Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« 7 More Reasons Why Sending Cleartext IM and Email Is *NOT* Secure Even If Your Doc Says It Is...Part 2 | Main | Show "Home Alone" To Raise Social Engineering Awareness »

Show Your CFO and CEO the Potential Financial Impact of a Privacy Breach

My central Iowa Infragard president, Tom Conley sent all our members a note on Wednesday with a link to a site that contains 9 variables to help demonstrate the range of financial impact to organizations that experience an incident involving personally identifiable information (PII).

The variables are actually a subset of a privacy breach impact calculator I created a few years ago that includes these costs and more. You can see an abbreviated version of it, which contains 21 variables, here.

I've used the full version of the calculator, which contains 36 variables, with great impact when speaking to business leaders about the need to implement safeguards. It is especially powerful when talking with CFOs...who usually control to a great degree the information security budget!

It is on my to-do list to update the calculator in 2008.

However, even if you don't want to get the full version, I know the abbreviated version has been used by many organizations to help their business leaders see the realistic potential impacts of a privacy breach in terms they can understand and better appreciate than just hearing technical jargon.

A note about my breach calculator site, it is important for you to change the values that are pre-filled in the variable fields to values that are appropriate to *YOUR* organization. The numbers that you see when you first get to the site are merely place-holders. I had wanted to put all 0's in the fields as the starting values, more like a regular calculator, but my publisher wanted to pre-fill the fields to show a scenario right off the bat when you go to the site.

If you have any comments or suggestions regarding my calculator, please let me know!

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/581

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.