Why Security Breaches Just Keep Getting Bigger and More Expensive

The battle against hackers and online criminals seems almost unfairly tilted to their advantage. After all, hackers just need to find one vulnerability, while companies must secure all possible vulnerabilities to keep their data secure.
While data security is a hard enough challenge for professional technology companies to manage, all kinds of companies from retailers to health care providers have your personal information, and they have to maintain security even though their core focus is elsewhere.
The result is that we’ve seen monumental breaches of personal data over the last decade, and the problem is only growing worse. In the last few months alone, companies ranging from Marriott and Discover to Reddit have notified users about data breaches, ranging from minor to severe.
In this article, we’ll review trends in data breaches, quantify how big the problem is and how much it costs companies in different countries and different industries. The data on security breaches reveals the scale of the problem: Breaches are increasing, they’re big (up to 3 billion accounts have been hacked at a time), and they’re especially costly in industries like healthcare and in countries like the United States.
A data breach is an unauthorized release of secure or private information into an unauthorized environment. These breaches can range from “hacks” from external sources or a company inadvertently making confidential information public.
Breaches range in severity on two dimensions: the sensitivity of the leaked data and whether that data is encrypted or not. Sensitive data could include things like credit card numbers, passport numbers, or the password to your email address or bank account. Even data that might not seem sensitive actually could have unforeseen consequences: Your birthdate could be used to open up accounts in your name when paired with other stolen information or if you re-used a password for opening up an account on a new social network you never really used (that was later hacked) for your bank account, you could be in serious trouble.
Because so many kinds of data are sensitive, what’s perhaps most important is whether the company that was hacked had encrypted your data or not. Unencrypted data, where your information is stored in “clear text” on a company’s servers means that if the company is hacked, the hackers have your data.
However, most companies today will encrypt sensitive data so that the data they store is jumbled unless you have the encryption key, which is hopefully stored separately from the data so it’s unlikely hackers steal both. As a result, sometimes when you hear about a large data breach in the press, the stolen data is encrypted which makes it mostly unusable for the hackers.
With that background on data breaches in mind, let’s dive into the data documenting the frequency and depth of these security incidents.
It’s not just your imagination, data breaches are becoming much more common in the United States. The Identity Theft Resource Center (IDRC), a non-profit tracking reported breaches at US businesses, government agencies and other organizations provides the count of incidents per year. In short, data breaches are becoming increasingly common:
By 2018, the number of breaches skyrocketed to 1,244 per year from just 157 in 2005. In the course of just over a decade, the breach frequency has increased over eight times.
![Data Science for Managers [Mindmap]](https://7wdata.be/wp-content/uploads/2018/09/CWBlogManagers01jpg.png)

