Security breach cost nonsense

Frank Hayes righly lampoons Websense's figures for the costs of Internet misuse.  The methodology for estimating the costs is uncontrolled and ridiculous, and the people involved are incentivized to overestimate them and thus inflate their own importance.

Just as bad, for exactly the same reasons,  is the annual CSI/FBI study.   Security managers are given a few round numbers to choose on a multiple choice form for the cost of attacks, and these are then solemnly averaged and reported out to several decimal places.  It's all tripe -- and, by the way, the FBI has almost nothing to do with the survey.  What's worse is that these bogus numbers are compared from year to year, and headlines breathlessly report the supposed annual growth or decline.

Surprisingly little has been written about the bogosity of that particularly well-publicized survey, but here's one exception from three years ago.. 

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?