<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The New School of Information Security &#187; data breach cost</title>
	<atom:link href="http://newschoolsecurity.com/tag/data-breach-cost/feed/" rel="self" type="application/rss+xml" />
	<link>http://newschoolsecurity.com</link>
	<description>The Blog Inspired By The Book</description>
	<lastBuildDate>Mon, 06 Feb 2012 16:09:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>NotObvious On Heartland</title>
		<link>http://newschoolsecurity.com/2009/12/notobvious-on-heartland/</link>
		<comments>http://newschoolsecurity.com/2009/12/notobvious-on-heartland/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 14:44:09 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Data Analysis]]></category>
		<category><![CDATA[metrics]]></category>
		<category><![CDATA[Reports and Data]]></category>
		<category><![CDATA[data breach cost]]></category>
		<category><![CDATA[incident metrics]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1207</guid>
		<description><![CDATA[I posted this also to the securitymetrics.org mailing list.  Sorry if discussing in multiple  venues ticks you off. The Not Obvious blog has an interesting write up on the Heartland Breach and impact.  From the blog post: &#8220;Heartland has had to pay other fines to Visa and MasterCard, but the total of $12.6 million they [...]]]></description>
			<content:encoded><![CDATA[<p>I posted this also to the securitymetrics.org mailing list.  Sorry if discussing in multiple  venues ticks you off.</p>
<p>The Not Obvious blog has an <a href="http://notobvious.info/the-bell-finally-but-softly-tolls-for-heartla">interesting write up on the Heartland Breach and impact</a>.  From the blog post:</p>
<blockquote><p>&#8220;Heartland has had to pay other fines to Visa and MasterCard, but the total of $12.6 million they have set aside to handle the one-time costs is a drop in the bucket compared $1.5 billion in 2008 revenue and does not really even skim much off the top of the $161 million in profits from that same year (the numbers for 2009 look to be tracking the same). It is almost a guarantee that any member of the class action who submits a claim will see many years of scrutiny before receiving any payment, something which Heartland can factor into their yearly financial plans (and accommodate for by increasing fees).&#8221;</p></blockquote>
<p><strong>For thought</strong>:</p>
<ol>
<li>One wonders how much a &#8220;sufficient&#8221; (loaded term, of course) InfoSec program for a company like Heartland costs on an annual basis.</li>
<li>Does this set a sort of &#8220;worst case&#8221; bounds to impact distributions?</li>
<li>If so, how does a worst case impact of ~$13million (US) impact security management at retailers (politically)?</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/12/notobvious-on-heartland/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>NEW: Verizon 2009 DBIR Supplement</title>
		<link>http://newschoolsecurity.com/2009/12/new-verizon-2009-dbir-supplement/</link>
		<comments>http://newschoolsecurity.com/2009/12/new-verizon-2009-dbir-supplement/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 07:04:25 +0000</pubDate>
		<dc:creator>Russell</dc:creator>
				<category><![CDATA[Reports and Data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach cost]]></category>
		<category><![CDATA[DBIR]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1177</guid>
		<description><![CDATA[The supplement provides case studies, involving anonymous Verizon clients, that detail some of the tools and methods hackers used to compromise the more than 285 million sensitive records that were breached in 90 forensic cases Verizon handled last year.

]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><a href="http://www.verizonbusiness.com/resources/security/reports/rp_2009-data-breach-investigations-supplemental-report_en_xg.pdf"><img class="aligncenter size-large wp-image-1178" style="border: white 5px solid" src="http://newschoolsecurity.com/wp-content/uploads/2009/12/verizon-DBIR-sup-1024x520.PNG" alt="verizon DBIR sup" width="502" height="255" /></a></p>
<p style="text-align: left">Full report is <a href="http://www.verizonbusiness.com/resources/security/reports/rp_2009-data-breach-investigations-supplemental-report_en_xg.pdf">here</a>.  A quick overview from a <em>Wired</em> magazine <a href="http://www.wired.com/threatlevel/2009/12/breaches-more-sophisticated/">article</a>:</p>
<blockquote><p>The supplement provides case studies, involving anonymous Verizon clients, that detail some of the tools and methods hackers used to compromise the more than 285 million sensitive records that were breached in 90 forensic cases Verizon handled last year.</p></blockquote>
<p>[Disclosure: Alex's paw prints are on this report somewhere.]</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/12/new-verizon-2009-dbir-supplement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cost of a Near-Miss Data Breach</title>
		<link>http://newschoolsecurity.com/2009/10/the-cost-of-a-near-miss-data-breach/</link>
		<comments>http://newschoolsecurity.com/2009/10/the-cost-of-a-near-miss-data-breach/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 20:11:42 +0000</pubDate>
		<dc:creator>Russell</dc:creator>
				<category><![CDATA[Science of Risk Management]]></category>
		<category><![CDATA[data breach cost]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[risk modeling]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=724</guid>
		<description><![CDATA[Near misses are very valuable signals regarding future losses.  If we ignore them in our cost metrics, we might make some very poor decisions.  This example shows  that there is a qualitative difference between “ground truth data” (in this case, historical cash flow for data breach events) and overall security metrics, which need to reflect our estimates about the future, a.k.a. risk.]]></description>
			<content:encoded><![CDATA[<div id="attachment_725" class="wp-caption alignright" style="width: 310px"><a href="http://www.tomandjerryonline.com/images/nearMiss.jpg"><img class="size-medium wp-image-725" src="http://newschoolsecurity.com/wp-content/uploads/2009/10/tom_and_jerry_near_miss-300x198.PNG" alt="Jerry escapes death, but is it cost-free?  (Image from tomandjerryonline.com)" width="300" height="198" /></a><p class="wp-caption-text">Jerry escapes death, but is it cost-free?</p></div>
<p>If one of your security metrics is Data Breach Cost, what is the cost of a near miss incident? This seemingly simple question gets at the heart of security metrics problem.</p>
<p>Consider the gleeful Jerry Mouse in this cartoon. Tom the Cat has just missed in his attempt to swat Jerry and turn him into mouse meat. Is there any cost to Jerry for this near miss? Is Jerry’s cost any different than if he was running with Tom no where in sight?</p>
<p>By “near miss” I mean a security incident or sequence of incidents that could have resulted in a severe data breach (think TJX or Heartland), but somehow didn’t succeed. Let’s call the specific near-miss event “NM” for short. For sake of argument, let’s assume that the lack of attack success was due to dumb luck or attacker mistakes, not due to brilliant defenses or detection. Let’s say that you only discover NM long after the events took place. For simplicity let’s assume that discovering NM doesn’t result in any extraordinary costs, meaning that out-of-pocket costs are the same just before and immediately after NM. Finally, assume that your expected cost of a successful large-scale data breach is on the order of tens of millions, with the worst case being hundreds of millions of dollars.</p>
<p>How much does NM cost?  The realist answer is “zero”.  (Most engineers are realists, by disposition and training.)  There is a saying in street basketball that expresses the realist philosophy about losses and associated costs: “No blood, no foul”.  If you ask your accountants to pour over the spending and budget reports, they will probably agree. Case closed, right?</p>
<p>Not so fast&#8230;.</p>
<p><span id="more-724"></span></p>
<p>The big problem with the realist approach is that it ignores the future and our rational expectations about future loss events. In other words, it ignores risk. It’s like the old joke about the guy who fell out of a 20-story building. As he passed the 4th floor, someone called out to him, “ARE YOU OK?”, to which he replied: “SO FAR, SO GOOD!!”. (Moments later… splat!)</p>
<p>We know intuitively that there is something wrong with the answer “so far, so good” when the signs of pending disaster appear.</p>
<p>Economists will arrive at a very different answer to account for this intuition. For economists, valuation and risk decisions are about the future, and especially about rational expectations about future cash flows and future valuations given available information. If you get significant new information that changes your expectations, then your risk and value metrics will change.</p>
<p>You could hardly imagine a more meaningful signal regarding risk than a near miss event. Safety engineers have known this for decades and it’s central to their practice.  (For example, see the book: <a href="http://www.amazon.com/Safety-Management-Qualitative-Systems-Approach/dp/0415303710/ref=sid_dp_dp#noop">Safety Management: A Qualitative Systems Approach </a>and the web page: “<a href="http://www.jmcampbell.com/february-2009">Three Simple Things to Improve Process Safety Management</a>”.)  What ever your estimation of risk before NM, it will probably go way up after NM.  Economists would argue that this increases your data breach costs, since your expectation of future cash flows has increased.</p>
<p>Does this economic cost of a data breach have any reality?  How could it be made tangible and meaningful for accountants and ordinary realistic managers?  Yes it can, through insurance. Imagine that your organization pays a regular insurance premium that is a probabilistic function of future data breach costs, based on all available information about likelihood and severity. (Assume either self-insurance or commercial insurance, or some combination. Assume “perfect pricing” and complete information sharing, etc.)  Forget about risk transfer. The purpose of insurance in this case is simply bringing the cost of risk into the present.</p>
<p>With this insurance in place, your data breach cost becomes not only the actual cash flows associated with loss events, but also the periodic insurance premiums, which would rise or fall based on risk factors and risk estimates. We are familiar with this from our experience with auto insurance, property and casualty insurance, etc.</p>
<p>The great advantage of this approach is that your data breach cost metrics will become a meaningful signal for management decision-making, performance management, and incentive instruments. All stakeholders will be more likely to pay attention to near misses and, hopefully, do their best to learn from them and mitigate risks.</p>
<p>Whether or not you buy into the details of the insurance mechanism, I hope that I have convinced you that there is a qualitative difference between “ground truth data” (in this case, historical cash flow) and overall security metrics, which need to reflect our estimates about the future, a.k.a. risk.</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/10/the-cost-of-a-near-miss-data-breach/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

