<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IAPP report states 80% of impacts customers would not do business with organisation in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58041#M830</link>
    <description>&lt;P&gt;Unlike Talk Talk in the UK, who handled their breach like this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ico.org.uk/about-the-ico/media-centre/talktalk-cyber-attack-how-the-ico-investigation-unfolded/" target="_blank"&gt;https://ico.org.uk/about-the-ico/media-centre/talktalk-cyber-attack-how-the-ico-investigation-unfolded/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 14:52:53 GMT</pubDate>
    <dc:creator>Steve-Wilme</dc:creator>
    <dc:date>2023-03-24T14:52:53Z</dc:date>
    <item>
      <title>IAPP report states 80% of impacts customers would not do business with organisation</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58025#M828</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very interesting report, &lt;SPAN class=""&gt;&lt;SPAN&gt;"More than 80% of impacted consumers said they are likely to stop doing business with a company after it is the victim&amp;nbsp;of a cyberattack"&lt;BR /&gt;&lt;BR /&gt;The IAPP first-ever Privacy and Consumer Trust report surveyed 4,750 consumers from 19 countries (including Australia but not NZ) and is well worth reading.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://lnkd.in/dnz7x-nW" target="_blank"&gt;https://lnkd.in/dnz7x-nW&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:28:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58025#M828</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: IAPP report states 80% of impacts customers would not do business with organisation</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58032#M829</link>
      <description>&lt;P&gt;I suspect that has to do with how the incident response is handled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The typical cyberattack response seems to be "oops, change your password and here are a few years of credit monitoring, on us".&amp;nbsp; &amp;nbsp;From the customer perspective a detective control was added but nothing to actually mitigate nor repair the damage.&amp;nbsp;In short, they frame the event as them being the victim of the attack instead of their customers being the victim of the data disclosure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Contrast this with how Tylenol handled their &lt;A href="https://www.ou.edu/deptcomm/dodjcc/groups/02C2/Johnson%20&amp;amp;%20Johnson.htm" target="_blank" rel="noopener"&gt;1982&lt;/A&gt; &lt;A href="https://en.wikipedia.org/wiki/Chicago_Tylenol_murders" target="_blank" rel="noopener"&gt;crisis&lt;/A&gt;.&amp;nbsp; After a few of their capsules were discovered to contain a poison,&amp;nbsp;their response was to very publicly protect their customers,&amp;nbsp;advertising "don't consume our product" and voluntarily recalling their entire product line.&amp;nbsp; Recovery was similarly publicly obvious - redesigning their product (capsules became caplets) and introducing the concept of &lt;A href="https://www.linkedin.com/pulse/history-benefits-tamper-evident-labeling-rafi-erg%C3%BCn" target="_blank"&gt;tamper evident&lt;/A&gt;&amp;nbsp;packaging to the world.&amp;nbsp; Both being a defense that "makes sense" to protect against an adversary-in-the-middle again tampering with the product.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 13:16:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58032#M829</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-03-23T13:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: IAPP report states 80% of impacts customers would not do business with organisation</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58041#M830</link>
      <description>&lt;P&gt;Unlike Talk Talk in the UK, who handled their breach like this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://ico.org.uk/about-the-ico/media-centre/talktalk-cyber-attack-how-the-ico-investigation-unfolded/" target="_blank"&gt;https://ico.org.uk/about-the-ico/media-centre/talktalk-cyber-attack-how-the-ico-investigation-unfolded/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 14:52:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58041#M830</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2023-03-24T14:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: IAPP report states 80% of impacts customers would not do business with organisation</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58062#M832</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;In short, they frame the event as them being the victim of the attack instead of their customers being the victim of the data disclosure. Contrast this with how Tylenol handled their &lt;A href="https://www.ou.edu/deptcomm/dodjcc/groups/02C2/Johnson%20&amp;amp;%20Johnson.htm" target="_blank" rel="noopener"&gt;1982&lt;/A&gt; &lt;A href="https://en.wikipedia.org/wiki/Chicago_Tylenol_murders" target="_blank" rel="noopener"&gt;crisis&lt;/A&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Great observation and reference. A good milestone case regarding customer data was back in 2004 when a former AOL employee stole and sold the database to a spammer. The crime the individual was charged with basically amounted to theft of corporate data. The problem wasn't that 30 million people had now been subjected to the annoyances of spam; It was that AOL didn't get paid for it. AOL already traded and sold its customer database at will. It was essentially a marketing company that also sold online access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we have progressed in the US from that time (mostly due to state laws), fundamentally, we still do not own our own data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2023 12:21:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/IAPP-report-states-80-of-impacts-customers-would-not-do-business/m-p/58062#M832</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2023-03-25T12:21:36Z</dc:date>
    </item>
  </channel>
</rss>

