Enterprise Strategy Group | Getting to the bigger truth.TM

Interesting Data about Data Breaches

In a recent ESG Research survey, we asked security professionals at enterprise organizations (i.e., 1,000 employees or more) whether their organization had suffered a data breach within the last year. Here are the results:

Yes, several incidents: 11%
Yes, one incident: 23%
No: 63%
Don’t know: 3%

My analysis:

  1. In total, 34% of these enterprise organizations suffered at least one breach. This is consistent with other ESG Research surveys over the past 5 years, indicating that the data breach problem is not getting any better.
  2. Curiously, organizations that must comply with more than three government or industry regulations suffered more breaches (19% of those organizations surveyed suffered more than one breach) than those that must comply with less than three government or industry regulations (6% of those surveyed suffered more than one breach). The obvious explanation is that the definition of a data breach is driven by regulatory compliance, thus the more compliance mandates, the more potential data breach incidents. This makes logical sense, but there is also an underlying cause for concern. Those organizations mandated to comply with lots of government and industry regulations tend to be the biggest organizations with matching IT and security budgets. If this is true, than the data indicates that large security budgets and resources do not necessarily equate to fewer data breaches.
  3. Thirty percent of federal, state, and local government organizations suffered more than one data breach over the past year. This is significantly higher than the cumulative average of 11%.

Related posts:

  1. Expect More Data Security Focus — and Legislation — in 2010
  2. Data Breach activity is getting worse
  3. I’ll give you 1.2 billion reasons to encrypt your backups
  4. The Top Three Risks to Confidential Data
  5. Federal data breach highlights difficulties of data security

Tags: data breach, , local government, regulatory compliance, state government

All views and opinions expressed in ESG blog posts are intended to be those of the post's author and do not necessarily reflect the views of Enterprise Strategy Group, Inc., or its clients. ESG bloggers do not and will not engage in any form of paid-for blogging. Click to see our complete Disclosure Policy.

Add a comment

Search
© 2010 Enterprise Strategy Group, Milford, MA 01757 Main: Fax:

Switch to our mobile site