Every few weeks a breach hits the news, and within hours there is a number attached to it. Sometimes it is a settlement, sometimes an estimate from a consulting firm, sometimes a figure pulled from a report that was never meant to be read that way. The number is almost always wrong, and it almost always misses the parts that hurt the most.
The visible costs are the easy ones. Forensic firms, legal counsel, notification mailings, credit monitoring, and regulatory fines all show up on an invoice. They are painful but they are bounded. You can plan for them, budget for them, and eventually pay them. The costs that do real damage are the ones that do not come with a line item.
The first is attention. When an incident happens, senior leadership stops doing whatever they were doing and starts doing incident response. Product launches slip. Hiring freezes. Strategic initiatives get shelved. That opportunity cost never appears in a post-mortem, but it is often the largest single expense of the entire event.
The second is trust. Customers forgive a lot, but they do not forgive silence. If your first communication is a vague statement three weeks after the fact, you have already lost ground. The organizations that come out of incidents with their reputation mostly intact are the ones that told people what happened, what they knew, and what they did not know, quickly and without spin.
The third is internal. Security teams burn out during incidents. Analysts work sixteen-hour days for weeks. When the dust settles, some of them leave. Replacing a senior detection engineer takes months and costs more than most people expect. The knowledge that walks out the door is not recoverable.
There is also the quieter cost of overcorrection. After a breach, it is tempting to buy everything, lock everything down, and freeze all change. This feels responsible. It usually is not. Overly restrictive controls push people to work around them, and a workforce that routes around security is worse off than one that never had the controls at all.
The organizations that handle incidents best tend to share a few traits. They have a written plan that has been rehearsed, not just filed. They know who makes decisions and who talks to the press. They have retainer agreements with forensic and legal partners before they need them, because negotiating a contract in the middle of a crisis is a bad time.
They also keep good records. Asset inventories, data flow diagrams, and access reviews sound bureaucratic until the moment you need to answer the question "what was on that server." Then they become the most valuable documents in the building.
Finally, they treat incidents as learning events rather than failures. The goal of a post-incident review is not to assign blame. It is to find the assumptions that turned out to be wrong and fix them. Every organization has those assumptions. The ones that survive contact with reality are the ones that went looking for them first.
This incident opened my eyes to the value of Insurance in general, so I decided to examine my personal and business insurance.
Comment (3)
The payments are made directly from one person to another without passing through a central bank or clearing house.
22 feb,2025
ReplyPhishing Kits Have Gotten Boring, and That Is the Problem
23 feb,2025
ReplyRansomware Negotiations: What the Data Does Not Tell You
23 feb,2025
Reply