institute" rel="homepage" href="http://www.ponemon.org/">Ponemon Institute</a> has determined the cost of a <a title="Data breach, data loss prevention" href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">data breach </a>is $204 per record. &#8220;Data breaches last year cost organizations $204 per exposed record on average, which represents an almost two percent increase over 2008, according to the fifth annual &#8220;<strong>Cost of  Data Breach</strong>&#8221; study released on Monday by the Ponemon Institute&#8230;  The study, which examined the experiences of 45 U.S. companies that suffered breaches last year, also found that the number of data breaches that were caused by malicious attacks and botnets doubled from 12 percent in 2008 to 24 percent  in 2009. In addition, data breaches caused by malicious attacks cost organizations 30 to 40 percent more on average than those caused by human negligence or by IT system glitches.&#8221; There are a number of ways to protect your data in transit such as <a title="PGP Encryption, Email Encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products"><strong><span style="color: #888888;">PGP Encryption</span></strong> </a>but when the companies looses data, there isnt much the end user can do to protect themselves.</p>
<p>Thats a lot of money. If we look at the data breach of Heartland, which was over 100 million records, that, well let me do the math, may take a minute. Its $20,400,000,000. Thats a lot of money. Condidering I was a shopper mostlikely of Heartland, I do not recall getting a check from anyone for $204. I will not hold my breath for that. We all asked if the retailers like Heartland and <a class="zem_slink freebase/en/tj_maxx" title="T.J. Maxx" rel="homepage" href="http://www.tjmaxx.com/">TJ Max</a> had a <a title="PCI Audit" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI Audit</a> done. Would this have protected our information?</p>
<p>So far, I am pretty sure I recieved a letter offering me free 2 year credit monitoring from Chase, <a class="zem_slink freebase/en/citibank" title="Citibank" rel="homepage" href="http://www.citibank.com/">Citibank</a>, Bank of America and Countrywide because thet lost my records. I am waiting for my check for $204 from each of those companies. Also, over the past few years I have had to have my <a class="zem_slink freebase/en/credit_card" title="Credit card" rel="wikipedia" href="http://en.wikipedia.org/wiki/Credit_card">credit cards</a> replaced with Chase, American Express, and several Visa versions. So I am still waiting for those $204 checks. Maybe in total I am owed about 9x$204=$1,836.  That will be a nice check when I get it.</p>
<h2>Security Requirements</h2>
<p>So what can a company do to help reduce these data breaches? The easy answers, yet not implemented, include:<br />
1) <a title="Encryption, PGP Encryption" href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">Encryption</a> of <a title="data backup" href="http://www.kraasecurity.com/products/yotta280">back-up data </a>and tapes<br />
2) Conduct yearly <a title="Vulnerability Assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">Vulnerability Assessments </a><br />
3) Conduct Quarterly or Monthly <a title="Vulnerability Scanning" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">Vulnerability Scanning</a><br />
4) Implement a <a title="Data loss prevention " href="http://www.kraasecurity.com/consulting-services/network-solutions/data-loss-prevention-assessment">Data loss prevention solution</a><br />
5) Go through a <a title="PCI Audit" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI Audit </a>or <a title="HIPAA Assessment" href="http://www.kraasecurity.com/compliance/hipaa-assessment">HIPAA Security Assessment </a>yearly</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2256886/breach-costs-continue-rise">Data breach costs continue to rise</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-27080_3-10440220-245.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">Survey: Data breaches from malicious attacks doubled last year</a> (news.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2256724/breach-numbers-fall-while-costs">Breach numbers fall while costs rise Ponemon study finds</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://it.slashdot.org/story/10/03/15/1227223/Humans-Continue-To-Be-Weak-Link-In-Data-Security?from=rss">Humans Continue To Be &#8216;Weak Link&#8217; In Data Security</a> (it.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/01/cost-of-data-breach-204-per-record.html">Cost of a Data Breach &#8211; $204 per record</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://online.wsj.com/article/SB10001424052748704541004575011113352790040.html">Private Sector Keeps Mum on Cyber Attacks</a> (online.wsj.com)</li>
</ul>
<p>Regards<br />
Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></p>
<p><a onclick="pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f1ed6c34-1f2a-4642-b40c-ac12e03f3b45/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f1ed6c34-1f2a-4642-b40c-ac12e03f3b45" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/01/27/what-is-the-value-of-a-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

