Reputation Damage & Measurement
Reputation damage can be one of the most difficult concepts to build measurements around. In fact, it can be difficult to develop the actual metrics for the measurements, as well. Damage to things like “corporate reputation” and “goodwill” and “brand equity” can be difficult to wrap even reasonable dollar estimates around (When I use FAIR, I really only care to use one metric when describing loss magnitudes - the almighty currency).
Complicating factors is the impact (or lack thereof) of incidents on stock price. Many researchers who identify themselves with the New School of Information Security (yours truly included) want to immediately look at stock price as a bell-weather metric for incident impact. I think this stems from our days of slinging FUD, back when we could scream “Buy a firewall or we’ll have an incident and you’ll be on the front page of the paper and the stock price will go down!” But these days notable incidents seem to suggest that the impact on stock price for an incident is short lived. With qualifications, of course.
So what would/should we make of this from Money.co.uk?
£12million ($24m) Wiped off Helphire Stock after Malicious Email Sent to Clients
Car hire firm Helphire have taken Google to court after a malicious email sent from a Gmail account saw their shares plummet £12million in a single day.
The Bath-based business who specialise in providing replacement cars to ‘no-fault’ drivers involved in accidents on behalf of car insurance companies, initiated legal proceedings against the search engine giant as part of their attempt to find out who is responsible for sending the defamatory mailing.
Google are now known to have complied with the court order and have controversially supplied details of the email account and ISP used by the meddler.
Written under the psudoname Peter Franks, the 1200 word email is know to have been sent from a gmail account that was opened specifically for this purpose and closed a few minutes after the damage had been done…
…The misdemeanour couldn’t have come at a worse time for the struggling firm who have undergone a £45million rights issue and seen a 75% drop in the value of their stock already this year.
That last paragraph, for me, explains some of the difficulty in tying reputation damage to stock decreases. It’s like when you read the headlines from Bloomberg about why the days stocks (or commodity) prices are up or down. You know, the “Oil closes $3 higher on news that a notable South American dictator has a rather unpleasant boil in a very uncomfortable area” type of headlines. You really do have to question the causality and correlation. So in the Helphire case above - is this new drop in stock really because of the email sent? If so, should we view that $24mil number as an independent data point to describe this sort of attack on reputation, or is the magnitude aggravated due to the long-term trend of stock price?
Even when we have “Objective Data” (an in-joke for Adam S.) like this decline in stock price, it is really difficult to provide any sort of precise estimate or measurement - about the future, present or past. The best we can do is use ranges, distributions, that are reasonable based on evidence and observation.
So it’s worth filing away this sort of datum for future use - while dutifully acknowledging the qualifiers we might place around it.
So the questions I ask here - what should we make of this new information, and how should we view the $24million drop - they’re not rhetorical. I am very interested in your views and welcome your comments!


James Arlen Aug 22
Alex,
I think that the impact security errors or breaches on reputation has significantly changed over the last 5 years.
Without making any attempt to cite sources, compare and contrast some of the early breach notifications (those which caused California SB1386) to the recent TJX issue. Big difference. TJX is doing better today than prior to the breach.
My suspicion is that like with so many other aspects of humanity, the increased tempo of breach notifications has created an implied “Everyone’s Doin’ It” mentality amongst the group which generates the reputation.
Loose mores?
Alex Aug 22
@James - That’s kind of where I’m at in my thinking. Right with the no attempt to cite sources and such.
How to Get Six Pack Fast Apr 15
The topic is quite hot on the Internet at the moment. What do you pay attention to when choosing what to write ?