Nearly every third corporate data breach gets employees fired

1 August 2018 Information Security

When a data breach strikes, the damage can reach further than a business’s finances, reputation, and customer privacy. A breach can also severely impact the careers of individuals at the company involved. According to a new report from Kaspersky Lab and B2B International, 25% of data breaches in the Middle East, Turkey and Africa (META) region in the past year have led to people losing their jobs.

Breaking careers with data breaches

A data breach in a company can be a life-changing experience for both its customers and employees, according to the recent report from B2B International and Kaspersky Lab: From data boom to data doom: the risks and rewards of protecting personal data. The study shows that 45% of businesses in the META region had at least one data breach in the last year. As for the staff involved, they don’t always - not even at C-level - get to keep their jobs afterwards.

The range of employees laid off after a data breach demonstrates that the incident can affect anyone, and 2017 alone saw a wide variety of people fired as a result of data breaches: from CEOs to a regular employee exposing the company’s customer data.

Of course, for businesses this means more than just lost talent: 43% of META companies have had to pay compensation to the customers affected, over a third (35%) have reported problems attracting new customers, and over a third (36%) have had to pay penalties and fines.

Data beyond control adds to the risk

In modern business, storing sensitive personal data is practically unavoidable: 88% of businesses in the META region and 81% of businesses in South Africa collect and store their customers’ personally identifiable information. Moreover, in today’s increasingly complex environment, new regulations like GDPR and PoPIA mean that storing personal information comes with compliance risks too.

What makes these risks even more tangible is the actual reality of how businesses store data. Approximately 13% of sensitive customer and corporate data in South Africa resides outside the corporate perimeter: in public cloud, BYOD devices and in SaaS applications, which makes controlling the data flow and keeping it safe a challenge for businesses.

Data protection measures beyond policies

The report says that 91% of businesses in the META region have at least some form of data security and compliance policy in place. However, a privacy policy itself isn’t a guarantee that data will in fact be handled properly.

There’s a need for security solutions that can protect data across the whole infrastructure - including cloud, devices, applications and more. Cybersecurity awareness among IT staff and beyond also needs to be improved, as more and more business units are now working with data, and thus need to understand how to keep it safe.

“While a data breach is devastating to a business as a whole, it can also have a very personal impact on people’s lives - whether they are customers or failed employees - so this is a reminder that cybersecurity has real-life implications and is in fact everyone’s concern. With data now traveling on devices and via the cloud, and with regulations like GDPR becoming enforceable, it’s vital that businesses pay even closer attention to their data protection strategies,” says Dmitry Aleshin at Kaspersky Lab.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...