A data breach does not cost millions because someone got in. It costs millions because of everything that happens after: forensics, crisis calls, downtime, lawyers, regulators, and customers who leave.

IBM’s Cost of a Data Breach Report 2026 — the 21st annual study, conducted by Ponemon Institute and sponsored, analyzed, and published by IBM — puts a number on that. Across 602 organizations with breaches between March 2025 and February 2026, the global average hit a record USD 4.99 million, up 12% from the prior year. IBM frames that as roughly USD 1,100 per hour. In the United States, the average was USD 11.5 million — more than twice the global figure.

If a board is budgeting “a few million for a ransom,” they are looking at the wrong line item.

$4.99 Million Globally, $11.5 Million in the United States

This is activity-based costing of incidents that already happened, not a poll of hypothetical risk.

The United States is not a rounding error on the global mean. IBM’s Key Findings page calls the US figure a record USD 11.5 million, more than twice the global average and up 13% over last year, citing higher regulatory fines and other business costs. Later in the same PDF, the country table narrative describes that same USD 11.5 million as an 11% increase, with the 2025 US average listed at USD 10.22 million. Both percentages are in the primary report. Use USD 11.5 million with the board. Do not flatten it into “about ten million,” and do not treat the 11% / 13% copy as if IBM settled on one number.

A US-based company should not underwrite cyber risk off the global headline. USD 4.99 million is the worldwide mean. USD 11.5 million is the US mean. They answer different questions.

The Majority of the Cost Is Detection, Escalation, and Lost Business

IBM splits the average into four process costs:

  • Detection and escalation — forensics, investigation, crisis management, board communications (USD 1.64 million)
  • Lost business — downtime, disrupted operations, reputational damage, customer churn and the cost of replacing those customers (USD 1.54 million)
  • Post-breach response — help desk, credit monitoring, legal spend, product discounts, regulatory fines (USD 1.36 million)
  • Notification — telling people, regulators, and third parties (USD 0.45 million)

Detection and escalation plus lost business make up 63% of the global average — about USD 3.18 million of the USD 4.99 million. Those two categories each rose 11.5% this year. Post-breach response, where fines and legal live, rose the most in percentage terms (15%) and is still not the majority.

That is the finding boards most often misread. Ransomware is in the mix — 39% of the breached organizations reported a ransomware incident — but IBM did not say ransom is the majority of the cost. The expensive part is finding the breach, escalating it through the organization, and living with the business that does not come back.

Time is the multiplier. Mean time to identify and contain a breach rose to 247 days (183 to identify, 64 to contain). Lifecycles longer than 200 days averaged USD 5.65 million. Lifecycles under 200 days averaged USD 4.32 million. Same report, same method — the difference is how long the organization spent inside the incident.

One in Four Malicious Breaches Are Now AI-Enabled

IBM’s July 29, 2026 newsroom summary leads with the line security teams are already quoting: one in four malicious breaches were AI-enabled, a 56% increase over last year, and those incidents cost about USD 6 million on average — roughly USD 1 million above the global mean. In the report’s breakdown, malicious AI-driven attacks averaged USD 6.04 million versus USD 5.03 million for malicious attacks that were not AI-driven.

“AI-enabled” here means attackers using AI as a tool. Deepfake or impersonation attacks drove the highest volume of those incidents (45%), followed by AI-enabled malware (19%) and AI-generated phishing or other communication (17%). Generative AI lowered the time, cost, and skill required to run social engineering that used to need a human operator. The consequence is not a new cost category. It is the same four categories, compressed: faster intrusion, messier identity, longer cleanup, more churn.

Voice or SMS phishing was the costliest initial vector in the study, at USD 5.29 million. The cheap thing to generate is the impersonation. The expensive thing to recover is trust.

Speed Still Moves the Number

Organizations that used security AI and automation extensively across prevention, detection, investigation, and response averaged USD 4.00 million per breach. Organizations that used none averaged USD 5.93 million. That is a USD 1.93 million gap, and a 65-day shorter identify-and-contain cycle (215 days versus 280).

Only 36% of the breached organizations used these tools extensively across the lifecycle. Half of those with a SOC have deployed agents there, mostly for threat hunting, response, and containment. Only 18% applied agents to vulnerability scanning and management — the work that shrinks the window before an exploit exists.

That is not an argument to buy a product. It is an argument to treat time-to-identify, time-to-contain, and customer retention after an incident as financial controls, not just SOC metrics.

The CISO Perspective

Put USD 4.99 million globally and USD 11.5 million in the United States in front of the board. Keep the sample at 602 organizations, March 2025 through February 2026. Attribute 63% of the global average — about USD 3.18 million — to detection, escalation, and lost business, including customer churn. Treat AI-enabled attacks as a 56% jump that now covers one in four malicious breaches and lands near USD 6 million, not as proof that ransom is the story.

Then ask the question the report is actually scoring: if we were in the 247-day cohort tomorrow, which of those four cost buckets would we still be paying six months later — and which ones have an owner today?

Sources: IBM Cost of a Data Breach Report 2026 and the IBM newsroom summary July 29, 2026.

We also broke the headline figures into a News Short, How Much Does a Data Breach Cost? $11.5M in the US, on The CISO Perspective YouTube channel. It is scheduled for Wednesday, August 26, 2026 at 12:00 p.m. ET. If the video is not live when you click through, subscribe on the channel so it appears when it publishes.

Make sure to follow us across all platforms for more explainers on cybersecurity and emerging tech.

Leave a comment

additional resources

Explore by category to find regularly updated content — including blog posts, scripts to YouTube and podcast videos, infographics, and other valuable resources