Cost of data breaches in Canada hit new record in 2021: IBM
The average cost of a data breach in Canada hit a record high last year as companies grappled with new cybersecurity risks during the COVID-19 pandemic.
According to a new report from IBM Security, the average cost of a data breach in Canada was $6.75 million per incident in the 2021 survey year. That's up from $6.35 million the year before and the highest since IBM first included Canada in its survey seven years ago. It's also higher than the 2021 global average of US$4.24 million ($5.34 million), which in itself is a 10 per cent increase from the prior year and the highest global average in the survey's 17-year history.
The study suggests cybersecurity efforts may have lagged behind as companies were forced to rapidly adapt to remote work during the pandemic, said IBM Security associate partner Ray Boisvert.
“This to me is a wake-up call,” Boisvert said, adding companies reported data breaches last year that were not only costly, but also hard to contain. For example, companies surveyed reported a mean time of 164 days to identify they had a breach and 60 days to contain it, one week longer than the prior year's report.
According to the study, data breaches cost $1 million more on average when remote work was indicated as a factor in the event.
“There was certainly a strong link to remote work,” Boisvert said. “We're now living in a perimeter-less environment … and trying to defend a multiplicity of inputs becomes very difficult.”
Charles Finlay, executive director of the Rogers Cybersecure Catalyst at Ryerson University, said the sheer volume of varying devices and network connections used by remote workers during the pandemic posed a cybersecurity threat.
“Employees are working from home using insecure Internet networks and computers, and the kind of security measures that would be imposed in a corporate environment in a workplace just are not always present,” Finlay said.
He added that a crisis like the global pandemic can also be easily exploited by cybercriminals - for example, through a phishing email that poses as official health advice.
“We know that fake websites have been set up purporting to provide information on COVID-19,” Finlay said. “So COVID-19 has provided a lot of opportunity, unfortunately, for malicious attackers and cybersecurity. I'm not surprised by IBM's findings.”
The survey found nearly half (44 per cent) of the breaches analyzed exposed customer personal data, such as names, emails, passwords, or even healthcare data. It found compromised user credentials (such as stolen passwords) were the most common method used as an entry point by attackers, representing 20 per cent of breaches studied.
Ransomware attacks are also growing increasingly common, said Finlay, pointing to high-profile incidents so far in 2021 like the Russian-linked cyberattacks on Colonial Pipeline and JBS Foods.
“When I look back at the last year, the most serious development that I see is around the increasingly serious ransomware attacks, in particular around critical infrastructure,” Finlay said. “Ransomware is exploding as a major international security problem. It is a multi-billion global industry.”
The IBM survey analyzed real-world data breaches experienced by 500 organizations worldwide (26 in Canada) between May 2020 and March 2021. It factored in costs to companies ranging from legal, regulatory and technical responses in the event of a cyberattack to loss of brand equity, customers, and employee productivity.
This report by The Canadian Press was first published July 28, 2021
CTVNews.ca Top Stories
Former homicide detective explains how police will investigate shooting outside Drake's Bridle Path mansion
Footage from dozens of security cameras in the area of Drake’s Bridle Path mansion could be the key to identifying the suspect responsible for shooting and seriously injuring a security guard outside the rapper’s sprawling home early Tuesday morning, a former Toronto homicide detective says.
Federal government grants B.C.'s request to recriminalize hard drugs in public spaces
The federal government is granting British Columbia's request to recriminalize hard drugs in public spaces, nearly two weeks after the province asked to end its pilot project early over concerns of public drug use.
Stormy Daniels describes meeting Trump during occasionally graphic testimony in hush money trial
Stormy Daniels took the witness stand Tuesday at Donald Trump's hush money trial, describing for jurors a sexual encounter the porn actor says she had with him in 2006 that resulted in her being paid off to keep silent during the presidential race 10 years later.
MPs agree Canadian gov't should improve new disability benefit
The federal government needs to safeguard the incoming Canada Disability Benefit from clawbacks and do more to ensure it actually meets the stated aim of lifting people living with disabilities out of poverty, MPs from all parties agree.
Bye-bye bag fee: Calgary repeals single-use bylaw
A Calgary bylaw requiring businesses to charge a minimum bag fee and only provide single-use items when requested has officially been tossed.
CFL suspends Argos QB Chad Kelly at least nine games following investigation
The CFL suspended Toronto Argonauts quarterback Chad Kelly for at least nine regular-season games Tuesday following its investigation into a lawsuit filed by a former strength-and-conditioning coach against both the player and club.
Boy Scouts of America changing name for first time in 114 years, aiming for inclusivity
The Boy Scouts of America is changing its name for the first time in its 114-year history and will become Scouting America. It's a significant shift as the organization emerges from bankruptcy following a flood of sexual abuse claims and seeks to focus on inclusion.
opinion Tom Mulcair: Trudeau's handling of Poilievre's 'wacko' House turfing a clear sign of Liberal desperation
When Speaker Greg Fergus tossed out Pierre Poilievre from the House last week, "those of us who have experience as parliamentarians simply couldn't believe our eyes," writes former NDP leader Tom Mulcair in his column for CTVNews.ca
New charges for Ont. woman who previously admitted to defrauding doulas
The Brantford, Ont. woman who was previously sentenced to house arrest after admitting to deceiving doulas has been charged again in connection to a new victim.