Data Breaches: Measurement Efforts and Issues Chris Walsh - - PowerPoint PPT Presentation

data breaches measurement efforts and issues
SMART_READER_LITE
LIVE PREVIEW

Data Breaches: Measurement Efforts and Issues Chris Walsh - - PowerPoint PPT Presentation

Data Breaches: Measurement Efforts and Issues Chris Walsh chris@cwalsh.org ChoicePoint as Impetus Breach Law Passage Dates 8 6 Num States Breach focused attention, 4 spurred legislative action 2 But, what can we actually 0 measure,


slide-1
SLIDE 1

Data Breaches: Measurement Efforts and Issues

Chris Walsh chris@cwalsh.org

slide-2
SLIDE 2

Breach Law Passage Dates

Date Law Passed Num States 2 4 6 8 Sep 2002 Jun 2003 Mar 2004 Dec 2004 Sep 2005

ChoicePoint as Impetus

Breach focused attention, spurred legislative action But, what can we actually measure, and how? How big is the problem, and how costly the solution(s)?

slide-3
SLIDE 3

Data Breaches and Identity Theft

Relationship clearly(?) exists How much of either is there? Are on-line breaches a significant source

  • f ID theft?
slide-4
SLIDE 4

Today’s ID Theft Measures

Illustrative/ Anecdotal: “Let’s call him Joe” Retrospective Surveys

Estimate P(“Identity Theft”) for population, subgroups thereof Summary statistics on losses Whodunit?

Industry fraud figures, FTC complaint volume

slide-5
SLIDE 5

Today’s Data Breach Measures

Lists: Do raw data a “metric” make? Aggregated: x breaches, at y locations, affecting z people Econometric: Statistical estimates of impact on breached organization/firm. Survey: Samples of convenience, “illustrative” results.

slide-6
SLIDE 6

Lists, Aggregates

Dataloss Emergent Chaos Privacyrights.org

Aggregated metrics are trivially derived from any of the above. There’s some unit confusion: “records” vs. “people” .

slide-7
SLIDE 7

Event Studies

Econometric estimates of “ abnormal return” across a sample of firms subject to similar events English: On average, how much does a security breach decrease a company’s stock price -- if at all? In pictures ...

slide-8
SLIDE 8

Is this typical?

Choicepoint

Data: Yahoo Finance

slide-9
SLIDE 9

Is this?

Honeywell, Inc.

Source: Google

slide-10
SLIDE 10

Results

Study Period Examined Abnormal Return N Campbell, et. al., 2003 1997

  • 2000
  • 5.4%

11 Cavusoglu, et. al., 2004 1996- 2001

  • 2.1%

78 Acquisti, et. al., 2006 2000- 2006

  • 0.6%

79

Hard to say which aspects of breaches contribute to losses -- confidentiality seems to matter (Campbell), but jury is out on other independent variables.

slide-11
SLIDE 11

Additional research is needed in this crucial area... More specifically... Chris the grad student sez:

Actual 1991 Photo

slide-12
SLIDE 12

Research Agenda

Measure impact on govt, educational

  • rganizations

Find independent variables affecting breach impact. Is time one of them? Is firm “frankness”? Is this an iceberg? How can we tell? Do we have enough info on breaches we know about?

slide-13
SLIDE 13

Validate model assumptions about investor attitude, using survey research Examine sampling issues in existing event studies -- has SB1386 improved data availability, added noise, or what? Look inside organizations -- do decision- makers act to minimize breach impact? Does behavior vary across organization types or governance structures?

slide-14
SLIDE 14

Can we integrate findings from fraud- detection ‘ sensor networks’, honeynets, and monitoring of underground economy in PII to validate breach volume information? Replicate Campbell, et. al. with more recent data. Some non-US data would be nice!

slide-15
SLIDE 15

Read me:

Acquisti, Alessandro, et. al., Is There a Cost to Privacy Breaches? An Event Study, [DRAFT -- URL omitted] Anderson, Keith B., Identity Theft: Does the Risk Vary with Demographics?, http:/ /www.ftc.gov/be/workpapers/wp279.pdf Belva, Kenneth F., How It's Difficult to Ruin a Good Name: An Analysis of Reputational Risk, http:/ / www.ftusecurity.com/pub/FiTechSummit_final_paper.pdf Campbell, et. al., The economic cost of publicly announced information security breaches: empirical evidence from the stock market, http:/ /iospress.metapress.com/link.asp?id=5nkxhffc775tuel9 Cavusoglu, et. al., The Effect of Security Breach Announcements on the Market Value of Breached Firms and Internet Security Developers, http:/ /mesharpe.metapress.com/link.asp?id=mx6xwxy2rfx166ge Ponemon, Larry, Lost Customer Information: What Does a Data Breach Cost Companies?

slide-16
SLIDE 16

Please see http://www.cwalsh.org/metricon/ for full citations, links to materials mentioned, and (real soon now) a more formal paper-length discussion of the issues raised here.

Thanks