<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How Damaging is a Breach?</title>
	<atom:link href="http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/comment-page-1#comment-2257</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Thu, 08 Jun 2006 11:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1754#comment-2257</guid>
		<description>Did they announce it, or tell the SEC?
Companies suffering decliing sales love to blame outside factors, rather than exec failures.
</description>
		<content:encoded><![CDATA[<p>Did they announce it, or tell the SEC?<br />
Companies suffering decliing sales love to blame outside factors, rather than exec failures.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Hutton</title>
		<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/comment-page-1#comment-2256</link>
		<dc:creator>Alex Hutton</dc:creator>
		<pubDate>Wed, 07 Jun 2006 21:28:57 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1754#comment-2256</guid>
		<description>Speaking of the cost of a breach, yesterday DSW announced that earnings were down because of their incident.  Has anyone seen how much money loss they allocate to the breach?
I&#039;m searching and I can&#039;t find anything off their investor relations site.
</description>
		<content:encoded><![CDATA[<p>Speaking of the cost of a breach, yesterday DSW announced that earnings were down because of their incident.  Has anyone seen how much money loss they allocate to the breach?<br />
I&#8217;m searching and I can&#8217;t find anything off their investor relations site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Walsh</title>
		<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/comment-page-1#comment-2255</link>
		<dc:creator>Chris Walsh</dc:creator>
		<pubDate>Tue, 06 Jun 2006 19:51:49 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1754#comment-2255</guid>
		<description>In related news...veterans&#039; (note apostrophe use, Adam) groups are seeking $26.5 billion from the VA in a class-action suit.
&lt;a href=&quot;http://www.internetnews.com/bus-news/article.php/3611586&quot; rel=&quot;nofollow&quot;&gt;http://www.internetnews.com/bus-news/article.php/3611586&lt;/a&gt;
</description>
		<content:encoded><![CDATA[<p>In related news&#8230;veterans&#8217; (note apostrophe use, Adam) groups are seeking $26.5 billion from the VA in a class-action suit.<br />
<a href="http://www.internetnews.com/bus-news/article.php/3611586" rel="nofollow">http://www.internetnews.com/bus-news/article.php/3611586</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/comment-page-1#comment-2254</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 05 Jun 2006 20:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1754#comment-2254</guid>
		<description>Alex,
I&#039;m looking for a baseline of risk for identity theft that&#039;s not the &quot;1.5%&quot; number that includes account takeover and fraud by impersonation.
&lt;a href=&quot;http://spiresecurity.typepad.com/spire_security_viewpoint/2006/05/100.html&quot; rel=&quot;nofollow&quot;&gt;http://spiresecurity.typepad.com/spire_security_viewpoint/2006/05/100.html&lt;/a&gt;
</description>
		<content:encoded><![CDATA[<p>Alex,<br />
I&#8217;m looking for a baseline of risk for identity theft that&#8217;s not the &#8220;1.5%&#8221; number that includes account takeover and fraud by impersonation.<br />
<a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2006/05/100.html" rel="nofollow">http://spiresecurity.typepad.com/spire_security_viewpoint/2006/05/100.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Hutton</title>
		<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/comment-page-1#comment-2253</link>
		<dc:creator>Alex Hutton</dc:creator>
		<pubDate>Mon, 05 Jun 2006 14:57:22 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1754#comment-2253</guid>
		<description>Are you looking for data or &quot;baseline risk&quot; of a breach?
Data, as you say, is problematic.  The trouble I see with determining baseline risk (assuming you like your definition of risk to be &quot;amount you will probably lose and how frequently you stand to lose that amount&quot;) is that risk calculations normally require that data.  Welcome to catch-22.
However, I think you can use probabilistic modeling to get a good range with which to arrive at &quot;baseline risk&quot;.  Got a link to Mr. Lindstrom?
</description>
		<content:encoded><![CDATA[<p>Are you looking for data or &#8220;baseline risk&#8221; of a breach?<br />
Data, as you say, is problematic.  The trouble I see with determining baseline risk (assuming you like your definition of risk to be &#8220;amount you will probably lose and how frequently you stand to lose that amount&#8221;) is that risk calculations normally require that data.  Welcome to catch-22.<br />
However, I think you can use probabilistic modeling to get a good range with which to arrive at &#8220;baseline risk&#8221;.  Got a link to Mr. Lindstrom?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Walsh</title>
		<link>http://emergentchaos.com/archives/2006/06/how-damaging-is-a-breach.html/comment-page-1#comment-2252</link>
		<dc:creator>Chris Walsh</dc:creator>
		<pubDate>Mon, 05 Jun 2006 11:45:19 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=1754#comment-2252</guid>
		<description>Since broadly speaking there is no requirement to report to anyone but the victims and the three CRAs, the information is either locked up (at the credit bureaus) or so widely dispersed that it is difficult to collect.
I assert that we learn of only the &quot;most newsworthy&quot; breaches, since these are the ones individuals who have been notified actually pipe up about.
&quot;Newsworthy&quot; in the preceding sentence I think means:
Shocking to the conscience
Affecting very large number of people
Having some quirky aspect
The state of the art in gathering &quot;comprehensive&quot; data on breaches (forget about individual-level impact for now) amounts to using Google, Lexis/Nexis, and Edgar On-Line.
My assertion in the second paragraph may be semi-testable, but it requires making some potentially unwarranted assumptions about how &quot;representative&quot; breaches reported to the NY State government are of breaches nationally.  I&#039;ll have more to say about this soon (ideally, in Vancouver, oh powerful program committee luminaries)
</description>
		<content:encoded><![CDATA[<p>Since broadly speaking there is no requirement to report to anyone but the victims and the three CRAs, the information is either locked up (at the credit bureaus) or so widely dispersed that it is difficult to collect.<br />
I assert that we learn of only the &#8220;most newsworthy&#8221; breaches, since these are the ones individuals who have been notified actually pipe up about.<br />
&#8220;Newsworthy&#8221; in the preceding sentence I think means:<br />
Shocking to the conscience<br />
Affecting very large number of people<br />
Having some quirky aspect<br />
The state of the art in gathering &#8220;comprehensive&#8221; data on breaches (forget about individual-level impact for now) amounts to using Google, Lexis/Nexis, and Edgar On-Line.<br />
My assertion in the second paragraph may be semi-testable, but it requires making some potentially unwarranted assumptions about how &#8220;representative&#8221; breaches reported to the NY State government are of breaches nationally.  I&#8217;ll have more to say about this soon (ideally, in Vancouver, oh powerful program committee luminaries)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

