<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cost of a Breach: $6, not $187?</title>
	<atom:link href="http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Mike Spinney</title>
		<link>http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html/comment-page-1#comment-3871</link>
		<dc:creator>Mike Spinney</dc:creator>
		<pubDate>Mon, 20 Aug 2007 15:36:39 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2462#comment-3871</guid>
		<description>For those reporters (and there were only a few) who bothered to ask Larry Ponemon about the costs, they got an answer that was in-line with the estimates TJX just announced.  Ross Kerber&#039;s reporting in the Boston Globe back in April (http://www.boston.com/business/personalfinance/articles/2007/04/12/analysts_tjx_case_may_cost_over_1b/) should serve to demonstrate Ponemon&#039;s grasp of the issue, and his own research.  Others weren&#039;t so bright, opting instead to simply multiply a breach that represented a statistical anomaly on the high end with the $183/per figure from our 2006 report.  While the resulting figure was certainly sensational it was, as others have already pointed out, a misread of the information in the report.
Economies of scale take over when the incident leaps from a sampling that included incidents numbering in the tens of thousands to a breach that was over 45 million.
Mike
</description>
		<content:encoded><![CDATA[<p>For those reporters (and there were only a few) who bothered to ask Larry Ponemon about the costs, they got an answer that was in-line with the estimates TJX just announced.  Ross Kerber&#8217;s reporting in the Boston Globe back in April (<a href="http://www.boston.com/business/personalfinance/articles/2007/04/12/analysts_tjx_case_may_cost_over_1b/" rel="nofollow">http://www.boston.com/business/personalfinance/articles/2007/04/12/analysts_tjx_case_may_cost_over_1b/</a>) should serve to demonstrate Ponemon&#8217;s grasp of the issue, and his own research.  Others weren&#8217;t so bright, opting instead to simply multiply a breach that represented a statistical anomaly on the high end with the $183/per figure from our 2006 report.  While the resulting figure was certainly sensational it was, as others have already pointed out, a misread of the information in the report.<br />
Economies of scale take over when the incident leaps from a sampling that included incidents numbering in the tens of thousands to a breach that was over 45 million.<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blake</title>
		<link>http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html/comment-page-1#comment-3870</link>
		<dc:creator>Blake</dc:creator>
		<pubDate>Thu, 16 Aug 2007 20:11:36 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2462#comment-3870</guid>
		<description>Typically, those discrepancies are between direct and indirect costs.  Most estimates of direct costs range in the $10-20 area, one hopes and expects there are economies of scale here.  The fearmongers make up big numbers to be estimate of &quot;lost revenue&quot; or &quot;brand impairment&quot; or some other intangible that isn&#039;t falsifiable.  Which is noit to say that they are wrong, just that there is no (little) data.  The lesson of the TJX breach appears to be that the vast majority of consumers (and maybe even a reasonable approximation of &quot;all&quot;) don&#039;t care about security.
</description>
		<content:encoded><![CDATA[<p>Typically, those discrepancies are between direct and indirect costs.  Most estimates of direct costs range in the $10-20 area, one hopes and expects there are economies of scale here.  The fearmongers make up big numbers to be estimate of &#8220;lost revenue&#8221; or &#8220;brand impairment&#8221; or some other intangible that isn&#8217;t falsifiable.  Which is noit to say that they are wrong, just that there is no (little) data.  The lesson of the TJX breach appears to be that the vast majority of consumers (and maybe even a reasonable approximation of &#8220;all&#8221;) don&#8217;t care about security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html/comment-page-1#comment-3869</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 16 Aug 2007 09:00:46 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2462#comment-3869</guid>
		<description>Gee, only $1bn US?  I had heard $4.5 bn:
&lt;a href=&quot;http://www.darkreading.com/document.asp?doc_id=123129&quot; rel=&quot;nofollow&quot;&gt;http://www.darkreading.com/document.asp?doc_id=123129&lt;/a&gt;
blogs need sarcasm tags...
</description>
		<content:encoded><![CDATA[<p>Gee, only $1bn US?  I had heard $4.5 bn:<br />
<a href="http://www.darkreading.com/document.asp?doc_id=123129" rel="nofollow">http://www.darkreading.com/document.asp?doc_id=123129</a><br />
blogs need sarcasm tags&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mordaxus</title>
		<link>http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html/comment-page-1#comment-3868</link>
		<dc:creator>Mordaxus</dc:creator>
		<pubDate>Thu, 16 Aug 2007 04:53:02 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2462#comment-3868</guid>
		<description>You get discounts when you breach in bulk. $187 is retail, quantity one. $6 is what you pay for a site license.
</description>
		<content:encoded><![CDATA[<p>You get discounts when you breach in bulk. $187 is retail, quantity one. $6 is what you pay for a site license.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: q</title>
		<link>http://emergentchaos.com/archives/2007/08/cost-of-a-breach-6-not-187.html/comment-page-1#comment-3867</link>
		<dc:creator>q</dc:creator>
		<pubDate>Thu, 16 Aug 2007 00:37:28 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2462#comment-3867</guid>
		<description>it&#039;s 256 million according to these guys:
&lt;a href=&quot;http://www.secguru.com/link/cost_data_breach_tjx_soars_256m&quot; rel=&quot;nofollow&quot;&gt;http://www.secguru.com/link/cost_data_breach_tjx_soars_256m&lt;/a&gt;
um
</description>
		<content:encoded><![CDATA[<p>it&#8217;s 256 million according to these guys:<br />
<a href="http://www.secguru.com/link/cost_data_breach_tjx_soars_256m" rel="nofollow">http://www.secguru.com/link/cost_data_breach_tjx_soars_256m</a><br />
um</p>
]]></content:encoded>
	</item>
</channel>
</rss>

