Certified Information Security Manager (CISM)Incident ManagementMedium

A large e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that disrupts its online sales for several hours. The incident response team successfully mitigates the attack, but the CISO is asked to quantify the total impact. Beyond direct revenue loss and mitigation costs, which of the following 'intangible' costs is MOST challenging to accurately quantify but can have a profound long-term impact?

  1. ACost of replacing compromised hardware and software licenses.
  2. BRegulatory fines and legal fees associated with non-compliance.
  3. CLoss of intellectual property due to data exfiltration.
  4. DIncreased customer churn and damage to brand reputation.
Show answer & explanation

Correct answer: D. Increased customer churn and damage to brand reputation.

Loss of brand reputation and customer churn are notoriously difficult to quantify accurately because their impact unfolds over time and can be influenced by many factors. While they are intangible, their long-term effect on future revenue and market share can be profound.

Why the other options are wrong

  • A. Replacing hardware and software licenses are direct, tangible costs that are relatively easy to calculate.
  • B. Regulatory fines and legal fees, while substantial, are generally quantifiable once assessed.
  • C. Loss of IP can be significant but is often quantifiable through market value or R&D costs.

Intangible Costs of Incidents

Non-monetary losses resulting from a security incident that are difficult to quantify but can significantly impact an organization's long-term viability.

  • Includes damage to reputation, customer trust, and brand value.
  • Can lead to loss of market share and future revenue.
  • Often more substantial in the long run than direct costs.

Memory trick: Reputation is like smoke, hard to catch and put a price on.

More Incident Management questions