How Much Does a Data Breach Really Cost You?

how much does a data breach cost

The good news: the question of “how much does a data breach cost?” came down in 2025 for the first time in five years. This according to IBM’s Cost of a Data Breach Report 2025. The global average dropped to $4.44 million, a 9% decline from the year prior, driven largely by faster detection powered by AI security tools.

The bad news: if you are in the United States, costs hit a record $10.22 million; the highest ever recorded for any country in the study’s history. Healthcare averaged $7.42 million; financial services $5.56 million. The global average is a useful headline. It is not your number.

Data Breach Cost by Industry and Geography (2025)

SegmentAverage Breach CostSource
Global average$4.44 millionIBM Cost of a Data Breach Report 2025
United States$10.22 millionIBM 2025 — highest ever recorded
Healthcare$7.42 millionIBM 2025 — most expensive industry, 15th year running
Financial services$5.56 millionIBM 2025
Technology$4.97 millionIBM 2025
Energy$4.72 millionIBM 2025
Retail$2.83 millionIBM 2025
Per compromised record$169IBM 2025 global average

Average Data Breach Cost by Attack Type (2025)

Attack vectorAverage breach costNotes
Phishing$4.88 millionMost common initial attack vector
Stolen or compromised credentials$4.81 millionLongest breach lifecycles
Business email compromise$5.01 millionHigh per-incident cost despite lower volume
Social engineering$4.77 million
Ransomware$5.13 millionExcludes ransom payment in IBM methodology
Malicious insider$4.99 millionHardest to detect; longest dwell time
Shadow AI / unauthorized tools+$670,000 added to base costIBM 2025 — new explicit cost factor

And none of those averages account for how much a data breach costs when litigation follows; when regulators investigate; when your cyber insurance carrier decides your controls were inadequate. When revenue forecasts are missed. When reputation damage turns from “soft cost” to bottom line impact that can persist for years. The final number is not a statistic. It is a line item on a legal settlement.

What the Average Data Breach Actually Includes

The IBM figure is a composite. It includes detection and escalation costs, notification costs, post-breach response, and lost business. Most organizations focus on the first three and underestimate the rest.

Lost business is where the compounding starts. Customers who leave. Contracts that do not renew. Partners who quietly distance themselves while the investigation is still open. These costs do not show up on an incident response invoice; they start to show up in the next four quarters of revenue. The 2025 IBM report found that 76% of organizations took more than 100 days to fully recover from a breach. That is not an IT timeline. That is a business disruption timeline.

Shadow AI is now an explicit cost factor. IBM found that breaches involving unauthorized AI tools used by employees added an average $670,000 to breach costs; and those incidents had longer lifecycles and higher rates of customer PII exposure. If your organization has employees using unapproved AI tools (and most do) that risk is already inside your perimeter.

Then there is the regulatory layer. GDPR penalties alone reached €1.2 billion in 2024. HIPAA fines scale by violation tier and can reach up to $2.1 million per category annually. State attorneys general are increasingly active. The regulatory cost of a breach is not theoretical; it is the next invoice that arrives after the first one is paid.

And then the lawyers arrive.

The Hidden Data Breach Costs Most Leaders Are Not Modeling

Class action litigation following a data breach is no longer a low-probability outcome. Conduent’s breach of 10.5 million records generated nine federal class action lawsuits and state regulatory investigations across multiple jurisdictions; all stemming from a single architectural gap: data that had to decrypt during processing. The full analysis is in The Conduent Breach: How Did ‘Industry Standard’ Security Fail 10.5M People?

The emerging legal standard is no longer whether you had encryption. It is whether you had encryption that covered data during active use. Courts are beginning to distinguish between organizations that encrypted data at rest and in transit (the current industry standard) and those that maintained encryption while data was being processed. That distinction is becoming a liability question.

Your legal counsel should be asking this question now; not after a breach notice goes out.

What a Data Breach Costs Small and Mid-Size Businesses

The IBM figure is a composite of organizations spanning a wide range of sizes. For small and mid-size businesses, the cost structure looks different, and in some ways more dangerous.

Small businesses typically spend between $120,000 and $1.24 million to respond to and resolve a security incident, according to 2025 estimates. That range reflects the variability in breach scope, industry, and whether litigation follows. At the lower end, a contained incident with no regulatory action and limited notification obligations. At the upper end, one that triggers class action filing, regulatory correspondence, and multi-quarter revenue disruption.

What makes the SMB number disproportionately damaging is not the absolute figure,  it is the ratio. A $500,000 breach response does not represent an existential event for a Fortune 500 company. For a 50-person firm, it often does. SBA data consistently shows that a significant percentage of small businesses that experience a serious breach do not recover to pre-incident revenue levels within two years.

Three cost factors hit smaller organizations harder than larger ones:

  • Cyber insurance gaps. Smaller organizations often carry coverage limits that were set years ago and have not kept pace with current breach response costs. The forensic investigation alone can exceed coverage limits before notification costs begin.
  • No dedicated incident response function. Larger organizations have internal IR teams. Smaller organizations pay external retainer rates at the moment they can least afford it, often at emergency pricing.
  • Customer concentration risk. A mid-size business with a handful of large clients faces a qualitatively different attrition risk than a large enterprise with a diversified customer base. Losing one major client in the aftermath of a breach can be the breach’s largest single cost.

The architecture question is the same regardless of organization size. The data that gets stolen does not care whether it came from a Fortune 100 or a 100-person firm. The liability that follows does not scale proportionally downward.

What Happens After a Data Breach: The Full Financial Timeline

The average breach takes 241 days to identify and contain according to the 2025 IBM report; a nine-year low, and a genuine improvement. But 241 days is still eight months during which your organization is simultaneously managing an active incident, notifying affected parties, responding to regulators, and fielding plaintiff counsel.

The first 72 hours are notification obligations. Most jurisdictions require breach notification within three days of confirmed discovery; GDPR requires 72 hours from awareness, regardless of whether the investigation is complete. Notifying before you fully understand the scope creates its own legal risk. Notifying late creates a different one.

The next 30 days are forensic investigation, customer support infrastructure (credit monitoring services, call centers, identity protection enrollment), and the beginning of regulatory correspondence. These costs alone routinely exceed $1 million before any litigation is filed.

The months that follow are where the compounding happens. Insurance claims. Discovery requests. Board-level scrutiny. Executive testimony. The breach that felt contained at day 30 is still generating costs at month 18.

How to Reduce Data Breach Costs: What Cyber Insurers Are Asking Now

Cyber insurance premiums have increased as carriers have repriced breach risk based on actual claims data. What underwriters are asking now is more specific than it was three years ago.

The standard questions around MFA, patch management, and endpoint protection are table stakes; necessary but no longer differentiating. The questions that are beginning to shift premium calculations are about data-in-use protection: whether sensitive data is encrypted not just at rest and in transit, but while applications are actively processing it.

Organizations that can demonstrate continuous encryption; meaning data that remains encrypted during active use, not just storage and transmission; are presenting a materially different risk profile. Stolen data that cannot be decrypted is not a breach in the meaningful sense. There is nothing to ransom, nothing to sell, nothing to expose.

The cost calculus is straightforward. As Red Hat’s $100M Cyber Breach Problem Is Likely Yours Too makes clear, the cost of a significant breach is not a risk to model in a spreadsheet; it is an existential event for most organizations. The investment in prevention is not an IT budget line. It is balance sheet protection.

Frequently Asked Questions

How much does a data breach cost on average?

The global average cost fell to $4.44 million in 2025; the first decline in five years, down 9% from $4.88 million in 2024, according to IBM and the Ponemon Institute. That improvement is real; it is driven by faster AI-powered detection. However, U.S. organizations averaged a record $10.22 million; the highest figure ever recorded for any country in the study’s history. Healthcare averaged $7.42 million; financial services $5.56 million.

What are the biggest cost drivers in a data breach?

Lost business is consistently the largest single category; customer attrition, contract losses, and reputational damage that plays out over multiple quarters. Post-breach response costs (notification, credit monitoring, call centers) are significant but finite. Litigation and regulatory fines are the most unpredictable; a single class action settlement can exceed all other breach costs combined.

What is data breach liability and how is it determined?

Data breach liability is the legal exposure an organization faces when a breach results in harm to individuals or other organizations. Courts evaluate whether the organization implemented reasonable security measures. That standard is evolving; “industry standard” encryption that only protects data at rest and in transit is increasingly insufficient as a defense when breaches occur during active data processing.

How to reduce cyber insurance premiums after a breach or at renewal?

Underwriters are increasingly asking about data-in-use protection; not just encryption at rest and in transit. Organizations that can demonstrate continuous encryption during active processing present a materially lower risk profile. Detection and response capabilities, incident response planning, and MFA remain baseline requirements. The differentiating factor at renewal is increasingly the data layer.

What happens after a data breach notification goes out?

Notification triggers a parallel set of obligations: regulatory correspondence, customer support infrastructure, forensic investigation, and often litigation. Most jurisdictions require notification within 72 hours of confirmed discovery. The costs that follow notification; credit monitoring, identity protection services, legal fees; routinely exceed $1 million in the first 30 days before any litigation is filed.

Does cyber insurance cover all data breach costs?

Cyber insurance covers defined categories of breach-related expenses; forensic investigation, notification, credit monitoring, legal defense, and sometimes ransom payments. It typically does not cover the full cost of lost business, reputational damage, or regulatory fines in all jurisdictions. Coverage gaps are common; organizations that have not reviewed their policy against current breach cost structures often discover the gaps at the worst possible time.

What is the average cost of a data breach for small businesses?

Small and mid-size businesses typically spend between $120,000 and $1.24 million to respond to and resolve a security incident, based on 2025 estimates. That range does not include litigation or multi-year reputational impact, which are the cost categories that most frequently determine whether a smaller organization recovers fully. The SMB figure is lower in absolute terms than the enterprise average, but proportionally far more damaging relative to revenue and reserves.

How does ransomware affect the total cost of a data breach?

Ransomware incidents average $5.13 million in total breach costs according to IBM 2025 data, above the global average and notably, that figure excludes the ransom payment itself in IBM’s methodology. The cost premium for ransomware comes from longer breach lifecycles, more extensive system recovery requirements, and higher rates of operational disruption. Organizations that pay the ransom do not reliably recover faster; IBM data has consistently shown that paying does not meaningfully reduce total breach cost.

How long does it take to recover from a data breach financially?

IBM’s 2025 report found that 76% of organizations took more than 100 days to fully recover from a breach. The 241-day average to identify and contain a breach means most of the financial exposure, litigation, regulatory correspondence, customer attrition, accumulates while the incident is still being investigated. Full financial recovery, meaning a return to pre-breach revenue trajectory and resolution of outstanding legal matters, typically takes 18 to 36 months for organizations that face litigation.

Does encrypting data reduce the cost of a data breach?

Yes, but the type of encryption matters. Organizations using AI and automation in security operations saved an average of $1.9 million per breach in IBM’s 2025 data. More structurally, continuous encryption, keeping data encrypted during active processing, not just at rest and in transit, changes the breach economics at the source. If an attacker exfiltrates data that remains encrypted and unusable, there is no ransom leverage, no notification obligation, and no class action plaintiff with cognizable damages. The cost of a breach of encrypted-in-use data is not lower. It is effectively zero.

What Actually Lowers the Cost of a Data Breach, and What Doesn’t

Most breach cost reduction strategies work after data is already compromised. Incident response, forensics, notification, litigation — these are damage-containment measures. They lower the bill. They don’t change the underlying exposure that generated it. The architectural question is different: what if stolen data couldn’t be used?

Continuous encryption changes the breach economics at the source. If data remains encrypted during active processing, an attacker who successfully breaches the perimeter; and breaches will happen; extracts nothing usable. No ransom demand has leverage. No notification is legally required. No class action plaintiff has damages to allege. As we covered in Perimeter Security Is Not Enough, the perimeter is not the last line of defense. The data layer is.

The architecture that changes those economics exists today. Donoma Seshat is a continuous encryption platform built to solve these challenges. It operates at the data layer, keeps data encrypted during active processing, and integrates at the application level without requiring changes to your existing infrastructure.

The technology is ready. The business case is clear. The time for action is now.

If you want to understand what the breach cost picture looks like for your specific organization and industry; and what architecture actually moves the risk profile; book a solution briefing with the Donoma team.

Additional Reading

The Conduent Breach: How Did “Industry Standard” Security Fail 10.5 Million People?

Data Breach Supply Chain Cost: The Red Hat $100M Lesson

Medtronic and the Healthcare Encryption In Use Gap

Encryption at Rest is Not Enough

Perimeter Security Is Not Enough: 5 Steps to Mitigate Risk in a Zero Trust Environment