Cybercrime Costs Rise Despite Awareness, HP Finds

New research from Hewlett-Packard has found that cyberattacks are increasingly plaguing businesses and government institutions, resulting in significant financial impact, despite widespread awareness.

The study found that recovery and detection are the most costly internal activities, suggesting a significant cost-reduction opportunity for organisations that are able to automate detection and recovery through enabling security technologies.

Conducted by the Ponemon Institute, the Second Annual Cost of Cyber Crime Study revealed that the median annualised cost of cybercrime incurred by a benchmark sample of organisations was $5.9 million (£3.6m) per year, with a range of $1.5 million (£915,000) to $36.5 million (£22.5m) each year per organisation.

Financial Impact

This represents an increase of 56 percent from the median cost reported in the inaugural study published in July 2010.

“Instances of cybercrime have continued to increase in both frequency and sophistication, with the potential impact to an organisation’s financial health becoming more substantial,” said Tom Reilly, vice president and general manager of HP’s enterprise security, division. “Organisations in the most targeted industries are reducing the impact by leveraging security and risk management technologies, which is grounds for optimism in what continues to be a fierce fight against cybercrime.”

The report found cyberattacks have become common occurrences. Over a four-week period, the organisations surveyed experienced 72 successful attacks per week, an increase of nearly 45 percent from last year. More than 90 percent of all cybercrime costs were caused by malicious code, denial of service, stolen devices and web-based attacks.

Cyberattacks can be costly if not resolved quickly. The average time to resolve a cyberattack is 18 days, with an average cost to participating organisations of nearly $416,000 (£253,697). This represents a nearly 70 percent increase from the estimated cost of $250,000 (£152,462) over a 14-day resolution period in last year’s study. Results also showed that malicious insider attacks could take more than 45 days to contain.

Best Defence

The report also indicated deploying advanced security intelligence and risk management solutions can mitigate the impact of cyberattacks.

Organisations that had deployed security information and event management (SIEM) solutions realised a cost savings of nearly 25 percent, resulting from the enhanced ability to quickly detect and contain cybercrimes. As a result, these organisations experienced a substantially lower cost of recovery, detection and containment than organisations that had not deployed SIEM solutions.

“As the sophistication and frequency of cyberattacks increases, so too will the economic consequences,” said Dr. Larry Ponemon, chairman and founder, Ponemon Institute. “Figuring out how much to invest in security starts with understanding the real cost of cybercrime.”

Nathan Eddy

Nathan Eddy is a contributor to eWeek and TechWeekEurope, covering cloud and BYOD

Recent Posts

EU Widens Investigations Into Chinese Imports, Subsidies

After the United States imposes 100 percent tariffs on certain Chinese goods, Europe widens its…

2 days ago

Reddit Deal With OpenAI Gives ChatGPT Access To Content

OpenAI strikes deal with Reddit to train its AI tech on user posts and give…

2 days ago

Microsoft Invests 4 Billion Euros In France For AI, Cloud

Global spending spree from Microsoft continues, with huge investment for new data centre to drive…

2 days ago

Toshiba Axes 4,000 Staff In Post-Delisting Restructuring Operation

Workforce blow. Newly privatised Toshiba has embarked on a 'revitalisation plan' that will entail the…

2 days ago

European Union Opens Child Safety Probe Into Meta

European Commission opens an official child safety investigation into Facebook and Instagram-owner Meta Platforms

2 days ago