Report: Data breaches on the rise, Australian businesses ill-prepared

​Data loss and the theft ​of confidential information incidents rose by 78.68 per cent in 2018

Data loss and theft continues to rise, yet two-thirds of organisations in Australia do not have a team or capability to respond to cyber security incidents.

According to the 2018/2019 BDO and AusCERT Cyber Security Survey, data loss and the theft of confidential information incidents rose by 78.68 per cent in 2018 compared to 2017, and data breaches experienced through third-party providers and suppliers also rose by 74.3 per cent.

Between 2017 and 2018 alone, professional and technical service organisations have seen a 300 per cent increase in data breaches via third-party providers and suppliers, and a 670 per cent increase in data loss and theft of confidential information. However, no professional and technical services respondents to the survey perceived an incident caused by a third party as a threat, indicating incidents were likely to have occurred, but were not detected.

Although cyber criminals are the most common sources of cyber attacks, respondents also reported a significant increase in suspected attacks from foreign governments and nation states, with 64 per cent of data breaches caused by malicious or criminal attacks, while 33 per cent could be attributed to human error.

While most organisations were confident in meeting compliance regulations as outlined by recently introduced cyber security and data privacy legislation, 66 per cent of businesses surveyed have no predefined plan or capability to contain, eradicate and recover from cyber security incidents.

On average, the cost to an Australian organisation for a data breach is almost $US2 million. The potential for huge financial implications is one reason 86.4 per cent of survey respondents indicated they expected to have a cyber security awareness plan in place within the next 12 months. By 2020, 84.8 per cent of respondents plan to implement regular cyber security risk assessments.

Respondents are anticipating data loss and theft of confidential information to be the most prevalent threat in 2019 and beyond, with respondents expecting attacks coming from activists (80%), insiders (68%), or foreign nationals (10%).

Recent high-profile cyber breaches at Dell, HealthEngine and PageUp have exposed Australia’s vulnerability to data-related breaches and prompted calls for greater investment in cyber security awareness and incident management in the professional services domain.

A recent Customer Loyalty 2018 Report by Gemalto also found Australian consumers are more likely than their global counterparts to walk away from a company (retail, financial or healthcare) that experiences a breach, with over two-thirds (70 per cent) admitting they would look elsewhere if financial and sensitive information such as card details and bank accounts were stolen. Over half (55 per cent) admitted they would also walk if passwords alone were stolen.

The report found retailers (62 per cent), social media sites (57 per cent) and banks (53 per cent) are most at risk of suffering the consequences of a breach, with Australian consumers prepared to avoid their business in future. Two-thirds of Australian consumers are worried that at some point their online personal information will be stolen.

BDO’s national cyber security leader, Leon Fouche, said all industries needed to ramp up their focus on employee education and training to empower their people to take action.

“While recent compliance regulations have boosted data breach notification numbers and industry leaders have endorsed the implementation of more comprehensive resilience measures, many Australian organisations do not have the capability to detect a breach or respond to it in a manner that contains cost and reputational damage,” Fouche said.

“Sophisticated cyber attacks and data breaches sit alongside weapons of mass destruction and natural disasters in terms of their ability to disrupt and damage; however, in many business cases, the focus on preventative measures has far outweighed response or incident management.

“Every organisation should have a pre-defined plan, which is regularly tested, to ensure that everyone in the organisation knows what to do and how to respond to cyber security incidents.”

The most common vehicle for cyber attack remained phishing, which accounted for 20.19 per cent of all cyber security incidents experienced in 2018 and has been trending upwards since the inaugural BDO and AusCERT Cyber Security Survey in 2016. Phishing was followed by malware (14.08%) and ransomware attacks (9.39%).

“That’s why education and training are so important. Employees need to be given the knowledge to detect a potential cyber attack and the tools to respond if they suspect there has been a breach or they have inadvertently disclosed sensitive information,” Fouche said.

The survey examined the cyber security risks and realities experienced by more than 500 board, business and IT executives across Australia and New Zealand.

Follow CMO on Twitter: @CMOAustralia, take part in the CMO conversation on LinkedIn: CMO ANZ, join us on Facebook: https://www.facebook.com/CMOAustralia, or check us out on Google+:google.com/+CmoAu  

 

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Latest Videos

More Videos

More Brand Posts

What are Chris Riddell's qualifications to talk about technology? What are the awards that Chris Riddell has won? I cannot seem to find ...

Tareq

Digital disruption isn’t disruption anymore: Why it’s time to refocus your business

Read more

Enterprisetalk

Mark

CMO's top 10 martech stories for the week - 9 June

Read more

Great e-commerce article!

Vadim Frost

CMO’s State of CX Leadership 2022 report finds the CX striving to align to business outcomes

Read more

Are you searching something related to Lottery and Lottery App then Agnito Technologies can be a help for you Agnito comes out as a true ...

jackson13

The Lottery Office CEO details journey into next-gen cross-channel campaign orchestration

Read more

Thorough testing and quality assurance are required for a bug-free Lottery Platform. I'm looking forward to dependability.

Ella Hall

The Lottery Office CEO details journey into next-gen cross-channel campaign orchestration

Read more

Blog Posts

Marketing prowess versus the enigma of the metaverse

Flash back to the classic film, Willy Wonka and the Chocolate Factory. Television-obsessed Mike insists on becoming the first person to be ‘sent by Wonkavision’, dematerialising on one end, pixel by pixel, and materialising in another space. His cinematic dreams are realised thanks to rash decisions as he is shrunken down to fit the digital universe, followed by a trip to the taffy puller to return to normal size.

Liz Miller

VP, Constellation Research

Why Excellent Leadership Begins with Vertical Growth

Why is it there is no shortage of leadership development materials, yet outstanding leadership is so rare? Despite having access to so many leadership principles, tools, systems and processes, why is it so hard to develop and improve as a leader?

Michael Bunting

Author, leadership expert

More than money talks in sports sponsorship

As a nation united by sport, brands are beginning to learn money alone won’t talk without aligned values and action. If recent events with major leagues and their players have shown us anything, it’s the next generation of athletes are standing by what they believe in – and they won’t let their values be superseded by money.

Simone Waugh

Managing Director, Publicis Queensland

Sign in