Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« U.S. ONDI and DOD Standardizing Security Policies | Main | Royal Academy of Engineering Releases Privacy Study Report: Emphasizes Importance of Engineering Security and Privacy Into Technology »

Study Reports The Companies Trusted Most For Privacy

The Ponemon Institute puts out an annual survey asking anyone who wants to participate in their online survey who the companies are that they believe respect their customers most and do the best job of protecting their privacy.

This year over 7,000 participants took part in the survey. The study found American Express was ranked number one again for the second straight year.

Here are the companies in ranked order:

1. American Express (was 1st last year)
2. The Charles Schwab Corp. (was 12th last year)
3. IBM (was 8th last year)
4. AOL
5. Amazon
6. Johnson & Johnson
7. U.S. Postal Serice
8. E-Bay
9. Nationwide
9. Procter & Gamble
10. Google
11. ELoan
12. WebMD
13. Dell
14. Countrywide
15. USAA
15. Disney
16. Hewlett Packard (was 4th last year)
17. US Bank
18. Bank of America
19. Intuit (all brands)
20. Weight Watchers


The study results pointed out the inherent connection between privacy and trust. If trust is broken, through security incidents and privacy breaches, that trust will be very hard to get back, and customers will be lost. Losing customers is often much more damaging to the business than any associated penalties, fines or legal judgments.

As an example, Hewlett-Packard was ranked 4th last year. However, after a difficult year of scandals involving their board members and pretexting, they fell this year to 16th.

As the annual survey continues to be performed, it is being shown that a company can, after considerable work and effort, regain trust after a significant period of time.

However, organizations shouldn't count on working hard following a breach to be the only part of their breach response plan; many organizations, particularly SMBs, will likely go out of business following a significant privacy breach and substantial loss of their customer base if they are not well prepared for how to respond. All the more reason to do everything reasonable to prevent a privacy breach from occurring in the first place.

Noticeably missing from the list are transportation companies, such as airlines; food service organizations, such as restaurants; retail organizations, such as toy companies; and nonprofit organizations.

Weight Watchers was an interesting top 20...indeed, I bet they do have a ton of personal information with which they've been entrusted!

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/363

Comments

So call me crazy but I feel that no company in the top 10 should have security breaches in the past year. Ebay while they have worked to keep innovative with their new key fobs still has struggled with security and phishing. Nationwide sets bells off in my head of their recent reprimand. I half expected to see the VA rounding out the top 20.

Yes, isn't it interesting that the people in the survey would go ahead and vote for such organizations? This could mean a couple of things; either the survey-takers were not aware of the breaches, or that the company aggressively and effectively communicated well with their customers about the breach, and in doing so regained their trust. All the more reason to not only implement strong safeguards, but to also have a well-thought-out and tested security incident and privacy breach response plan.

Lol...if the VA was on the list it would certainly be a depressing statement on our society's understanding of privacy, wouldn't it?

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.