Data Breach Impact: The Real Cost Is Indirect

The real impact is not in the fine or the media hype, but in the indirect costs that affect your organization in both the short and long term.
Lars van Zijl
Co-Founder
5
Min reading
Table of contents

You couldn't have missed it: a major data breach at Odido. Many information security or risk professionals have a personal data breach high up in their risk register. But why, exactly?

Our gut feeling tells us that the impact of such a risk is high. But as soon as you ask for a justification of that impact, things quickly become murky.

A Risk

First, let's take a step back. When it comes to information security risks, it is important to keep two things in mind:

  1. A risk is an uncertainty regarding an (organizational) objective. Think of making a profit, providing care, or serving citizens. No relationship to an objective? No risk.
  2. Risk is a function of probability and impact. Only if a data breach can occur AND you as an organization experience negative consequences from it, is there a risk. A data breach of the 2024 annual report already filed by the organization is not very interesting.

With this in mind, the question arises: in what way does (a data breach of) personal data pose an uncertainty to business objectives?

The Impact

The direct impact on an organization in the event of a data breach is not necessarily significant. After all:

  • There is no business interruption; primary business processes can continue as usual
  • A GDPR fine is not automatically on the table in the event of a data breach, and certainly not the 4% of global annual turnover that many executives are scared with

Because of this, there seems to be little relationship with the organization's business objectives.

Or... is there?

The core of a data breach lies in the indirect impact on an organization. While the organization may still be able to function, a lot happens behind the scenes immediately following a data breach:

  • Affected individuals must be informed in accordance with the GDPR, all while you are still searching for answers yourself.
  • Reporting obligations under GDPR and NIS2/Cbw come into play.
  • The press has questions, speculation runs wild on LinkedIn, and before you know it, an inaccurate picture is being painted on a talk show that same evening.
  • The old doomsday story about a GDPR fine of 4% of global annual turnover is being dragged out again.
  • Customer service capacity needs to be increased, as there is a lot of confusion among customers.
  • Depending on the cause of the data breach, a forensic IT investigation into the circumstances may need to be conducted.

Simply organizing a response to these points can already come with a hefty price tag (read: impact).

Conclusion

For for-profit organizations, making a profit is a clear business objective. Costs incurred to manage a data breach reduce short-term profit (business objective). In the long term, profit can be reduced by declining market share, liability, fines, and legal judgments.

Government institutions and NGOs are slightly different. After all, they are not profit-driven. For their business objectives, they depend on a budget to achieve their goals. Costs incurred due to a data breach cannot be used for your business objectives.

The impact of a personal data breach therefore strongly depends on the long-term impact your organization expects. Short-lived media hype does not necessarily lead to a high impact on the bottom line.

Is the impact of a personal data breach clear for your organization?

Stay up to date

Sign up for the newsletter and receive our latest insights on cyber risk quantification.

By subscribing you agree to our privacy statement
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.