The cost of achieving regulatory security compliance is on average $3.5 million each year, according to a survey of 160 individuals leading the IT, privacy and audit efforts at 46 multinational organizations. The cost of achieving regulatory security compliance is on average $3.5 million each year, according to a survey of 160 individuals leading the IT, privacy and audit efforts at 46 multinational organizations.“The True Cost of Compliance,” a research study done by Ponemon Institute and sponsored by Tripwire, makes the point that if that $3.5 million figure for the average cost sounds high, the average cost for organizations that experience non-compliance-related problems is far higher — $9.4 million. Costs related to “business disruption, reduced productivity, fees, penalties and other legal and non-legal settlement costs” pile up when legal and regulatory compliance goals are not met, the study asserts.MORE RESEARCH: Regulatory compliance hogs security pros attentionThe array of regulatory requirements facing organizations runs the gamut from the U.S. state laws for data breach to Sarbanes-Oxley to the European Union’s Privacy Directive and more. But the Payment Card Industry Data Security Standard was deemed to be “most important” in terms of influence and “the most difficult to comply with,” according to the survey’s respondents. “PCI seems to affect everyone,” says Rekha Shenoy, Tripwire’s vice president of strategy. She adds that the PCI DSS, unlike some compliance requirements, is very “prescriptive” in putting forth what’s expected in terms of technologies and procedures.The Ponemon report covered industries that include consumer products, technology, retail, industrial, public sector, healthcare, communications, education and research, financial services, transportation, pharmaceutical and energy. The survey respondents hold job titles that include chief information security officer, compliance officer, IT operations leader, audit director and others. In divvying up “expense categories,” the report says the use of “specialized technologies,” “incident management,” and “audit and assessment” take up large portions of data-compliance costs, with the corporate IT department, line of business and legal division regarded as functional areas that account for significant portions of the expenditures.The burden of both compliance and non-compliance costs were highest in organizations with fewer than 5,000 employees and smallest in organizations with 25,000 to 75,000 employees, where economies of scale may apply.In terms of the number of internal compliance audits performed each year, the report says “surprisingly, 28% of companies say they do not conduct compliance audits, and only 11% say they conduct more than five audits each year.”However, internal compliance audits seem to be worth it. According to the report’s analysis, “organizations that conduct three to five internal compliance audits per year have the lowest per capita compliance cost (average $154). The highest compliance cost (average $341) is associated with organizations that do not conduct any internal compliance audits.” In addition, the lowest per capita non-compliance cost (with an average of $226) is said to be associated with organizations that conduct five or more audits, while the highest per capita non-compliance cost (average $1,275) is associated with organizations that do not conduct audits.Read more about wide area network in Network World’s Wide Area Network section. Related content news Multibillion-dollar cybersecurity training market fails to fix the supply-demand imbalance Despite money pouring into programs around the world, training organizations have not managed to ensure employment for professionals, while entry-level professionals are finding it hard to land a job By Samira Sarraf Oct 02, 2023 6 mins CSO and CISO CSO and CISO CSO and CISO news Royal family’s website suffers Russia-linked cyberattack Pro-Russian hacker group KillNet took responsibility for the attack days after King Charles condemned the invasion of Ukraine. By Michael Hill Oct 02, 2023 2 mins DDoS Cyberattacks feature 10 things you should know about navigating the dark web A lot can be found in the shadows of the internet from sensitive stolen data to attack tools for sale, the dark web is a trove of risks for enterprises. Here are a few things to know and navigate safely. By Rosalyn Page Oct 02, 2023 13 mins Cybercrime Security news ShadowSyndicate Cybercrime gang has used 7 ransomware families over the past year Researchers from Group-IB believe it's likely the group is an independent affiliate working for multiple ransomware-as-a-service operations By Lucian Constantin Oct 02, 2023 4 mins Hacker Groups Ransomware Cybercrime Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe