I posted this also to the securitymetrics.org mailing list. Sorry if discussing in multiple venues ticks you off. The Not Obvious blog has an interesting write up on the Heartland Breach and impact. From the blog post: “Heartland has had to pay other fines to Visa and MasterCard, but the total of $12.6 million they [...]
Filed under: Data Analysis, metrics, Reports and Data by alex on Monday, December 21, 2009 | Social tagging: data breach cost > incident metrics > metrics
1 Comment »
The supplement provides case studies, involving anonymous Verizon clients, that detail some of the tools and methods hackers used to compromise the more than 285 million sensitive records that were breached in 90 forensic cases Verizon handled last year.
Filed under: Reports and Data by Russell on Wednesday, December 9, 2009 | Social tagging: data breach > data breach cost > DBIR
No Comments »
Near misses are very valuable signals regarding future losses. If we ignore them in our cost metrics, we might make some very poor decisions. This example shows that there is a qualitative difference between “ground truth data” (in this case, historical cash flow for data breach events) and overall security metrics, which need to reflect our estimates about the future, a.k.a. risk.
Filed under: Science of Risk Management by Russell on Tuesday, October 6, 2009 | Social tagging: data breach cost > risk management > risk modeling
6 Comments »