Every year, IBM's Cost of Data Breach report releases a headline number that gets cited in board presentations, security budget requests, and vendor pitches for the next 12 months. In 2026, that number is $4.44M — the global average, down 9% from the prior year. The decline is real. It is also the wrong number for most organisations doing risk planning.

The US average hit $10.22 million simultaneously — an all-time high. Healthcare averaged $11.2 million. Financial services averaged $6.08 million. The global average fell because more breaches occurred in lower-cost regions, not because breaches became cheaper in the markets where most of the readers of this article operate. Understanding the difference between those two things — and understanding which part of the cost curve is growing fastest and why — is the difference between a security budget built on accurate risk data and one built on a headline that flatters the threat.

$4.44M
global average breach cost — IBM 2025, first decline in 5 years
IBM Cost of Data Breach, 2025
$10.22M
US average — all-time high, 15th consecutive year as world's most expensive
IBM Cost of Data Breach, 2025
241
days average breach lifecycle — 181 to identify, 60 to contain; 9-year low
IBM Cost of Data Breach, 2025
$20.9B
total reported cybercrime losses in the US in 2025 — FBI IC3 Annual Report
FBI IC3, 2025

The headline that misleads — global average vs US reality

The 9% decline in the global average is the first good news in IBM's Cost of Data Breach longitudinal data since the series began. It reflects two real factors: AI-powered security detection tools that IBM's 2025 data shows are cutting breach lifecycles and costs for security-mature organisations, and a shift in breach volume toward lower-cost regions where the per-breach cost is structurally lower. Neither of those factors means breaches are cheaper for US organisations, for healthcare providers, or for any regulated industry.

The same report, two different stories
The headline number
$4.44M
Global average — down 9% from $4.88M. First decline in five years. Driven by AI detection improvements and a shift in breach volume toward lower-cost regions. The number cited in most news coverage.
The number that matters for most readers
$10.22M
US average — an all-time high. Up 9% from $9.36M in 2024. Driven by steeper regulatory fines, higher litigation exposure, and the concentration of healthcare and financial services organisations. The number to use for US risk planning.

The reason the US leads global breach costs by 2.3× — a gap it has maintained for 15 consecutive years — is structural rather than incidental. All 50 US states have mandatory breach notification laws, each with different timing, scope, and penalty provisions. Class action litigation following a breach is aggressive and expensive in ways that most other legal systems do not replicate. Federal and state regulatory fines have escalated sharply in the past three years. And the US has a disproportionate concentration of healthcare and financial services organisations — both of which sit in the highest-cost breach categories — relative to other countries in IBM's study population.

By industry — where breach costs sit in 2026

Industry is the single most predictive variable in breach cost after geography. The difference between the highest-cost industry (healthcare, $11.2M) and the global average ($4.44M) is 2.5× — larger than the difference between the highest-cost country (US, $10.22M) and the global average. Understanding where your industry sits on this spectrum is the foundation of any accurate risk quantification.

Industry Avg. breach cost vs global avg Key cost driver
Healthcare $11.2M +152% HIPAA penalties up to $1.9M/violation/yr; medical records high dark-web value; 15th consecutive year #1
Financial services $6.08M +37% 300× more cyberattacks than other industries; regulatory fines (SEC, FINRA, OCC); high customer churn post-breach
Pharmaceuticals $5.01M +13% IP theft of drug formulations and clinical trial data; FDA regulatory exposure; supply chain disruption costs
Technology $4.97M +12% Shadow AI breach vectors; IP theft; customer trust damage cascades to B2B relationships; high forensic costs
Energy $4.65M +5% IoT/OT attack surface growing 107% YoY; critical infrastructure regulatory penalties; operational downtime costs
Professional services $4.47M +1% Client data exposure; reputational damage; legal professional liability; client relationship termination
Critical infrastructure $4.82M +9% Rising IoT-related threats; 98% encryption rate in ransomware attacks on government sector
Education $3.80M -14% Below-average cost but record 252 incidents in 2026; high attack volume, lower per-incident cost
Government $2.83M -36% Lower average cost but 98% ransomware encryption rate; budget constraints extend containment timelines

Source: IBM Cost of Data Breach Report 2025; StationX Data Breach Statistics (July 2026, cross-referencing IBM data with Verizon DBIR 2026 and CrowdStrike Global Threat Report 2025). Healthcare's 15-year dominance is structural. The regulatory framework (HIPAA, with penalties up to $1.9M per violation category per year), the data value (medical records trade at premium prices on criminal markets because they combine PII, insurance data, and health history with long fraud utility lifespans), and the critical system impact (healthcare infrastructure being offline during incident response carries direct patient safety implications) all compound simultaneously in a way that no other industry matches.

The number the headline hides — $18,400 per day

$18,400
per day of
undetected breach

The IBM data allows a precise per-day calculation

At $4.44M over a 241-day mean lifecycle, the effective cost of each day an attacker remains undetected is approximately $18,400. This figure is not a budget estimate — it is the operational implication of IBM's correlation between breach lifecycle and cost. Breaches contained within 200 days cost $3.87M on average. Breaches taking over 200 days cost $5.01M — a $1.14M gap from 41 additional days. The most effective single investment in breach cost reduction is not post-breach response capability — it is detection speed.

IBM's 2025 data shows the mean breach lifecycle fell to 241 days — the shortest in nine years — driven by AI detection adoption. But 241 days is still eight months of an attacker operating inside a network before containment. The attack vector with the longest detection time in IBM's 2025 data was stolen or compromised credentials at 292 days. Healthcare breaches took 279 days — nearly six weeks longer than the global average — partly because healthcare organisations often prioritise clinical operations continuity over security incident response during active incidents.

The practical investment implication: IBM's data shows that going from no AI security tools to extensive AI/automation in security operations cuts detection time by 51 days. At $18,400 per day, those 51 days represent approximately $938,400 in avoided breach cost from detection speed alone — before counting the full $1.9M total cost differential IBM documents between organisations with and without AI security tools.

The 4 cost categories — what the total is actually made of

IBM's methodology breaks breach cost into four categories. Most articles cite only the total. Understanding which category is growing fastest and which causes the most hidden long-term damage changes where a rational organisation invests in prevention and response capability.

Category 1
Detection & Escalation
Forensic investigation, assessment and audit, crisis management, and board communications. Includes the cost of external forensic teams, legal counsel, and crisis communications firms engaged during and immediately after discovery.
↑ Growing fastest — sophisticated attacks require more advanced tools and more skilled investigators to find
Category 2
Notification
Legally required breach notifications to affected individuals, regulators, and relevant authorities. Costs vary dramatically by regulatory jurisdiction — GDPR requires 72-hour notification, HIPAA 60 days, and all 50 US states have mandatory notification laws with different timing and content requirements.
→ GDPR adds avg $170K per incident; NIS2 adds $50K-100K additional per incident in EU
Category 3
Post-Breach Response
Credit monitoring, legal fees, regulatory fines, and technical remediation. The regulatory component has escalated sharply — HIPAA penalties reach $1.9M per violation category per year, GDPR fines reach 4% of global annual revenue. Regulatory fines are now a near-certainty for any organisation handling personal data that experiences a breach.
↑ Regulatory component growing — non-compliance adds avg $173,700 above baseline
Category 4
Lost Business
Revenue lost during downtime, customer churn, cost of acquiring replacement customers, and reputation damage. For B2B organisations, this is particularly severe — enterprise customers conduct vendor security assessments and may terminate relationships following a breach, taking their full LTV with them. Least visible in the immediate aftermath, most destructive long-term.
⚠ Most underestimated — customer churn compounds well beyond the incident response period

The AI arms race — both sides are upgrading simultaneously

IBM's 2026 data makes the case for AI-powered security tools unambiguously: organisations with extensive AI and automation in security operations pay $3.62M per breach versus $5.52M without — a $1.9M differential and the largest single cost differentiator in the entire study. AI-equipped teams detect breaches 51 days faster, limiting dwell time and lateral movement. But the same technology that reduces breach costs for defenders is simultaneously increasing breach severity for organisations that have not adopted it.

AI on the defence — what it delivers
  • $1.9M average saving per breach for organisations with extensive AI/automation (IBM 2025)
  • 51 days faster detection vs organisations without AI security tools
  • $3.62M average cost with AI vs $5.52M without — the largest cost differentiator in IBM's data
  • Automated response to known attack patterns reduces human response lag that attackers exploit
  • Behavioural anomaly detection surfaces credential-based attacks that signature-based tools miss
AI on the attack — what it enables
  • AI-powered breaches cost $4.49M vs $4.20M for non-AI attacks — attackers are exploiting AI to increase damage (IBM 2025)
  • AI-generated phishing achieves higher click rates than human-crafted equivalents (Harvard Business Review research)
  • $25M deepfake CFO scam documented in CrowdStrike 2025 reporting — voice and video impersonation now accessible to mid-tier criminal groups
  • Shadow AI creates new breach vectors — IBM 2025 identified growing breaches involving unauthorised AI use inside organisations
  • AI-automated reconnaissance compresses the time from initial access to lateral movement

"The gap between organisations with and without AI security tools is $1.9 million per breach — and it is widening annually. Organisations that haven't adopted AI-driven security are falling behind not just in detection speed but in overall resilience."

StationX — Data Breach Statistics 2026 Analysis, July 2026
Building software that handles sensitive data?

Choose a development partner verified on security practices

Third-party vendors now account for a significant share of data incidents. The security posture of the agency building your software — their code practices, security testing, data handling protocols, and compliance certifications — directly determines your breach probability. TechRadiant verifies agencies on security capability, not just delivery speed.

The controls that reduce breach costs — ranked by documented impact

IBM's 2025 report analyses the cost impact of specific security controls in isolation — showing how much each one reduces the breach cost for organisations that have it versus those that do not. These figures are relative comparisons, not guarantees: they show which practices correlate with lower breach costs across the 604-organisation study population. The pattern is consistent with prior IBM editions: the controls with the highest cost-reduction impact are also among the most accessible in terms of implementation cost.

Security control Breach cost reduction Implementation cost est. ROI multiple (per breach avoided)
Incident response plan + tested IR team $2.66M (combined with other controls) $15K–$30K/yr (plan + testing) 8–15× per incident
AI / automation in security operations $1.9M per breach + 51-day faster detection $100K–$300K/yr (SIEM + SOC) 6–8×
Zero-trust architecture $1.76M per breach $200K–$600K (implementation) 3–5× over 3 years
MFA (multi-factor authentication) Up to 32× ROI on investment (databreachcost.com analysis) $5K–$20K/yr (enterprise) 32× per incident avoided
Employee security awareness training 24% lower breach costs; phishing success rate reduction $10K–$50K/yr 15× per incident
Law enforcement involvement (ransomware) $990K average saving (FBI/Europol coordination) No direct cost High — 69% of victims who refuse to pay report involvement
Encryption of sensitive data ~$200K saving; reduces per-record exposure cost $20K–$80K (implementation) 3–5×
Regulatory compliance programme Avoiding non-compliance adds avg $173,700 in fines $30K–$150K/yr 2–4×

The practical investment insight from IBM's data: the four highest-impact controls — incident response planning, AI/automation, zero-trust architecture, and MFA — can together produce combined savings that exceed the average breach cost. An organisation with all four in place and tested could realistically see effective breach costs fall below $2M even in a high-cost industry. An organisation with none of them faces the full $10.22M US average exposure, plus the regulatory and litigation premium that follows inadequate documented controls.

The security posture of any third-party software development partner contributes directly to this risk profile. Choosing a development agency without documented security practices, SOC 2 certification, or secure development lifecycle controls is a direct input into breach probability — particularly given that vendor-sourced breaches now account for a significant proportion of total incidents. For the broader framework for evaluating software development agency security depth before engagement, see our agency evaluation guide covering red and green flags.

Ransomware — the numbers behind the headlines

Ransomware appeared in 48% of all confirmed breaches in 2026 per Verizon's DBIR 2026, up from 44% the prior year. The median ransom payment was $139,875 — and 69% of victims paid nothing at all. These numbers require context: the median is the mid-point, pulled downward by many small payments from smaller organisations, while a small number of large payments from enterprises and hospitals pull the mean substantially higher.

Sophos's State of Ransomware 2025 survey — a vendor-commissioned survey of 3,400 organisations that were actually hit, which is directional data rather than census data — put the average ransom payment at $1.0M and average recovery costs excluding any ransom at $1.53M. IBM's 2025 report found 63% of ransomware victims refused to pay. The practical implication of these figures together: recovery costs without paying ransom are significant (the $1.53M Sophos average), paying the ransom does not eliminate recovery costs, and the downtime and reputational damage occur regardless of payment decision. FBI and cybersecurity agencies recommend not paying, as payment does not guarantee data restoration and funds continued attacks.