CSOs know that information security breaches cost a lot of money. It takes work to investigate and fix what went wrong and to alert affected California citizens, as required by state’s breach disclosure. But how much does it cost? The answer, like the answers to man questoins in the security field, depends on the circumstances; your mileage will vary based on your industry, the scope of the problem and the public’s reaction.Take two recent and high profile examples, ChoicePoint and CardSystems. ChoicePoint, the data aggregator that admitted in February that it had information stolen by imposters posing as business customers, went on to post record revenues in its most recent quarter. The company’s financial report, released July 20, claims that its stock would have risen 44 cents per share for the quarter were it not for the “dilutive effect of specific expenses related to the fradulent data access previously disclosed.” Instead, the stock rose 40 cents per share. (With 90 million shares outstanding, those pennies add up.) Operating income for the quarter also took a pre-tax hit worth $6 million to cover legal expenses and other professional fees related to data breach episode.The Wall Street Journal recently reported that security breaches create a drag on stock prices of about one percent right away. The ChoicePoint case appears more acute. While ChoicePoint stock, which hit a low in March of $36.35, has rebounded to $43, it is still 10 percent less than its 52-week high.Academic researchers have sought to quantify the precise impact of security breaches. Looking at breaches occuring in a range of industries, researchers from the University of Maryland’s Robert H. Smith School of Business have found that the stock market punishes companies where a breach of confidential data occurred; other breaches don’t hurt stock prices as much. Which brings us to CardSystems Solutions. Atlanta-based CardSystems, a 115-employee credit card transactions processor, in May discovered a security breach had compromised as many as 40 million MasterCard, Visa, American Express and other credit card accounts. Since the breach came to light June 19, the heat has been on. Both Visa and American Express are slated to terminate their contracts on Oct. 31. That action, saysCardSystems’ president and CEO, John M. Perry, will spell the end of the company. Perry told a Congressional committee on July 21: “We are disappointed with these actions and, in light of our diligent efforts to remediate, hope that both Visa and American Express will agree to discuss their decision with us and reconsider, lest we be forced to permanently close our doors.” Related content news Multibillion-dollar cybersecurity training market fails to fix the supply-demand imbalance Despite money pouring into programs around the world, training organizations have not managed to ensure employment for professionals, while entry-level professionals are finding it hard to land a job By Samira Sarraf Oct 02, 2023 6 mins CSO and CISO CSO and CISO CSO and CISO news Royal family’s website suffers Russia-linked cyberattack Pro-Russian hacker group KillNet took responsibility for the attack days after King Charles condemned the invasion of Ukraine. By Michael Hill Oct 02, 2023 2 mins DDoS Cyberattacks feature 10 things you should know about navigating the dark web A lot can be found in the shadows of the internet from sensitive stolen data to attack tools for sale, the dark web is a trove of risks for enterprises. Here are a few things to know and navigate safely. By Rosalyn Page Oct 02, 2023 13 mins Cybercrime Security news ShadowSyndicate Cybercrime gang has used 7 ransomware families over the past year Researchers from Group-IB believe it's likely the group is an independent affiliate working for multiple ransomware-as-a-service operations By Lucian Constantin Oct 02, 2023 4 mins Hacker Groups Ransomware Cybercrime Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe