Be Mindful of Insider Fraud Against Seniors
California's Financial Abuse Reporting Act, SB 1018, which r…
Eligible |
![]() |
The latest report by the IT Policy Compliance Group finds that nine of ten companies are exposed to financial risk from data losses and thefts that can be cost-effectively avoided. The report, "Why Compliance Pays - Reputations and Revenues at Risk," finds the majority of the 475 firms surveyed must contend with six to 17 business disruptions and five to 22 instances of losses or thefts of sensitive information each year. Those firms with the best IT compliance results have, at most, two disruptions annually.
"There are two real key findings from this ongoing report for financial institutions. We are finally able to quantify publicly reported data losses, (this data was also checked from historical databases as well). Financial risk for losing data is absolutely huge, compared to the amount of money being spent on compliance and data protection," said Jim Hurley, a senior research manager for Symantec and senior director of the IT Policy Compliance Group.
"The second key finding is, and we stumbled onto this by accident, is the relationship between compliance and data loss. How well (or poorly) a company does compliance, and how well (or poorly) they're doing on data loss, we found a relationship between the two," Hurley noted.
"I expected a normal distribution, a normal spread like what we see in the rest of the world of compliance. But it's a one to one mapping between the two. At first I thought the numbers were skewed, but we checked them and they are right. I expected a different distribution, but across the entire universe of companies, this distribution rings true," Hurley said. The companies that are doing well in compliance efforts are suffering far fewer data loss events and base business disruptions.
Notably, Hurley said, financial and accounting service industry sees more "compliance laggards." This number is higher by about 5 percent of the rest of population at large. "The banking industry matches the entire population, they don't do any better or any worse than the rest of the industries in the survey," he explained.
Key Findings
Most organizations are exposed to financial risk from data loss and theft
Nine out of ten firms are not leveraging compliance and IT governance procedures that could help mitigate financial risk from lost or stolen data. Benchmark results include:
Compliance leaders have the fewest business disruptions
Firms with the best IT compliance results have the least business downtime from IT security events. Findings show:
Firms with the best IT compliance report the fewest data losses. Results include:
Probability of a financial loss: Not if, but when
Financial loss will occur with data loss and theft. The question is when and by how much. The probability of making the front page of the paper for a data loss or theft is:
Financial risk and loss are significant enough to manage
The expected financial risk for publicly disclosed data loss and theft is matched by limited actual experience. Financial risks include:
Returns are high
Due to high financial risk and relatively low spending on compliance and data protection, returns on spending for compliance and data protection are high:
Best practices to improve results: Follow the leaders
|
The Electronic Funds Transfer (EFT) Act - Regulation E..Next Topic
The Electronic Funds Transfer (EFT) Act - Regulation E..Next Topic
FFIEC Issues 2009 Mortgage Fraud White Paper:The Detection and Deterrence of Mortgage..Next Topic
DoJ: Report to Congress on Implementation of Section 1001 of the USA PATRIOT Act..Next Topic
FDIC: Fraudulent Work-at-Home Funds Transfer Agent Schemes..Next Topic
Joint Statement by Education Secretary Duncan, Homeland Security Secretary Napolitano and..Next Topic
Obama's Cyberspace Policy Review: Assuring a Trusted and Resilient Information and..Next Topic
Obama's Cyberspace Policy Review: Assuring a Trusted and Resilient Information and..Next Topic
NIST: PIV Card Application and Middleware Interface Test Guidelines, SP800-85A-1..Next Topic