How Is Data Privacy Risk Calculated?

Updated

Table of Contents

Our platform displays risk as the number of files and records and an estimated assessment of the monetary risk the data would pose if a data privacy incident happened.

One question we are often asked about this dollar value is, “How do you calculate the risk?”

Data Privacy Risk Calculation

Skepticism about the assessed numbers is justified. Maybe they seem:

  • Too high — “Are you trying to scare me?”
  • Too low — “Is this worth addressing?”

The calculation of the assessment is simple: multiply the ‘number of records’ found by the ‘value per record’:

Here is a calculator you can try.

About the ‘value per record’

The ‘value per record’ is an estimation based on currently known ‘best numbers’ averages gleaned from sources such as large consulting agencies and privacy consultants/researchers, derived from public and private sources for different data violations that occurred in the past.

The numbers are normalized to the number of records lost in these incidents, and an average is then used to calculate a ‘value per record.’

Understanding that the numbers can only serve as a rough estimation is essential.

Even regulators, the main body that levies fines and penalties, do little to dispel uncertainty. For example, HIPAA fines can be assessed between $100 and $50,000 per ‘violation,’ depending on whether they are HIPAA category 1 to 4 violations.

Furthermore, regulators are not the only expense when an incident happens.

Forensic analysis is needed if you can’t show what happened, and it costs a pretty penny (upwards of $50k). A lawyer may be an unavoidable expense when trying to convince the regulator to drop (or at least lower) the fines and penalties. PR expenses to notify affected customers. Increased insurance costs, etc.

It is customary for the ‘value per record’ to be lower for single-item-based rules (e.g., a credit card number by itself) than when found in conjunction with additional supportive information (such as SSN). Thus, ePHI, which requires records to be found (personal identifiers + medical diagnosis or procedural data), is of a higher value than a standalone SSN or CCN.

The value per record is set as part of the policy and can be changed as needed by an administrator. See the example below.

Sensitive Data Discovery, Risk Quantification & Encryption

See how Actifile gives you unprecedented visibility to sensitive data files, discovers what needs protecting, and makes it useless to cyber criminals.