Cost of data breaches in Canada hit new record in 2021: IBM

The average cost of a data breach in Canada hit a record high last year as companies grappled with new cybersecurity risks during the COVID-19 pandemic.
According to a new report from IBM Security, the average cost of a data breach in Canada was $6.75 million per incident in the 2021 survey year. That's up from $6.35 million the year before and the highest since IBM first included Canada in its survey seven years ago. It's also higher than the 2021 global average of US$4.24 million ($5.34 million), which in itself is a 10 per cent increase from the prior year and the highest global average in the survey's 17-year history.
The study suggests cybersecurity efforts may have lagged behind as companies were forced to rapidly adapt to remote work during the pandemic, said IBM Security associate partner Ray Boisvert.
“This to me is a wake-up call,” Boisvert said, adding companies reported data breaches last year that were not only costly, but also hard to contain. For example, companies surveyed reported a mean time of 164 days to identify they had a breach and 60 days to contain it, one week longer than the prior year's report.
According to the study, data breaches cost $1 million more on average when remote work was indicated as a factor in the event.
“There was certainly a strong link to remote work,” Boisvert said. “We're now living in a perimeter-less environment … and trying to defend a multiplicity of inputs becomes very difficult.”
Charles Finlay, executive director of the Rogers Cybersecure Catalyst at Ryerson University, said the sheer volume of varying devices and network connections used by remote workers during the pandemic posed a cybersecurity threat.
“Employees are working from home using insecure Internet networks and computers, and the kind of security measures that would be imposed in a corporate environment in a workplace just are not always present,” Finlay said.
He added that a crisis like the global pandemic can also be easily exploited by cybercriminals - for example, through a phishing email that poses as official health advice.
“We know that fake websites have been set up purporting to provide information on COVID-19,” Finlay said. “So COVID-19 has provided a lot of opportunity, unfortunately, for malicious attackers and cybersecurity. I'm not surprised by IBM's findings.”
The survey found nearly half (44 per cent) of the breaches analyzed exposed customer personal data, such as names, emails, passwords, or even healthcare data. It found compromised user credentials (such as stolen passwords) were the most common method used as an entry point by attackers, representing 20 per cent of breaches studied.
Ransomware attacks are also growing increasingly common, said Finlay, pointing to high-profile incidents so far in 2021 like the Russian-linked cyberattacks on Colonial Pipeline and JBS Foods.
“When I look back at the last year, the most serious development that I see is around the increasingly serious ransomware attacks, in particular around critical infrastructure,” Finlay said. “Ransomware is exploding as a major international security problem. It is a multi-billion global industry.”
The IBM survey analyzed real-world data breaches experienced by 500 organizations worldwide (26 in Canada) between May 2020 and March 2021. It factored in costs to companies ranging from legal, regulatory and technical responses in the event of a cyberattack to loss of brand equity, customers, and employee productivity.
This report by The Canadian Press was first published July 28, 2021
CTVNews.ca Top Stories

WATCH 'Jumped over their heads': Kangaroo escapes Ontario zoo during overnight stay
A kangaroo destined for Quebec escaped an Ontario zoo during an overnight stay on Friday. According to an employee, it "jumped" over handlers' heads.
With Canada set to reimpose cap on working hours, international students worry about paying for tuition, living expenses
Canada is set to reimpose the cap on the number of hours that international students can work off campus. But with heightened cost-of-living concerns in Canada, many international students say they're not sure how they'll be able to afford their tuition and living expenses if they can't work full-time.
Inmate stabbed Derek Chauvin 22 times, charged with attempted murder, prosecutors say
A federal inmate was charged Friday with attempted murder in the prison stabbing of Derek Chauvin, the former Minneapolis police officer convicted of murdering George Floyd.
Environment Canada calls for mild, rainy winter for most of Canada
Winter will be unusually warm and rainy across much of the country this year, according to the latest data from Environment and Climate Change Canada.
More salmonella-contaminated fruits pulled amid outbreak: Here's what was recalled in Canada this week
Here's a list of recalled items that got taken off the shelves this week
Alleged Montreal-area 'Chinese police stations' planning to sue RCMP for $2.5 million
Two Chinese community centres in the Montreal area are planning to launch a $2.5 million defamation lawsuit against the RCMP and the Attorney General of Canada after being accused by the police force of hosting 'alleged Chinese police stations.'
Live updates Israeli strikes kill over 175 people in Gaza as cease-fire ends, health officials say
Israeli strikes on houses and buildings have killed at least 178 people throughout the Gaza Strip on the first hours of fighting after a weeklong truce collapsed Friday, according to the Health Ministry there. Israel said it struck more than 200 Hamas targets.
Suspect charged with 4 counts of second-degree murder in Winnipeg mass shooting
A suspect has been charged with four counts of second-degree murder in connection with the Langside homicide.
Former Sask. hockey coach found guilty of sexual assault and assault
Former Saskatchewan junior hockey coach Bernard (Bernie) Lynch was found guilty by a Regina Court of King’s Bench judge on Friday of sexual assault and assault stemming from incidents that took place in August of 1988.