In today’s digital age, the average cost of a data breach has surged to $4.88 million, marking a 10% increase from last year, according to a recent report. As businesses become more reliant on technology, cyberattacks are growing in sophistication and frequency, posing greater risks. So, how can your organization safeguard its profits and assets from these cyber threats?
Recent Findings
In August 2024, IBM released the “Cost of a Data Breach Report 2024.” Conducted independently by the Ponemon Institute, the research examined 604 organizations that experienced data breaches between March 2023 and February 2024. Among the 16 countries studied, the United States reported the highest average data breach cost at $9.36 million.
The report breaks down the global average cost per breach ($4.88 million) into four key components:
- $1.47 million for lost business, including revenue loss due to system downtime, costs related to lost customers, reputation damage, and diminished goodwill.
- $1.63 million for detection and escalation, covering forensic and investigative activities, assessment and audit services, crisis management, and communications to executives and boards.
- $1.35 million for post-breach response, which includes product discounts, regulatory fines, legal fees, and costs related to setting up call centers and credit monitoring/identity protection services for breach victims.
- $430,000 for notifying regulators, as well as individuals and organizations affected by the breach.
A positive takeaway from the report is that the average time to identify and contain a breach has decreased to 258 days from 277 days in the 2023 report, reaching a seven-year low. This improvement is largely due to organizations placing greater emphasis on cybersecurity measures.
Implementing Cybersecurity Protocols
Cybersecurity involves designing and implementing internal controls to:
- Identify potential threats,
- Protect systems and information from security events, and
- Detect and respond to potential breaches.
The rise in remote work has exposed employers to greater cybersecurity risks. Many companies now store sensitive data in more locations than ever before, including laptops, firm networks, cloud-based storage, email, portals, mobile devices, and flash drives, creating numerous potential points of unauthorized access.
Targeted Data
When establishing new cybersecurity protocols and reviewing existing ones, it’s crucial to identify potential vulnerabilities. This begins with inventorying the types of employee and customer data that hackers might target. Sensitive material may include:
- Personally identifiable information, such as phone numbers, physical and email addresses, and Social Security numbers,
- Protected health information, such as test results and medical histories, and
- Payment card data.
Companies must have effective controls over this data to comply with federal and state laws and industry standards.
Hackers may also attempt to access a company’s network to steal valuable intellectual property, such as customer lists, proprietary software, formulas, strategic business plans, and financial data. These intangible assets can be sold or used by competitors to gain market share or a competitive advantage.
Auditing Cyber Risks
No organization, large or small, is immune to cyberattacks. As the frequency and severity of data breaches continue to rise, cybersecurity has become a critical component of the audit risk assessment.
Audit firms provide varying levels of guidance, both when assessing risk at the start of the engagement and when uncovering a breach that occurred during the period under audit or during audit fieldwork.
We Can Help
Contact us to discuss your organization’s vulnerabilities and the effectiveness of its existing controls over sensitive data.
©2026