7 Key Lessons From Companies That Prevented Data Breaches in 2018

by Michael Bruemmer 4 min read March 12, 2019

Any responsible business manager knows that protection business and client data is a vital part of running a success organization. Now a new report identifies key factors that can improve a company’s ability to avoid hacks and prevent data breaches.

And here’s the good news: These tactics really work.

During 2018, the number of personal records exposed in data breaches soared — a total of 446.5 million pieces of data – an increase that was more than double the number of records breached during 2017, according to the Identity Theft Resource Center. The business, healthcare and financial sectors were the top three sectors hit, with hacking being the most common form of attack.

But among the companies surveyed in the latestannual study sponsored by Experian Data Breach Resolution, there are important signs of hope. Despite the startling increase in the number of records stolen by data thieves – a gain of 126 percent – the number of survey participants reporting a breach increased by just 5 percent.

This trend demonstrates that while hackers might be grabbing more data when they do manage to crack a database, the smaller increase in total breaches reported in the survey indicate that a growing number of institutions are improving their abilities to fend off cybercriminals.

What’s their secret? To encourage more effective strategies to handle and prevent breaches, “Is Your Company Ready for a Big Data Breach?” uncovers several important lessons learned from companies that are successfully insulating themselves – and their customers – from data theft.

  1. Prevention is the best response: The overarching lesson that researches found is that an effective data breach response plan starts with preventing breaches in the first place, rather than reacting after customer and business data has been stolen. Of the 643 U.S. business people surveyed who work on privacy, compliance and IT security, 29 percent reported that their organizations had prevented any breach involving more than 1,000 records for the past two years.
  2. Rate your plan: The Ponemon researchers found that the percentage of companies that find their data breach response plans to be very effective increased from 42 percent in 2016 to 52 percent in 2018. Not surprisingly, more people at organizations that didn’t report a breach rated their response plans as effective – 62 percent – while 45 percent of those at companies that suffered data theft nonetheless felt their plans were effective.
  3. Money matters: Ponemon researchers found that more investment in cybersecurity technology seemed to pay off. One of the most common factors among companies that prevented breaches was increased spending on technology to detect and prevent attacks. Of companies that prevented breaches, 73 percent increased their tech spending, versus 61 percent of those companies that were breached.
  4. No train, no gain: An even bigger improvement came from training employees and making them aware of privacy and data protection issues and practices. The likelihood of a data breach was significantly reduced when awareness training specifically targeted employees and other stakeholders in business processes who work with or access sensitive or confidential personal data. At organizations that implemented training, 79 percent avoided a breach versus 69 percent of those that were hacked.
  5. Cybersafety starts at the top: Executive engagement also matters. Making data security a priority among C-suite executives and corporate board members translates into keeping records safer. The study found that 54 percent of executives and 39 percent of directors were knowledgeable and engaged in planning data breach responses. At companies that were breached, 49 percent of executives and 32 percent of board members were involved with cybersecurity response.
  6. Sharing is caring: Another key finding in preventing breaches is that organizations that sharing their insights and experiences in handling and preventing breaches improved their cybersafety. Operations that participated in learning about data protection and hacks from industry peers and government agencies were more likely to avoid a breach – 59 percent of those who joined sharing programs didn’t suffer an attack, while 46 percent of those participating experienced a breach.
  7. Cybersafety is a process: Finally, organizations that want to stay cyber-safe might want to adopt the Boy Scout motto, “Be Prepared.” Companies that successfully prevented a data breach took several preventive measures to guard against attacks. That includes conducting regular reviews of physical security and access to confidential information, instituting third-party cybersecurity assessments, making data breach response part of their business continuity plans and creating backup websites that can be activated to provide content and information should a breach occur.

For the study, Ponemon researchers surveyed 643 professionals working in information technology and security, compliance and privacy who deal with data breach response plans in their organizations. The entire comprehensive survey of cybersecurity practices – “Sixth Annual Study: Is Your Company Ready for a Big Data Breach?” – is available to download now.

The Ponemon Institute, headquartered in Traverse City, Michigan, conducts independent research on data protection and emerging information technologies. Experian Data Breach Resolution helps businesses of all sizes manage the risk of fines, customer loss, negative press and litigation due to a breach of data, and is a subsidiary of Experian, the global leader in consumer and business credit reporting and marketing service operating in 80 countries.

Related Posts

Workflow Automation for Financial Services

Manual processes are quietly expensive. Every handoff between teams, every file transfer waiting in a queue and every decision that sits on someone's desk adds cost, introduces risk and slows the customer experience. For financial institutions, those delays translate directly into lost revenue and eroded margins. That’s why workflow automation is becoming critical for financial institutions looking to stay competitive. Done well, it doesn't just make existing tasks faster. It reshapes how decisions get made across the entire customer lifecycle, from the first marketing touch to account servicing and beyond. What is workflow automation? Workflow automation is the use of technology to run a sequence of tasks, decisions and handoffs with minimal manual intervention. Instead of a person moving work from one step to the next — pulling data, applying a rule, routing an account and sending a communication — software executes those steps automatically based on defined logic and real-time data. For financial institutions, workflow automation usually combines four ingredients: Data Connecting to the internal and external data sources that inform a decision. Analytics Scores, models and attributes that turn raw data into insights. Decisioning A rules engine that determines the right action for each customer or account. Execution The operational layer that carries out the action, whether that's an offer, a credit line change or outreach. The benefits of workflow automation The value of automation goes well beyond "doing the same thing faster." The benefits financial institutions consistently see include:Greater efficiency and lower operating costsAutomation frees underwriters, analysts and agents to focus on exceptions and high-value work rather than repetitive processing. Faster, more consistent decisionsA credit application that once waited in a queue can be assessed in real time against consistent, auditable policies, improving both the applicant's experience and portfolio quality. Better customer experiencesAutomation enables financial institutions to personalize communications at the point of interaction and offer the self-service options that many people now prefer. Improved compliance and governanceReduce the risk of costly compliance failures with built-in controls, audit trails and guided workflows. ScalabilityRespond to changing volumes without sacrificing speed, consistency or the customer experience. Where workflow automation makes the biggest difference Workflow automation tends to deliver the most value where decisions are frequent, repeatable and informed by data. In financial services, those opportunities exist across the customer lifecycle. Onboarding Onboarding is a customer's first experience of your organization, and it's also where friction can cause customers to abandon the process and turn to another provider. Forty percent of U.S. consumers have considered walking away from opening a new account when the process felt burdensome.1 An automated onboarding workflow can bring together document verification, device intelligence, behavioral analytics, credit attributes and more, then orchestrate them into a single decision. The result is a lower-friction experience for the customer and a consistent, auditable process. Once customers are on the books, serving them well means making continuous, high-volume decisions: credit line changes, cross-sell and up-sell opportunities, risk monitoring and retention actions. Automation makes it practical to run these recurring decisions consistently across an entire portfolio, using a holistic view of each customer that draws on multiple scores and attributes. Lending The underwriting process is a great example of how workflow automation can help prevent applicants from waiting days for an answer. Loan origination and credit decisioning capabilities are designed to create a seamless review process across consumer and commercial lending. After automating originations with our solutions, Michigan State University Federal Credit Union cut application processing time to under 24 hours. Fraud Financial institutions are checking fraud at every touchpoint, and the standard for AI fraud detection continues to rise as fraudsters use AI to slip under the thresholds of any single detection tool. Rather than running fraud checks in isolation, an automated workflow can run multiple fraud and identity verification services in parallel and weigh signals together. A fraud decisioning platform connects signals across internal systems, Experian data and third-party services, allowing teams to stay on top of evolving threats. Build a strong foundation for workflow automation Workflow automation can connect these stages, creating a consistent decisioning framework. What ultimately separates good automation from great automation is the quality of the data and decisioning software underneath it. An automated workflow is only as good as the information feeding it. That's where our comprehensive credit, alternative and identity data with the tools financial institutions need to act on it. Learn more here FAQs How does automated decisioning improve credit decisions? Automated decisioning applies consistent logic to every account in real time or in bulk, enabling faster and more informed decisions, quicker responses to market and regulatory changes at the point of interaction. What is workflow automation in financial services? It's the use of software to execute sequences of data gathering, analysis, decisioning and action. Does workflow automation replace human judgment? No. The goal is to automate routine, high-volume decisions so skilled staff can focus on the exceptions and complex cases that genuinely require human judgment. For example, a sensitive collections conversation or a nuanced underwriting call. Are we still compliant with regulations if we use an automated workflow process? Well-designed platforms include built-in governance, audit trails and compliance controls that help institutions align with requirements like the Fair Credit Reporting Act (FCRA) and other regulatory guidelines improving compliance compared with manual processes. How long does it take to implement? It varies by solution and scope, but modern cloud-based platforms are designed for fast onboarding and limited IT involvement. 1Global Fraud Snapshot 2025: Opportunities and challenge in identity, fraud and financial crime

September 9, 2026 by Zohreen Ismail
Expanding the Prescreen View with Alternative Credit Data

Start with a simple question Credit prescreen is an important tool in many lenders’ growth strategies. But the precision of any prescreen strategy depends on the data behind it. What financial behavior might traditional credit data alone not reveal? With Clarity data now available for Instant Prescreen decisioning, lenders can bring alternative credit insights into their targeting strategy, helping them identify prospects who may align with their established criteria, refine targeting strategies and explore additional acquisition opportunities while maintaining control over their risk thresholds. Additional insights alongside traditional credit data For many consumers, a traditional credit file tells a rich and reliable story. But it doesn't always tell the whole story. Consumers may also be using alternative financial products, such as small-dollar installment loans, single-payment loans, auto title loans or rent-to-own agreements and building payment histories that provide additional signals about their financial behavior. For lenders, those unseen signals can represent untapped opportunities. With more than 60 million unique subprime identities, Clarity's database helps lenders gain a more complete view of their applicant pool. Clarity data adds another dimension to that view, providing alternative credit insights that can help lenders better understand consumers whose financial behavior may not be fully represented by traditional credit data alone. How Clarity data sharpens instant prescreen decisioning Clarity provides specialty alternative credit data, with insights into subprime and near-prime consumer activity that may not appear in traditional credit files. And because Clarity is part of Experian, those insights can now be brought directly into Instant Prescreen decisioning. That means lenders can incorporate additional attributes and scores into their credit decisioning strategies without managing a separate data feed or stitching together disconnected sources. It has quickly become a visibility gap lenders can't ignore. Additional data may help support more granular segmentation and targeting strategies. Lenders remain in control of their criteria and risk thresholds while gaining additional information to inform their prescreen strategies. When considered alongside traditional credit data, alternative credit insights can support several aspects of prescreen decisioning: Identify more opportunities: Surface qualified prospects who may be harder to identify using traditional credit data alone. Refine targeting: Add alternative credit insights to help differentiate consumers with greater precision. Inform offer strategies: Use a broader view of financial behavior to help align consumers with appropriate offers. Expand intelligently: Explore incremental audience opportunities while maintaining control over your established risk criteria. Simplify execution: Access Experian and Clarity insights within a connected Instant Prescreen decisioning environment. See more opportunity in your prescreen strategy Growth doesn’t always require looking for an entirely new audience. Sometimes, it starts with seeing more in the audience already in front of you. By bringing Clarity data into Instant Prescreen, lenders can add another layer of insight to their decisioning, helping identify incremental opportunities, refine targeting and support acquisition decision processes across a broader range of consumers. Explore prescreen solutions

September 3, 2026 by Zohreen Ismail
Are Fraudsters Building Better Identities Than Your Customers?

Fraudsters are getting surprisingly good at onboarding. Sometimes, better than your customers. Legitimate customers treat onboarding like an errand. They start an application between other tasks, get distracted, forget a password, switch devices, upload a document or come back later to finish. Their digital lives aren’t always linear, because real life isn’t either. Fraudsters approach onboarding differently. For them, opening an account is the objective. Every interaction is designed to increase the odds of success. The difference raises an uncomfortable question hanging over onboarding: What exactly are we rewarding? When smooth becomes suspicious Digital onboarding has traditionally rewarded experiences that feel smooth, consistent and complete. The challenge is that legitimate customers rarely behave that way. Most people approach onboarding somewhere between mildly distracted and mildly annoyed. They pause halfway through because dinner is burning. They reopen an old account only to realize everything is attached to an email they made in college and, somehow, still use for airline receipts. Digital life accumulates history unevenly, because ordinary life does too. Fraudsters have every reason to eliminate those inconsistencies. Applications may be rehearsed. Identity attributes are assembled deliberately. Contact points are prepared in advance. Every interaction is optimized to make the application appear credible. Ironically, the qualities organizations often associate with confidence — clean submissions, steady progression and few corrections — can also describe applications that have been carefully engineered to pass inspection. The challenge isn't that smooth onboarding is meaningless. It's that smooth onboarding, by itself, doesn't tell the whole story. Context changes interpretation A smooth onboarding experience should be the beginning of the evaluation, not the end. Behavior provides important context. How someone moves through an application can reveal whether the experience feels naturally human or unusually orchestrated. Do they interact naturally? Do they hesitate, correct mistakes or navigate in ways that resemble ordinary human behavior? Or does the session appear unusually scripted, automated or repetitive? Identity verification adds another layer. Matching information across trusted sources, validating identity details and strengthening confidence in account creation remain important, particularly when onboarding decisions carry financial, fraud or customer experience consequences. But verification largely answers a point-in-time question: Does this information match right now? A third layer comes from digital history. An inbox attached to years of airline receipts, loyalty accounts, subscription renewals, account recovery, financial notifications and familiar digital routines introduces a different kind of confidence. Legitimate digital identities leave behind patterns of persistence and engagement that develop gradually over time. Fraudsters can assemble convincing identity attributes, but creating years of ordinary digital life is much harder. Building confidence in an identity requires more than verifying information submitted during a single onboarding session. It requires understanding whether the identity reflects a broader history that supports what the application suggests. A multilayered approach builds stronger identity confidence No single signal can provide a complete view of identity risk. Organizations need multiple sources of confidence that reinforce one another. That's the thinking behind our approach: combining behavioral intelligence, identity verification and digital identity continuity into a more complete view of risk. We bring these complementary layers together through: • NeuroID adds behavioral context during onboarding and account creation, helping identify interaction patterns that may indicate automation, manipulation or coordinated fraud. • Precise ID® strengthens identity verification and resolution by comparing applicant information with trusted identity data. • AtData, recently added to our portfolio, contributes email-centered intelligence based on persistence, engagement and long-term digital history. Together, these capabilities help organizations move beyond evaluating a single moment in time to understanding whether an identity is supported by consistent behavior, trusted identity data and an established digital history. The future of fraud prevention isn't about rewarding the smoothest application. It's about recognizing the most trustworthy identity. Fraudsters can rehearse an application. They can optimize an onboarding journey. They can even assemble convincing identity attributes. What they can't easily manufacture is years of ordinary digital life. That's why digital identity continuity has become an important layer of modern fraud prevention. Combined with identity verification and behavioral intelligence, it helps organizations distinguish between identities that simply look convincing and those supported by a history that is much harder to fake. Learn more Contact us

September 2, 2026 by Julie Lee

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe