Damage limitation: timely software updates can cut business data breach costs in half
December 2020 by Kaspersky
According to a recent Kaspersky report, ‘How businesses can minimise the cost of a data breach’, enterprises with outdated technology can lose 47% more money when they suffer a data breach compared to those who update everything in a timely manner. For small and medium-sized businesses, the difference is even starker – up to 54%. The problem of obsolete and unpatched software is quite common and important for businesses to address, since nearly half of organisations (47%) use at least some form of out-of-date technology in their infrastructure.
While vulnerabilities are inevitable in any software, regular patching and updates can minimise the risk of exploitation. That’s why users are always advised to install the latest software versions as soon as they are available, even if these updates can sometimes be difficult or a time-consuming task for organisations. With many businesses globally having at least some form of outdated technology (47%), Kaspersky’s survey shows that organisations should prioritise renewing software and be prepared to invest because doing so could save them money in the long-term.
If a data breach happens, enterprises with any form of outdated technology, including unpatched operating systems, old software and unsupported mobile devices, can suffer an additional $425k in financial damage, taking losses to a total of $1.225m. This is 47% more than the cost for companies with completely updated technologies ($836k). As for small and medium-sized businesses, they can lose an additional $40k. The total cost rises to $114k – 54% more compared to $74k for businesses with all required updates installed.
Chart 1: Average cost of a data breach depending on whether the company has outdated technology
Among the reasons given for not updating technologies, the most commonly reported is an incompatibility of updates with in-house applications (48%). This reason can be critical for organisations developing software internally to meet their own needs or when using very specific applications with limited support. Other reasons seem more down-to-earth: employees often refuse to work with new versions of the software they use (48%). In some cases, technologies are not updated because they belong to members of the C-suite (34%). “Any additional costs for business are of course critical, especially now. The global economic situation is unstable because of the pandemic and investments in IT and IT security are predicted to decrease. This is why in this year’s ‘IT Security Economics’ report we wanted to explore how businesses can reduce the burden in case of a cybersecurity incident. It offers strong reasoning why the issue of obsolete software is so important. Even if it is impossible to get rid of it overnight, there are still some measures to mitigate the risk. Companies can not only save money, but also avoid other potential consequences - which is crucial for any business,” comments Sergey Martsynkyan, Head of B2B Product Marketing at Kaspersky.
In order to save money and minimise the risk of data breaches as a result of software vulnerabilities, Kaspersky suggests the following measures:
• Ensure the organisation is using the latest version of its chosen operating systems and applications, with auto-update features enabled so that the software is always up to date.
• If it is not possible to update software then organisations are advised to address this attack vector through smart separation of vulnerable nodes from the rest of the network, along with other measures.
• Enable the vulnerability assessment and patch management feature in an endpoint protection solution. This can automatically eliminate vulnerabilities in infrastructure software, proactively patch them and download essential software updates.
• It is important to boost security awareness and practical cybersecurity skills for IT managers, as they are at the frontline of IT infrastructure updates. A dedicated Security for IT Online training course can help.
• For critical IT or operational technology systems, it is important to always be protected regardless of any available software updates. This means they should only enable activity that is predetermined by the purpose of the systems. KasperskyOS supports this concept of cyber-immunity and can be used to build IT systems that are secure by design.