http://www.edelman.com/post/the-communications-imperative-for-managing-data-breaches/
BY DAVID CHAMBERLIN
PUBLISHED JULY 3, 2013

Over the past several months, how companies and governments manage data security and privacy issues have become a major news driver. Not a week goes by that we don’t see headlines about hacking incidents at major companies in virtually every industry. With the continued take-down of major banking institutions, allegations of widespread hacking of major U.S. companies by China and the outcry over revelations of the National Security Administration’s collecting of domestic phone and internet records through the PRISM program, it’s clear this issue is not going away anytime soon.
For companies and organizations that collect, store and use information, this new level of scrutiny makes effective communications about security and privacy an imperative. No matter if a business deals with private financial information, personal health records or trade secrets that provide a competitive advantage, there is a hacker somewhere in the world who sees this valuable information as a potential target. Breaches that result in the loss of proprietary or confidential business information can make a company look ill-prepared, careless or incompetent, which could lead to a loss of customer trust and corporate reputation.
According to the Ponemon Institute’s ninth annual “Cost of Data Breach Study,” the average data breach in the United States now costs an organization more than $5.4 million, which includes the cost of forensic investigations, customer notification, lost business and harm to corporate reputation. Ponemon also found that breaches due to hacking are on the rise and that these types of incidents cost companies 60 percent more per record when compared to breaches caused by a system glitch or human error.
The good news is that companies can mitigate the costs of issues with a little foresight. Ponemon examined factors that often lower the cost of a breach and found organizations that had an “incident response plan” at the time of their breaches saw an average cost that was $42 less than the national average per compromised record.
So what does this mean for senior communications executives? Reputation is one of an organization’s most valuable assets and managing it when a data breach occurs is not about spin and is not a job to be left to the legal department. It is a management function that must begin at the top. When a breach occurs, every interaction must be well planned and aligned, including media interviews, customer and employee outreach, regulator and policymaker interactions and operational decisions. The only way to mitigate the reputational and financial repercussions of a data breach are, following the Boy Scouts’ lead, to be prepared.
David Chamberlin is executive vice president and general manager, Edelman Dallas.
BY DAVID CHAMBERLIN
PUBLISHED JULY 3, 2013
Over the past several months, how companies and governments manage data security and privacy issues have become a major news driver. Not a week goes by that we don’t see headlines about hacking incidents at major companies in virtually every industry. With the continued take-down of major banking institutions, allegations of widespread hacking of major U.S. companies by China and the outcry over revelations of the National Security Administration’s collecting of domestic phone and internet records through the PRISM program, it’s clear this issue is not going away anytime soon.
For companies and organizations that collect, store and use information, this new level of scrutiny makes effective communications about security and privacy an imperative. No matter if a business deals with private financial information, personal health records or trade secrets that provide a competitive advantage, there is a hacker somewhere in the world who sees this valuable information as a potential target. Breaches that result in the loss of proprietary or confidential business information can make a company look ill-prepared, careless or incompetent, which could lead to a loss of customer trust and corporate reputation.
According to the Ponemon Institute’s ninth annual “Cost of Data Breach Study,” the average data breach in the United States now costs an organization more than $5.4 million, which includes the cost of forensic investigations, customer notification, lost business and harm to corporate reputation. Ponemon also found that breaches due to hacking are on the rise and that these types of incidents cost companies 60 percent more per record when compared to breaches caused by a system glitch or human error.
The good news is that companies can mitigate the costs of issues with a little foresight. Ponemon examined factors that often lower the cost of a breach and found organizations that had an “incident response plan” at the time of their breaches saw an average cost that was $42 less than the national average per compromised record.
So what does this mean for senior communications executives? Reputation is one of an organization’s most valuable assets and managing it when a data breach occurs is not about spin and is not a job to be left to the legal department. It is a management function that must begin at the top. When a breach occurs, every interaction must be well planned and aligned, including media interviews, customer and employee outreach, regulator and policymaker interactions and operational decisions. The only way to mitigate the reputational and financial repercussions of a data breach are, following the Boy Scouts’ lead, to be prepared.
David Chamberlin is executive vice president and general manager, Edelman Dallas.