Hardly a week goes by without headlines about a breach of customer data. Less frequent, but just as alarming, are the publicly reported examples and allegations of intellectual property theft. Data security and privacy — and, by extension, brand reputation — are front and center today and will quickly become a business differentiator for tomorrow. The question remains: How will organizations respond?

IBM commissioned Forrester Research to evaluate data security decision-making by security buyers and influencers. Much of the research focused on what it means to engage in proactive data security and privacy efforts to address threats both today and in the future. This study began in May 2014 and was completed in June 2014. Forrester developed a hypothesis testing the assertion that enterprises today have many more stakeholders involved in data control, data governance, security and privacy. However, despite this involvement, organizations approach data security in a very reactive fashion and often do not have a clear understanding of the value of their data.

As part of the study, Forrester conducted surveys with 200 security decision-makers in the U.S., U.K. and Germany and had five in-depth follow-up phone interviews for additional context. The final report found that while these companies’ data security efforts are primarily driven by compliance and are tactical in nature, security teams have the attention of executives who are increasingly aware of and concerned about data security. These decision-makers also place a high priority on helping securely enable big data and data quality initiatives, both of which have implications for revenue growth and customer experience.

Key Findings

Forrester’s study yielded five key findings:

1. Data security efforts are policy- and compliance-driven.

Compliance is necessary, and policies are an important part of data security. However, organizations that drive data security efforts based on policy and compliance put the business at risk by neglecting to take a more holistic and proactive approach to their data security strategy. Remember: Compliance does not equal security.

2. Firms do not understand what sensitive data is.

What is sensitive data to the organization? And does the entire organization share a common understanding of what constitutes sensitive data? In order to protect our data, we must first know and understand it.

3. Proactive data security goes beyond technology implementation.

Technology is only one part of the equation; people and processes matter. Data privacy and security are conjoined concepts that require coordination between businesses’ employees, customers and operations to successfully address these concerns.

4. Many firms struggle with data security and are not mature in measuring the success of data security initiatives.

The transition from network- and device-centric security to data-centric security is new to most enterprises. There is a significant cultural shift that must take place for organizations to mature their data security practices.

5. For better or worse, breaches are an organizational catalyst.

As a direct result of a data breach, 45 percent of firms implemented new security controls and policies, and 42 percent said that security and privacy have become bigger topics of discussion. However, 35 percent also indicated that the breach caused a lot of disruption in the organization, with 18 percent of companies laying off employees as a direct result.

Read the complete Forrester Consulting report on Data Security and privacy

More from Data Protection

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

How Do You Plan to Celebrate National Computer Security Day?

In October 2022, the world marked the 19th Cybersecurity Awareness Month. October might be over, but employers can still talk about awareness of digital threats. We all have another chance before then: National Computer Security Day. The History of National Computer Security Day The origins of National Computer Security Day trace back to 1988 and the Washington, D.C. chapter of the Association for Computing Machinery’s Special Interest Group on Security, Audit and Control. As noted by National Today, those in…

Resilient Companies Have a Disaster Recovery Plan

Historically, disaster recovery (DR) planning focused on protection against unlikely events such as fires, floods and natural disasters. Some companies mistakenly view DR as an insurance policy for which the likelihood of a claim is low. With the current financial and economic pressures, cutting or underfunding DR planning is a tempting prospect for many organizations. That impulse could be costly. Unfortunately, many companies have adopted newer technology delivery models without DR in mind, such as Cloud Infrastructure-as-a-Service (IaaS), Software-as-a-Service (SaaS)…

Millions Lost in Minutes — Mitigating Public-Facing Attacks

In recent years, many high-profile companies have suffered destructive cybersecurity breaches. These public-facing assaults cost organizations millions of dollars in minutes, from stock prices to media partnerships. Fast Company, Rockstar, Uber, Apple and more have all been victims of these costly and embarrassing attacks. The total average cost of a data breach has increased by 2.6% since 2021 and is now $4.35 million. Organizations that don't deploy zero trust security models also incur an average of $1 million more in…