<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: True Cost Of Data Breaches Much Less Than Thought</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Sun, 20 May 2012 01:49:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Steve Sommers</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52922</link>
		<dc:creator>Steve Sommers</dc:creator>
		<pubDate>Wed, 14 Jan 2009 15:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52922</guid>
		<description>I think the cost to a merchant for a breach depends on many factors: the size of the breach, how deep the merchant&#039;s pockets are, how big the merchant&#039;s legal staff, how much acquiring business the merchant represents, etc.

With TJX and Hannaford they had a couple things going for them: 1) Due to the size of the breach they got a quantity discount (both would have fought the settlement costs A LOT more if the card associations stuck to their $200-300 per account figure!), 2) They both have large legal staffs.

If you&#039;re the size of TJX or Hannaford and you get breached, you may only pay $7′ish per account exposed. If, on the other hand, you are significantly smaller in size (as are most merchants), your costs will be much higher and after legal fees, fines, forensics, etc., etc., etc., may approach the $200-300 per account number.

The fact is that the average merchant will pay much more than $7 per account exposed if breached. Will they pay $200-300 per account? I don&#039;t know. My guess is that the true costs are somewhere in the middle but I have heard of instances of cardholders suing merchants over breaches. If this trend is allowed to continue, I could see the number going much higher. If this is fear mongering, then so be it.</description>
		<content:encoded><![CDATA[<p>I think the cost to a merchant for a breach depends on many factors: the size of the breach, how deep the merchant&#8217;s pockets are, how big the merchant&#8217;s legal staff, how much acquiring business the merchant represents, etc.</p>
<p>With TJX and Hannaford they had a couple things going for them: 1) Due to the size of the breach they got a quantity discount (both would have fought the settlement costs A LOT more if the card associations stuck to their $200-300 per account figure!), 2) They both have large legal staffs.</p>
<p>If you&#8217;re the size of TJX or Hannaford and you get breached, you may only pay $7′ish per account exposed. If, on the other hand, you are significantly smaller in size (as are most merchants), your costs will be much higher and after legal fees, fines, forensics, etc., etc., etc., may approach the $200-300 per account number.</p>
<p>The fact is that the average merchant will pay much more than $7 per account exposed if breached. Will they pay $200-300 per account? I don&#8217;t know. My guess is that the true costs are somewhere in the middle but I have heard of instances of cardholders suing merchants over breaches. If this trend is allowed to continue, I could see the number going much higher. If this is fear mongering, then so be it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: S Hudson</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52921</link>
		<dc:creator>S Hudson</dc:creator>
		<pubDate>Tue, 13 Jan 2009 15:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52921</guid>
		<description>Why doesn&#039;t this include the financial penalties and fines levied for this type of breach? Shouldn&#039;t those be factored in as part of total cost?</description>
		<content:encoded><![CDATA[<p>Why doesn&#8217;t this include the financial penalties and fines levied for this type of breach? Shouldn&#8217;t those be factored in as part of total cost?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI Guy</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52919</link>
		<dc:creator>PCI Guy</dc:creator>
		<pubDate>Fri, 09 Jan 2009 15:54:11 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52919</guid>
		<description>More fear-mongering from Shift4! Randy, 93% of ALL businesses fail within 5 years. The question is, what percentage of business failures are CAUSED by data breach? (NOTE: Disaster Recovery Journal referred to &quot;loss&quot; not &quot;breach,&quot; because they mean due to a fire or a flood, not because of hackers as Mr. Carr implies.) According to Dun &amp; Bradstreet, less than 1% of business failures are due to &quot;neglect, fraud, or disaster,&quot; the category that would include a data loss OR a breach OR fraud, etc., meaning the portion of it that is due to a breach is probably less than one hundredth of one percent. I suspect it&#039;s MUCH less. See http://cpa.utk.edu/pdffiles/adc24.pdf</description>
		<content:encoded><![CDATA[<p>More fear-mongering from Shift4! Randy, 93% of ALL businesses fail within 5 years. The question is, what percentage of business failures are CAUSED by data breach? (NOTE: Disaster Recovery Journal referred to &#8220;loss&#8221; not &#8220;breach,&#8221; because they mean due to a fire or a flood, not because of hackers as Mr. Carr implies.) According to Dun &amp; Bradstreet, less than 1% of business failures are due to &#8220;neglect, fraud, or disaster,&#8221; the category that would include a data loss OR a breach OR fraud, etc., meaning the portion of it that is due to a breach is probably less than one hundredth of one percent. I suspect it&#8217;s MUCH less. See <a href="http://cpa.utk.edu/pdffiles/adc24.pdf" rel="nofollow">http://cpa.utk.edu/pdffiles/adc24.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52924</link>
		<dc:creator>Luke</dc:creator>
		<pubDate>Thu, 08 Jan 2009 15:53:39 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52924</guid>
		<description>I did a quick search and found an article from the Boston Globle publushed August 15, 2007:

Cost of data breach at TJX soars to $256m
http://www.boston.com/business/globe/articles/2007/08/15/cost_of_data_breach_at_tjx_soars_to_256m/

Who&#039;s wrong?</description>
		<content:encoded><![CDATA[<p>I did a quick search and found an article from the Boston Globle publushed August 15, 2007:</p>
<p>Cost of data breach at TJX soars to $256m<br />
<a href="http://www.boston.com/business/globe/articles/2007/08/15/cost_of_data_breach_at_tjx_soars_to_256m/" rel="nofollow">http://www.boston.com/business/globe/articles/2007/08/15/cost_of_data_breach_at_tjx_soars_to_256m/</a></p>
<p>Who&#8217;s wrong?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Randy Carr, Shift4 Corporation</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52915</link>
		<dc:creator>Randy Carr, Shift4 Corporation</dc:creator>
		<pubDate>Thu, 08 Jan 2009 15:49:03 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52915</guid>
		<description>Evan,

The U.S. Department of Labor has warned that 93% of businesses that experience a significant data loss go out of business with five years. &quot;Of those companies 43% go out of business within the first year, and 72% go out the second year,&quot; according to Disaster Recovery Journal, a leading publication dedicated to the importance of contingency planning in the event of a disastrous occurrence.

So I ask you this direct question: Given the current dire economic conditions in the U.S., is it prudent to downplay the importance of the negative impact breaches have on businesses?

Would it not make more sense to do all we can to bring market awareness to solutions that can actually stop cardholder data theft from merchant systems?

Now might be a good time to remove all at risk data from the merchant environment and do everything we can to protect the businesses that are the backbone of our economy.</description>
		<content:encoded><![CDATA[<p>Evan,</p>
<p>The U.S. Department of Labor has warned that 93% of businesses that experience a significant data loss go out of business with five years. &#8220;Of those companies 43% go out of business within the first year, and 72% go out the second year,&#8221; according to Disaster Recovery Journal, a leading publication dedicated to the importance of contingency planning in the event of a disastrous occurrence.</p>
<p>So I ask you this direct question: Given the current dire economic conditions in the U.S., is it prudent to downplay the importance of the negative impact breaches have on businesses?</p>
<p>Would it not make more sense to do all we can to bring market awareness to solutions that can actually stop cardholder data theft from merchant systems?</p>
<p>Now might be a good time to remove all at risk data from the merchant environment and do everything we can to protect the businesses that are the backbone of our economy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sid Sidner</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52914</link>
		<dc:creator>Sid Sidner</dc:creator>
		<pubDate>Thu, 08 Jan 2009 15:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52914</guid>
		<description>I am puzzled because I don&#039;t understand the link between the merchant breach and issuer notification of their cardholders. How does this occur? Does the merchant (TJX) do the actual notification, or does the card issuer? How is the cost to the card issuer if a card needs to be reissued included in this cost?

I understand the costs of breach notification at an issuer, but not at a merchant.</description>
		<content:encoded><![CDATA[<p>I am puzzled because I don&#8217;t understand the link between the merchant breach and issuer notification of their cardholders. How does this occur? Does the merchant (TJX) do the actual notification, or does the card issuer? How is the cost to the card issuer if a card needs to be reissued included in this cost?</p>
<p>I understand the costs of breach notification at an issuer, but not at a merchant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evan Schuman</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52911</link>
		<dc:creator>Evan Schuman</dc:creator>
		<pubDate>Thu, 08 Jan 2009 15:40:33 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52911</guid>
		<description>As far as the media attention is concerned, not sure what value that would have. TJX sustained tons of negative media coverage and their revenue increased. Consumers were entirely oblivious to it.</description>
		<content:encoded><![CDATA[<p>As far as the media attention is concerned, not sure what value that would have. TJX sustained tons of negative media coverage and their revenue increased. Consumers were entirely oblivious to it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chandra Shekaran</title>
		<link>http://storefrontbacktalk.com/securityfraud/true-cost-of-data-breaches-much-less-than-thought/comment-page-1/#comment-52910</link>
		<dc:creator>Chandra Shekaran</dc:creator>
		<pubDate>Thu, 08 Jan 2009 15:40:13 +0000</pubDate>
		<guid isPermaLink="false">http://staging.storefrontbacktalk.com/?p=1726#comment-52910</guid>
		<description>The results of data breaches can be relatively extreme and from what I can think, I dont think, the way to estimate taking the total spending versus the number of accounts compromised is the right way to calculate. I would think the best way to arrive at the total cost would be to take into consideration, the financial cost, plus, the other impacts such as the media attention and the brand which is difficult to quantify. While measuring in financial terms, the total limit on the card that is exposed for fraud to the total number would be the best yard stick. So I dont think security assessment agencies ever over estimate the cost just to show and ROI.</description>
		<content:encoded><![CDATA[<p>The results of data breaches can be relatively extreme and from what I can think, I dont think, the way to estimate taking the total spending versus the number of accounts compromised is the right way to calculate. I would think the best way to arrive at the total cost would be to take into consideration, the financial cost, plus, the other impacts such as the media attention and the brand which is difficult to quantify. While measuring in financial terms, the total limit on the card that is exposed for fraud to the total number would be the best yard stick. So I dont think security assessment agencies ever over estimate the cost just to show and ROI.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

