The Internet Society has released findings from its 2016 Global Internet Report in which 59 percent of users admit they would likely not do business with a company which had suffered a data breach.
Highlighting the extent of the data breach problem, the report makes key recommendations for building user trust online, stating that more needs to be done to protect online personal information.
Michael Kende, economist and internet society fellow who authored the report, said: “According to the Online Trust Alliance, 93 percent of breaches are preventable. And steps to mitigate the cost of breaches that do occur are not taken – attackers cannot steal data that is not stored, and cannot use data that is encrypted. This status quo isn't good enough anymore. As more and more of our lives migrate online, the cost and risk of a data breach is greatly increased and will lead to lost revenues and a lack of trust.”
The average cost of a data breach is now £3.2 million ($4 million), up 29 percent since 2013. With Gemalto reporting 1673 breaches and 707 million exposed records occurring in 2015, the scale of the problem is not know and can't be known because only a small proportion of breaches are ever reported.
The Internet Society is urging organisations to change their stance and follow five recommendations to reduce the number and impact of data breaches globally:
- Put users – who are the ultimate victims of data breaches – at the centre of solutions. When assessing the costs of data breaches, include the costs to both users and organisations.
- Increase transparency about the risk, incidence and impact of data breaches globally. Sharing information responsibly helps organisations improve data security, helps policymakers improve policies and regulators pursue attackers and helps the data security industry create better solutions.
- Data security must be a priority – organisations should be held to best practice standards when it comes to data security.
- Increase accountability – organisations should be held accountable for their breaches. Rules regarding liability and remediation must be established up front.
- Increase incentives to invest in security – create a market for trusted, independent assessment of data security measures so that organisations can credibly signal their level of data security. Security signals help organisations indicate that they are less vulnerable than competitors.
The report also draws parallels with threats posed by the Internet of Things (IoT). Forecast to grow to tens of billions of devices by 2020, interconnected components and sensors that can track locations, health and other daily habits are opening gateways into users' personal lives, leaving data exposed.
“We are at a turning point in the level of trust users are placing in the Internet,” said Internet Society's Olaf Kolkman, chief internet technology officer. “With more of the devices in our pockets now having Internet connectivity, the opportunities for us to lose personal data is extremely high. Direct attacks on websites such as Ashley Madison and the recent IoT-based attack on Internet performance management company Dyn, that rendered some of the world's most famous websites including Reddit, Twitter and The New York Times temporarily inaccessible, are incredibly damaging both in terms of profits and reputation, but also to the levels of trust users have in the Internet.”