Data Breach Cost Statistics (2026)
The global average cost of a breach fell 9% to USD 4.44 million in IBM's 2025 study, driven by faster containment. The published cost figures, what moves them, and how to use them without overstating your own exposure.
Priya NandalAnalyst, Security & Health DataUpdated September 2026USD 4.44M
global average total cost of a data breach in the 2025 study
Updated September 2026 · 9 min read
Sources
- 01IBM — Cost of a Data Breach Report 2025Global average USD 4.44M, -9% year on year, US average USD 10.22M
- 02IBM Think — what the 2025 report foundFaster containment as the driver of the decline; the AI oversight gap
Overview
Breach cost statistics are used for two incompatible purposes: sizing a security budget and scaring a board. The published averages are useful for the first only if you keep their construction in view.
IBM's Cost of a Data Breach Report is the most widely cited series, based on interviews with organisations that experienced a breach. Its 2025 edition recorded the first meaningful decline in years — and located the cause in containment speed rather than in fewer incidents.
Key takeaways
- The global average is USD 4.44M, down 9% — a fall in cost per incident, not in incident volume.
- Regional spread is enormous: the US average is more than double the global figure.
- Containment speed is the lever the data most consistently rewards.
- AI cuts both ways in the 2025 edition: it speeds up defence and opens an ungoverned surface.
- An average is not a forecast for one company; cost scales with records, regulation and downtime.
The headline number and its shape
IBM's 2025 report puts the global average total cost of a breach at USD 4.44 million, down 9% from USD 4.88 million. The report attributes the improvement principally to organisations identifying and containing breaches faster than in the prior year.
Two cautions. First, this is a mean across breached organisations of very different sizes, so it is pulled upward by large incidents. Second, a lower average cost per breach says nothing about how many breaches occurred.
- Use the average for direction of travel, not as a per-incident estimate for your business.
- Pair any cost figure with your own record counts and regulatory exposure.
Geography dominates the variance
The United States average of USD 10.22 million sits far above the global mean, reflecting litigation exposure, notification regimes and higher recovery labour costs. A European or Asian entity quoting the US figure overstates its exposure substantially — and vice versa.
If you operate in several markets, cost modelling belongs at entity level, because the regulatory driver of cost is jurisdictional.
Time to contain is the controllable lever
The mechanism behind the 2025 decline is the one security teams can act on. Cost accrues while an intruder retains access: more records touched, longer downtime, wider notification, more forensics. Compressing detection and containment compresses nearly every cost line at once.
That is also why the report links AI-assisted defence to the decline: its measurable contribution shows up in lifecycle duration rather than in prevention.
- Instrument and rehearse detection-to-containment as a single measured interval.
- Test the incident plan on a schedule; untested plans fail at the notification stage.
- Log and alert on identity events — credential misuse is the recurring cheap entry route.
The AI oversight gap
The 2025 edition is subtitled around AI oversight: organisations have deployed AI faster than they have governed it, leaving models, data pipelines and agent credentials outside normal access review.
For 2026 planning this is the practical implication of the whole report. AI in the SOC is a cost reducer; AI adopted without an owner, an inventory and access control adds a new class of exposure that existing controls do not see.
Averages hide the shape of the distribution
Breach cost is heavily skewed: most incidents are contained cheaply and a small number are catastrophic. An average pulled up by outliers describes neither group, which is why the median and the range are more useful for planning than the headline mean.
When a figure is used to justify spend, state whether it is a mean or a median and what the sample was. A mean across a sample dominated by large regulated enterprises will not describe a mid-market company.
- Mean: sensitive to a few extreme incidents
- Median: describes the typical contained incident
- Tail: the scenario your insurance and board care about
Detection and containment time drive the total
The clearest and most repeatable finding in breach research is that incidents found and contained faster cost less. That relationship holds across sectors and years, which makes time-to-detect a more actionable target than any single control.
It also makes the number auditable internally: you can measure your own detection and containment times from past incidents and tabletop exercises, and compare them against published ranges without needing to model cost at all.
What the cost figures include
Published totals typically combine detection and escalation, notification, response and lost business. Fines and litigation may or may not be included, and lost business is estimated rather than invoiced.
If you are building an internal expected-loss figure, rebuild it from your own components instead of importing a headline. The published number is best used to sanity-check the shape of your estimate, not to replace it.
Questions we get asked
What is the average cost of a data breach?
USD 4.44 million globally in IBM's 2025 Cost of a Data Breach Report, down 9% from USD 4.88 million in the previous edition.
Why did breach costs fall?
IBM attributes the decline mainly to faster identification and containment, associated with AI-assisted detection and response.
Which country has the highest breach costs?
The United States, with an average of USD 10.22 million in the 2025 study — more than double the global average.
Does a lower average mean breaches are less common?
No. The average measures cost per breached organisation in the study sample; it is not a measure of incident frequency.
How to read this
IBM's figures come from research conducted with Ponemon Institute, based on interviews with organisations that suffered a breach; costs are activity-based estimates including detection, response, notification, lost business and legal exposure. The sample excludes very large catastrophic breaches, which limits skew but also means the average is not an upper bound. Averages are cross-industry and cross-region; regional and sector figures inside the report differ substantially from the global mean.
Before you act on this
- 01Use median and range, not the mean alone, for planning.
- 02Measure your own time to detect and contain.
- 03List which cost components your internal estimate includes.
- 04Check whether fines and litigation sit inside the quoted figure.
- 05Test the tail scenario with the board, not just the typical one.
Terms used above
- Time to detect
- Interval between initial compromise and its discovery.
- Time to contain
- Interval between discovery and the incident being stopped.
- Lost business
- Estimated revenue and churn effects attributed to an incident.
- Tail risk
- The rare, high-cost incident that dominates averages.