Insurance and cybersecurity, the parallels are clear

This post was originally published here by shaane syed.

Itā€™d be awfully nice not to need car insurance. Or homeowners insurance. Or fire insurance. These added expenses donā€™t increase the value of your car or home, and thereā€™s a good chance youā€™ll never use them. The money you pour into insurance is arguably even being frittered away, of better used spent on investments or property improvements. You havenā€™t been in a car accident in ten years. Wouldnā€™t it have been better to put that money towards something else?

That question is clearly ludicrous. Insurance is a necessity you hope is never actually necessary since its use arises from an accident or catastrophe. The potential for crippling financial burden that youā€™d face minus insurance makes paying for it worthwhile. The minute you cancel your car insurance you could find yourself in an accident whose costs dwarf the total amount of money youā€™ve previously put in. The risk is too great.

Information security is similar to insurance in that having no (or weak) security is an incredible risk. Considering the massive damage that could hit your company following a data breach, itā€™s always worth investing resources in ensuring you never face one. But since security doesnā€™t seem all that valuable until the moment youā€™re breached, it can be tempting to invest security expenditures elsewhere.

For that reason, maybe you disagree about how severely your company would be harmed by a breach. If so, you wouldnā€™t be alone. Back in 2014, Home Depot was hit by a huge breach that cost themĀ close to $200 millionĀ just in settlement payouts to consumers and credit card providers.

This breach didnā€™t come out of nowhere, though. In the year before, Home Depot was hit withĀ two smaller breachesĀ exposing issues that, had they been dealt with, would likely have enabled them to avoid the larger breach altogether. But itā€™s not like they were previously ignoring security concerns out of maliceā€“ there were almost certainly just other things in the company that received precedent due to their perceived value versus making improvements to security. Home Depot was just one ofĀ many companiesĀ that were aware of the inherent security flaws found in POS systems while doing nothing about them because of the added cost to do so.

Of course, itā€™s possible to view all of this through the lens of moral hazard. If you lose customer credit card numbers or other sensitive data, itā€™s ultimately their problem. Theyā€™ll cancel their cards, spend a couple of hours on the phone jumping through hoops with their provider to get fraudulent charges removed, but your company will be fine, ultimately. Itā€™ll cost you some money, force you to fire a few people for PR purposes, bring down profits for the year, give your lawyers something to do to justify their cost, and cause your support staff to break down crying, but thatā€™s the cost of doing business and everything will return to normal after a bit.

And occasionally that might even be true. A company whose customers already hold them in fairly high esteem can recover quickly. Targetā€™s breach in 2014 cost them $175 million and a quick drop in revenue, but less than a year later business had pretty muchĀ returned to normal. Terrible, but not catastrophic in the long term.

Target is unique, though, in that they have an established brand identity and a broad, loyal customer base. As a rule,Ā 64% of customersĀ say theyā€™re less likely to do business with a company that lost some of their sensitive data. 50% of customers say theyā€™re less likely even if the lost data is non-sensitive. Thereā€™s a reason why one of the only activities that brings both sides of Congress together is publicly grilling and condemning CEOs whose companies incurred massive data breaches.

Being cavalier with your data is essentially the same as being cavalier with your company, just as being cavalier with your insurance is essentially being cavalier with your life. If you didnā€™t have car insurance, youā€™d likely get through a major accident, but the damage would be felt for years after. You wouldnā€™t take that risk in your daily life, so donā€™t take that risk with your business.

Photo:WeLiveSecurity

Ad

No posts to display