A data breach doesn't stop costing you the day it's contained. It can cost you an enormous amount of time while you recover. It can also cost you clients.
If you’re hoping to make a case for better cybersecurity, numbers are incredibly helpful. And when it comes to a data breach, they can make that case for you very easily.
How much does a data breach cost?

Here are a few recent stats from IBM:
- The global average cost of a breach is now $4.99M
- In the U.S., average data breach costs are $11.5M
- Average costs for finance hover at $6.29M
- Technology and industrial organizations face $5.50M
- Healthcare is spending $6.64M on average
Government and education organizations typically report lower average costs than healthcare or finance, largely because they hold less data that's directly monetizable on the black market.
That doesn't mean fewer attacks — it means the successful ones are less likely to produce an eight-figure headline.
How do data breaches happen?

Most data breaches happen in a similar way. For example, a phishing email leads to stolen credentials, which leads to business email compromise, which leads to ransomware.
Here's how each one actually plays out.
Vulnerability exploitation
Attackers scan the internet for known, unpatched flaws in software like VPNs and firewalls, then exploit them directly — no phishing email or stolen password required.
It's now the single most common way in. Only 26% of critical, known vulnerabilities were fully patched in 2025, down from 38% the year before. A patch existing and a patch actually getting applied are two different things, and that gap is where a lot of breaches start.
Web application and API attacks
Anything you expose to the public internet — a login page, a web form, an API endpoint — is reachable by attackers by design. They test those entry points for weak input handling or missing authentication, then use one to reach the database sitting behind it.
Phishing and stolen credentials
An email convinces someone to hand over a password, or a credential gets bought off the dark web from an unrelated breach at a completely different company.
Once an attacker has a real, valid login, your systems don't see an intruder — they see an employee, which is exactly why these breaches take so long to catch.
Third-party and vendor compromise
Attackers increasingly go after whichever vendor has the weakest defenses instead of coming at you directly. And, unfortunately, a compromised software provider or contractor often will have access to dozens or hundreds of client environments at once.
One breach can easily become many, which is why third-party breaches now account for 48% of all breaches. If a contractor's login can reach your systems, an attacker who compromises that contractor now has that same access into yours.
Vendor due diligence — vetting a vendor's security before they get access, not after — is what keeps someone else's weak link from becoming your breach.
Insider actions and human error
Not every breach starts with an outside attacker at all. Someone emails a spreadsheet to the wrong address, a cloud storage folder gets left open to the public, or an employee reuses a personal password that later leaks somewhere unrelated.
These stories don't always make headlines the way a ransomware gang does, but they show up consistently across every major industry dataset — and they're often the easiest ones to address with basic access controls and training.
Where do data breach costs come from?
Total costs are a slow accumulation across detection, response, and everything that happens later. It typically takes businesses 247 days to identify and contain a breach, and every one of those days adds cost.
Direct costs
These show up fast and are the easiest to itemize:
- Forensic investigation and containment
- Legal counsel and regulatory notification
- Credit monitoring for affected individuals
- System recovery and hardware replacement
-
Cyber insurance deductibles
Costs that don't show up on an invoice
These take longer to surface, and they're usually the larger half of the bill:
- Lost business from downtime and customer churn
- A cyber insurance renewal at a higher rate
- Employee time diverted from actual work for months
-
Reputational damage that shows up in next year's sales numbers, not this year's
This is exactly why a documented incident response plan — not just antivirus software — is so important.
Is AI making data breaches more expensive?
Yes, AI is making data breaches more expensive. But there’s good and bad news there.
First, the bad news.
AI-driven attacks increased 56% year over year. Shadow AI incidents (where employees use AI tools that were never approved or governed) more than doubled to 43% of security incidents this year. And breaches involving shadow AI averaged $5.39 million, and one in five resulted in a regulatory fine.
On the flip side, organizations that used security AI and automation extensively cut their average breach cost by $1.93 million and shortened their breach lifecycle by 65 days.
How do you keep your number closer to the low end?
Eliminating risk entirely isn’t realistic. But you can reduce it and mitigate any costs.
Here’s how:
-
Know where you actually stand — most clients I talk to significantly underestimate how many unpatched systems or unmonitored vendor connections they're carrying
-
Write the plan before you need it — a response plan that exists only in someone's head falls apart the moment that person is unreachable
-
Treat vendor access like your own — if a contractor's login can reach your systems, audit it the same way you'd audit an employee's.
-
Patch on a real schedule — a consistent patching cadence removes the most common way attackers get in
-
Shrink the detection window — faster detection is consistently the single biggest factor in final costs
Frequently asked questions
Here are the questions I hear most often about this.
Is the cost of a data breach different from the cost of a cyberattack?
Yes. A cyberattack is any attempt to compromise your systems, while a data breach specifically means someone accessed, stole, or exposed your data. A ransomware attack that only encrypts files without stealing anything is a cyberattack but not technically a breach — though in practice, most ransomware attacks today do both.
Does cyber insurance cover the full cost of a data breach?
Not usually. Most policies cover a portion of direct costs like notification and legal fees, but deductibles, coverage exclusions, and higher premiums after a claim mean insurance offsets the cost of a breach rather than eliminating it.
What's the single biggest factor in how much a breach costs?
Detection and containment speed. Breaches identified and contained faster consistently cost less than those that go undetected for months, which is why an incident response plan matters as much as any individual security tool.
How can I find my biggest cybersecurity risks?
Marco’s cybersecurity team has designed an online tool that’s free to use. Answer a few questions, and in minutes, you’ll get custom recommendations of what to fix first.
Expert advice on how to prepare your business for a data breach
My colleagues, Ben Bowman, Shelly Caldwell, and Patrick Voight, put on an excellent webinar this past fall that walked through what businesses should do to update their incident response capabilities.
Click the link below to watch them go through vulnerability management, incident response planning, and the specific things most IT providers don't cover, like forensics, legal coordination, and threat containment.