The following statistics are drawn from primary research reports: the IBM Cost of a Data Breach 2024 report (covering breaches from March 2023 to February 2024, 604 organizations), the IBM Cost of a Data Breach 2025 report (covering breaches from March 2024 to February 2025, approximately 600 organizations), the Verizon Data Breach Investigations Report 2024 (30,458 security incidents, 10,626 confirmed breaches), and the DLA Piper GDPR Fines and Data Breach surveys. Each statistic is labeled with its source.
Statistics from secondary sources or aggregators without a traceable primary citation are excluded. Where the 2024 and 2025 IBM reports differ on the same metric, both figures are included to show the trend.
Global Averages and Overall Cost
- The global average cost of a data breach was $4.88 million in 2024, a 10% increase from $4.45 million in 2023 and the largest annual increase since the pandemic. [IBM Cost of a Data Breach 2024]
- The global average cost fell to $4.44 million in 2025, a 9% decrease from 2024, driven largely by faster detection and containment through AI-assisted security operations. [IBM Cost of a Data Breach 2025]
- The 2024 report represented the 19th consecutive year of the IBM and Ponemon Institute Cost of a Data Breach study, covering breaches across 17 industries in 16 countries. [IBM Cost of a Data Breach 2024]
- 70% of breached organizations in 2024 reported that the breach caused significant or very significant disruption to their business operations. [IBM Cost of a Data Breach 2024]
- Only 12% of breached organizations were able to fully recover from a breach, and for those that did, recovery took more than 100 days. [IBM Cost of a Data Breach 2024]
- 63% of organizations said they would increase the cost of goods or services as a result of a breach, up from 57% the previous year, marking the third consecutive year that a majority planned to pass breach costs to customers. [IBM Cost of a Data Breach 2024]
United States and Regional Costs
- The United States had the highest average breach cost of any country studied for the 14th consecutive year, at $9.36 million in 2024, a slight decrease from $9.48 million in 2023. [IBM Cost of a Data Breach 2024]
- US breach costs hit a record $10.22 million in 2025, a 9% increase from 2024, driven by higher regulatory fines and rising detection and escalation costs. [IBM Cost of a Data Breach 2025]
- The Middle East had the second-highest average breach cost in 2024 at $8.75 million, followed by Germany at $5.31 million. [IBM Cost of a Data Breach 2024]
- European breach notifications averaged 363 per day in 2024, up from 335 per day in 2023, under the GDPR’s 72-hour breach notification obligation. [DLA Piper GDPR Fines and Data Breach Survey 2025]
Industry-by-Industry Breakdown
- Healthcare had the highest average breach cost of any industry in 2024 at $9.77 million, a position it has held every year since 2011. [IBM Cost of a Data Breach 2024]
- Healthcare breach costs fell to $7.42 million in 2025, a significant drop from 2024, though the sector retained the highest average cost of any industry. [IBM Cost of a Data Breach 2025]
- Healthcare had the longest average breach lifecycle in 2025 at 279 days to identify and contain. [IBM Cost of a Data Breach 2025]
- Financial services had the second-highest average breach cost in 2024 at $6.08 million, 22% above the global average. [IBM Cost of a Data Breach 2024]
- The industrial sector experienced the largest year-over-year cost increase in 2024, rising 18% to $5.56 million, placing it third among 17 industries studied. [IBM Cost of a Data Breach 2024]
- Breaches involving public cloud environments cost an average of $5.17 million in 2024, the highest of any storage environment, a 13.1% increase from the prior year. [IBM Cost of a Data Breach 2024]
- Approximately 40% of breaches in 2024 involved data stored across multiple environments (public cloud, private cloud, and on-premises). These cross-environment breaches averaged more than $5 million and took the longest to identify and contain at 283 days. [IBM Cost of a Data Breach 2024]
Attack Vectors and Root Causes
- Phishing was the most common initial attack vector for breaches in 2024, accounting for 15% of breaches, with an average cost of $4.88 million per phishing-originated breach. [Verizon DBIR 2024]
- Compromised or stolen credentials were involved in 38% of breaches as the initial access vector in 2024, and in 16% of breaches as the root cause according to the IBM report, with those breaches averaging $4.81 million. [Verizon DBIR 2024; IBM Cost of a Data Breach 2024]
- Exploitation of vulnerabilities accounted for 14% of breaches in 2024, nearly triple the percentage from the prior year’s report, largely due to MOVEit and other mass-exploitation events. [Verizon DBIR 2024]
- The average time to patch 50% of critical vulnerabilities was 55 days in 2024, creating a significant window during which systems remain exposed after a vulnerability is publicly disclosed. [Verizon DBIR 2024]
- Breaches caused by stolen credentials took the longest to identify and contain of any attack vector at 292 days on average. [IBM Cost of a Data Breach 2024]
- Malicious insider attacks produced the highest average breach cost per incident at $4.99 million in 2024. [IBM Cost of a Data Breach 2024]
- Human error (non-malicious) was involved in 68% of breaches in 2024, according to Verizon’s definition that excludes deliberate insider misuse. [Verizon DBIR 2024]
- 46% of breaches in 2024 involved customer personal identifiable information (PII) such as tax identification numbers, email addresses, phone numbers, and home addresses. [IBM Cost of a Data Breach 2024]
- Intellectual property records were compromised in 43% of breaches studied in 2024. [IBM Cost of a Data Breach 2024]
Ransomware
- 62% of financially motivated incidents in 2024 involved either ransomware or extortion, with a median loss of $46,000 per breach. [Verizon DBIR 2024]
- The average cost of a ransomware or extortion incident was $5.08 million in 2025. [IBM Cost of a Data Breach 2025]
- 63% of ransomware victims in 2025 did not pay the ransom, up from 59% the prior year, though fewer victims involved law enforcement despite evidence that doing so reduces costs. [IBM Cost of a Data Breach 2025]
- Ransomware victims that involved law enforcement lowered their breach costs by approximately $1 million on average (excluding the cost of any ransom payment made). [IBM Cost of a Data Breach 2024]
Detection and Containment Timelines
- The average time to identify and contain a breach dropped to 258 days in 2024 (194 days to identify, 64 days to contain), a 7-year low and an improvement from 277 days in 2023. [IBM Cost of a Data Breach 2024]
- Organizations with a high level of security AI and automation identified and contained breaches nearly 100 days faster than those without these technologies in 2024. [IBM Cost of a Data Breach 2024]
- Breaches involving a ‘mega breach’ of 1 million to 10 million records cost an average of approximately $42 million in 2024, nearly nine times the global average. [IBM Cost of a Data Breach 2024]
- When 50 million or more records were compromised, average breach costs in both healthcare and financial services reached $375 million. [IBM Cost of a Data Breach 2024]
AI and Automation: Cost Impact
- Organizations using AI and automation extensively in security operations averaged breach costs of $3.84 million in 2024, compared to $5.72 million for those not using these technologies, a savings of $1.88 million. [IBM Cost of a Data Breach 2024]
- The largest savings from AI came from prevention workflows: organizations applying AI specifically to security prevention saved an average of $2.2 million compared to those without AI in prevention. [IBM Cost of a Data Breach 2024]
- 31% of organizations made extensive use of AI and automation in security operations in 2024, a 10.7% increase from the prior year. [IBM Cost of a Data Breach 2024]
- Organizations using AI and automation in security saved an average of $1.9 million and reduced their breach lifecycle by 80 days in 2025. [IBM Cost of a Data Breach 2025]
- Only 24% of generative AI initiatives across organizations were being secured as of the 2024 report, creating potential exposure through shadow AI data and unsanctioned model use. [IBM Cost of a Data Breach 2024]
- 13% of organizations in 2025 reported breaches of AI models or applications specifically, with 97% of those organizations reporting that they lacked proper AI access controls. [IBM Cost of a Data Breach 2025]
Security Staffing and Skills Gaps
- More than half of breached organizations in 2024 faced high levels of security staffing shortages, a 26% increase from the prior year. [IBM Cost of a Data Breach 2024]
- Organizations with significant security staffing shortages experienced an average of $1.76 million more in breach costs than those with low or no staffing shortages. [IBM Cost of a Data Breach 2024]
- Only 49% of breached organizations planned to increase security spending following a breach in 2025, down from 63% in 2024. [IBM Cost of a Data Breach 2025]
Regulatory Costs and Third-Party Breaches
- Total GDPR fines issued across Europe reached approximately $1.2 billion in 2024. The cumulative total since GDPR took effect in May 2018 stood at approximately $6.17 billion as of early 2025. [DLA Piper GDPR Fines and Data Breach Survey 2025; Infosecurity Magazine]
- The largest GDPR fine of 2024 was a $326 million penalty issued by Ireland’s Data Protection Commission against LinkedIn for processing of personal data in advertising practices. [DLA Piper GDPR Fines and Data Breach Survey 2025]
- A 22.7% increase in the share of organizations paying regulatory fines of more than $50,000 was reported among breach victims in 2024. [IBM Cost of a Data Breach 2024]
- 15% of breaches in 2024 involved a third party or supplier, including software supply chains, hosting infrastructure, and data custodians. [Verizon DBIR 2024]
- The 2024 Verizon DBIR analyzed a record 30,458 security incidents and 10,626 confirmed data breaches, more than double the number of confirmed breaches from the prior year’s report. [Verizon DBIR 2024]
Software Supply Chain Incidents
- The Change Healthcare ransomware breach in 2024 disrupted claims processing, pharmacy operations, and patient care across the US healthcare system. The parent company UnitedHealth Group disclosed total costs including response, recovery, and lost revenue exceeding $870 million in a single quarter, later revised upward. The breach affected an estimated one-third of the US population’s health records. [UnitedHealth Group SEC filings and earnings disclosures, 2024]
- The 2020 SolarWinds supply chain attack, in which malicious code was embedded in a signed software update and distributed to approximately 18,000 customers including US federal agencies, remains the benchmark incident for software supply chain integrity failure and is directly cited by CISA, NIST, and OWASP’s A08:2021 category (Software and Data Integrity Failures) as the canonical example of why software signing and update verification require security controls beyond the signature alone. [CISA Advisory AA20-352A; OWASP Top 10:2021]
All IBM Cost of a Data Breach statistics above are from research conducted by the Ponemon Institute, sponsored and analyzed by IBM. The 2024 report is based on 604 organizations experiencing breaches between March 2023 and February 2024. The 2025 report covers approximately 600 organizations experiencing breaches between March 2024 and February 2025. IBM’s methodology excludes the smallest and largest outlier breaches from the average cost calculation. Readers requiring the primary source documents can access them at ibm.com/reports/data-breach and verizon.com/dbir.
What These Numbers Mean for Software Publishers
The statistics above describe breach costs for organizations that hold and process data. Software publishers face a related but distinct exposure: a software supply chain compromise can make a publisher the source of a breach rather than the victim. The SolarWinds incident (statistic 50) illustrates this: the publisher’s signing infrastructure was compromised, and the signed update became the delivery mechanism for a breach affecting 18,000 downstream organizations.
The direct connection between code signing practice and breach exposure: a signed update from a compromised build environment, where the signing certificate’s private key is accessible to the attacker, produces a legitimate-looking signature on malicious code. The CA/B Forum’s June 2023 hardware storage requirement for code signing private keys specifically addresses this attack path by requiring keys to be stored in hardware that cannot be silently copied.
Supply chain breaches attributed to a publisher’s infrastructure represent both a direct financial cost to the publisher (incident response, regulatory investigation, civil liability) and a reputational cost that is difficult to quantify from industry averages. The $870 million disclosed by UnitedHealth Group in a single quarter from one ransomware incident indicates the upper range of what infrastructure-level compromise can cost a large organization.
—————————————————-
Primary Sources Referenced
IBM Cost of a Data Breach Report 2024 (ibm.com/reports/data-breach)
IBM Cost of a Data Breach Report 2025 (ibm.com/reports/data-breach)
Verizon Data Breach Investigations Report 2024 (verizon.com/dbir)
DLA Piper GDPR Fines and Data Breach Survey 2024 and 2025 (dlapiper.com)
UnitedHealth Group 2024 SEC filings and earnings disclosures
CISA Advisory AA20-352A (SolarWinds), OWASP Top 10:2021

Gloria Bradford is a renowned expert in the field of encryption, widely recognized for her pioneering work in safeguarding digital information and communication. With a career spanning over two decades, she has played a pivotal role in shaping the landscape of cybersecurity and data protection.
Throughout her illustrious career, Gloria has occupied key roles in both private industry and government agencies. Her expertise has been instrumental in developing state-of-the-art encryption and code signing technologies that have fortified digital fortresses against the relentless tide of cyber threats.