IBM's Cost of a Data Breach Report, produced by the Ponemon Institute, is the closest thing the industry has to a canonical annual price tag on a security incident. The 2024 edition — its nineteenth — surveys roughly 604 organisations across 17 countries and 16 industries that experienced a breach between March 2023 and February 2024 ( IBM Cost of a Data Breach 2024, retrieved 2026-09-03).
The headline number: $4.88M global average total cost of a data breach. Up 10%year-over-year from 2023's $4.45M — the largest single-year jump since the pandemic. Every downstream cost calculation in this piece works off that number and the segment cuts IBM publishes underneath it.
The headline — $4.88M, up 10% YoY
- $4.88M — global average total cost per breach
- +10% — year-over-year change (largest since 2021)
- $258 — average cost per compromised record
- 258 days — mean time to identify plus contain a breach (MTTI 194 + MTTC 64)
- 40% — share of breaches involving data across multiple environments (cloud + on-prem + third-party)
- 35% — share of breaches involving shadow data (data outside sanctioned repositories)
- $2.22M — average savings for organisations using AI and automation extensively in security operations
The report's total-cost figure aggregates four categories: detection and escalation costs, notification costs, post-breach response costs (legal, credit monitoring, discounts to retained customers), and lost business (churn, opportunity cost, revenue impact). Lost business is the largest single component, typically 30–40% of the total, and it is also the hardest to bring down through controls — which is why prevention is so much cheaper than response.
By sector: healthcare, finance, tech
Sector averages from the 2024 report ( ibm.com/reports/data-breach, retrieved 2026-09-03):
- Healthcare — $9.77M. Top of the table for the fourteenth consecutive year. Regulatory notification obligations under HIPAA plus the long tail of downstream litigation drive it. Down modestly from 2023's $10.93M but still nearly 2× the cross-industry average.
- Financial services — $6.08M. Regulatory disclosure requirements (SEC in the US, FCA in the UK, RBI in India) plus material customer-notification costs.
- Industrial — $5.56M. Includes manufacturing. Downtime is the dominant component here — a shop floor idled by ransomware costs more per hour than an office.
- Technology — $5.55M. Third-party liability and reputational damage on top of the base incident cost.
- Energy — $5.29M. Regulatory scrutiny under NERC CIP (US) and equivalent regimes.
- Pharmaceuticals — $4.82M. IP theft is a heavier component than in most other sectors.
- Retail — $3.48M. Lower per-record cost partially offset by higher record counts per breach.
- Public sector — $2.55M. Lowest in the table, largely because the litigation and churn components don't apply the same way.
The sector spread — $2.55M to $9.77M — is the single most useful data point in the report for anyone building a security budget. It tells you how much of your industry's cost comes from regulatory exposure versus operational disruption versus lost customers, and where a control marginally improves the total.
By country: US at $9.36M
Country averages ( ibm.com/reports/data-breach):
- United States — $9.36M. Highest in the report. State-level breach-notification laws (all 50 states plus DC now have one), plus class-action-litigation risk, plus the largest per-capita software liability, drive it.
- Middle East (aggregate) — $8.75M.
- Benelux — $5.90M.
- Germany — $5.31M.
- Canada — $5.13M.
- United Kingdom — $4.79M.
- ASEAN aggregate — $3.23M. India specifically is not broken out as a discrete country in the 2024 report but rolls up here.
- Brazil — $1.36M. Lowest in the sample.
A US-headquartered organisation with revenue in Europe faces the higher of the two cost pressures. Cross-border regulatory obligations do not neatly stack; they layer.
By attack vector: phishing, credentials, insider
By initial-vector cut ( ibm.com/reports/data-breach):
- Phishing — $4.76M average. Most common vector in the sample. See what is a phishing link.
- Compromised credentials — $4.81M. Second most common; overlaps heavily with phishing on the causal side (stolen credentials often originate in a phishing attack).
- Malicious insider — $4.99M. Fewer incidents, higher average cost per incident because insiders have privileged access.
- Business email compromise — $4.88M. The subset of phishing targeting payment workflows; see the FBI IC3 2024 BEC breakdown.
- Zero-day vulnerability exploit — $4.87M. Rare, high per-incident, publicity spike.
- Cloud misconfiguration — $4.20M. Most preventable via automated posture checks.
- Physical security compromise — $4.02M. Lowest of the meaningful vectors.
Phishing and credential compromise together account for the majority of incidents in the sample. That is the practical case for DMARC enforcement (what is DMARC, DMARC enforcement gap) plus MFA-everywhere plus attack-surface monitoring being the highest-leverage set of controls a mid-sized organisation can adopt.
The detection clock — 258 days
The report's operational number that matters most: mean time to identify (MTTI) plus mean time to contain (MTTC).
- 194 days — MTTI, the average time from the breach occurring to the organisation knowing.
- 64 days — MTTC, the average time from detection to containment.
- 258 days total — nearly nine months. In many cases the attacker has full network access and can exfiltrate data unimpeded for the entire MTTI window.
Every day of that 258 costs money. IBM's regression analysis puts the difference between a breach detected in under 200 days and one detected after 200 days at roughly $1.02Min average total cost. Cutting the clock is more effective on the total than any single downstream response optimisation.
What shortens the clock (and what it's worth)
IBM's own segmentation shows what moves MTTI most effectively:
- Extensive AI and security automation. Organisations using it save an average of $2.22M per breach and cut MTTI plus MTTC by roughly 108 days. Interpret this cautiously — the sample is self-selecting; organisations that invest in the tooling also invest in the process.
- Incident response teams with tested playbooks. Cut MTTC materially even when MTTI is not helped.
- Threat intelligence integration. Feeds correlated with internal telemetry catch known-bad indicators faster than pure anomaly detection.
- Continuous attack-surface monitoring. New subdomains, new certificates, new DNS records — the leading indicators of both external attack preparation (typosquats, dangling CNAMEs) and internal shadow-IT expansion. See the apex-only monitoring cost analysis for the leverage this specifically provides.
- Employee training focused on phishing and BEC. The Verizon 2025 DBIR ( verizon.com/business/resources/reports/dbir, retrieved 2026-09-03) confirms these two vectors dominate the initial-access distribution across industries.
How to read the report — and the caveats
Three caveats to keep in mind when using the numbers to size controls:
- The average masks the tail. IBM's headline $4.88M is a mean across a sample that excludes breaches above 100,000 records. Sizeable public incidents (Equifax, Marriott, T-Mobile, MOVEit) cost hundreds of millions to billions of dollars. Neither end of the distribution is the median-case number.
- Ponemon interviews the organisations that agree. Sample selection is not random. Organisations that experienced catastrophic incidents are typically less willing to participate; the sample skews toward containable, documented breaches.
- Cost of prevention isn't in the report. IBM measures breach cost, not defence cost. To make a real ROI case you need both — but the breach-cost side is where the industry-standard number lives, and where the CFO on the receiving side of a budget ask will index.
The right way to use the report: pull the sector and country cuts closest to your organisation, add the phishing/credentials/insider vector cut, and use the 258-day detection clock as the operational number to move. Every day off the clock is roughly $4,000 in average total cost.
FAQ
Is $4.88M the biggest number in the 2024 IBM report?
No — it is the global cross-industry average. Healthcare's sector average sits at $9.77M and the US country average sits at $9.36M. A US-headquartered healthcare organisation will be measuring against numbers well above the global mean.
How does the 258-day detection window compare to previous years?
Modest improvement year-over-year, but the overall trend across the last five reports is that MTTI has been broadly flat. Organisations are getting better at detection in pockets (endpoint EDR is much more effective than five years ago) while getting worse in others (cloud and third-party surfaces expanded faster than monitoring did). Net: no material acceleration.
Does the report cover ransomware separately?
Yes. Ransomware breaches average higher total cost than non-ransomware breaches, and the report breaks out the impact of paying versus not paying the ransom. In the 2024 cut, paying the ransom did not materially reduce total breach cost — a consistent finding across the last four reports.
What is the difference between MTTI and MTTC?
MTTI (mean time to identify) is the elapsed time from breach occurrence to organisational awareness. MTTC (mean time to contain) is the elapsed time from detection to full containment (attacker no longer has access, exfiltration stopped, remediation begun). MTTI is where continuous external monitoring and attack-surface tooling helps most; MTTC is where incident-response process and tabletop exercises help most.
How much of the $4.88M is regulatory versus operational?
Ponemon's four-category breakdown puts lost business (churn plus opportunity cost) at roughly 30–40% of total cost, post-breach response (legal, notification, credit monitoring) at 25–30%, detection and escalation at 15–20%, and notification at 5–10%. Regulatory fines are captured within post-breach response and vary massively by jurisdiction — GDPR fines alone can add hundreds of millions in outlier cases that the sample deliberately excludes.
What is the fastest way to defend against the top vector?
Phishing is the top vector by both frequency and cost. The cheapest control that materially reduces phishing-initiated incidents is DMARC at p=reject plus lookalike-domain monitoring. See the DMARC enforcement gap piece for the 30-day path.