Complex regulations and sophisticated cyber attacks inflate non-compliance costs

Stu Sjouwerman | Dec 15, 2017

ponemon-globalscape1

The cost of non-compliance has significantly increased over the past few years, and the issue could grow more serious. 90 percent of organizations believe that compliance with the GDPR would be difficult to achieve, according to a new study conducted by the Ponemon Institute.

GDPR is considered by respondents to be the most challenging among other data compliance regulations such as Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA) and Federal Information Security Management Act (FISMA).

Non-compliance costs 2.71 times the cost of maintaining or meeting compliance requirements.

Here are some highlights:

  • The average cost of compliance increased 43 percent from 2011, and totals around $5.47 million annually. However, the average cost of non-compliance increased 45 percent from 2011, and adds up to $14.82 million annually.
  • Non-compliance costs 2.71 times the cost of maintaining or meeting compliance requirements. Non-compliance costs come from the costs associated with business disruption, productivity losses, fines, penalties, and settlement costs, among others.
  • The cost of compliance can vary by industry: media organizations average $7.7 million annually to comply with regulations and policies, while financial services companies face more than $30.9 million annually in compliance costs. These costs widely vary based on the amount of sensitive or confidential information a particular industry handles and is required to secure.
  • Among the individual regulations, survey respondents found that GDPR is the most difficult to achieve compliance, even though enforcement for GDPR doesn’t start until May 25, 2018. 90 percent of respondents felt that GDPR would be difficult, while only 55 percent felt that the Payment Card Industry Data Security Standard (PCI-DSS) was a challenge, the second highest amongst all regulations.
  • Companies are not spending enough on maintaining or meeting compliance, as it only accounts for an average of 14.3 percent of the IT department’s budget.

Source: HelpnetSecurity

See Compliance Plus in Action

Learn how easy it is to deliver your compliance training program using Compliance Plus with KnowBe4's training platform.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.