On the evolution of data breach reporting patterns and frequency in the United States: a cross-state analysis
Benjamin Avanzi (1), Xingyun Tan (1), Greg Taylor (2), Bernard Wong, (2) ((1) University of Melbourne, (2) UNSW Sydney)

TL;DR
This study analyzes data breach reporting patterns and frequency trends across eight U.S. states with established laws, revealing stable pre-2020 breach rates and increasing post-2020, with insights into reporting delays and state-specific differences.
Contribution
It provides a consistent, comparative analysis of breach frequency over time across multiple states, accounting for reporting standards and uncovering new trends in breach severity and reporting delays.
Findings
Reporting delays are lengthening over time.
Breach frequency was stable before 2020 and increased afterward.
Significant differences in breach trends across states and severity levels.
Abstract
Understanding the emergence of data breaches is crucial for cyber insurance. However, analyses of data breach frequency trends in the current literature lead to contradictory conclusions. We put forward that those discrepancies may be (at least partially) due to inconsistent data collection standards, as well as reporting patterns, over time and space. We set out to carefully control both. In this paper, we conduct a joint analysis of state Attorneys General's publications on data breaches across eight states (namely, California, Delaware, Indiana, Maine, Montana, North Dakota, Oregon, and Washington), all of which are subject to established data collection standards-namely, state data breach (mandatory) notification laws. Thanks to our explicit recognition of these notification laws, we are capable of modelling frequency of breaches in a consistent and comparable way over time. Hence,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Cybercrime and Law Enforcement Studies · Software Reliability and Analysis Research
