100%
Privacy Breach Index

 
Dear Participant,

Has your organization provided notification of a data breach? If you sent notification about the loss or theft of personal information entrusted to you, were you satisfied with the steps your organization took to complete the incident response process? The first two parts of this survey focuses on how well you believe your organization responded to a recent data breach. Part three asks how important you believe certain attributes are in preventing and responding to a data breach.

We appreciate your frank responses to all survey questions. Please be assured that we will not collect any personally identifiable information. If you have any questions, contact Ponemon Institute at research@ponemon.org or call us at 1.800.887.3118.

Thank you in advance for your participation.

Dr. Larry Ponemon
Chairman
 
Key Definitions
 
Data breach victim is defined as the individual or household receiving notification that their personal information was either lost or stolen.

Personal information is information about a natural person, household or family. This information includes name, address, telephone numbers, e-mail address, Social Security number, other personal identification numbers, access codes, age, gender, income and tax information, shopping information, account activity and any other sensitive pieces of data about an individual.
 
 
Please respond to all questions based on your most recent incident requiring data breach notification
 
 
Q1 What type of personal information was lost or stolen in this breach incident?
 
 
     
 
 
Q2 What was the root cause of this data breach incident?
 
 
Q3 In your opinion, what grade would you assign to your organization’s overall performance in responding to the data breach incident?
                   
 
 
Privacy Breach Index Questions
 
 
Prevention: Please answer each question listed below with a Yes, No or Unsure response. For each "Yes" response, please rate the importance of each control activity from very important to irrelevant.
 
 
Q4 Does your organization have policies describing how personal information should be protected from being lost or stolen?
           
 
If you answered "yes"
                   
 
 
Q5 Does your organization have a training and awareness program available to customer service employees who might receive questions about privacy and data protection practices?
           
 
If you answered "yes"
                   
 
 
Q6 Does your organization promptly change physical and electronic access rights of employees when they change jobs or are terminated?
           
 
If you answered "yes"
                   
 
 
Q7 Does your organization practice strong authentication measures for granting employees and contractors access to its information systems?
           
 
If you answered "yes"
                   
 
 
Q8 Are employees’ mobile devices (i.e. laptops, PDAs, cell phones) encrypted?
           
 
If you answered "yes"
                   
 
 
Q9 Is the transmission of sensitive personal information encrypted?
           
 
If you answered "yes"
                   
 
 
Q10 Does your organization regularly monitor its information systems for unusual traffic flow or other activity?
           
 
If you answered "yes"
                   
 
 
Q11 Does your organization secure physical locations where personal information is stored?
           
 
If you answered "yes"
                   
 
 
Q12 Are operating systems, applications and databases where data is stored and transmitted secured against intrusion?
           
 
If you answered "yes"
                   
 
 
Q13 Do your employees have the ability to report data protection risks that might result in a data breach to appropriate supervisors or management personnel (upward communication)?
           
 
If you answered "yes"
                   
 
 
Q14 Does your organization verify that its privacy and security procedures can prevent a data breach?
           
 
If you answered "yes"
                   
 
 
Q15 Does your organization conduct periodic risk assessments to determine where personal information is vulnerable to a data breach?
           
 
If you answered "yes"
                   
 
 
Q16 Does your organization conduct periodic risk assessments of third parties, vendors or business partners that have access to its personal information?
           
 
If you answered "yes"
                   
 
 
Q17 Are these risk assessments used to improve the security of sensitive or confidential information in your organization?
           
 
If you answered "yes"
                   
 
 
Q18 Are data-bearing devices containing personal information disposed of in a secure manner?
           
 
If you answered "yes"
                   
 
 
Detection & Escalation: Please answer each question listed below with a Yes, No or Unsure response. For each "Yes" response, please rate the importance of each control activity from very important to irrelevant.
 
 
Q19 Is there a process in place to determine the potential harms experienced by victims as a result of the breach?
           
 
If you answered "yes"
                   
 
 
Q20 Is there a function or leader responsible for managing the data breach incident?
           
 
If you answered "yes"
                   
 
 
Q21 Has your organization established a cross-functional incident response team?
           
 
If you answered "yes"
                   
 
 
Q22 Does your organization have enabling technology (such as DLP) to monitor potential data breaches?
           
 
If you answered "yes"
                   
 
 
Q23 Are employees informed about how to report a data breach within the organization (upward communication)?
           
 
If you answered "yes"
                   
 
 
Q24 Is there a process for restricting the release of information about the data breach incident (e.g., on a need to know basis only)?
           
 
If you answered "yes"
                   
 
 
Q25 Are third parties, including contractors and business partners, instructed on how to inform your organization when they have a data breach involving your company's sensitive personal information?
           
 
If you answered "yes"
                   
 
 
Q26 Does your organization have a special team assigned to investigate a data breach incident?
           
 
If you answered "yes"
                   
 
 
Q27 Does your organization have internal specialized forensic tools and techniques in place to investigate a data breach?
           
 
If you answered "yes"
                   
 
 
Q28 Is your organization's privacy leader involved in the detection and escalation process?
           
 
If you answered "yes"
                   
 
 
Q29 As part of the assessment or forensic investigation, are conclusions developed, reviewed and approved by management?
           
 
If you answered "yes"
                   
 
 
Q30 Are there standard operating procedures or protocols established for communicating relevant and appropriate information to law enforcement in the event of data theft or other criminal activity involving the breach incident?
           
 
If you answered "yes"
                   
 
 
Notification: Please answer each question listed below with a Yes, No or Unsure response. For each "Yes" response, please rate the importance of each control activity from very important to irrelevant.
 
 
Q31 Does your organization have a communications plan for notifying all appropriate regulatory authorities and law enforcement?
           
 
If you answered "yes"
                   
 
 
Q32 Does your organization have a communications plan for notifying the media?
           
 
If you answered “yes”
                   
 
 
Q33 Does your organization have a communications plan for employees who are responsible for responding to data breach victims?
           
 
If you answered “yes”
                   
 
 
Q34 Does your organization have internal customer service and call center employees who respond to data breach victims' questions?
           
 
If you answered “yes”
                   
 
 
Q35 Is there an existing contact channel (letter, email, phone call) to communicate with the data breach victim?
           
 
If you answered “yes”
                   
 
 
Q36 Is there a process for verifying that contact with each data breach victim has been completed?
           
 
If you answered “yes”
                   
 
 
Q37 Is there a process for managing incomplete or failed notification and contact returns?
           
 
If you answered “yes”
                   
 
 
Q38 Is there a repository of standardized and approved communications available for use in advance of the incident?
           
 
If you answered “yes”
                   
 
 
Q39 Is there a mechanism for receiving and tracking feedback about the quality and responsiveness of the organization to data breach victims?
           
 
If you answered “yes”
                   
 
 
Q40 Is there a process for addressing special circumstances (i.e., disgruntled victims that require escalated management attention)?
           
 
If you answered “yes”
                   
 
 
Q41 Is there a process for differentiating victims based on their personal information and accompanying exposure to ID theft or criminal activity?
           
 
If you answered “yes”
                   
 
 
Q42 Is there a process for ensuring that all communications are done according to a pre-determined timeline?
           
 
If you answered “yes”
                   
 
 
Q43 Is there a process for ensuring that communication about the breach is kept confidential until the company notifies victims and other stakeholders?
           
 
If you answered “yes”
                   
 
 
Q44 Does your organization provide a website or link on your website for data breach victims to learn more about the data breach incident and remedies available to them?
           
 
If you answered “yes”
                   
 
 
Q45 Does your organization provide free or subsidized identity protection services, including credit monitoring, to minimize harm to data breach victims?
           
 
If you answered “yes”
                   
 
 
Q46 Does your organization offer more than one year of free credit monitoring to data breach victims?
           
 
If you answered “yes”
                   
 
 
Q47 Is there some outreach effort to communicate the benefits of identity protection services to data breach victims?
           
 
If you answered “yes”
                   
 
 
Q48 Does your organization purchase specialized insurance to reimburse for loss related to a data breach event?
           
 
If you answered “yes”
                   
 
 
Q49 Does your organization fully document the incident response from initial discovery to disclosure?
           
 
If you answered “yes”
                   
 
 
Q50 Is there subsequent communication or disclosure to data breach victims when new information about the breach event comes available?
           
 
If you answered “yes”
                   
 
 
Ex-post Response: Please answer each question listed below with a Yes, No or Unsure response. For each "Yes" response, please rate the importance of each control activity from very important to irrelevant.
 
 
Q51 Is there an assessment, audit or post-mortem procedure required after the incident is closed?
           
 
If you answered “yes”
                   
 
 
Q52 Is there a final report to senior management or the board of directors?
           
 
If you answered “yes”
                   
 
 
Q53 Is there a performance review of the incident response team conducted by management?
           
 
If you answered “yes”
                   
 
 
Q54 Is there a process to make recommendations for improvement?
           
 
If you answered “yes”
                   
 
 
Q55 Is there a training program for those who were responsible for the breach?
           
 
If you answered “yes”
                   
 
 
Q56 Does your organization attempt to calculate the cost of the data breach?
           
 
If you answered “yes”
                   
 
 
Q57 Is there a process to implement recommendations for privacy and data protection risk assessment programs?
           
 
If you answered “yes”
                   
 
 
Q58 Is there a process to determine responsibility for the data breach incident?
           
 
If you answered “yes”
                   
 
 
Q59 Is there a process to determine appropriate actions and enforcement for non-compliance with policies?
           
 
If you answered “yes”
                   
 
 
Organization Characteristics
 
 
Your current title is:
   
 
 
What organizational level best describes your current position?
 
 
Total years of business experience?
   
 
 
Total years in privacy or security?
   
 
 
Total years in current position?
   
 
 
Check the Primary Person you or your supervisor reports to within your organization.
 
 
Check the country or U.S. region where your company’s primary headquarters is located.
 
If in the United States, what state?
 
 
Educational and career background:
 
 
What is the approximate size of your IT department in terms of full-time equivalent (FTE) headcount?
 
 
What industry best describes your organization’s industry concentration or focus?
 
 
What best describes your role in managing privacy and data protection risks within your organization? Check all that apply.
 
 
 
 
 
 
 
What is the worldwide headcount of your organization?
 
Ponemon Institute LLC
Advancing Responsible Information Management

Ponemon Institute is dedicated to independent research and education that advances responsible information and privacy management practices within business and government. Our mission is to conduct high quality, empirical studies on critical issues affecting the management and security of sensitive information about people and organizations. As a member of the Council of American Survey Research Organizations (CASRO), we uphold strict data confidentiality, privacy and ethical research standards. We do not collect any personally identifiable information from individuals (or company identifiable information in our business research). Furthermore, we have strict quality standards to ensure that subjects are not asked extraneous, irrelevant or improper questions.