34

Click here to load reader

Webinar: Business Impact of a Breach...And What You Can Do About It

  • Upload
    flexera

  • View
    88

  • Download
    2

Embed Size (px)

Citation preview

Page 1: Webinar: Business Impact of a Breach...And What You Can Do About It

BUSINESS IMPACT OF A BREACH… AND WHAT YOU CAN DO ABOUT IT

Page 2: Webinar: Business Impact of a Breach...And What You Can Do About It

S R . A N A LY S T, F O R R E S T E R

GUEST SPEAKER:

HEIDI SHEY

Page 3: Webinar: Business Impact of a Breach...And What You Can Do About It

3© 2 0 1 7 FORRES TER. RE P ROD U C TI ON P ROH I B I T ED.

>>Click here to Watch this Webinar On Demand Now<<

Page 4: Webinar: Business Impact of a Breach...And What You Can Do About It

4© 2017 FORRESTER. REPRODUCTION PROHIBITED.

- NPR, September 26, 2017

Page 5: Webinar: Business Impact of a Breach...And What You Can Do About It

5© 2017 FORRESTER. REPRODUCTION PROHIBITED.

- eSecurity Planet, April 10, 2015

- NPR, September 26, 2017

Page 6: Webinar: Business Impact of a Breach...And What You Can Do About It

6© 2017 FORRESTER. REPRODUCTION PROHIBITED.

- eSecurity Planet, April 10, 2015

- Reuters, June 23, 2017

- NPR, September 26, 2017

Page 7: Webinar: Business Impact of a Breach...And What You Can Do About It

7© 2017 FORRESTER. REPRODUCTION PROHIBITED.

- eSecurity Planet, April 10, 2015

- Reuters, June 23, 2017

- NPR, September 26, 2017

- DarkReading, July 25, 2017

Page 8: Webinar: Business Impact of a Breach...And What You Can Do About It

8© 2017 FORRESTER. REPRODUCTION PROHIBITED.

› Image of complicated math

Page 9: Webinar: Business Impact of a Breach...And What You Can Do About It

9© 2017 FORRESTER. REPRODUCTION PROHIBITED.

$1.6M settlement. Much of the

settlement goes to insurance. Consumers take

home only $400K; $1.2M goes to lawyers fees.

$115M settlement. 2 years of credit

monitoring for all people affected, or up to $50

cash to affected people who are already enrolled

$5.5M paid to 31 states. Settlement required updates to its security

practices, disclosure of data collection practices.

Page 10: Webinar: Business Impact of a Breach...And What You Can Do About It

10© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Response and notification

Estimated cost range

Customer-facing breach

notification and response

$5-$10 per individual generally, but ranges

from $1-$40

Incident response and

investigation

$20K-$10M or more; hourly rates range from

$250-$550

Public relations crisis

management servicesHourly rates range from $200-$500

Page 11: Webinar: Business Impact of a Breach...And What You Can Do About It

11© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Lost employee productivity and turnover

Estimated cost range

Cost of new CISO, CPO or

security hire

Example CISO salary ranges: EU, €200K to

€1 million (£171K to £853K). US, $223K

(median) to $420K+

CPO salaries: median salary of $171,000

globally and $191,000 in the US

Cost of employee turnoverPer employee, estimate 21% of annual

salary in total

Recruiting services for hiring

CISO, CPO, security staff

Placement fees can run anywhere from 20%

to as high as 50% (for a senior exec or hard

to fill role) of a new hire’s annual salary

Page 12: Webinar: Business Impact of a Breach...And What You Can Do About It

12© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Lawsuits and settlements; regulatory fines+response

Estimated cost range

Legal fees/third-party breach

counsel

Rates can range from $380 to $1,200 per

hour

Legal settlementsHighly variable: from a few thousands to

hundreds of millions of dollars.

Regulatory fines $0 to a % of annual revenue

Page 13: Webinar: Business Impact of a Breach...And What You Can Do About It

13© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Additional audit requirements; other liabilities

Estimated cost range

Remediation cost of additional

security requirementsHighly variable: $0 to X millions

Cost of an independent third-

party security audit$10,000 to $120,000 or more

Other liabilities

Highly variable (e.g., discounts, gift cards,

reduced acquisition cost, renegotiated

deals, etc.)

Page 14: Webinar: Business Impact of a Breach...And What You Can Do About It

14© 2017 FORRESTER. REPRODUCTION PROHIBITED.

What decreases or increases the cost of a breach?

>>Click here to Watch this Webinar On Demand Now<<

Page 15: Webinar: Business Impact of a Breach...And What You Can Do About It

15© 2017 FORRESTER. REPRODUCTION PROHIBITED.

What decreases or increases the cost of a breach?

Cyber insurance

Incident response planning

Breach notification services

Encryption

Page 16: Webinar: Business Impact of a Breach...And What You Can Do About It

16© 2017 FORRESTER. REPRODUCTION PROHIBITED.

What decreases or increases the cost of a breach?

Cyber insurance

Incident response planning

Breach notification services

Encryption

New audit requirements

Need for new technology

Noncompliance with regulation

Lack of transparency with customers

Page 17: Webinar: Business Impact of a Breach...And What You Can Do About It

17© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Data is the gift that keeps on giving…

Firm Data

Business intelligence

Customer intelligence

Customer experience

Innovation

Page 18: Webinar: Business Impact of a Breach...And What You Can Do About It

18© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Data is the gift that keeps on giving…to everyone

Business intelligence

Customer intelligence

Customer experience

Innovation

Firm Data Criminal

Ransom

Blackmail

Fraud/ID theft

Resale

Page 19: Webinar: Business Impact of a Breach...And What You Can Do About It

19© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Costs

Page 20: Webinar: Business Impact of a Breach...And What You Can Do About It

20© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Value

Data

Relationships

Reputation

Morale

Page 21: Webinar: Business Impact of a Breach...And What You Can Do About It

21© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Q2 2016 sales were down

26% from Q2 2015 sales

Breach-related costs of

$87.5 million and Q4 2017

profit losses of 27% YoY

Reputational damage has top line consequences

Page 22: Webinar: Business Impact of a Breach...And What You Can Do About It

22© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Top causes of external attacks in 2017

Page 23: Webinar: Business Impact of a Breach...And What You Can Do About It

23© 2017 FORRESTER. REPRODUCTION PROHIBITED.

ResponsePrevention

Detection

Response

Page 24: Webinar: Business Impact of a Breach...And What You Can Do About It

FORRESTER.COM

Thank you© 2017 FORRESTER. REPRODUCTION PROHIBITED.

Heidi Shey

+1 617-613-6076

[email protected]

Page 25: Webinar: Business Impact of a Breach...And What You Can Do About It

“PREVENTION IS BETTER THAN CURE”

- Desiderius Erasmus

>>Click here to Watch this Webinar On Demand Now<<

Page 26: Webinar: Business Impact of a Breach...And What You Can Do About It

Prevention is the Foundation of Security

PREVENTION:

Reduce the Risk of a Breach

Prevention

Detection

ResponseYou’ve Been

Breached!

Pre-Breach

26

Page 27: Webinar: Business Impact of a Breach...And What You Can Do About It

2 Key Prevention Strategies

1. Reduce the “Attack Surface” – SAM Teams

2. Close the “Risk Window” –

Security and Operations Teams

27

Page 28: Webinar: Business Impact of a Breach...And What You Can Do About It

© 2017 Flexera | Company Confidential

REDUCE THE ATTACK SURFACE

• Rationalize and Consolidate the Software Portfolio

• Remove or Upgrade End of Life Software

• Eliminate Unauthorized Software

© 2017 Flexera | Company Confidential 28

Page 29: Webinar: Business Impact of a Breach...And What You Can Do About It

© 2017 Flexera | Company Confidential

D I S C L O S U R E T O

A W A R E N E S S

A W A R E N E S S T O

R E M E D I A T I O N

Close the Risk Window – with Software Vulnerability Management

29

DAYS186

DISCLOSURE AWARENESS REMEDIATION

D

99%Exploit known

vulnerabilities

30Days to first

exploitation

Page 30: Webinar: Business Impact of a Breach...And What You Can Do About It

© 2017 Flexera | Company Confidential

VULNERABILITYINTELLIGENCE

TIME TO AWARENESS GAP

C L O S E T H E R I S K W I N D O W …

30

Page 31: Webinar: Business Impact of a Breach...And What You Can Do About It

© 2017 Flexera | Company Confidential

VULNERABILITY ASSESSMENT & PATCHING

AWARENESS REMEDIATION GAP

C L O S E T H E R I S K W I N D O W …

31

Page 32: Webinar: Business Impact of a Breach...And What You Can Do About It

© 2017 Flexera | Company Confidential

WE’RE REIMAGINING THE WAY SOFTWARE IS

BOUGHTSOLDMANAGEDSECURED

32

>>Click here to Watch this Webinar On Demand Now<<

Page 33: Webinar: Business Impact of a Breach...And What You Can Do About It

Q & A

READ THE FORRESTER REPORT: CALCULATE THE BUSINESS IMPACT AND COST OF A BREACH

AVAILABLE ON OUR WEBSITE – HTTPS://INFO.FLEXERASOFTWARE.COM/SLO-WP-CALCULATE-IMPACT-DATA-BREACH-COST

33

Page 34: Webinar: Business Impact of a Breach...And What You Can Do About It

© 2017 Flexera | Company Confidential

THANKS FORATTENDING!

[email protected]

www.flexera.com/Enterprise

34

>>Click here to Watch this Webinar On Demand Now<<