Data protection is a priority topic for every responsible business. However, managing large amounts of information is still a problem in itself, temporarily setting aside the additional aspect of GDPR and other regulations and legal provisions, as well as the related consequences and financial penalties.

The answer to the need to manage an ever-growing amount of dispersed data is DLP technology, which is presented in the Data Loss Prevention and Cybersecurity report prepared by Xopero Software. Its overarching goal is to prevent leaks of confidential data and to identify people who should not have access to it.

How much does a data breach cost?

How much does a data breach cost?

In the Cost of a Data Breach Report 2019 by IBM Security, we read that the average cost of a data breach last year was $3.92 million(!). On average, more than 25,000 records were leaked, which translates to $150 per record. Meanwhile, the average time needed to discover a breach is as much as 279 days

The healthcare industry was hit the hardest, where the average cost of a data breach was $6.45 million. It was followed by the financial and banking sector ($5.86 million), energy ($5.6 million), manufacturing ($5.2 million), pharmaceuticals ($5.2 million) and technology ($5.05 million). The largest share — as much as 43% of data breach victims — comes from the SME sector, and the most costly types of records are information that enables identification of individuals.

According to the latest information, as a result of the COVID-19 pandemic, the costs of data protection breaches will increase (according to 70% of respondents), and the consequence of remote work will be a longer time to identify and contain the threat (76% of responses).

All the more reason to look at solutions that are designed to prevent data loss.

DLP - confidential technology

DLP - confidential technology

How does DLP differ from other security technologies? While tools such as firewalls or IDS/IPS search for all potential events, DLP focuses only on data confidentiality. The program searches for content of key importance to the organization, marks that data as sensitive and highly critical. Although DLP can prevent intrusions and data theft by hackers, it is much more often used as a mechanism for detecting “disruptions” in normal business processes.

How much does a data breach cost in individual industries?

Cost of a data breach by industry

DLP technology consists of several key functionalities. Data discovery is intended to determine what data a company has and where it is stored. This is followed by data classification, meaning grouping it according to adopted permission levels. Security policy management here has a centralized character and is based on rules and policies that increase the level of data security. Finally, the tool is equipped with control functions and real-time monitoring, thanks to which the organization is able to detect a breach, unauthorized copying of data or sending it by email much faster (than 279 days!).

However, to speak of comprehensive protection of company resources, DLP must be used in combination with other solutions such as backup and disaster recovery software, or 2FA/MFA.

- DLP technology should therefore guarantee “visibility” of all resources - including those transferred from endpoints to the cloud - and monitor this in real time. Another challenge is the fact that incident response mechanisms tend to treat internal threats as events in time, which usually begin on the day the alert appears - comments Bartosz Jurga, Business Development Manager at Xopero Software - Next-Gen DLP must take into account trends in user activity - preferably up to 90 days back, before they signal an intention to leave the company and, for example, take a valuable customer database with them. Equally important in this context is storing data for as long as it is essentially possible. Without the proper “historical” context, the data needed for such analysis will be incomplete and will give unreliable results - he adds.

DLP and GDPR

DLP and GDPR

With the help of data, companies are able to create new value for customers and develop digital services in line with market expectations. If, however, they are unable to properly protect it, the competitive advantage gained will disappear. Therefore, data security today is much more than cost reduction and avoiding penalties, although GDPR has shown us that these can be severe.

- Responsibility for data security has become a major challenge in business and the public sector. The first million-zloty fines for data breaches have been imposed in Poland. Managers may be held administratively, civilly and criminally liable for deficiencies in an organization's digital security systems. Thus, the topic of data protection has moved beyond the walls of IT departments - says Grzegorz Oleksy, President of the Management Board at Axence - Public administration faces a great challenge - according to a NIK report, almost 70 percent of audited offices are unable to ensure the security of information processing - he adds.

Preventing data loss is more a business problem than a technological one. It is much easier to solve it with internal policies, top-down rules, physical controls and specially designed processes. New technologies merely extend traditional measures with appropriate software - designed to protect confidential information in today's internet-connected world.

DLP is a tool that helps control where sensitive data is going. This makes it a key component of compliance policy and protection of sensitive data.

Summary

A data breach costs companies an average of $3.92 million, and detecting it takes as long as 279 days. The healthcare industry ($6.45 million) and the financial sector ($5.86 million) are the most affected. As many as 43% of victims are small and medium-sized enterprises, and the COVID-19 pandemic is expected to further increase the costs of breaches.

The solution is DLP technology, which focuses exclusively on data confidentiality and monitors it in real time. Experts emphasize that it must analyze user activity trends as far back as 90 days in order to catch potential internal threats. Effective data protection today is not only a matter of technology, but above all of business responsibility.