Why data breaches are costing organisations more than ever
Data breaches remain one of the most significant risks facing organisations today. While cyber-attacks continue to evolve in sophistication, the financial impact of these incidents has also grown substantially, placing increasing pressure on security teams, executives and boards.
The past five iterations of IBM's Cost of a Data Breach Report reveal an upwards trajectory relating to the financial impact of cyber incidents and for organisations today the average breach cost is now in the multi-millions.
- 2026: $4.99m average cost of a data breach (+12% YoY from 2025), reaching a new record high.
- 2025: $4.44m average cost (-9% YoY from 2024), marking the first decline in five years.
- 2024: $4.88m average cost (+10% YoY from 2023), the largest annual increase since the COVID-19 pandemic.
- 2023: $4.45m average cost (+2.3% YoY from 2022).
- 2022: $4.35m average cost (+2.6% YoY from $4.24m in 2021).
IBM's annual Cost of a Data Breach Report is based on breaches experienced during the preceding 12 months, so for instance the 2026 report analysed incidents from March 2025 to February 2026.
It is important to be mindful that these are global average costs and do not consider geographic or industry variances, which can see these figures almost double.
How breach costs reached record levels
Why 2025 broke the trend
IBM’s 2025 analysis showed the first decline in the cost of a data breach in five years. The fall was in part attributed to improved detection and containment capabilities in organisations, boosted by AI and automation tools.
The cost of detection and escalation was found to have fallen by 10% compared to 2024.
While IBM applauded the role of AI in driving faster data breach containment, which dropped to a mean time of 241 days, a nine-year low, the firm warned that the speed of AI deployment had equally created new risks.
The 2026 rebound: why costs jumped again
AI-driven attacks are transforming the economics of cybercrime, enabling threat actors to launch attacks at greater speed and lower cost while forcing organisations to spend more to detect, contain and recover from breaches.
In the 2025 report, security teams were said to have been “turning the tide” in the AI arms race between attackers and defenders. However, 2026 saw security teams lose ground in some key areas.
AI-driven attacks increased 56% over the 2025 study and added an average for $1m per breach as AI has enabled attackers to increase the scale and volume of attacks.
On the other hand, AI was said to save an average of $1.93m in breach-related costs.
The 2026 report noted that AI and automation remain among the most effective ways to reduce breach impact.
“Organisations need to move faster from reactive security to a continuous autonomous defence if they want to keep up,” said Mark Hughes, global managing partner for cybersecurity services at IBM.
However, IBM noted that the 12% increase in cost compared to 2025 was largely driven by detection, escalation and lost business costs. Together they accounted for $3.18m of the $4.99m global average.
Register your interest for Europe’s leading cybersecurity event
Be the first to hear more about Infosecurity Europe 2027, 8-10 June at London Excel.
What the five-year trend tells security leaders
Over the past half decade, the cost of a data breach has steadily increased and remains persistently high. As AI aids threat actors in the speed and volume of attacks they conduct, it is up to defenders to counter this.
While prevention is vital, this tactic alone is not enough, and focus should also be placed on recovery.
Breaches that take longer to discover and remediate lead to higher costs. Therefore, security teams should focus on reducing both detection and response times through continuous monitoring, proactive threat hunting and well-practised incident response plans.
In its 2026 report, IBM recommended that monitoring how data enters, transforms within and exits systems can help security teams proactively identify sensitive data exposure risks, while also strengthening governance and compliance.
Regular security assessments, employee awareness training and clear response procedures enable organisations to react more quickly when incidents occur, minimising operational disruption and reducing recovery expenses.
ADVERTISEMENT
Enjoyed this article? Make sure to share it!
Latest articles
Keep up to date with the latest infosecurity news and trends in our latest articles.
Stay in the know
Receive updates about key events, news and recent insights from Infosecurity Europe.
Looking for something else?
