A data breach now costs a company $4.99 million on average (IBM, 2026).
That is a record. It is up 12% in a single year.
The figure comes from research by the Ponemon Institute for IBM. It covers 602 organisations across 16 countries and 17 industries.
So this is not a guess. It is one of the largest studies of its kind.
But the headline number is the least interesting part.
What matters is why it rose. And this year, the answer is new. 🔐
🧾 Key Findings at a Glance
| Measure | Figure | Source |
|---|---|---|
| Average breach cost | $4.99 million | IBM (2026) |
| Change on last year | +12% | IBM (2026) |
| Rise in AI-driven attacks | +56% | IBM (2026) |
| Extra cost when AI is involved | About $1 million | IBM (2026) |
| AI-breached firms with no AI access controls | 92% | IBM (2026) |
| Supply chain breach lifecycle | 258 days | IBM (2026) |
| Ransomware involving public shaming | 41% | IBM (2026) |
| Firms planning for quantum risk | Only 26% | IBM (2026) |
💸 What “Average Cost” Actually Counts
People assume breach cost means the ransom. It rarely does.
The figure bundles four very different things.
Detection and escalation. Finding out, investigating, calling in experts.
Notification. Telling customers and regulators.
Response. Legal fees, help desks, credit monitoring.
Lost business. Customers who leave and never come back.
IBM notes the 2026 rise was driven by higher detection, escalation and lost business costs (IBM, 2026).
📊 Average breach cost, and what pushed it up
Why “lost business” is the scary line
Legal fees end. Customers who leave may not come back.
That cost keeps running long after the incident is closed.
A breach is a trust event first and a technical event second.
Why averages mislead here
Breach costs are wildly uneven.
A small firm may lose tens of thousands. A hospital chain may lose hundreds of millions.
An average sits between two very different worlds.
Use it to understand direction, not to budget.
🤖 The AI Finding That Changes the Picture
This is the genuinely new part of the 2026 research.
AI-driven attacks rose 56% in a year (IBM, 2026).
And when AI was involved, breaches cost about $1 million more than average.
That is a fifth added to the bill, from one factor.
The 92% number is the one to remember
Here is the finding that should make people uncomfortable.
92% of organisations that suffered an AI-related breach had no AI access controls in place (IBM, 2026).
Not weak controls. None.
Nine in ten firms hit through AI had never restricted who could use it, or how.
🥧 AI-related breaches: were AI access controls in place?
What “AI access controls” means in practice
It is less technical than it sounds.
It means knowing which AI tools staff use.
It means deciding what data may be pasted into them.
And it means being able to switch access off.
Most firms cannot answer the first question, let alone the third.
Shadow AI is the underlying problem
Staff adopt AI tools faster than policy can follow.
Someone pastes a customer list into a free chatbot to summarise it.
No malice. No hacking. Data has simply left the building.
If you are choosing tools for a team, our AI tools guide covers what to look for.
🔗 Supply Chain: The Slowest and Costliest Route In
Attackers increasingly do not attack you. They attack your supplier.
IBM found supply chain compromise was the second most common way in (IBM, 2026).
It also tied for the longest breach lifecycle, at 258 days to identify and contain.
And it added the largest cost increase, averaging $227,250 above the global average.
| Why supply chain breaches cost more |
|---|
| You do not control the compromised system |
| Detection depends on someone else telling you |
| Many customers are affected at once |
| Legal responsibility is often unclear |
| Fixing it means changing supplier, slowly |
258 days is the number that matters
That is over eight months.
An attacker inside a system for eight months is not stealing one file.
Time inside the network is what turns an incident into a catastrophe.
Every extra week raises the cost.
What smaller firms can actually do
You cannot audit a large vendor. Be realistic.
But you can ask three questions before signing.
Has this supplier had a breach? What data will they hold? How would they tell me?
Most suppliers will answer. Few customers ask.
📅 What a Breach Actually Looks Like, Week by Week
Cost figures feel abstract. A timeline makes them concrete.
Using the 258-day supply chain lifecycle as the worst case, here is the shape.
| Stage | What is happening | Cost driver |
|---|---|---|
| Day 0 | Attacker gets in, quietly | None visible yet |
| Days 1–180 | Nobody knows | Data leaves the building |
| Detection | Alert, or a call from outside | Investigation begins |
| First 72 hours | Scramble, experts, legal | Detection and escalation |
| Weeks 1–4 | Notify customers and regulators | Notification costs |
| Months 2–8 | Containment and rebuild | Response costs |
| Year 1–2 | Customers quietly leave | Lost business |
Look at the second row again.
The longest stage is the one where nothing appears to be wrong.
📊 Days to identify and contain, by route in
Why the quiet stage costs the most
Every day inside means more data taken.
It also means more systems reached, and more customers affected.
Cost grows with dwell time, not with attacker skill.
A clumsy attacker with eight months does more damage than a brilliant one with a day.
The regulator clock starts at detection
This catches firms out badly.
Many rules require notification within a short window of discovery.
That window is often 72 hours.
Firms that have never rehearsed this lose days deciding who is in charge.
🏭 Why Some Industries Pay So Much More
The $4.99 million average hides enormous variation by sector.
The pattern is consistent across years of this research.
| What raises the cost | Why |
|---|---|
| Regulated data | Fines and mandatory notification |
| Health or financial records | Cannot be reissued like a card number |
| High customer trust dependence | Lost business runs deeper |
| Long data retention | More records exposed per breach |
| Complex legacy systems | Slower to investigate and contain |
Notice that only one of those is technical.
Most of what drives breach cost is the nature of the data, not the quality of the firewall.
The retention lesson
Here is a cheap and unpopular control.
Delete data you no longer need.
Records you do not hold cannot be stolen.
Most organisations keep far more, for far longer, than any rule requires.
Why this matters for online shops
Retailers hold order histories, addresses and payment tokens.
That is attractive data, and it accumulates silently.
Our look at ecommerce growth shows how fast transaction volumes are rising.
More sales means more records, which means more to lose.
😨 Ransomware Changed Its Business Model
The old model was simple. Encrypt files, sell the key back.
Backups made that less effective. So attackers adapted.
41% of ransomware attacks now involve reputational threats and public shaming (IBM, 2026).
They steal the data first, then threaten to publish it.
Why backups no longer save you
A good backup restores your systems. It does not un-steal your data.
If the threat is publication, restoring changes nothing.
Backups protect availability. They do not protect confidentiality.
That distinction is now central to planning.
The uncomfortable implication
Once data is taken, you cannot make it untaken.
Paying a ransom buys a promise from a criminal.
Law enforcement generally advises against paying, and for good reason.
Prevention matters more than it used to, because recovery does less than it used to.
🔮 The Quantum Number Nobody Is Acting On
This finding is quieter and stranger.
Only 26% of organisations have started planning for post-quantum cryptography (IBM, 2026).
Quantum computers cannot break today’s encryption yet.
But there is a strategy called “harvest now, decrypt later”.
How harvest-now-decrypt-later works
An attacker steals encrypted data today.
They cannot read it. They store it anyway.
When quantum computing matures, they decrypt it.
Data stolen today can become readable in ten years.
For medical records or state secrets, that is a real problem.
Why three quarters of firms ignore it
It is a distant, abstract risk with a cost today.
Most organisations struggle to fund next quarter’s security.
That is understandable. It is also how long-horizon risks get missed.
The firms that act early tend to be those holding data with a long secret life.
📊 How to Read This Research Properly
The IBM report is strong, but it has limits worth naming.
| Strength | Limit |
|---|---|
| 602 real organisations studied | Only firms willing to participate |
| 16 countries, 17 industries | Skews to larger firms |
| Independent research by Ponemon | Published by a security vendor |
| Same method each year | Costs are estimated, not audited |
| Detailed cost breakdown | Averages hide huge variation |
That third row deserves honesty.
IBM sells security products, and this report supports that business.
The research is conducted independently by Ponemon, which helps.
But you should read any vendor research with that context in mind.
Why it is still worth trusting
The method is published. The sample is named. The approach repeats yearly.
Those three things let others check the work.
Compare that with the many security statistics circulating with no source at all.
A number with a stated method beats a number with a confident tone.
💡 What Small and Mid-Sized Firms Should Take From This
Most readers do not run a bank. So what applies?
The $4.99 million figure does not. Your exposure is far smaller.
But three findings scale down perfectly.
| Finding | What to do this month |
|---|---|
| 92% had no AI access controls | Write down which AI tools staff use |
| Supply chain took 258 days to find | List suppliers holding your data |
| 41% of ransomware threatens publication | Assume stolen data becomes public |
| Detection costs rose most | Turn on logging you already pay for |
| Lost business is the lasting cost | Draft what you would tell customers |
None of those needs a budget.
Four of the five are lists you write in an afternoon.
Start with the AI list
It is the newest risk and the easiest to map.
Ask your team which AI tools they use for work.
Do not make it a disciplinary question. You want honest answers.
Most managers are surprised by the length of the list.
Then decide what may go into them
One short rule is enough to start.
Name what must never be pasted in. Customer data is the usual line.
A one-page rule that people read beats a policy nobody opens.
⏱️ Why Speed of Detection Drives Everything
Across breach research, one pattern repeats.
Faster detection means lower cost. Every time.
The supply chain figure of 258 days shows the opposite extreme.
What makes detection slow
Usually not sophistication. Usually absence.
Nobody was watching. Logs were off. Alerts went to an unused inbox.
Most slow detection is an attention problem, not a technology problem.
The cheapest improvement available
Turn on the logging your existing tools already include.
Send alerts somewhere a human actually looks.
Check that someone knows what to do when one fires.
None of this is expensive. Most of it is already paid for.
🧯 The Cheapest Controls With the Biggest Effect
Security advice often assumes a large budget. Most of it does not need one.
These five cost little and address what the research actually found.
| Control | Cost | Which finding it answers |
|---|---|---|
| Multi-factor sign-in everywhere | Usually free | Stolen passwords |
| Written list of AI tools in use | An afternoon | The 92% finding |
| Delete data past its useful life | Staff time | Fewer records to lose |
| Turn on and read logs | Already paid for | 258-day detection gap |
| One-page incident plan | A morning | 72-hour notification clock |
Not one of those requires new software.
The gap in most organisations is attention, not budget.
Why multi-factor still tops the list
Stolen credentials remain among the most common ways in.
Multi-factor sign-in stops a stolen password being enough on its own.
It is built into almost every business tool already.
Many firms have it available and switched off.
The incident plan nobody writes
One page. Three questions.
Who decides? Who calls the lawyer? Who tells customers?
Deciding this during a breach costs days you do not have.
Deciding it in advance costs a morning.
💰 How to Estimate Your Own Exposure
The global average is not your number. But you can build a rough one.
Breach cost research often works from a per-record basis.
You can do something similar in about ten minutes.
A rough four-step estimate
Count how many customer records you hold. Be honest about old ones.
Ask what regulation applies to that data in your country.
Estimate what share of customers might leave after a public breach.
Multiply that share by your yearly revenue.
That last figure is usually far larger than any technical cost.
Why the exercise is worth doing
It converts a vague fear into a number you can act on.
A number makes it possible to argue for a budget.
It also tends to reveal how much old data you are storing for no reason.
Several firms find deleting data is the single cheapest risk reduction available.
🚫 What These Numbers Do Not Tell You
Being clear about limits matters, especially with security data.
They do not tell you your risk. Averages describe a population.
They do not prove AI causes breaches. AI-related breaches cost more; that is correlation.
They do not cover firms that never noticed. Undetected breaches cannot be counted.
They skew large. Small firms are underrepresented in this kind of study.
They are self-reported. Organisations estimated their own costs.
Correlation is doing heavy lifting here
The AI finding is the clearest example.
Firms hit by AI-related breaches lacked AI controls. That is not proof the missing controls caused the breach.
Organisations without AI governance may be less mature in every other way too.
The controls may be a symptom of good management rather than the cause of safety.
That does not make the finding useless. It makes it a signal, not a formula.
The undetected-breach problem
This is the deepest limit in all breach research.
Every study only counts breaches somebody found.
Breaches nobody noticed are invisible to the data.
The true rate is certainly higher than any published figure.
🏁 The Short Version
Breaches cost $4.99 million on average, up 12% and a record (IBM, 2026).
AI-driven attacks rose 56% and add about $1 million when involved.
92% of AI-related victims had no AI access controls at all.
Supply chain attacks take 258 days to contain and cost the most.
Ransomware has shifted from locking data to threatening to publish it.
The through-line is speed. Every finding here is really about time.
Time to notice, time to contain, time before a new risk is governed.
Firms that shorten those windows pay less. That is the whole lesson. 🔐
❓ Frequently Asked Questions
What is the average cost of a data breach in 2026?
$4.99 million globally, a record and up 12% year on year (IBM, 2026). The study covered 602 organisations in 16 countries.
Why did breach costs rise?
IBM points to higher detection and escalation costs, plus greater lost business after incidents.
How much do AI-related breaches add?
About $1 million above the average. AI-driven attacks also rose 56% in a year.
What are AI access controls?
Knowing which AI tools staff use, deciding what data may go into them, and being able to revoke access. 92% of AI-breached firms had none.
Why are supply chain breaches so expensive?
They take 258 days to identify and contain, and added $227,250 above the global average.
Do backups protect against modern ransomware?
Only partly. 41% of attacks now threaten to publish stolen data. Backups restore systems but cannot un-steal information.
What is harvest now, decrypt later?
Stealing encrypted data today to decrypt once quantum computing matures. Only 26% of firms have begun planning for it.
Does this apply to small businesses?
The dollar figure does not, but the patterns do. The AI, supplier and detection findings scale down directly.
What is the single cheapest thing to fix first?
Multi-factor sign-in on every account. It is usually free, already available in your tools, and blocks the most common route in.
How long do breaches usually go unnoticed?
Far longer than people expect. Supply chain breaches averaged 258 days to identify and contain (IBM, 2026).
Should we pay a ransom?
Law enforcement generally advises against it. Payment buys a promise from a criminal, and with 41% of attacks threatening publication, it may not stop disclosure anyway.
How do I estimate my own risk?
Count your customer records, check what regulation applies, estimate what share of customers would leave, and multiply by revenue. That last figure usually dwarfs the technical costs.
Is deleting old data really a security control?
Yes, and an underrated one. Records you no longer hold cannot be stolen, notified about, or fined over.
Can I read the original report?
Yes. IBM publishes it free. It is linked in the references below.
📚 References
IBM. (2026). Cost of a data breach report 2026. Retrieved August 8, 2026, from https://www.ibm.com/reports/data-breach
Infosecurity Magazine. (2026). The average cost of a data breach rises to $5 million. Retrieved August 8, 2026, from https://www.infosecurity-magazine.com/news/cost-of-a-data-breach-5m-ibm/
Northdoor. (2026). Cost of a data breach 2026: Global headline numbers. Retrieved August 8, 2026, from https://www.northdoor.co.uk/insight/blog/cost-of-a-data-breach-2026-global-findings/
Stanford Institute for Human-Centered Artificial Intelligence. (2026). The 2026 AI Index report. Retrieved August 8, 2026, from https://hai.stanford.edu/ai-index/2026-ai-index-report
International Energy Agency. (2026). Energy and AI: Executive summary. Retrieved August 8, 2026, from https://www.iea.org/reports/energy-and-ai/executive-summary
Related reading on this site
For choosing AI tools with governance in mind, see our AI tools roundup. The small business software guide covers the wider stack, and our analysis of AI’s electricity demand looks at another cost of the same boom.
About this analysis
All figures come from IBM’s Cost of a Data Breach Report 2026, researched independently by the Ponemon Institute. The report is published by a company that sells security products, and that context is stated in the text rather than hidden. Figures were checked against the original publication on August 8, 2026.
- Seven in Ten Carts Are Abandoned — And That Has Not Changed Since 2010 🛒 - August 11, 2026
- 88% Adopted AI. Under 10% Scaled It. The 2026 Gap 🤖 - August 10, 2026
- The $4.99 Million Data Breach: What IBM Found in 602 Companies 🔐 - August 9, 2026
