Security breach cost nonsense
- IT TOPICS:Management, Security
Frank Hayes righly lampoons Websense's figures for the costs of Internet misuse. The methodology for estimating the costs is uncontrolled and ridiculous, and the people involved are incentivized to overestimate them and thus inflate their own importance.
Just as bad, for exactly the same reasons, is the annual CSI/FBI study. Security managers are given a few round numbers to choose on a multiple choice form for the cost of attacks, and these are then solemnly averaged and reported out to several decimal places. It's all tripe -- and, by the way, the FBI has almost nothing to do with the survey. What's worse is that these bogus numbers are compared from year to year, and headlines breathlessly report the supposed annual growth or decline.
Surprisingly little has been written about the bogosity of that particularly well-publicized survey, but here's one exception from three years ago..

