Complex regulations and sophisticated cyber attacks inflate non-compliance costs



ponemon-globalscape1

The cost of non-compliance has significantly increased over the past few years, and the issue could grow more serious. 90 percent of organizations believe that compliance with the GDPR would be difficult to achieve, according to a new study conducted by the Ponemon Institute.

GDPR is considered by respondents to be the most challenging among other data compliance regulations such as Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA) and Federal Information Security Management Act (FISMA).

Non-compliance costs 2.71 times the cost of maintaining or meeting compliance requirements.

Here are some highlights:

  • The average cost of compliance increased 43 percent from 2011, and totals around $5.47 million annually. However, the average cost of non-compliance increased 45 percent from 2011, and adds up to $14.82 million annually.
  • Non-compliance costs 2.71 times the cost of maintaining or meeting compliance requirements. Non-compliance costs come from the costs associated with business disruption, productivity losses, fines, penalties, and settlement costs, among others.
  • The cost of compliance can vary by industry: media organizations average $7.7 million annually to comply with regulations and policies, while financial services companies face more than $30.9 million annually in compliance costs. These costs widely vary based on the amount of sensitive or confidential information a particular industry handles and is required to secure.
  • Among the individual regulations, survey respondents found that GDPR is the most difficult to achieve compliance, even though enforcement for GDPR doesn’t start until May 25, 2018. 90 percent of respondents felt that GDPR would be difficult, while only 55 percent felt that the Payment Card Industry Data Security Standard (PCI-DSS) was a challenge, the second highest amongst all regulations.
  • Companies are not spending enough on maintaining or meeting compliance, as it only accounts for an average of 14.3 percent of the IT department’s budget.

But How Do You Keep Track Of These Hundreds Of Controls? 

Here is a great way to get through audits in half the time and at half the cost. The KnowBe4 Compliance Manager (KCM) simplifies the complexity of getting compliant and eases your burden of staying compliant year round:

  • Quick Implementation with Compliance Templates - Pre-built requirements templates for the most widely used regulations like NIST and GDPR
  • Enable Users to Get the Job Done - You can assign responsibility for controls to the users who are responsible for maintaining them.
  • Dashboards with Automated Reminders - Quickly see what tasks have been completed, not met, and past due. With automated email reminders, your users can stay ahead of any gaps in compliance.

See for yourself how you can minimize the busy work associated with audits and compliance, and how easy this becomes using KCM. Request a demo:  https://www.knowbe4.com/demo_kcm

Source: HelpnetSecurity

 

 


Subscribe To Our Blog


Traditional Security Webinar Kevin Mitnick




Get the latest about social engineering

Subscribe to CyberheistNews