It may be hard to find the good news in a security report placing the average data breach cost at almost $5 million, but IBM researchers did see at least one reason for optimism: Companies are more frequently detecting their breaches.
In a study of more than 600 organizations in 16 countries that suffered a data breach between March 2023 and February 2024, the IBM team found that security pros and their tools discovered their compromises at a greater rate than previous years. And self-discovery has its savings: When an attacker disclosed a breach, the median cost reached $5.53 million, compared to $4.55 million when an in-house security team made the discovery.
“The faster you can identify and the faster you contain, the less harm that’s done to you, your company, and your customers, potentially,” Diana Kelley, CISO at cybersecurity company Protect AI (and former global executive security advisor at IBM), said on an August 13 presentation from IBM.
Got ID? Forty-two percent of IBM’s studied organizations spotted the compromise themselves—an increase from 33% last year. Also, the resident defenders had slightly quicker reflexes, taking, on average, 194 days to spot a breach, compared to 2023’s ID time of 204 days. The mean time for security teams to identify and contain a breach fell to 258 days—a seven-year low, according to the report.
Read the rest here.—BH
|