impact of breaches on reputation and shareholder value

26
1 IMPACT OF BREACHES ON REPUTATION AND SHAREHOLDER VALUE Ponemon 2017 Study

Upload: centrify-corporation

Post on 23-Jan-2018

447 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Impact of Breaches on Reputation and Shareholder Value

1

IMPACT OF BREACHES ON REPUTATION AND

SHAREHOLDER VALUE

Ponemon 2017 Study

Page 2: Impact of Breaches on Reputation and Shareholder Value

2

In March alone

129 BREACHES

Page 3: Impact of Breaches on Reputation and Shareholder Value

3

YTD increase in breaches

65% INCREASE

Page 4: Impact of Breaches on Reputation and Shareholder Value

4

2/3 of companies report experiencing 5 or more

data breaches within the past two years

66% BREACHED

Page 5: Impact of Breaches on Reputation and Shareholder Value

5

THERE’S NO SINGLE ENTRY POINTHackers have no common path in where they decide to breach

MOBI LE / ENDPOI NT

DATABASES

N E T W O R K

ON-PREM A N D

SAAS A P P S

SERVERS 4.7

6.6

5.2

5.8

6.4

# OF DATA BREACHES IN 2 YEARS

Page 6: Impact of Breaches on Reputation and Shareholder Value

6

after Chipotle reported better than expected Q1 results but gains chopped in half when it revealed it had a breach

$400 MILLIONLOSS TO SHAREHOLDERS

Page 7: Impact of Breaches on Reputation and Shareholder Value

7

TODAY’S SECURITY IS NOT SECURE

Page 8: Impact of Breaches on Reputation and Shareholder Value

8

RETHINK SECURITY

Enterprises breached 5+ times

in last two years (Forrester)66%

IT security spend in 2016(Gartner)$80B

THE ENTERPRISE TODAY HAS NO PERIMETER

150,000Enterprise cloud apps

90% Enterprises using cloud

50BIoT devices

8Bmobile devices

PROTECTED BY ONLY A PASSWORD

breaches involve privileged

credential misuse (Forrester)80%

breaches involve weak, default

or stolen passwords (Verizon)81%

NO USER IS SAFE

Hackers target all users whether customers,

partners, employees or privileged IT users

Page 9: Impact of Breaches on Reputation and Shareholder Value

THE IMPACTS OF A DATA BREACH

ON REPUTATION AND SHARE VALUE

Page 10: Impact of Breaches on Reputation and Shareholder Value

Ponemon Institute surveyed three groups that

influence companies brand and reputation:

• IT operations and information security (448 professionals)

• CMOs and corporate communications (334 professionals)

• Consumers (549 individuals)

Ponemon also studied the affect on stock

value and customer churn after a breach of

113 COMPANIES

Page 11: Impact of Breaches on Reputation and Shareholder Value

MISCALCULATION OF SECURITY RISK

ON SHAREHOLDER VALUE

Page 12: Impact of Breaches on Reputation and Shareholder Value

12

Avg stock price decline after breach announced

5% DROP

Page 13: Impact of Breaches on Reputation and Shareholder Value

13

AVERAGE STOCK INDEX DROPS THE DAY

A BREACH IS ANNOUNCED

Page 14: Impact of Breaches on Reputation and Shareholder Value

14

LOW SECURITY POSTURE COMPANIES

DROPS UP TO 7% & RECOVERS SLOWER

Page 15: Impact of Breaches on Reputation and Shareholder Value

15

In customer churn for companies with poor security posture(lack of response plan, inadequate investment in security — especially IAM, frequent turnover of security personnel, etc.)

Up to 7% INCREASE

Page 16: Impact of Breaches on Reputation and Shareholder Value

16

Impacted consumers stated intent to

discontinue relationship with breached organization30%+

Page 17: Impact of Breaches on Reputation and Shareholder Value

BLIND SPOTS IN THE C-SUITE

WITH COSTLY CONSEQUENCES

Page 18: Impact of Breaches on Reputation and Shareholder Value

18

IT leaders are not confident in their ability

to prevent, detect and resolve data breaches

56% NOT CONFIDENT

Page 19: Impact of Breaches on Reputation and Shareholder Value

19

Marketing and IT leaders have a blind spot

regarding the impact of a breach on stock price

80+% HAVE BLIND SPOT

Page 20: Impact of Breaches on Reputation and Shareholder Value

20

CMOs & IT professionals disagree with consumers

who say companies have an obligation to control

access to personal information

50%+ DISAGREE

Page 21: Impact of Breaches on Reputation and Shareholder Value

21

MISCALCULATION of security risk on shareholder value

BLIND-SPOTSin C-suite have costly consequences

DATA BREACHESare a board and C-suite challenge not just an IT issue

RETHINK SECURITY

Page 22: Impact of Breaches on Reputation and Shareholder Value

HOW DO ENTERPRISES REDUCE RISK?

Page 23: Impact of Breaches on Reputation and Shareholder Value

23

MATURITY

Mitigate VPN Risk

Automate App Provisioning

Require Access Approvals

BETTER

Limit Lateral Movement

Grant Just Enough Privilege

Grant Just-in-Time Privilege

GREAT

EnforceLeast

Privilege

Risk Analytics

Complete automation

OPTIMAL

Log & Monitor

DANGER

Too Many Passwords

Too Much Privilege

REDUCING RISK IN HYBRID ENTERPRISE

MFA Everywhere

Risk-based Access

Consolidate Identities

SSO Everywhere

GOOD

Establish Identity Assurance

RISK

Page 24: Impact of Breaches on Reputation and Shareholder Value

24

HOW CUSTOMERS USE CENTRIFY

STOP BREACHES THAT

Target Application

Single Sign-on

Adaptive MFA

Workflow & Lifecycle

Device Management

App Gateway

STOP BREACHES THAT

Start on Endpoints

Device Management

Adaptive MFA

App Management

Endpoint Privilege

Smartcard & Derived Credentials

STOP BREACHES THAT

Abuse Privileged Access

Least Privilege

Adaptive MFA

Identity Consolidation

Shared Password Management

Secure Remote Access

Session Recording & Monitoring

Auditing & Reporting

Page 25: Impact of Breaches on Reputation and Shareholder Value

25

A RECOGNIZED LEADER

LEADER FORRESTER PIM WAVE

The Forrester Wave™ is copyrighted by Forrester Research, Inc. Forrester and Forrester Wave

are trademarks of Forrester’s call on a market and is plotted using a detailed spreadsheet with

exposed scores, weightings, and comments. Forrester does not endorse any vendor, product, or

service depicted in the Forrester Wave. Information is based on best available resources. Opinions

reflect the judgement at the time and are subject to change.

NETWORK WORLD

CLEAR CHOICE WINNERLEADER GARTNER IDAAS MQ

Gartner “Magic Quadrant for Identity and Access Management as a Service” by Gregg

Kreizman, June 2016. Gartner does not endorse any vendor, product or service depicted in

its research publications, and does not advise technology users to select only those vendors

with the highest ratings or other designation. Gartner research publications consist of the

opinions of Gartner's research organization and should not be construed as statements of

fact. Gartner disclaims all warranties, expressed or implied, with respect to this research,

including any warranties of merchantability or fitness for a particular purpose. .

GARTNER CRITICAL CAPABILITIES

TOP VENDOR

Gartner does not endorse any vendor, product or service depicted in its research

publications, and does not advise technology users to select only those vendors

with the highest ratings or other designation. Gartner research publications consist

of the opinions of Gartner's research organization and should not be construed as

statements of fact. Gartner disclaims all warranties, expressed or implied, with

respect to this research, including any warranties of merchantability or fitness for a

particular purpose.

Page 26: Impact of Breaches on Reputation and Shareholder Value

26

THANK YOU