An IBM-commissioned study by the Ponemon Institute reveals new insights into how organizations in the Middle East and around the world are being impacted financially as a result of data breaches — and whether enough is being done to prevent these attacks from getting worse.
Across the globe there are almost daily reports of corporate data breaches and stolen information. Many experts have also chimed in along the way. Yet during the last year, we have spoken to many organizations across the Gulf region that still question how relevant these threats really are, and how significant they would be to their own company’s bottom line.
The latest Cost of Data Breach Study commissioned by IBM and conducted by the Ponemon Institute, found that globally the average cost of a data breach actually increased 15 percent in the last year. Perhaps even more surprising is that the average cost of these incidences reached an astounding $3.5 million; far more than what many companies consider when evaluating cybersecurity threats. Organizations surveyed in the Middle East region — which in our case included respondents from the UAE and Saudi Arabia in particular — were pretty close to the global median with the average total cost at $3.11 million.
While some of these are direct costs, we also identified something called “lost business”; a fact that many organizations forget to account for. This includes the abnormal turnover of customers, having to increase customer acquisition activities, and reputational losses. Among the Middle East companies surveyed, we actually found that on average this “lost business” accounted for nearly half the total cost of all data breaches over the long term.
It is also important to consider the unique cultural aspects of the Middle East and the GCC region. This is a region that puts a great emphasis on trust, relationships, and reputation. Thus trust and customer loyalty are very important aspects of business, and a corporation’s reputational risk has a much deeper meaning.
Given this scenario, how can organizations better understand the types of data breaches that could impact their business, and how best to prevent such incidents in future.
One area we explored is recognizing why these data breaches are happening in the first place. Within the Middle East for example, 50 percent of the reported incidents involving data theft or criminal misuse as opposed to a system glitch or employee error. This is actually a higher percentage than the global average, and this category of incidents also happens to be the most costly type of data breach. Such recognition may seem simple, but they are tremendously important in guiding companies to adopt the right kind of external and internal security policies.
The study further revealed that certain industries may be impacted more than others. In the Middle East, organizations in the technology and retail field were for instance, far more likely to incur a data breach in contrast to energy and industrial companies.
Staying Afloat
Given all of this, one may think that the seriousness of such cyber threats is by now self-evident. However, that doesn’t seem to always be the case.
In fact, about half of the companies we surveyed globally were found to have low or no confidence that they are making the right investments in people, process and technologies to address potential and actual threats. Only 38 percent of the organizations surveyed globally reported to even have a security strategy to protect their IT infrastructure.
One problem is too many organizations are addressing the issue with multiple, disjointed security solutions. They may use antivirus software to weed out malware and firewalls to keep the bad guys out, but these systems do not communicate with each other in an intelligible way.
Within the Middle East, we found that the most profitable security investments include having an incident response plan, understanding your environment (data classification, access rights and environment risks), and also the appointment of an information security leader with a clear responsibility for breach containment. On average companies would ideally like to invest $14 million over the next 12 months to execute their organization’s security strategy. Regrettably, in the same 12-month period these companies anticipate having only about half that amount to invest.
What does this mean for the future? Cyber threats have clearly grown in both volume and complexity over the past few years, with the brash sophistication of recent attacks elevating the conversation from the IT room into the boardroom. Despite the business value of this critical enterprise data, it seems as though more needs to be done to help organizations recognize what their most signification information is, where it resides, and how it can be protected.
—
Tamer Aboualy is CTO Security Services at IBM MEA.
Avoiding the pitfalls of a corporate data breach



