The Real Cost of a Data Breach in 2026

The Real Cost of a Data Breach in 2026

A data breach doesn't stop costing you the day it's contained. It can cost you an enormous amount of time while you recover. It can also cost you clients. 
If you’re hoping to make a case for better cybersecurity, numbers are incredibly helpful. And when it comes to a data breach, they can make that case for you very easily. 

How much does a data breach cost?

how-much-does-a-data-breach-cost-infographic

Here are a few recent stats from IBM: 

  • The global average cost of a breach is now $4.99M
  • In the U.S., average data breach costs are $11.5M
  • Average costs for finance hover at $6.29M
  • Technology and industrial organizations face $5.50M
  • Healthcare is spending $6.64M on average 

Government and education organizations typically report lower average costs than healthcare or finance, largely because they hold less data that's directly monetizable on the black market. 

That doesn't mean fewer attacks — it means the successful ones are less likely to produce an eight-figure headline.

How do data breaches happen?

common-pathways-data-breaches-infographic

Most data breaches happen in a similar way. For example, a phishing email leads to stolen credentials, which leads to business email compromise, which leads to ransomware. 

Here's how each one actually plays out.

Vulnerability exploitation

Attackers scan the internet for known, unpatched flaws in software like VPNs and firewalls, then exploit them directly — no phishing email or stolen password required. 

It's now the single most common way in. Only 26% of critical, known vulnerabilities were fully patched in 2025, down from 38% the year before. A patch existing and a patch actually getting applied are two different things, and that gap is where a lot of breaches start.

Web application and API attacks

Anything you expose to the public internet — a login page, a web form, an API endpoint — is reachable by attackers by design. They test those entry points for weak input handling or missing authentication, then use one to reach the database sitting behind it.

Phishing and stolen credentials

An email convinces someone to hand over a password, or a credential gets bought off the dark web from an unrelated breach at a completely different company. 

Once an attacker has a real, valid login, your systems don't see an intruder — they see an employee, which is exactly why these breaches take so long to catch. 

Third-party and vendor compromise

Attackers increasingly go after whichever vendor has the weakest defenses instead of coming at you directly. And, unfortunately, a compromised software provider or contractor often will have access to dozens or hundreds of client environments at once. 

One breach can easily become many, which is why third-party breaches now account for 48% of all breaches. If a contractor's login can reach your systems, an attacker who compromises that contractor now has that same access into yours. 

Vendor due diligence — vetting a vendor's security before they get access, not after — is what keeps someone else's weak link from becoming your breach. 

Insider actions and human error

Not every breach starts with an outside attacker at all. Someone emails a spreadsheet to the wrong address, a cloud storage folder gets left open to the public, or an employee reuses a personal password that later leaks somewhere unrelated. 

These stories don't always make headlines the way a ransomware gang does, but they show up consistently across every major industry dataset — and they're often the easiest ones to address with basic access controls and training. 

Where do data breach costs come from?

Total costs are a slow accumulation across detection, response, and everything that happens later. It typically takes businesses 247 days to identify and contain a breach, and every one of those days adds cost.

Direct costs

These show up fast and are the easiest to itemize:

  • Forensic investigation and containment
  • Legal counsel and regulatory notification
  • Credit monitoring for affected individuals
  • System recovery and hardware replacement
  • Cyber insurance deductibles

Costs that don't show up on an invoice

These take longer to surface, and they're usually the larger half of the bill:

  • Lost business from downtime and customer churn
  • A cyber insurance renewal at a higher rate
  • Employee time diverted from actual work for months
  • Reputational damage that shows up in next year's sales numbers, not this year's

     

This is exactly why a documented incident response plan — not just antivirus software — is so important. 

Is AI making data breaches more expensive?

Yes, AI is making data breaches more expensive. But there’s good and bad news there. 

First, the bad news. 

AI-driven attacks increased 56% year over year. Shadow AI incidents (where employees use AI tools that were never approved or governed) more than doubled to 43% of security incidents this year. And breaches involving shadow AI averaged $5.39 million, and one in five resulted in a regulatory fine.

On the flip side, organizations that used security AI and automation extensively cut their average breach cost by $1.93 million and shortened their breach lifecycle by 65 days. 

How do you keep your number closer to the low end?

Eliminating risk entirely isn’t realistic. But you can reduce it and mitigate any costs. 

Here’s how: 

  • Know where you actually stand — most clients I talk to significantly underestimate how many unpatched systems or unmonitored vendor connections they're carrying

  • Write the plan before you need it — a response plan that exists only in someone's head falls apart the moment that person is unreachable

  • Treat vendor access like your own — if a contractor's login can reach your systems, audit it the same way you'd audit an employee's.

  • Patch on a real schedule — a consistent patching cadence removes the most common way attackers get in

  • Shrink the detection window — faster detection is consistently the single biggest factor in final costs

Frequently asked questions

Here are the questions I hear most often about this.

Is the cost of a data breach different from the cost of a cyberattack?

Yes. A cyberattack is any attempt to compromise your systems, while a data breach specifically means someone accessed, stole, or exposed your data. A ransomware attack that only encrypts files without stealing anything is a cyberattack but not technically a breach — though in practice, most ransomware attacks today do both. 

Does cyber insurance cover the full cost of a data breach?

Not usually. Most policies cover a portion of direct costs like notification and legal fees, but deductibles, coverage exclusions, and higher premiums after a claim mean insurance offsets the cost of a breach rather than eliminating it.

What's the single biggest factor in how much a breach costs?

Detection and containment speed. Breaches identified and contained faster consistently cost less than those that go undetected for months, which is why an incident response plan matters as much as any individual security tool.

How can I find my biggest cybersecurity risks?

Marco’s cybersecurity team has designed an online tool that’s free to use. Answer a few questions, and in minutes, you’ll get custom recommendations of what to fix first. 

Expert advice on how to prepare your business for a data breach

My colleagues, Ben Bowman, Shelly Caldwell, and Patrick Voight, put on an excellent webinar this past fall that walked through what businesses should do to update their incident response capabilities. 


Click the link below to watch them go through vulnerability management, incident response planning, and the specific things most IT providers don't cover, like forensics, legal coordination, and threat containment.

 

Related Posts

Mastering Cybersecurity Compliance in Regulated Industries
Mastering Cybersecurity Compliance in Regulated Industries

First off, I just want to say that I’ve never met a business owner who was happy about having to comply with regulations. Meeting compliance can require time and money, often from ...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

Financial Services Cybersecurity: Best Practices That Actually Hold Up
Financial Services Cybersecurity: Best Practices That Actually Hold Up

The financial services organizations that handle cybersecurity well aren't necessarily spending more than their peers. They just have clearer visibility into their risk — and the t...

What Is a Keylogger and How Can You Protect Yourself?
What Is a Keylogger and How Can You Protect Yourself?

You probably don't think much about what happens between the moment your fingers hit the keys and the moment your password reaches a login server. That journey — keystrokes traveli...

What Long-Term Care Facilities Should Know About the Independent Living Systems Data Breach
What Long-Term Care Facilities Should Know About the Independent Living Systems Data Breach

Long-term care has quietly become one of the most targeted sectors in cybersecurity. In the first quarter of 2025 alone, more than a half-dozen nursing homes and rehabilitation cen...

What To Look for in a Small Business Cybersecurity Partner
What To Look for in a Small Business Cybersecurity Partner

There are two questions to ask a provider that often clear things up right away. First off, if they haven’t significantly updated their tools over the past five years, that’s a red...

Cybersecurity Compliance Requirements for Financial Services: A Simplified Checklist
Cybersecurity Compliance Requirements for Financial Services: A Simplified Checklist

If you're reading this, you're probably already drowning in compliance requirements. Maybe you're trying to figure out which regulations actually apply to your organization. Or you...

Understanding Cybersecurity Threats to the Manufacturing Industry
Understanding Cybersecurity Threats to the Manufacturing Industry

In 2024, 26% of cyberattacks targeted the manufacturing industry. I'm not trying to be alarmist. But I am trying to be real with you. Because while most manufacturers have been foc...

What Law Firms Should Know About Meeting Cybersecurity Compliance
What Law Firms Should Know About Meeting Cybersecurity Compliance

29% of law firms experienced a security breach in 2023, according to the ABA Cybersecurity TechReport. As someone who has spent years helping organizations navigate cybersecurity c...

What Our Online Microsoft Insights Assessment Can Reveal
What Our Online Microsoft Insights Assessment Can Reveal

Microsoft has invested billions into cybersecurity, but users are still responsible for protecting their own data and using its powerful tools correctly. Unfortunately, where you f...