Beating the Breach鈥攁nd Saving Millions in the Process

Illinois Tech Professor Co-Authors Book Exploring Data Breaches and How Companies Can Better Defend Against Them

Date

Author

By Jacqueline Seaberg
Beating the Breach鈥攁nd Saving Millions in the Process

According to a 2019 study sponsored by IBM Security, the average total cost of a data breach in the United States is $8.19 million. And yet, many companies don鈥檛 invest enough time or money to protect themselves and their customers from hackers.

Professor Richard Warner of 电车无码-Kent College of Law and Professor Robert Sloan, head of the computer science department at the University of Illinois at 电车无码, explore this issue and possible solutions in their new book Why Don't We Defend Better?: Data Breaches, Risk Management, and Public Policy, published in summer 2019 by CRC Press. The book is written in accessible language for anyone interested in data security from a practical or policy perspective. 

In Why Don't We Defend Better?, Warner and Sloan combine issues of technology, business, risk management, and legal liability to explain why data breach defense is often ineffective, and how to respond to the increasing frequency of data breaches. 

鈥淎s a society we鈥檙e losing money that we shouldn鈥檛 lose,鈥 Warner says, 鈥渁nd individual businesses are facing significant losses.鈥 

The authors propose creating a database鈥攁dministered by the federal government or an industry group鈥攚here companies could anonymously report their data breaches. The information would be selectively available to other businesses and researchers. 

鈥淲e don鈥檛 have sufficient data on the probabilities of data breaches and sufficient data on the harms, so businesses are paralyzed,鈥 explains Warner, whose research focuses on the regulation of online privacy, security, and competition. He has given lectures on behalf of the United Nations on internet security and on behalf of the FBI on global cybercrime. Warner currently serves as a member of the U.S. Secret Service's Electronic Crimes Task Force.

With the information from the database, companies would be better able to calculate the probability of a data breach, to assess the potential losses for themselves and their customers, and to estimate how much to spend on reasonable data security. Lawyers suing or defending a company could use the information to assess the reasonableness of the company鈥檚 defensive procedures. 

The book鈥檚 message, the authors鈥 note, has taken on particular urgency with the growth of the internet of things. 

鈥淲e think we鈥檙e connected now, but the internet of things is a hyper-connected world,鈥 says Warner. 鈥淚t鈥檚 not just your cell phone. It鈥檚 your refrigerator. It鈥檚 your doorbell. It鈥檚 your car. It鈥檚 practically every device you have, plus the sensors in the street, the drone surveillance, the data that feeds in. Everything is hyper-connected.鈥

With more devices鈥攆rom Bluetooth-controlled locks and security cameras to self-driving cars and traffic lights鈥攃onnected to the internet, hackers could not only steal data but potentially take control of these devices. 

鈥淣ow is the time to have this conversation,鈥 the authors insist.