New Ponemon Institute Study Reveals Average Phishing Costs Soar to $14.8M Annually, Nearly Quadrupling Since 2015
August 17 2021 - 8:05AM
Proofpoint, Inc. (NASDAQ: PFPT), a leading cybersecurity and
compliance company, and Ponemon Institute, a top IT security
research organization, today released the results of a new
study on the Cost of Phishing
. The report
reveals that the cost of phishing attacks have almost quadrupled
over the past six years, with large U.S. companies losing an
average of $14.8 million annually (or $1,500 per employee), up
sharply from 2015’s figure of $3.8 million.
According to the study, which surveyed nearly 600
IT and IT security practitioners, the most expensive threats to
businesses include BEC and ransomware attacks. But the costs to
organizations extend far beyond the funds transferred to the
attackers.
“When people learn that an organization paid
millions to resolve a ransomware issue, they assume that fixing it
cost the company just the ransom. What we found is that ransoms
alone account for less than 20 percent of the cost of a ransomware
attack,” said Larry Ponemon, Chairman and Founder of Ponemon
Institute. “Because phishing attacks increase the likelihood of a
data breach and business disruption, most of the costs incurred by
companies come from lost productivity and remediation of the issue
rather than the actual ransom paid to the attackers.”
Credential compromise (credential theft) generally
precedes attacks like BEC and ransomware, usually in the form of an
employee being “phished” into giving up their login credentials.
According to the Anti-Phishing Working Group (APWG), phishing is a
crime employing both social engineering and technical subterfuge to
steal personal identity data and financial account credentials. The
growth of phishing is not gradual – it’s growing exponentially,
with the APWG estimating that phishing attacks doubled in 2020
alone.
Other key findings from the 2021 Cost of Phishing report
include:
- Loss of Productivity is one of phishing’s
costliest outcomes. In an average sized U.S. corporation of 9,567
people, this translates to 63,343 wasted hours every year. Each
employee wastes an average of seven hours annually due to phishing
scams, an increase from four hours in 2015.
- Business Email Compromise costs nearly $6M annually for
a large organization. Of that, illicit payments made
annually to BEC attackers is $1.17M.
- Ransomware annually costs large organizations $5.66
million. Of that, $790,000 accounts for the paid ransoms
themselves.
- Security Awareness Training reduces phishing expenses
by more than 50 percent on average.
- Costs for resolving malware infections have more than
doubled since 2015. The average total
cost to resolve malware attacks is $807,506 in 2021, an increase
from $338,098 in 2015.
- Credential compromise costs have increased
dramatically since 2015. As a result, organizations are
spending more to respond to these attacks. The average cost to
contain phishing-based credential compromises increased from
$381,920 in 2015 to $692,531 in 2021. Organizations experienced an
average of 5.3 compromises over a 12-month period.
- Business leaders should pay attention to probable
maximum loss scenarios. For instance, BEC attacks could
incur losses from business disruptions of up to $157 million if
organizations aren’t prepared. Malware resulting in data
exfiltration could cost businesses up to $137 million.
“Because threat actors now target employees instead of networks,
credential compromise has exploded in recent years, leaving the
door wide-open for much more devastating attacks like BEC and
ransomware,” said Ryan Kalember, executive vice president of
cybersecurity strategy, Proofpoint. “Until organizations deploy a
people-centric approach to cybersecurity that includes security
awareness training and integrated threat protection to stop and
remediate threats, phishing attacks will continue.”
To download the Ponemon Cost of Phishing 2021 report, please
visit:
https://www.proofpoint.com/us/resources/analyst-reports/ponemon-cost-of-phishing-study
For more information on Proofpoint’s fully integrated Phishing
solutions, visit:
https://www.proofpoint.com/us/solutions/protect-against-phishing
About Proofpoint, Inc.
Proofpoint, Inc. (NASDAQ: PFPT) is a leading
cybersecurity and compliance company that protects organizations’
greatest assets and biggest risks: their people. With an integrated
suite of cloud-based solutions, Proofpoint helps companies around
the world stop targeted threats, safeguard their data, and make
their users more resilient against cyberattacks. Leading
organizations of all sizes, including more than half of the Fortune
1000, rely on Proofpoint for people-centric security and compliance
solutions that mitigate their most critical risks across email, the
cloud, social media, and the web. More information is available at
www.proofpoint.com.
Connect with
Proofpoint: Twitter | LinkedIn | Facebook | YouTube
Proofpoint is a registered trademark or tradename of Proofpoint,
Inc. in the U.S. and/or other countries. All other trademarks
contained herein are the property of their respective owners.
PROOFPOINT MEDIA CONTACT:Kristy
CampbellProofpoint, Inc.(408) 850-4142kcampbell@proofpoint.com
Proofpoint (NASDAQ:PFPT)
Historical Stock Chart
From Nov 2024 to Dec 2024
Proofpoint (NASDAQ:PFPT)
Historical Stock Chart
From Dec 2023 to Dec 2024