Cost of data breaches in Canada hit new record in 2021: IBM
The average cost of a data breach in Canada hit a record high last year as companies grappled with new cybersecurity risks during the COVID-19 pandemic.
According to a new report from IBM Security, the average cost of a data breach in Canada was $6.75 million per incident in the 2021 survey year. That's up from $6.35 million the year before and the highest since IBM first included Canada in its survey seven years ago. It's also higher than the 2021 global average of US$4.24 million ($5.34 million), which in itself is a 10 per cent increase from the prior year and the highest global average in the survey's 17-year history.
The study suggests cybersecurity efforts may have lagged behind as companies were forced to rapidly adapt to remote work during the pandemic, said IBM Security associate partner Ray Boisvert.
“This to me is a wake-up call,” Boisvert said, adding companies reported data breaches last year that were not only costly, but also hard to contain. For example, companies surveyed reported a mean time of 164 days to identify they had a breach and 60 days to contain it, one week longer than the prior year's report.
According to the study, data breaches cost $1 million more on average when remote work was indicated as a factor in the event.
“There was certainly a strong link to remote work,” Boisvert said. “We're now living in a perimeter-less environment … and trying to defend a multiplicity of inputs becomes very difficult.”
Charles Finlay, executive director of the Rogers Cybersecure Catalyst at Ryerson University, said the sheer volume of varying devices and network connections used by remote workers during the pandemic posed a cybersecurity threat.
“Employees are working from home using insecure Internet networks and computers, and the kind of security measures that would be imposed in a corporate environment in a workplace just are not always present,” Finlay said.
He added that a crisis like the global pandemic can also be easily exploited by cybercriminals - for example, through a phishing email that poses as official health advice.
“We know that fake websites have been set up purporting to provide information on COVID-19,” Finlay said. “So COVID-19 has provided a lot of opportunity, unfortunately, for malicious attackers and cybersecurity. I'm not surprised by IBM's findings.”
The survey found nearly half (44 per cent) of the breaches analyzed exposed customer personal data, such as names, emails, passwords, or even healthcare data. It found compromised user credentials (such as stolen passwords) were the most common method used as an entry point by attackers, representing 20 per cent of breaches studied.
Ransomware attacks are also growing increasingly common, said Finlay, pointing to high-profile incidents so far in 2021 like the Russian-linked cyberattacks on Colonial Pipeline and JBS Foods.
“When I look back at the last year, the most serious development that I see is around the increasingly serious ransomware attacks, in particular around critical infrastructure,” Finlay said. “Ransomware is exploding as a major international security problem. It is a multi-billion global industry.”
The IBM survey analyzed real-world data breaches experienced by 500 organizations worldwide (26 in Canada) between May 2020 and March 2021. It factored in costs to companies ranging from legal, regulatory and technical responses in the event of a cyberattack to loss of brand equity, customers, and employee productivity.
This report by The Canadian Press was first published July 28, 2021
CTVNews.ca Top Stories
DEVELOPING Gunman's steps after killing UnitedHealthcare's CEO gives police new clues in hunt for the killer
As the hunt for a masked gunman who stalked and killed the head of the largest U.S. health insurer moved into its third day Friday, surveillance footage provided more clues about the suspect's travels and the places he visited before the shooting.
Purolator, UPS pause shipments from couriers amid Canada Post strike
Purolator and UPS have paused shipments from some courier companies as they try to work through a deluge of deliveries brought on by the Canada Post strike.
NDP's Singh forces debate on $250 cheques for more Canadians; Conservatives cut it short
With the fate of the federal government's promised $250 cheques for 18.7 million workers hanging in the balance, the NDP forced a debate Friday on a motion pushing for the prime minister to expand eligibility. The conversation was cut short, though, by Conservative MPs' interventions.
Sask. father who kept daughter from mom to prevent COVID-19 vaccine free from additional prison time
Michael Gordon Jackson, the Saskatchewan father who withheld his then seven-year-old daughter from her mom for nearly 100 days to prevent the girl from getting a COVID-19 vaccine, was handed a 12-month prison sentence and 200 days probation on Friday, but credited with time served.
Ticketmaster hidden fees settlement credits expected in 2025 following class-action lawsuit by Regina lawyer
A longstanding lawsuit against Ticketmaster is nearing its end, with a judge expected to approve the more than $6 million dollar settlement before the end of the year.
What is still being delivered? What to know about the Canada Post strike
With Canada Post workers on strike, many individuals and businesses are facing the challenge of sending and receiving mail. Here are the answers to some of Canadians’ most-asked questions.
How the combination of diapers and splash pads led to 10K illnesses
New research is raising concerns about the safety of splash pads, which can be ground zero for germs and greatly increase the risk of spreading disease.
Which guns are now banned in Canada? Here's what you need to know
Canada is expanding its federal ban on firearms, adding 324 makes and models of guns to the prohibited weapons list, effective immediately.
Canada's 6.8% jobless rate boosts bets for 50-point interest rate cut
Canada had 1.5 million unemployed people in November, propelling its jobless rate to a near-eight-year high outside of the pandemic era and boosting chances of a large interest rate cut on Dec. 11.