Data Breach Madness Declares 2011 Winner

"Bracket madness" has hit the institutional hallways of numerous colleges and universities across the country, as fans await the outcome of 126 separate basketball games to determine the men and women's champion teams in the NCAA tournament. For many, the activity will dominate sports news throughout March.

But a security company that monitors data breaches is using the occasion to come up with its own set of brackets--this one to proclaim the winner of "Data Breach Madness." In this contest, the participants may not be so proud. They've made it into the competition by having more data breaches during 2011 than any other institutions.

TeamSHATTER, the research arm of Application Security, has put together a graphical version of reported data breaches for the year that have hit American institutions.

Who takes first place for 2011? The unwanted distinction goes to Virginia Commonwealth University, which reported a breach of 176,567 records on November 11. Other top contenders for the title include the University of Wisconsin Milwaukee (79,000), Yale University (43,000), and the University of South Carolina (31,000).

If the estimated cost by the Ponemon Institute in its March 2011 study, "U.S. Cost of a Data Breach" is on target, those institutions spent about $112 per record to mitigate the damage caused by its breach. Based on that tally, the Virginia Commonwealth has spent nearly $20 million in mop-up efforts related to the security problem.

There is one note of good news. For 2011, the company tallied a dramatic decrease in the total number of reported records affected (478,490), as well as institutions (48) that reported breaches.

However, just two months into 2012, the year has already seen painful security incidents. Arizona State University reported a breach of 300,000 records in January. City College of San Francisco, University of North Carolina Charlotte, and Central Connecticut State University have also entered the running with breaches of their own.

"While it is encouraging to see the both number of reported higher education breaches and records breached significantly down from 2011, security and operations personnel should not relax their data security efforts," said Alex Rothacker, director of security research at TeamSHATTER. "In 2012 we have already seen some sizable breaches reported, and while exact data on the number of records compromised is not official, we estimate that this year's total has already exceeded that of 2011."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • abstract illustration of artificial intelligence

    CSU Shares AI Learnings in Systemwide Survey

    In a systemwide survey of more than 94,000 faculty, staff, and students, California State University recently documented widespread AI use across its 22 campuses.

  • AI logo near computer equipment

    White House Releases National Policy Framework for AI

    The White House has released a four-page AI policy framework aimed at setting a national approach to AI, with priorities including child safety, intellectual property protections, truth and accuracy guardrails, and worker training for an AI-driven economy.

  • Dana Brunson facilitates a roundtable discussion with research and higher education IT leaders

    Internet2: Closing the Access Gap for Research Cyberinfrastructure

    Internet2's Research Engagement Team brings CIOs and other campus technology leadership together with research computing and data facilitators, forming a community that enables research cyberinfrastructure at institutions of all types and sizes.

  • Silhouettes of business professionals stand against a blurred futuristic city skyline at night, with a glowing digital network data connection

    It's Time for Higher Ed to Get Serious About AI Strategy

    Without a coordinated strategy that involves multiple academic and administrative units across the entire campus, colleges risk wasting resources, duplicating efforts, and ultimately failing to deliver on the promise of deploying technology to improve learning and operations.