Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Hidden Costs of a Data Breach
Articles

The Hidden Costs of a Data Breach

ISBuzz TeamBy ISBuzz TeamSeptember 3, 2015Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Hidden Costs of a Data Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When tallying up the costs of a data breach, it is easy to focus on the bills that have to be paid. There are significant, tangible expenses: credit cards that need to be re-issued, special PR projects that need to be implemented and the cost of specialized forensic consultants – the list goes on. But, are these the only costs that impact the business?

The short answer is no, and here’s why.

Some of the most important costs of a data breach don’t easily show up on bills. Significant intangible costs accompany any data breach event, including strategic opportunity costs, reputational damage, loyalty costs, lost customers and the loss of institutional momentum.

Take Target, for example. Looking only at the tangible costs, the retail chain incurred approximately $250 million directly. Cyber insurance covered nearly 40 percent of these fees, which could all be attributed to the costs of services and goods immediately needed post-breach. But, Target’s reputation suffered mightily as a result of the breach – sales were down, loyal Target customers shifted their allegiances to competitors, and not surprisingly, the stock price fell dramatically.

Even beyond these significant, “in-market” issues, Target had more to pay following the breach. After the cyberattack, the retail chain announced that it would be replacing its CIO and then, just a short time later, the CEO resigned.

In short, as a result of this data breach, Target – one of the most successful, well-run retail organizations – found that its best path forward involved a change in executive leadership. There is hardly anything more costly to a company than changing executives. Generally, a new CEO begins a multi-year process of organizational and strategic change.

The True Costs of a Breach are Incalculable :

There is no easy way to put a total price tag on what the breach cost Target. Lost customers are not easily reacquired, and skittish shareholders quickly find new investments to hold. When coupled with internal costs that the senior leadership changes will necessitate, the total costs are staggering. Eventually, the new leadership team should help Target move forward and regain some of the market position that it has lost – and recently, almost two years after the breach was announced, Target has shown signs of recovery. But, there is no doubt that the company spent a lot of time stopped dead in the water.

After a Breach, Everything is on Hold :

It is not an exaggeration to say that the recovery process from a major data breach consumes 100 percent of the organization’s focus for many weeks – or even months. The company is seemingly plunged into survival mode – product launches are delayed, new market initiatives are put on hold, PR efforts are diverted, and IT initiatives are halted. And, more often than not, all teams are required to abandon their usual day-to-day activities to concentrate efforts on event containment, analysis and short-term recovery.

Some companies will have a disaster recovery plan, carefully created by a cross-departmental team, to use as a blueprint for their actions. But, many companies will make it up as they go along, often times being forced to hire externally, including communications, image and executive consultants to lead them through the tumultuous days.

Recoup Customer Loyalty and Trust :

Customer loyalty and trust is potentially the most harmful hidden cost of a data breach. Since breaches often result in some customers’ personal information being stolen, ALL customers have to deal with the increased possibility that they will be victims of identity theft. And, no matter how the breach occurred, customers are likely to blame the brand for putting them at risk. This, in turn, leads to an immense lack of trust. Sadly, many once-loyal customers will seek out competitors’ services instead. All corporate leaders know that the cost of acquiring new customers is far higher than the cost of keeping current ones. Following a breach, many customers consider alternative options to serve their business, and once they have moved away, they don’t often return.

The Breach Is Just the Beginning :

Think back to the Anthem Health Insurance attack. Information was stolen from nearly 80 million people who were, at some point, affiliated with the company. Overnight these 80 million individuals (and EVERY OTHER ANTHEM SUBSCRIBER) became easy targets for a raft of cyber criminals. Suddenly their inboxes were bombarded them with phishing emails, all claiming to be from Anthem, another healthcare provider, or even a credit bureau, reminding them of their exposure to identify theft or account compromise. Sample emails might say, “Click here to update your billing information.” But, these email are not what they seem – they are phishing emails, secondary attacks from another wave of cybercriminals looking to cash in on the misfortune of the breached company’s employees and customers.

Following a breach event, companies must take responsibility to step up their monitoring for cyberattacks of all kinds, including phishing schemes, domain impersonations, social media scams and executive masquerading. Without full-scale cyber and social threat monitoring, companies are essentially leaving their people to fend for themselves, despite publicly saying they are doing everything they can – all to protect their brand.

Just as a home with an alarm company decal in the window is a less desirable target to a would-be thief, a potential attacker will be discouraged by brands that publically demonstrate their determination to stop secondary attacks by aggressively monitoring for cyber threats.

A Proactive Approach to Cybersecurity :

Cybercriminals aren’t going anywhere, so businesses must do everything in their power to prepare for incoming attacks, rather than planning while in the crossfire. The true cost of a data breach goes much deeper than dollar signs, as cyber insurance can only help so much. It’s a lengthy rebuilding and recovery process – and that’s all time your businesses cannot get back.

In today’s digital world, it’s never ideal to play defense when it comes to cybersecurity. The choice is yours to be a business that plays offense to dodge the true hidden costs of time, budget and customers you may lose after a data breach.[su_box title=”About Greg Mancusi-Ungaro” style=”noise” box_color=”#336588″]greg_mancusi-ungaroGreg Mancusi-Ungaro is responsible for developing and executing the BrandProtect market, marketing, and go to market strategy.  A passionate evangelist for emerging technologies, business practices, and customer-centricity, Greg has been leading and advising world-class marketing initiatives, teams and organizations for more than twenty-five years.  Prior to joining BrandProtect, Greg served in marketing leadership roles at ActiveRisk, Savi Technologies, Sepaton, Deltek, Novell, and Ximian, building breakthrough products and accelerating business growth. He is a co-founder of the openSUSE project, one of the world’s leading open source initiatives.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}