Privacy and security
Data breaches and what they cost
The most-quoted breach cost figure comes from a company that sells breach response; independent data puts the typical incident far lower.
No census of data breaches exists anywhere. Every figure in circulation comes from a convenience sample — a vendor's customer base, a set of public notices, an insurer's claims file — and the samples disagree on almost everything that matters, including how breaches start. The claim that travels furthest, a global average cost of several million dollars per breach, comes from a benchmark study run by a company that sells breach response, and it is a mean drawn from a heavy-tailed distribution, the statistic least suited to describing a typical case. Where an accredited national statistics agency asked a random sample of businesses what their worst breach cost, the median answer was zero. For a concrete commercial example of the monitoring category discussed here, see stealth monitoring software.
The cost figure everyone quotes is a vendor benchmark
The IBM and Ponemon Institute annual report is the most cited source in corporate security, and it is both commercially interested and unsuited to the use it gets.
IBM reports a 2026 global average breach cost of $4.99 million, up 12% year on year and a record high.
Direction: Increase. Strength of evidence: Weak.
Caveat Commercially interested — IBM sells breach-response and security products, and this is a mean over a self-selected benchmark panel including modelled "lost business" costs, not a probability sample of breached firms.
The problem is not only the seller's interest. An independent regression on Ponemon's own published figures found the cost-per-record model those reports popularised had almost no explanatory power.
The linear "cost per record" model explained only 13% of the variance in reported breach costs for 2013 and 2% for 2014, and grossly overstates losses above 100,000 records.
Direction: No detectable effect. Strength of evidence: Mixed.
Caveat A blog analysis rather than peer-reviewed work, addressing the 2013-2014 editions; IBM has since dropped per-record framing, but the mean-of-a-heavy-tail problem remains.
Independent loss data puts the typical incident far lower
The best non-vendor estimate comes from insurance claims rather than interviews.
The typical cyber incident cost under $200,000, about 0.4% of the affected firm's annual revenue.
Direction: Decrease. Strength of evidence: Strong.
Caveat A decade old and based on Advisen's insurance dataset, which skews toward incidents generating a claim or press coverage.
The UK government's official statistics point the same way from a different direction: a random probability sample of businesses and charities, asked what their most disruptive breach cost.
43% of UK businesses, around 612,000, identified a breach or attack in the previous 12 months, but the median perceived cost of the most disruptive one was GBP 0, with an interquartile range of GBP 0 to GBP 200.
Direction: No detectable effect. Strength of evidence: Strong.
Caveat An accredited Official Statistic, but it captures only identified breaches and costs are respondent estimates.
Both numbers can be true at once. Edwards, Hofmeyr and Forrest showed in 2016 that breach sizes follow heavy-tailed log-normal distributions and that the median malicious breach in their US dataset involved 383 records, while estimating that 60% to 89% of incidents were never reported at all (Journal of Cybersecurity, 2016). A mean drawn from that shape tells a reader almost nothing about the case in front of them.
The two leading threat reports contradict each other
The two reports most used to explain how breaches begin reach opposite conclusions about the top initial access vector over overlapping periods.
Exploitation of software vulnerabilities became the most common initial access vector at 31% of breaches, ahead of phishing at 16% and stolen credentials at 13%.
Direction: Cuts both ways. Strength of evidence: Mixed.
Caveat Vendor-published — Verizon sells security services — and the shift partly reflects Verizon's own expanded collection from extortion-site leaks, so some of the change is methodological.
ENISA found phishing, including vishing and malspam, to be the top initial access vector at 60%, with vulnerability exploitation at 21.3%.
Direction: Cuts both ways. Strength of evidence: Mixed.
Caveat ENISA states plainly that open sources and voluntarily shared information "do not constitute a complete picture", and this vector split directly contradicts Verizon's.
Anyone deciding whether to spend on patching or on defences against phishing and social engineering cannot settle it from these reports. The question is open, and any article presenting one of these percentages as the answer is quoting a sample, not a measurement.
Breach notices are disclosing less every year
The largest count of publicly reported US breaches documents its own erosion. The Identity Theft Resource Center recorded 3,322 US data compromises in 2025, a record and 79% above the 2020 level, while victim notices fell 79% to 278.8 million, the lowest since 2014 — a collapse reflecting the absence of one or two mega-breaches rather than better security (ITRC, 2026).
70% of 2025 US breach notices, 2,324 of 3,322, disclosed no information about the attack at all, up from 65% in 2024.
Direction: Increase. Strength of evidence: Strong.
Caveat ITRC is a non-profit but corporate-sponsored; this is the strongest single indicator that breach-cause statistics rest on a shrinking, self-selected disclosure base.
If seven in ten notices say nothing about cause, every published breakdown of causes rests on the minority that chose to explain themselves.
People and suppliers appear in most breaches
Verizon's 2026 report puts a human element in 62% of breaches and third-party involvement in 48%, a 60% year-on-year rise, with ransomware in 48% of breaches, a median observed ransom payment of $139,875 and 69% of victims not paying (Verizon Business, 2026). These come from the same vendor convenience sample, and the ransomware share is inflated by heavy ingestion of extortion-site data. The direction is consistent with the other sources: exposure runs through staff, suppliers and the software an organisation runs on.
The short version
- No census of breaches exists in any jurisdiction, so every statistic in circulation comes from a convenience sample.
- The global average cost of $4.99 million is a mean from a self-selected benchmark panel published by IBM, which sells breach response (IBM and Ponemon, 2026).
- The most-cited independent estimate, from over 12,000 insured cyber events, put the typical incident at 0.4% of the firm's revenue (Romanosky, 2016).
- In the UK's random-sample official statistics, the median cost of a business's most disruptive breach was zero (DSIT, 2026).
- The evidence cannot say how breaches usually start: over near-identical periods Verizon puts vulnerability exploitation first, ENISA phishing.