This blog is a roll-up of all the posts from analysts who serve Security & Risk Professionals. Individual analyst blogs are listed below. Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Recent Analyst Tweets
- @MissDestructo Hey, thanks for the kind wishes! See you soon! :)8 hours 24 min ago
- @johnrrymer Bummer. ;-(11 hours 39 min ago
- @johnrrymer will I see you in London?12 hours 18 min ago
- See all
Analyst Blogs
- Andras Cser (30)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (19)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- IT security (27)
- GRC (22)
- Privacy (22)
- Enterprise Risk Management (15)
- data security (12)
- Disaster recovery (11)
- Identity and access management (10)
- IT Risk Management (10)
- Business continuity (9)
- Incident Response (9)
- See all
Archives
- May 2013 (4)
- April 2013 (10)
- March 2013 (2)
- February 2013 (9)
- January 2013 (3)
- December 2012 (5)
- November 2012 (5)
- October 2012 (7)
- September 2012 (8)
- August 2012 (5)
- July 2012 (2)
- May 2012 (10)
- April 2012 (7)
- See all

Calculating the cost of a data breach should be a part of every organization’s information security risk management strategy. It’s not an easy task by any means, but making efforts to do so upfront — as opposed to after a breach, when calculating cost is the last thing on the to-do list! — for your organization can help to assess risk and justify security investments. But where does one begin, and what should be considered in cost estimates? There are the usual suspects, or direct costs, relating to discovery, response, notification, and damage control such as:


