The high price of data breaches
Si Kellow · Computer Fraud & Security · 2013
It's a miserable afternoon, and you spot a new email in your inbox. The subject line is innocuous enough, but when you get into the content you realise that there is a significant problem – you've just been informed of a data breach, and you now have to deal with it. When a data breach occurs, if you're in the public sector then you need to inform your senior information risk owner. Your board and executive team will more than likely face questions about the organisation's ability to ‘look after’ information, and there will be worries about ‘public trust’. In the private sector things are a bit different. The risk and damage limitation calculations made by private firms often revolve around regulatory repercussions versus reputational damage. But the laws have changed and are changing still, and there may be smarter ways to deal with the issue, says Si Kellow of Proact.