The cost of a data breach has reached a new record.

According to the latest IBM Cost of a Data Breach Report 2026, the global average cost of a data breach has risen to $4.99 million, an increase of 12% compared with the previous year.

For UK organisations, the average cost now stands at $4.17 million, up from $4.14 million in 2025.

But the headline figures only tell part of the story.

The 2026 report shows that the financial consequences of a cyber incident increasingly extend beyond technical recovery. Detection and escalation costs are rising, business disruption is becoming more expensive, ransomware groups are placing greater pressure on corporate reputations, and AI is giving attackers new ways to increase the speed and scale of their operations.

At the same time, there is evidence that organisations can significantly reduce breach costs through faster detection and containment, effective security operations, strong identity controls and greater use of AI and automation.

So, what does the Cost of a Data Breach Report 2026 tell us about the real financial impact of cyberattacks?

What is the average cost of a data breach in 2026?

The global average cost of a data breach in 2026 is $4.99 million, according to IBM's Cost of a Data Breach Report 2026.

That is the highest figure recorded by the report and represents a 12% increase from $4.44 million in 2025.

The longer-term trend is also striking.

Average breach costs have risen from $3.92 million in 2019 to:

  • $3.86 million in 2020
  • $4.24 million in 2021
  • $4.35 million in 2022
  • $4.45 million in 2023
  • $4.88 million in 2024
  • $4.44 million in 2025
  • $4.99 million in 2026

Following last year's temporary fall, breach costs have returned to their longer-term upward trajectory.

The increase has largely been driven by the growing cost of identifying incidents, escalating them internally and dealing with the business disruption that follows.

Source: IBM Cost of a Data Breach Report 2026

How much does a data breach cost in the UK?

The average cost of a data breach in the UK reached $4.17 million in 2026, compared with $4.14 million in 2025.

Although this remains below the global average, the financial impact is substantial.

The United States recorded by far the highest average breach cost at $11.5 million, followed by the Middle East at $8 million and Benelux at $7.37 million.

Other 2026 averages included:

  • Canada: $5.20 million
  • Germany: $4.93 million
  • LATAM: $4.65 million
  • United Kingdom: $4.17 million
  • Italy: $4.12 million
  • France: $4.05 million
  • South Africa: $3.04 million

The differences reflect a combination of factors including regulatory costs, business disruption and the economic environments in which organisations operate.

What makes a data breach so expensive?

A breach does not become expensive simply because information has been stolen.

Organisations face costs throughout the lifecycle of the incident.

IBM divides breach expenditure into four broad categories:

Detection and escalation: $1.64 million
Lost business: $1.54 million
Post-breach response: $1.36 million
Notification: $450,000

Detection and escalation together with lost business accounted for 63% of the average breach cost in 2026.

Both categories increased by 11.5% compared with the previous year.

Post-breach response costs increased even faster, rising by 15%. These can include regulatory fines, legal expenses and services provided to customers affected by the breach.

The figures highlight an important point for security leaders. The cost of a cyberattack does not end when the attacker is removed.

Operational disruption, legal obligations, customer churn and reputational damage can continue long after the immediate incident has been contained.

How long does it take to identify and contain a data breach?

The average breach lifecycle increased slightly in 2026.

Organisations took an average of 183 days to identify a breach and another 64 days to contain it, producing a total average lifecycle of 247 days.

That represents a 2.5% increase from 241 days in 2025 and reverses several years of improving detection and containment times.

Those figures also show why continuous detection remains so important.

An attacker that remains undetected for months has significantly more opportunity to access data, establish persistence, compromise additional systems and disrupt business operations.

Longer breaches cost considerably more

Time has a direct relationship with breach cost.

Data breaches that took more than 200 days to identify and contain cost an average of $5.65 million.

Breaches contained in less than 200 days averaged $4.32 million.

That is a difference of $1.33 million.

The cost of longer-running breaches also increased by 12% compared with the previous year.

Faster detection therefore does more than reduce technical risk. It can materially reduce the financial consequences of an incident.

Who detects a breach matters

The report also provides an interesting comparison between organisations that detected incidents themselves, Managed Security Service Providers (MSSPs), external third parties and attackers.

Internal IT and security teams identified 38% of breaches.

MSSPs identified another 31%.

In contrast, attackers disclosed 17% of breaches themselves, while third parties identified 14%.

The financial impact differed depending on how the breach was found.

Where an MSSP detected the incident, the average breach cost was $4.86 million, 2.6% below the global average.

Breaches discovered internally averaged $5.01 million, while organisations that only became aware of an incident when the attacker disclosed it faced average costs of $5.12 million.

There were also substantial differences in detection and containment times.

Internal security teams averaged 209 days, while MSSP-identified breaches averaged 230 days. Incidents disclosed by attackers took 268 days, and breaches identified by third parties took 281 days.

The lesson is clear: finding an attacker yourself is considerably better than waiting for somebody else to tell you that you have been breached.

What is the most common cause of a data breach?

Malicious or criminal activity remained the leading root cause of data breaches in 2026.

It accounted for 55% of breaches, compared with 23% caused by human error and 22% caused by IT failure.

Among individual initial attack vectors, phishing remained the most common for the fourth consecutive year.

Voice and SMS phishing attacks also produced the highest average breach cost among the attack vectors assessed, at $5.29 million.

Social engineering techniques such as IT or helpdesk impersonation produced average breach costs of $5.23 million, while attacks involving abuse of legitimate accounts averaged $5.07 million.

These findings reinforce the need to protect identities and users alongside traditional infrastructure.

Security controls may be technically strong, but an attacker who can persuade an employee to hand over credentials or approve an authentication request may be able to bypass many of them.

AI-driven attacks are increasing rapidly

One of the defining themes of the 2026 report is the growing use of artificial intelligence by attackers.

More than one in four organisations experiencing a malicious attack reported that it was AI-driven.

That represents a 56% increase from the previous year.

AI-powered deepfake and impersonation attacks accounted for the largest proportion of those incidents at 45%, followed by AI-enabled malware at 19% and AI-generated phishing or other communications at 17%.

The financial consequences were significant.

AI-driven attacks added an average of approximately $1 million to the cost of a malicious breach.

Malicious AI-driven attacks averaged $6.04 million compared with $5.03 million for attacks that did not use AI.

AI is therefore not creating an entirely new cyber threat landscape. In many cases, it is making existing attack techniques faster, cheaper and easier to scale.

AI itself is becoming an attack surface

Organisations are not only facing attackers using AI. Their own AI models and applications are increasingly becoming targets.

The report found significant costs associated with AI-related security incidents:

Model evasion: $4.72 million
Malicious models: $4.94 million
Cloud misconfigurations affecting AI workloads: $5.25 million
Prompt injection: $5.89 million
Model inversion: $6.07 million

Perhaps more concerning is the lack of basic access controls around many AI environments.

Among organisations that experienced an AI-related breach, 92% lacked proper AI access controls.

Only 40% of organisations reported using access controls on AI models and data.

As organisations integrate AI deeper into business processes, AI security therefore needs to form part of wider identity, cloud, data and application security strategies.

Ransomware continues to evolve

Ransomware affected 39% of breached organisations in 2026, compared with 34% the previous year.

The figure has increased substantially since 2023, when ransomware was present in 24% of breaches.

But the way attackers apply pressure is changing.

Encryption and operational disruption remain important, but ransomware groups increasingly threaten an organisation's reputation as another means of forcing payment.

41% of ransomware incidents included threats of public shaming or leaking information to the media.

Attackers also targeted:

  • Employee personal data in 35% of incidents
  • Intellectual property in 31%
  • Customer information in 30%
  • Operational systems in 23%
  • Internal communications in 19%

The impact of ransomware therefore extends well beyond encrypted servers. Stolen internal information, intellectual property and communications can create reputational and commercial consequences even if systems are successfully recovered.

Which industries face the highest data breach costs?

Healthcare remained the industry with the highest average breach cost for the 13th consecutive year, at $6.64 million.

Financial services followed at $6.29 million.

Other high-cost sectors included:

  • Industrial: $5.50 million
  • Technology: $5.50 million
  • Entertainment: $5.38 million
  • Pharmaceuticals: $5.25 million
  • Energy: $5.24 million
  • Services: $5.08 million

Healthcare was the only industry in the study where average breach costs fell. Its average decreased from $7.42 million in 2025.

Every other industry recorded an increase.

Customer data remains the biggest target

Customer personally identifiable information (PII) was compromised in 52% of breaches, making it the most commonly affected type of data.

The average cost associated with compromised customer PII was $192 per record.

Employee PII appeared in 35% of breaches and averaged $188 per record.

However, intellectual property was the most expensive category on a per-record basis at $196, despite being compromised in a smaller 32% of incidents.

For organisations handling large volumes of personal or commercially sensitive information, understanding where that data exists and who can access it remains fundamental to reducing breach risk.

More than half of breached organisations had not encrypted sensitive data

One of the more striking findings in the report is that 53% of breached organisations had not encrypted sensitive data both at rest and in transit.

Another 10% were unsure whether their data was encrypted.

Only 37% confirmed that appropriate encryption was in place.

Encryption cannot prevent a breach from occurring, but it can make compromised information considerably harder for attackers to exploit.

Data discovery, classification and protection therefore need to form part of a wider cybersecurity programme rather than being treated solely as compliance requirements.

Security AI and automation can save almost $2 million per breach

While AI is providing attackers with new capabilities, the report also shows its potential value for defenders.

Organisations making extensive use of security AI and automation experienced an average breach cost of $4 million.

Those making no use of the technology averaged $5.93 million.

That represents a $1.93 million difference.

Extensive users also identified and contained breaches 65 days faster, averaging 215 days compared with 280 days among organisations making no use of security AI and automation.

However, adoption remains relatively limited.

Only 36% of breached organisations reported extensive use of AI and automation across security operations.

Organisations are beginning to deploy AI agents in security operations

The report examines agentic AI within the Security Operations Centre for the first time.

Half of organisations with an SOC reported deploying AI agents.

Among those organisations, the most common applications were:

  • Threat hunting: 56%
  • Automated response and containment: 54%
  • Threat investigation: 45%
  • Alert triage: 34%
  • Penetration testing: 33%
  • Reporting and compliance automation: 19%
  • Vulnerability scanning and management: 18%

The low adoption of AI agents for vulnerability management is particularly notable.

As attackers increasingly use AI to identify and exploit weaknesses more quickly, organisations also need to look at how automation can be used to reduce exposures before they are exploited.

Recovery can take considerably longer than containment

Containing the attacker is not the same as recovering from the incident.

The report defines recovery as reaching the point where normal business operations have resumed, compliance obligations have been addressed, customer and employee confidence has been restored, and controls have been implemented to reduce the risk of another breach.

Only 42% of organisations had fully recovered from their breach at the time of the research.

Although this represents a substantial improvement from 35% in 2025, fewer than one in 20 organisations completed recovery in under 50 days.

For 19% of organisations, recovery took more than 150 days.

Incident response planning therefore needs to consider the entire recovery process, not simply removing an attacker from the network.

How can organisations reduce the cost of a data breach?

The findings point towards one overarching priority: reduce the time between compromise, detection and containment while making it harder for attackers to reach valuable data in the first place.

That requires several layers of defence.

Organisations need strong identity and access management, effective vulnerability management, secure configuration, data discovery and encryption, continuous security monitoring, threat detection and tested incident response processes.

Security teams also need visibility across increasingly complex environments.

A breach may involve identities, endpoints, cloud workloads, applications, SaaS platforms and third parties. Treating each environment independently makes it harder to recognise the wider attack.

Regular cybersecurity testing can help identify exposures before an attacker finds them, while Managed Detection and Response provides continuous monitoring and investigation when preventative controls are bypassed.

Incident Response planning and retainers can then help ensure that organisations have immediate access to specialist expertise when a serious incident occurs.

Reduce the impact of your next cyber incident

The 2026 figures demonstrate that preventing every cyberattack is an increasingly unrealistic objective.

The more important question is what happens when an attacker gets through.

Organisations that can identify suspicious activity quickly, understand what has been compromised and contain the attacker are in a much stronger position to limit operational disruption and financial loss.

Integrity360 provides cybersecurity services across the complete incident lifecycle, including Cybersecurity Testing, Managed Detection and Response, Incident Response, Digital Forensics, Compromise Assessments and Incident Response Retainers.

By identifying exposures before they are exploited, continuously monitoring for malicious activity and ensuring specialist incident responders are available when needed, organisations can reduce both the likelihood and potential impact of a serious data breach.

Talk to an Integrity360 cybersecurity specialist about strengthening your organisation's ability to prevent, detect and respond to data breaches.

 

Contact Us

 

Frequently asked questions

What is the average cost of a data breach in 2026?

The global average cost of a data breach is $4.99 million, according to IBM's Cost of a Data Breach Report 2026.

This represents a 12% increase from $4.44 million in 2025.

What is the average cost of a data breach in the UK?

The average UK data breach cost reached $4.17 million in 2026, up slightly from $4.14 million in 2025.

How long does it take to detect a data breach?

Organisations took an average of 183 days to identify a breach in 2026.

Containment required another 64 days, resulting in an average breach lifecycle of 247 days.

Do longer data breaches cost more?

Yes.

Breaches taking longer than 200 days to identify and contain cost an average of $5.65 million, compared with $4.32 million for breaches contained within 200 days.

How much can AI and automation reduce data breach costs?

Organisations making extensive use of security AI and automation experienced breach costs averaging $1.93 million less than organisations that did not use those technologies.

They also identified and contained breaches 65 days faster.

What is the most expensive cause of a data breach?

Among the initial attack vectors assessed in the report, voice and SMS phishing produced the highest average breach cost at $5.29 million.

Social engineering involving techniques such as IT or helpdesk impersonation followed closely at $5.23 million.

Which industry has the highest data breach costs?

Healthcare remains the most expensive industry for data breaches, with an average cost of $6.64 million in 2026.

Financial services follows at $6.29 million.

How can businesses reduce data breach costs?

Reducing breach costs requires a combination of prevention, early detection and effective response. Strong identity security, vulnerability management, encryption, continuous monitoring, MDR, security testing and a tested incident response plan can all help reduce the likelihood that an intrusion develops into a major breach.

 

 

Updated 18.8.26