Data theft is a serious problem at a consumer as well as enterprise level. A study published by Pew Research in January 2014 showed that nearly 18 percent of American adults online have had confidential information including Social Security numbers, credit cards data and bank account information stolen. The numbers are a lot scarier among enterprise customers. Close to 70 percent of respondents in a recent Accenture study reported having experienced attempted or successful theft or corruption of data by company insiders during the prior 12 months.
Whether it is done by company insiders, competitors or hackers, data theft can seriously damage the credibility of an organization and can have a direct impact on the bottom-line. While the Accenture study points out that the threat is only likely to worsen from here, what’s worse is that enterprise investments in data security continue to remain abysmal due to insufficient budgets and resources. Nearly 36% of respondents in the study believe that the management considers investment in cyber-security an unnecessary expense.
One of the main reasons why a lot of these businesses don’t seem to be addressing the low investments in data security appears to be ‘moral hazard’; the practice of taking more risks when the cost is borne by somebody else. According to Benjamin Dean, Fellow for Internet Governance and Cyber-Security at Columbia University, data breach related expenses are largely offset by insurance payouts and tax deduction (data breach related expenses are tax-deductible) and consequently, the eventual loss is significantly lower compared to the investments required to prevent such breaches in the first place. With data breaches among large brand names like Sony, Target and Home Depot becoming common, the perceivable loss of brand reputation is no longer as strong as it once was. What this means is that it is cheaper to risk data theft than to proactively secure them.
But this may not be true for long. Recent studies show that the cost of data breaches is actually on the rise and is currently growing at the rate of 15% each year. Add to this, a growing number of industry experts have been advocating the removal of “incentives” like tax breaks for businesses that lose data. But as Dean points out, such policies require government intervention which require careful planning so as to not make the situation worse.
Having said that, not all data security processes require high investments. While a business owning millions of customer data would need large investments to protect them from hackers, businesses that see their biggest threats coming from company insiders stealing data won’t have to spend as much. According to Cassity Ming, the Marketing Manager at SecureDocs, there are a few easily implementable features that can go a long way in securing data and keeping them safe from thieving company insiders. This includes technical security features like data encryption, 2-factor authentication, file-based permission management and human security features like dynamic watermarking that can help businesses pin-point the exact source of theft (and thereby offering a disincentive to employees who want to steal). Add to this specific controls regarding who can download/print these documents as well as maintaining comprehensive audit logs to monitor user-access, it is quite easy to protect data from potential theft from inside the organization.
Data theft is a huge problem and it is only going to get worse before it becomes better. While it costs less to handle data theft than it is to secure them today, this may not remain this way for long. Also, businesses need to identify the various ways data can be lost and categorize them based on the potential investments required. This would provide them with a better understanding of the cost and benefits of plugging these different holes which in turn is critical information for strategizing future cyber-security investments.