Should companies care about privacy breaches?

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Large companies do not have an economic incentive to prevent privacy breaches occurring, according to researchers from Harvard and Carnegie Mellon Universities this week.

The researchers studied 78 breaches from 2000 to 2006 in publicly traded companies, and looked at whether there was any major change in the stock price. Overall, stock dipped sharply on the first and second days after a breach was revealed, but started to climb on the third, and eventually reached pre-breach levels.

On average, companies had just under $10m (£5.5m) wiped from their stock price over the two days after the breach, leading the researchers to question whether there was any economic reason in terms of share price for companies to implement measures to stop privacy breaches.

"The potential costs for the company in terms of share price may not be enough of an incentive. Should companies care?" asked researcher Allan Friedman, who appeared at the Workshop on the Economics of Information Security at the University of Cambridge on Wednesday.

If companies have to implement privacy procedures, hire lawyers to ensure compliance and track backup tapes, it may cost more to prevent privacy breaches than ensure they don't happen, Friedman told ZDNet UK.

Recently, there has been a proliferation of customer privacy breaches, where confidential customer information is leaked through lost or stolen equipment, hacking, or insider attacks. It can often lead to identity theft. ChoicePoint, Time Warner, Ernst and Young, Medical Excess and UPS are all examples of companies whose sensitive customer information was exposed through such incidents.

Both Friedman and fellow researcher Alessandro Acquisti stressed that companies need to consider other possible fallout from privacy breaches aside from the minimal effect on share price.

"There could be [contractual] liabilities, fines, loss of reputation, loss of sales and loss of partnerships," said Acquisti.

The researchers said that it was difficult to take into account all these factors when calculating the total economic damage to a company compared with the cost of trying to guard against privacy breaches, because of the difficulties of measuring the effect of loss of reputation.

"It's a harder case to show the total expected value [of preventing privacy breaches] is negative," added Friedman.

Security experts from encryption vendor PGP Corporation agreed that it would be difficult to measure the overall effect of privacy breaches on a company.

"It's very hard to measure how much it loosens up customers," said Jon Callas, chief technical officer for PGP Corporation. "Some say 'I'll leave immediately', some don't. It's hard to establish how this leads to loss of revenue."

Callas also argued that preventing security breaches can be relatively inexpensive.

"For example, if someone loses a laptop containing sensitive information. Having encryption on that laptop would have stopped the breach, as would deploying encryption throughout the company in backup procedures, tapes and storage. If everything is encrypted properly you don't have to worry if a tape is lost," Callas claimed.

Talkback

Sigh. The 'encryption' solves everything sales talk again. If 'encryption' is really such a total solution for everything then I'm sure your 'encryption' supplier wouldn't mind signing a little contract that states then whenever your administration reveals an 'encryption' breach the 'encryption' supplier will pay out up front, no questions asked, $1,000,000,000.00 per occurance.

What? They don't? Wow, very sure of themselves, aren't they? It's OK to put your assets on the line, but theirs? Excuse me, but talking the talk doesn't mean anything to me if you don't walk the walk. Put your money where your mouth is, it's as simple as that.

via Facebook 30 June, 2006 22:26
Reply

What kind of stupid question is "Should companies care about privacy breaches?" Of course they should, just like factories in the 1890s should have cared about 10-year old workers losing arms in machines.

The problem is that neither laws nor insurance companies financially compel them to do so. As long as we lack any meaningful privacy laws and politicians keep getting paid to keep it that way, the situation is unlikely to change.

And indeed, encryption is not a 100% solution. You can use a trivial algorithm or use a good algorithm badly. However, using even something like PGP to encrypt the data raises the bar high enough as to make cracking it technically infeasible for all but the most committed criminals, you know, the ones with PhDs in Mathematics and an army of Crays at their disposal. Certainly it would make it harder than many companies' current state of the art, which is to leave the data in the cleartext on a laptop computer in a car.

via Facebook 2 July, 2006 18:33
Reply

I'm very curious as to whether the data would be the same for 2005-2006, when there has been much more attention focused on these issues. 2000 was the prehistoric era for security breaches, in terms of identity theft risk, media attention, regulatory requirements, etc. I think risks and costs for companies are much more significant today. Whehter that translates to stock price, I don't know.

via Facebook 6 July, 2006 17:53
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

5 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

6 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

12 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

16 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

17 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

22 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

3 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround