마이크로칩 8월
This page was machine-translated and may differ from the original. View original

Data breaches per Korean company increased by 7% compared to last year.

Google 우선 소스Published2020.07.30 10:01
The gap in damages is wide depending on whether or not a security automation solution is available.
South Korea ranks 10th among 17 countries surveyed for data breaches.



The gap in damages between companies that leverage security automation technologies in their businesses and those that don't continues to widen.

On the 30th, IBM, in collaboration with the Ponemon Institute, released the "2020 Global State of Corporate Data Breach" report , which analyzed the data breaches of 524 companies in 17 countries around the world. Following last year's survey, 24 Korean companies were included in the report, providing information on the current state of data breach damage in Korea.

According to the report, the average cost per company from a data breach worldwide was $3.86 million, a decrease of approximately 1.5% from last year's $3.9 million. Factors contributing to the decline include the rise of companies and industries with mature security automation and incident response processes, the stabilization of GDPR, and the availability of cyber insurance.

However, among the 16 countries or regions surveyed in 2019 and 2020, the average damage amount increased in 12 of them, including South Korea.

An in-depth analysis of all data breaches revealed that 80% involved the leak of personally identifiable information (PII) from customers. In terms of the scale of damage, data breaches involving customer PII were the most damaging to companies. IP leaks followed at 30%.

As corporate remote work has increased in recent years, critical data has tended to migrate to environments with less stringent controls, reducing network visibility and making them more vulnerable to breaches.

One of the notable findings from this report is that the average loss for companies that utilize security automation technology is $2.45 million, while the average loss for companies that do not is $6.03 million, resulting in a cost gap of approximately $3.85 million.
▲ Status of Korean corporate data breaches in 2020 [Figure = IBM]
(Open in a new tab to enlarge)

Companies leveraging security automation technologies like AI and machine learning were able to detect and contain breaches approximately 27% faster. Looking at the cost gap between 2018 ($1.51 million) and 2019 ($2.51 million), the gap in damages between companies with and without the adoption of the latest security technologies continues to grow.

◇ 24 domestic companies report increased spending per data breach.

According to a survey of 24 domestic companies, data breaches resulted in financial losses of 3.8 billion won per company, a 7% increase from the previous year (3.553 billion won). This ranked 10th among the 17 countries or regions surveyed. Additionally, it was found that 195,200 won was spent per data breach, an 18.2% increase from the previous year (165,100 won).

Half of data breaches at domestic companies were caused by malicious or criminal attacks. Internal system flaws (29%) and simple employee errors (21%) followed. The average time to identify the cause of a data breach increased from 216 days in 2019 to 223 days in 2020, and the average time to remediate a data breach increased from 71 days in 2019 to 78 days in 2020.

IBM's report also revealed differences in the scale of damage depending on mean time to breach (MTTI) and mean time to breach (MTTC).

According to the report, data breaches that took less than 100 days to identify their cause resulted in an average of 2.61 billion won in damages, while breaches that took more than 100 days incurred a significant loss of 4.998 billion won. Data breaches that took less than 30 days to resolve resulted in 3.31 billion won in damages, but this figure jumped sharply to 4.299 billion won for breaches that took more than 30 days.

Meanwhile, the industry that suffered the most damage from data breaches globally was healthcare, and domestically, it was finance. The service sector ranked second, and the technology industry, which suffered the most damage last year, ranked third this year.

Kim Yong-tae, managing director of IBM Korea's security business division, emphasized, "The recent major direction of domestic security control is advancement through AI and SOAR," and "Security automation is expected to become a key technology that accelerates the transition to the cloud, resolves the shortage of security personnel, and supports business agility."
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자