{"id":3759,"date":"2020-12-11T16:25:27","date_gmt":"2020-12-11T13:25:27","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=3759"},"modified":"2021-04-13T15:27:31","modified_gmt":"2021-04-13T12:27:31","slug":"a-look-at-data-breach-statistics-in-2020","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/a-look-at-data-breach-statistics-in-2020\/","title":{"rendered":"A Look at Data Breach Statistics in 2020"},"content":{"rendered":"<p>2020 has proved to be a challenging year from all points of view. With the health crisis brought on by the COVID-19 pandemic disrupting the worldwide economy and crippling both large and\u00a0small businesses,\u00a0cybersecurity\u00a0may have been the last thing on anyone\u2019s mind. However,\u00a0cybercriminals\u00a0took advantage of the chaos to increase\u00a0phishing\u00a0scams\u00a0and\u00a0malware\u00a0cyberattacks, cashing in on the relaxation of\u00a0security measures. As a consequence, 2020 has been a stellar year for\u00a0data breaches\u00a0and regulatory fines.<\/p>\n<p>The rushed adoption of widespread remote work policies in all sectors created large gaps in\u00a0data\u00a0security\u00a0measures\u00a0which resulted in an increase in\u00a0cybercrime\u00a0and\u00a0data breaches. According to\u00a0cybersecurity\u00a0company Malwarebytes\u2019\u00a0<a href=\"https:\/\/resources.malwarebytes.com\/files\/2020\/08\/Malwarebytes_EnduringFromHome_Report_FINAL.pdf\" target=\"_blank\" rel=\"noopener\">Enduring from Home: COVID-19\u2019s Impact on Business Security<\/a>\u00a0report, remote workers became the source of nearly 20% of\u00a0cybersecurity\u00a0incidents in 2020. Among the companies that answered their survey, 24% also faced unexpected expenses directly linked to\u00a0malware\u00a0attacks and a higher\u00a0number of\u00a0data breaches\u00a0due to work from home.<\/p>\n<p>The report also showed a worrying trend among remote workers of using their personal devices instead of their company-issued ones. 27.7% of respondents said they used their personal devices more than their work computers, with a further 31.2% admitting they sometimes used personal devices for work and checking\u00a0business emails. Only 39.1% strictly used only work-issued devices to perform their duties.<\/p>\n<p>Cybersecurity risks and information security threats associated with remote work were an increased likelihood of cybercrime due to unsecure internet connections, devices being exposed to access from unauthorized individuals, the difficulty of managing devices using remote work resources, and a decrease in the effectiveness of IT support carried out remotely.<\/p>\n<h2>Cost of a\u00a0data breach<\/h2>\n<p>According to the\u00a0IBM\u00a0and the\u00a0Ponemon\u00a0Institute\u00a0<a href=\"https:\/\/www.ibm.com\/security\/digital-assets\/cost-data-breach-report\/#\/\" target=\"_blank\" rel=\"noopener\">Cost of a\u00a0Data Breach\u00a0report\u00a02020<\/a>, which interviewed 3200 IT and\u00a0security professionals\u00a0working for 524 organizations in 17 countries and regions, the global\u00a0average cost\u00a0of a\u00a0data breach\u00a0reached $3.86 million\/breach in 2020.<\/p>\n<p>Companies in the\u00a0United States\u00a0had the highest\u00a0average total cost\u00a0at $8.64 million\/breach, followed by the Middle East at $6.52 million\/breach. Lost business continued to be the biggest contributing cost factor, accounting for 39.4% of the\u00a0average cost\u00a0of a\u00a0data breach, and included business disruption and revenue loss from system downtown, loss of existing and new customers as well as reputational damage.<\/p>\n<p>The\u00a0healthcare\u00a0industry\u00a0continued to average the highest\u00a0security breach\u00a0costs of any industry, reaching $7.1 million\/breach, a 10.5% increase from\u00a0last year. The energy sector overtook the financial industry, reaching the second-highest\u00a0data breach\u00a0cost with $6.39 million\/breach, registering a worrying 14.1% increase from 2019. The finance sector came in third, with $5.85 million\/breach, recording a small 0.2% decrease from the previous year.<\/p>\n<p>The reaction time to\u00a0security breaches\u00a0also varied greatly by industry, with\u00a0healthcare\u00a0organizations\u00a0taking 329 days on average to identify and contain a breach, while\u00a0financial institutions\u00a0only took 233 days.<\/p>\n<p>Customers\u2019 personally identifiable information (PII) which includes\u00a0sensitive data\u00a0such as\u00a0credit card\u00a0numbers, addresses and\u00a0phone numbers, was compromised in 80% of all\u00a0security breaches, making it the type of data most often lost or stolen.\u00a0Personal data\u00a0was also the costliest type of data compromised in a\u00a0data breach, averaging $150\/data\u00a0record.<\/p>\n<h2>Main causes of\u00a0data breaches<\/h2>\n<p>The\u00a0IBM\u00a0and\u00a0Ponemon\u00a0Institute&#8217;s report also showed that 52% of all\u00a0data breaches\u00a0were caused by\u00a0cybercriminals, with a further 25% by system glitches and 23% by\u00a0human error.<\/p>\n<p>Compromised credentials and\u00a0cloud computing\u00a0misconfiguration were responsible for 19% of malicious\u00a0data breaches, with third-party software vulnerabilities accounting for another 16%.\u00a0Human error\u00a0was also not the only way employees contributed to\u00a0security breaches. Malicious insiders were the root cause of 7% of\u00a0data breaches, while social engineering and\u00a0phishing\u00a0attacks\u00a0that targeted employees directly accounted for a further 17%.<\/p>\n<p>Employees were also shown to be more negligent in some sectors than in others. At the top of the list was the entertainment industry where 34% of all\u00a0security breaches\u00a0were caused by careless employees, followed by the public and consumer products sectors where\u00a0human error\u00a0accounted for 28% of\u00a0data breaches. In the\u00a0healthcare\u00a0sector, despite heavy regulations, employee negligence was responsible for 27% of all\u00a0data breaches.<\/p>\n<h2>GDPR\u00a0fines keep increasing<\/h2>\n<p>While the enforcement of some\u00a0data protection\u00a0regulations, such as\u00a0<a href=\"https:\/\/www.endpointprotector.com\/blog\/hipaa-compliance-and-covid-19\/\" target=\"_blank\" rel=\"noopener\">HIPAA<\/a> in the United States, have been relaxed because of the pandemic, European data protection agencies have continued their work unhindered. This year has brought a number of record fines due to non-compliance with the European Union\u2019s <a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener\">General\u00a0Data Protection\u00a0Regulation<\/a>\u00a0(GDPR). To date, 281 fines have been issued this year, amounting to over $190 million.<\/p>\n<p>Google was the worst hit, with its appeal of France\u2019s\u00a0Data Protection\u00a0Authority CNIL\u2019s $59 million fine being dismissed by the country\u2019s highest court and the Swedish Data Authority slapping the tech giant with another $8.2 million fine for its failure to comply with an individual\u2019s right to be forgotten.<\/p>\n<p>In October 2020, the second-largest\u00a0GDPR\u00a0fine ever imposed, of approximately $41 million, was issued by the\u00a0Data Protection\u00a0Authority of Hamburg, Germany to clothing retailer H&amp;M for recording meetings with employees during which\u00a0sensitive information\u00a0was disclosed and then sharing them internally among managers.<\/p>\n<p>British Airways was fined $26 million for its failure to prevent a\u00a0data\u00a0breach\u00a0that affected 400,000 customers due to poor\u00a0security measures. Marriott meanwhile was hit with a $24 million fine for the spectacular breach that affected 83 million guest records which included\u00a0sensitive data\u00a0such as\u00a0payment card\u00a0information and passport numbers. The\u00a0data breach\u00a0investigation\u00a0showed that the security incident was a consequence of Marriott&#8217;s lack of due diligence after acquiring the Starwood Group which was at the root of the incident.<\/p>\n<h2>Reducing\u00a0data breach\u00a0costs<\/h2>\n<p>Incident response plans\u00a0were the biggest cost saver when it came to the\u00a0average cost\u00a0of a\u00a0data breach. Businesses that had appointed an\u00a0incident response team\u00a0and extensively tested their\u00a0incident response plan\u00a0had an average\u00a0data breach\u00a0cost of $3.29 million\/breach, while those that didn\u2019t have either of them had an\u00a0average cost\u00a0of $5.29 million\/breach, an impressive $2 million difference.<\/p>\n<p><a href=\"http:\/\/endpointprotector.com\/\" target=\"_blank\" rel=\"noopener\">Data loss\u00a0prevention<\/a>\u00a0is also a key factor in cost-saving, helping companies save on average approximately $165,000\/data breach\u00a0through the direct protection of\u00a0sensitive data. Extensive encryption can reduce\u00a0data breach\u00a0costs by a further $237,000.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2020 has proved to be a challenging year from all points of view. With the health crisis brought on by the COVID-19 pandemic disrupting the worldwide economy and crippling both large and\u00a0small businesses,\u00a0cybersecurity\u00a0may have been the last thing on anyone\u2019s mind. However,\u00a0cybercriminals\u00a0took advantage of the chaos to increase\u00a0phishing\u00a0scams\u00a0and\u00a0malware\u00a0cyberattacks, cashing in on the relaxation of\u00a0security measures. &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/a-look-at-data-breach-statistics-in-2020\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;A Look at Data Breach Statistics in 2020&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":3763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115,1],"tags":[],"class_list":["post-3759","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=3759"}],"version-history":[{"count":4,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3759\/revisions"}],"predecessor-version":[{"id":4048,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3759\/revisions\/4048"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/3763"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=3759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=3759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=3759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}