https://www.miningweekly.com

Cost of data breaches rising, says IBM Security

11th August 2023

By: Schalk Burger

Creamer Media Senior Deputy Editor

     

Font size: - +

Cybersecurity company IBM Security’s ‘Cost of a Data Breach 2023’ report shows that the average total cost of a data breach for South African organisations increased by 8% over the past three years, reaching R49.45-million this year, which is an all-time high.

The average cost of a data breach has also increased by 73% since the report series started studying South Africa’s data eight years ago.

The average total cost of data breaches per record reached an all-time high at R2 750, which is a 20% increase from R2 300 in 2021, said IBM South Africa GM and technology leader Ria Pinto.

The financial sector experienced the highest average total costs of data breaches at R73.1-million. The industrial sector saw average total costs of data breaches at R71.37-million and the services sector reached R58.78-million.

The bulk of cyber threats were the results of stolen or compromised credentials constituting 14% of the initial attack vectors and phishing scams constituting 14% of the initial attack vectors. Attacks through compromised business emails were second at 12%, and attacks owing to cloud misconfiguration were third at 11%, she highlighted.

Further, detection and escalation costs reached R20.88-million, which is the highest portion of breach costs and indicates a shift towards more complex breach investigations. This was followed by costs associated with lost business at R13.56-million, post-breach responses at R13.29-million and notifying relevant stakeholders at R1.72-million.

Globally, the study also found that 95% of studied organisations, including South African organisations, have experienced more than one breach. Further, breached organisations were more likely to pass incident costs on to consumers (57%) than to increase security investments (51%).

More than 51% of data breaches studied resulted in data loss across multiple environments, including public cloud, private cloud and on-premises, showing that attackers could compromise multiple environments while avoiding detection. Data breaches impacting multiple environments also led to higher costs, of R51.49-million on average.

Additionally, organisations across all industries that had a high-level incident response (IR) team saw the average cost of a data breach of R2.96-million and those that had a robust IR plan with regular testing in place saw the average cost of a data breach of R2.92-million, which are lower than those studied with a low level or no use of an IR approach.

“The financial sector is the most targeted. Organisations should look to modernise their perimeter security strategies to enhance protection of their financial data by using zero-trust security solutions, underpinned by artificial intelligence (AI) and automation, to increase their cyber resiliency, manage the risks and comply with strict data privacy policies such as the Protection of Personal Information Act,” she advised.

Further, AI and automation had the biggest impact on speed of breach identification and containment for studied organisations. In South Africa, organisations with extensive use of both AI and automation experienced a data breach lifecycle that was 95 days shorter compared with studied organisations that did not deploy these technologies, or 190 days using AI and automation versus 285 days without, and only 28% of studied organisations have extensively implemented security AI and automation.

“Organisations in the report that deployed security AI and automation extensively saw, on average, nearly R10.49-million lower data breach costs than organisations that did not deploy these technologies, which is the biggest cost saver identified in the report. Further, with nearly 29% of organisations not yet deploying security AI and automation and 43% using them sparingly, most organisations still have a considerable opportunity to boost detection and response speeds,” Pinto noted.

Edited by Chanel de Bruyn
Creamer Media Senior Deputy Editor Online

Comments

The content you are trying to access is only available to subscribers.

If you are already a subscriber, you can Login Here.

If you are not a subscriber, you can subscribe now, by selecting one of the below options.

For more information or assistance, please contact us at subscriptions@creamermedia.co.za.

Option 1 (equivalent of R125 a month):

Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine
(print copy for those in South Africa and e-magazine for those outside of South Africa)
Receive daily email newsletters
Access to full search results
Access archive of magazine back copies
Access to Projects in Progress
Access to ONE Research Report of your choice in PDF format

Option 2 (equivalent of R375 a month):

All benefits from Option 1
PLUS
Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.

Already a subscriber?

Forgotten your password?

MAGAZINE & ONLINE

SUBSCRIBE

RESEARCH CHANNEL AFRICA

SUBSCRIBE

CORPORATE PACKAGES

CLICK FOR A QUOTATION