Connect with us

Hi, what are you looking for?

White Papers

Average cost of data breach in ASEAN countries reached $3.05M in 2023

Detection and escalation costs jumped 15% over this same time frame, representing the highest portion of breach costs, and indicating a shift towards more complex breach investigations.

IBM Security released its annual Cost of a Data Breach Report, showing the average cost of a data breach in ASEAN countries, including in Philippines, reached $3.05 million in 2023– an all-time high for the report and a 6% increase year-to-year. Detection and escalation costs jumped 15% over this same time frame, representing the highest portion of breach costs, and indicating a shift towards more complex breach investigations.

According to the 2023 IBM report, globally businesses are divided in how they plan to handle the increasing cost and frequency of data breaches. The study found that while 95% of studied organizations have experienced more than one breach, breached organizations were more likely to pass incident costs onto consumers (57%) than to increase security investments (51%).

The 2023 Cost of a Data Breach Report is based on in-depth analysis of real-world data breaches experienced by 553 organizations globally between March 2022 and March 2023. The ASEAN region includes a cluster sample of companies located in Singapore, Indonesia, the Philippines, Malaysia, Thailand and Vietnam. The research, sponsored and analyzed by IBM Security, was conducted by Ponemon Institute and has been published for 18 consecutive years. Some key findings in the 2023 IBM report include:

·                     AI Picks Up Speed – AI and automation had the biggest impact on speed of breach identification and containment for studied organizations. In ASEAN countries, including the Philippines, organizations with extensive use of both AI and automation experienced a data breach lifecycle that was 99 days shorter with nearly $1.25 million lower data breach costs compared to studied organizations that have not deployed these technologies – the biggest cost saver identified in the report.

·                     The Cost of Silence – Globally, ransomware victims in the study that involved law enforcement saved $470,000 in average costs of a breach compared to those that chose not to involve law enforcement. Despite these potential savings, 37% of ransomware victims studied did not involve law enforcement in a ransomware attack. 

Advertisement. Scroll to continue reading.

·                     Detection Gaps – At a global level, only one third of studied breaches were detected by an organization’s own security team, compared to 27% that were disclosed by an attacker. Data breaches disclosed by the attacker cost nearly $1 million more on average compared to studied organizations that identified the breach themselves.

“In addition to time to identify and contain a data breach, extensive security AI and automation use is also a crucial factor that delivers significant cost savings to organizations in ASEAN countries,” said Chris Hockings, Chief Technology Officer of IBM Security, Asia Pacific. “In 2023, the industry is reaching a tipping point in the maturity curve for AI in security operations where enterprise grade AI capabilities can be trusted and automatically acted upon via orchestrated response. This will unlock tangible benefits for speed and efficiency, which are desperately needed in today’s business landscape where early detection and fast response can significantly reduce the impact and losses of businesses.”

Ransomware ‘Discount Code’

Some studied organizations remain apprehensive to engage law enforcement during a ransomware attack due to the perception that it will only complicate the situation. For the first time this year, the IBM report looked closer at this issue and found evidence to the contrary. At a global level, participating organizations that did not involve law enforcement experienced breach lifecycles that were 33-days longer on average than those that did involve law enforcement – and that silence came with a price. Ransomware victims studied that didn’t bring in law enforcement paid on average $470,000 higher breach costs than those that did.

Despite ongoing efforts by law enforcement to collaborate with ransomware victims, 37% of respondents still opted not to bring them in. Add to that, nearly half (47%) of studied ransomware victims reportedly paid the ransom. It’s clear that organizations should abandon these misconceptions around ransomware. Paying a ransom, and avoiding law enforcement, may only drive-up incident costs, and slow the response.

Advertisement. Scroll to continue reading.

Security Teams Rarely Discover Breaches Themselves

Threat detection and response has seen some progress. According to IBM’s 2023 Threat Intelligence Index, defenders were able to halt a higher proportion of ransomware attacks last year. However, adversaries are still finding ways to slip through the cracks of defense. Globally, the report found that only one in three studied breaches were detected by the organization’s own security teams or tools, while 27% of such breaches were disclosed by an attacker, and 40% were disclosed by a neutral third party such as law enforcement.

Responding organizations that discovered the breach themselves experienced nearly $1 million less in breach costs than those disclosed by an attacker ($5.23 million vs. $4.3 million). Breaches disclosed by an attacker also had a lifecycle nearly 80 days longer (320 vs. 241) compared to those who identified the breach internally. The significant cost and time savings that come with early detection show that investing in these strategies can pay off in the long run.

Breaching Data Across Environments – In ASEAN and Philippines, nearly 38% of data breaches studied resulted in the loss of data across multiple environments including public cloud, private cloud, and on-prem—showing that attackers were able to compromise multiple environments while avoiding detection. Data breaches studied that impacted multiple environments also led to higher breach costs ($3.14 million on average).

Additional findings in the 2023 IBM report include:

Advertisement. Scroll to continue reading.
  • Target Industries – Financial services and energy companies see the highest breach costs. By far the most impacted across ASEAN, the financial sector is paying nearly $4.81 million on average per breach, while the energy sector is paying $3.60 million on average.
  • The Develops Advantage – At a global level, studied organizations across all industries with a high level of DevSecOps saw a global average cost of a data breach nearly $1.7 million lower than those studied with a low level/no use of a DevSecOps approach.
  • Critical Infrastructure Breach Costs Break $5 Million – Globally, critical infrastructure organizations studied experienced a 4.5% jump in the average costs of a breach compared to last year – increasing from $4.82 million to $5.04 million – $590K higher than the global average. 
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

The new architecture is designed to scale into the modular, shared, and ultra-cold system required to link hundreds of quantum chips into a more...

HEADLINES

IBM expects its scalable cryogenic modules to help speed its pace of innovation. For example, three essential components of IBM Quantum System Two’s environment...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

Eligible institutions can access Lightwell’s library of validated fixes for open source software vulnerabilities, helping them secure the software and focus resources supporting research,...

HEADLINES

The partnership embeds OpenAI frontier models like GPT-5.6 and products like Codex and ChatGPT Work into IBM Consulting Advantage, IBM’s AI platform for delivering consulting...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

Advertisement