Cost of Breaches – John Dwyer, IBM
John Dwyer, IBM Security X-Force, assesses the cost of breaches for organizations in today’s industry.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with John Dwyer, who's head of research for X-Force at ibm, and we're talking about a new report that they've come up with that analyzes what the cost of a breaches these days, and they've been at this for a while, so let's just dive in because they have some new and interesting insights.
John, welcome to the show. Thank you, Mike. Happy to be here.
I love this report. It's great because it kind of quantifies some of the risk out there for organizations, And it seems like there are immediate costs and softer costs and how we have to analyze all that. And some folks will be more interested in the immediate cost versus the softer costs.
But how do we go about assessing the total cost of a breach? Because sometimes I feel like it's in the eye of the beholder. True.
Yeah. So the, the overall cost of the, the breach, right, could be introduced through many different areas. There is the functional cost of responding to the breach, which has been an increasing cost year over year.
So like the actual incident. So the people process and technology that you have to introduce time, you have to spend into containing and remediating the breach that is getting more ex more and more expensive year over year. Um, because the investigations are becoming more complex, there's a lot more rioting on the results of that investigations, right?
So there's more cyber insurance involved, there's more lawyers that are involved, there's more regulations that are involved. And so you, the breadth and depth of the investigation has to increase alongside at the time because there's more breaches, more investigations, more expensive, yada, yada yada. Then there's also, you know, just the operational costs of the, the threat landscape.
You know, everything's moving to disruptive or destructive. And so by having an incident that often incurs a cost into yourself as well, in terms of regulatory or fines or litigation that may come out of that, there's a lot of different costs that are baked into that, that, um, what I like about that report is that those that read this often probably change their mindset of like, where, where's, where am I gonna incur costs if I have a data breach? And then you realize that it comes from a lot, a lot of different areas and, and you're kind of exposed in a lot of different areas by ha going through one of these crisis.
So you've done this report several times now. Um, what surprised you in this latest edition? Is there something that leapt out at you that said, wow, I didn't think that would happen, or, I bet folks didn't think about this?
I didn't think, I don't think anything really surprised me. There are data points in the report that I really love that I would like to touch on, right? So at, at a high level, for those of you who, who wanna get to or haven't got to read the report yet, um, like costs are up.
They've been continuing to go up 15% since 2020, um, because of the costs that are incurred through data breaches. Um, 57% of organizations have raised the costs of whatever they offer, good services, people, whatever that may be. Um, and then 51% of organizations have said that they're going to increase security budget as a result of data breaches, right?
So they are going to reinvest 51% split 50 50, right? Split are going to increase their security budget as a result to data breaches in the associated costs. Now, what I love about, and this is the number one message I think that is great about the, the analysis is that we also dive into what organizations can do to reduce that cost, right?
What are the, what are the things that are really gonna move the needle? And if you look at lower end, the tables there, it's a nice broken up table and it will show you like what is going to help reduce the cost the most and what is going to add to the cost. And what I love about the, the top five things that an organization can do to reduce the cost of the data breach are not transactional items.
Which means that it's not something that you just go and buy off the shelf and you're like, I'm done with security, right? It is five things that require a cultural shift of an organization to invest and do the security as in a journey and to adopt security into every aspect of their organization. Re like the realization that, you know, these risks are here, these risks are to stay, the stakes are too high.
So we need to, uh, include security into every avenue of our business. And organizations that do that get to, you know, reduce, get to the, enjoy the, you know, convenience of having their risk reduced by, I think, you know, I think on on the top five, the average is over $200,000 for each one of them. Like DevSecOps I think was like, you reduce the cost of your average data breach by $250,000.
And because we know this is year over year and we can expect a 15% growth just on past data, like that's an investment now that's gonna pay for itself in the future. I think that's so important to take away from this is that organizations really need to start thinking about or realizing that security is not a transactional thing. It's not something that you buy, it is something that you grow into, you mature into.
And as you add it in as not just a cost center center, but as a mechanism of this is how we do business, we do business securely at your organization, then you get to enjoy the benefits of that and reduce costs and reduce risks. I don't think this is transactional, but you can't walk down the street these days without somebody talking about generative ai. So mm-hmm.
Will that help us reduce the cost of managing a security breach? Cuz maybe we could figure out what was breached in a way we can understand, Right? Yeah.
So it was actually the fourth biggest mover, right? So AI automation, machine learning, advanced technologies like that when implemented well, now that is, that's the key there, Mike, is that all of those technologies are, if you want to use them properly, if you want to integrate them into your services and your cybersecurity strategy properly, that requires a long term strategy. Like you ha you real, it's not like, oh, I buy, you know, the cyber terminator at Walmart and he comes in and he fixes all my problems, right?
It's when you deploy these technologies, there's a lot of planning and maturity and um, kind of like onboarding work that you have to do to get the most out of those technologies. So it is, it is, while it is a product or something that you would purchase for an organization, the implementation to get the most out of it is a long-term strategy, right? You have to do that kind of work to assess where do you wanna identify the places in your network or your security strategy that you wanna introduce something like automation or ai, and then you will reduce your costs, right?
So we saw that, that it calls it out in the report that, you know, one of the biggest, uh, movers makers that you can do is adding automation to your detection and response, right? So the element of time is something that all organizations need to consider in in this report. It calls it out that the longer an attacker is in your network, the longer it takes you to detect a breach, the more expensive it is at the end.
In our regular security analysis, we know that, you know, ransomware or an extortion based attacks are happening faster than ever before. So your window opportunity is closing time is an element that is now a new avenue of pressure for defenders. Um, and so we need to understand that tools like ai, machine learning, natural language process, all these kind of things, there are areas in our security that we can implement them that are going to reduce the time and make us more efficient and therefore reduce our costs.
But you gotta do a lot of legwork to get the most out of them. Is it your sense that the bad guys are getting more sophisticated and smarter, or is it just that we have a much broader attack surface to defend and there's just not enough resources to go around? So we're seeing more of these breaches?
Well, yes. I mean, I, I do think like, so it is impressive. Like you, you have to understand and give credit or credits due that the cyber criminals available to grow a global business as big as they have and keep it operational for so long that they, they do understand, like while we haven't, from a technical point of se, uh, point of view, seen a ton of innovation from the attack point of view, like there's not much difference of an extortion based attack in 2020.
There it is in 2023, the attacks are generally the same. They're, they have the same goals and objectives and at the end of it, it's an extortion based attack. But they are, you can't call that, you can't say that they're not sophisticated if you look at how many different moving parts there are to a global criminal syndicate, right?
So they are more advanced, they are getting more efficient, they understand who is going to pay where they want to target. Um, so that's part of it, right? But in the attack types, if you look in the report, phishing credentials, exploitation of web services has remained the same.
So they're getting in the same way. The attacks are generally the same. Um, so there's not a ton of sophistication in there.
I think what the compounds that is the increased complexity into people's, uh, operation, their organizations and in their environments, like we call that out as well. It's like when there is a data breach that occurs across multiple different environments, so hybrid cloud, multiple different cloud on-prem, the more the bigger and the more complex the environment becomes, then the potential cost for the breaches increases, right? Because you need to do more investigations, longer investigations, there's more attack attack surface given the expansion of organizations into cloud or hybrid cloud or on-prem or adding new services to enable more remote work or any of those kind of things that have all kind of happened in these last few years that have contributed to, you know, the situation that we're in right now As we kind of think about this, um, are we shifting our mindsets to think about the risks and managing according to risks?
I mean, we talk about this all the time, but I'm curious, you know, are we seeing organizations shift their mentality? Because we were so heavily invested in trying to defend everything, and I think it was Frederick the great that said, he who defends everything, defends nothing. So are we getting smarter about how we approach this whole thing?
So I do, we do have a bit of positive news, right? And I love to call this out. So, um, outside of the cost of the data breach report, we have as we release something called the threat intelligence index.
And there's a very important data point in there in that for the first time over the last few years, we saw an improvement in our client's ability to detect, uh, ransomware attacks before the ransomware was being deployed. So the investments into, you know, detection response, working with IR firms like interfacing with the security vendors that have insights into this pays off, right? Goes back into what we can do to move the needle into reducing the cost, is one of the things is called out there is, you know, interfacing with an IR team doing an IR plan and testing, right?
So assume breach, assume that you're gonna have an incident and then practice and identify gaps and improve through, you know, working with an IR team has tangible results, not only in your ability to prevent a crisis type of, uh, incident. Like if you stop a ransomware attack before ransomware is deployed, you still had an incident, but it's not a crisis and the cost goes down and then the, because you didn't have that crisis event, the overall investigation costs reduce and you don't have the disruption which reduces. So I think like we, there is a lot of evidence to suggest that we are moving things in the right direction.
We just have to continue to understand that this is the path of the new reality. The new reality is that we have to be as prepared as possible to handle an incident as efficiently and effectively as possible. Speaking of new realities, it seems like there's a lot of legislation floating around that has more accountability for, um, how data is managed in, in, in the event of a breach, there might be more penalties.
So will the total cost of a data breach start to continue to increase or can we bring it all down? That's, it's a interesting point, right? So in the data there that calls out like what are the differences in costs between a highly regulated environment and an unregulated environment, and where do those costs kind of distribute, right?
And what's what was interesting in there is that in unregulated environments, usually the upfront immediate cost is higher, but in the regulated environment, there's a tail to that cost where two years later, the highly regulated environment who had a data breach is still in current costs for that data breach that happened two years ago. So you can imagine a situation is if, you know, uh, I forget the data point in there, but more, I forget, X percent of organizations had more than one data breach in a year. Now, if you're in a highly regulated environment and you're incurring costs every two years at a time for every data breach and you have one to two data breaches every two years, then you can envision this reality in which you're carrying the debt of like an incident in perpetuity, right?
So those costs are gonna be compounding year over year. So it's really interesting to say, like, I, I do believe that there's, there we call it out there like whether or not regulation actually incurs more fines or anything like that, that really implements the total cost of it, but the long tail of regulatory requirements and a data breach, there is evidence to suggest that that is a long-term kind of cost. As we kinda look at some of the other regulations that are floating around, especially around data privacy, it seems like with data privacy, we will be required to manage data better.
And it seems to me at least that a lot of the root cause of our data security issues comes back to our lack of data management discipline. So do you think things will steadily improve as we address one? Will there be a side benefit for the other?
Yeah, so you're not wrong. I mean, data spillage and, and knowing, like we've been talking about the idea of data provenance forever. Like if you could identify at its root where a piece of data originated from, we could have a lot better handle on data management, right?
Because then you would know whether or not a piece of data should be where it is, right? It should be as close to the origin as possible, or at least be able to be tagged as such. Where I do think the application of advanced technologies like these generative ais and, and learning models is to help us understand where our data is constantly, um, which should be able to reduce the risk of associated with it, right?
Because you're absolutely right that if we had data security and data management completely buttoned up and we are encrypting data at rest everywhere or in transit everywhere, then the costs of the data breaches wouldn't go up, right? Because it would be re extraordinarily hard to steal data, right? And we wouldn't see adversaries moving towards data theft as an application of pressure, right?
So it's criminals they don't, they wanna find the path of least resistance to payment. If it's really hard for them to seal data, then they're not gonna do it. They're gonna move to a different way to elicit a payment out of some someone.
So I'm hopeful that we'll figure it out. Like I, I think that I'm, I'm hopeful that we'll figure it out using advanced technologies. Like we're right in this, this explosion of expanse, like of, of onboarding multiple different cloud environments.
And we have on-prem and usually organizations have cloud presences in every one of the major vendors. And so we've seen this expanse into ac uh, uh, growth into technology, into all these different platforms. Because of that, we've seen data expand further and further away from the core risk holder.
Um, and because of that data is more accessible except that I do think that we are, we, there's a path forward with advanced technologies to help us kind of start mitigating that. So based on everything you saw in the report, what's your best advice to folks? What's the thing that they should probably be focusing on today to maybe mitigate all this stuff tomorrow?
Um, based on the report, I really want people to pay attention to the quantified numbers of the reduction in the cost by investing in the right things. And that doesn't, and that means like fundamentally changing how we think about our incident response teams and incident response planning and how serious it is because it will save you at the end of the day, um, to start implementing using the data in here to implement a cultural shift towards securing, adding security into everything. Security is a fundamental operation of every single one of our business units going forward.
And because of that, we'll be able to reduce our risk. Um, and the second thing that I really wanna call out is the numbers of the reduced costs when involving law enforcement and notifying law enforcement. Whenever you have a data breach, the federal government specifically like the FBI, has radically changed, um, their tactics in which now they're carrying out offensive operations against these cyber criminals and organizations that notify law enforcement.
When you pair that with a professional incident response team, the costs dramatically reduce because the F B I is able to take actions offensively against organizations where only they're unable to do so. And so it is a, um, a, a phenomenal idea to, to, uh, incorporate them into your incident response plan. And the great thing about how, uh, when you include law enforcement is that it's a net win for everyone in the market.
All right, folks. Well, just like in any other part of the criminal empire, the def defeating crime starts with reporting it, and then we work our way backwards from there. John, thanks for being on the show.
Thanks, Mike. Always a pleasure. Thank you all for watching the latest episode in Techstrong tv and back to you guys in the studio.