Padlock
Firms need better data loss strategies

Firms not ready for data breaches, says survey

Many firms have no strategy for dealing with the fallout from data loss

Written by Tom Young

Only a quarter of UK organisations feel able to respond effectively to a data breach, despite the fact that they experience on average 1.5 data breaches every year, according to a survey from computer forensics firm Kroll Ontrack.

And while 56 per cent of respondents have conducted a vulnerability assessment in the past 12 months, only 25 per cent are confident in their incident response.

In addition, 15 per cent of companies believe their responses to data breaches are not effective at all.

Martin Carey, managing director of Kroll Ontrack UK said it is concerning that so few UK organisations believe they could mount a strong response to a data breach incident.

“Since no company can expect to completely eliminate the threat of data breaches through preventative measures, an organisation’s ability to detect and react swiftly to an incident is paramount,” he said.

"The cost implications, in terms of replacing lost data and compensating those affected are evident, but businesses may also face legal consequences following a breach due to the rising number of data breach notification laws."

The report also points out that companies could suffer reputational damage and loss of customer trust as a result of a major breach incident - and that these may be the most severe consequences of all.

The most important finding from the research revealed that while most organisations have a document retention policy, only 41 per cent have a discovery readiness strategy – a policy of what to do when information goes missing.

Organisations have a legal obligation to preserve documents if they anticipate litigation, but 43 per cent do not have a mechanism to preserve potentially relevant data when litigation or an investigation is anticipated.

In addition, 38 per cent of firms do not know if they have updated their security policies as a result of virtualisation, cloud computing and social networking in the corporate realm.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

EU flagsGovernment

Europe gets tough on UK data protection

Viviane Reding calls for improved citizens' rights 29 Oct 2009

 

Online retailers come bottom in data security survey

Banks command most trust, but all sectors need to raise their game, says study 29 Oct 2009

Symantec opens up data loss prevention platform

Firm promises more choice and flexibility 27 Oct 2009

Zurich loses financial details of 51,000 UK customers

No evidence that the data has been misused but whereabouts still unknown 22 Oct 2009

UK companies lag behind their US counterparts in updating technology policies

Most UK organisations are failing to revisit and review the policies regarding document retention and electronically stored information (ESI), despite the widespread adoption of rapidly developing technologies, found the third annual ESI Trends Report 24 Nov 2009

Red Bull hit with record fine for breaking waste rules

Red Bull gives you… a serious breach of recycling legislation 31 Jul 2009

Two-thirds of organisations hit by data breach in last year

Public sector and financial services the biggest culprits 08 Jul 2009

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation