IBM Study: Hidden Costs of Data Breaches Increase Expenses for Businesses
01/11/2018
This year for the first time, the study also calculated the costs associated with "mega breaches" ranging from 1 million to 50 million records lost, projecting that these breaches cost companies between $40 million and $350 million respectively.
"While highly publicized data breaches often report losses in the millions, these numbers are highly variable and often focused on a few specific costs which are easily quantified," said Wendi Whitmore, Global Lead for IBM X-Force Incident Response and Intelligence Services (IRIS). "The truth is there are many hidden expenses which must be taken into account, such as reputational damage, customer turnover, and operational costs. Knowing where the costs lie, and how to reduce them, can help companies invest their resources more strategically and lower the huge financial risks at stake."
Hidden Figures Calculating the Cost of a Mega Breach
In the past five years, the amount of mega breaches (breaches of more than 1 million records) has nearly doubled - from just nine mega breaches in 2013, to 16 mega breaches in 2017.3 Due to the small amount of mega breaches in the past, the Cost of a Data Breach study historically analyzed data breaches of around 2,500 to 100,000 lost records.
Based on analysis of 11 companies experiencing a mega breach over the past two years, this year s report uses statistical modelling to project the cost of breaches ranging from 1 million to 50 million compromised records. Key findings include:
Average cost of a data breach of 1 million compromised records is nearly $40 million dollars
At 50 million records, estimated total cost of a breach is $350 million dollars
The vast majority of these breaches (10 out of 11) stemmed from malicious and criminal attacks (as opposed to system glitches or human error)
The average time to detect and contain a mega breach was 365 days almost 100 days longer than a smaller scale breach (266 days)
For mega breaches, the biggest expense category was costs associated with lost business, which was estimated at nearly $118 million for breaches of 50 million records almost a third of the total cost of a breach this size. IBM analyzed the publicly reported costs of several high profile mega breaches, and found the reported numbers are often less than the average cost found in the study.4 This is likely due to publicly reported cost often being limited to direct costs, such as technology and services to recover from the breach, legal and regulatory fees, and reparations to customers.
What Impacts the Average Cost of a Data Breach?
For the past 13 years, the Ponemon Institute has examined the cost associated with data breaches of less than 100,000 records, finding that the costs have steadily risen over the course of the study. The average cost of a data breach was $3.86 million in the 2018 study, compared to $3.50 million in 2014 representing nearly 10 percent net increase over the past 5 years of the study.
The study also examines factors which increase or decrease the cost of the breach, finding that costs are heavily impacted by the amount of time spent containing a data breach, as well as investments in technologies that speed response time.
The average time to identify a data breach in the study was 197 days, and the average time to contain a data breach once identified was 69 days.
Companies who contained a breach in less than 30 days saved over $1 million compared to those that took more than 30 days ($3.09 million vs. $4.25 million average total)
The amount of lost or stolen records also impacts the cost of a breach, costing $148 per lost or stolen record on average. The study examined several factors which increase or decrease this cost:
Having an incident response team was the top cost saving factor, reducing the cost by $14 per compromised record
The use of an AI platform for cybersecurity reduced the cost by $8 per lost or stolen record
Companies that indicated a "rush to notify" had a higher cost by $5 per lost or stolen record
This year for the first time, the report examined the effect of security automation tools which use artificial intelligence, machine learning, analytics and orchestration to augment or replace human intervention in the identification and containment of a breach. The analysis found that organizations that had extensively deployed automated security technologies saved over $1.5 million on the total cost of a breach ($2.88 million, compared to $4.43 million for those who had not deployed security automation.)
Regional and Industry Differences
The study also compared the cost of data breaches in different industries and regions, finding that data breaches are the costliest in the U.S. and the Middle East, and least costly in Brazil and India.
U.S. companies experienced the highest average cost of a breach at $7.91 million, followed by the Middle East at $5.31 million.
Lowest total cost of a breach was $1.24 million in Brazil, followed by $1.77 million in India.
One major factor impacting the cost of a data breach in the U.S. was the reported cost of lost business, which was $4.2 million more than the total average cost of a breach globally, and more than double the amount of "lost business costs" compared to any other region surveyed. One major factor impacting lost business costs is customer turnover in the aftermath of a breach; in f
More from IBM
05/04/2024
IBM and The Government of Spain Collaborate to Advance National AI strategy and Build the World's Leading Spanish Language AI Models
Madrid, Spain April 5, 2024 The President of the Government, Pedro S nchez, ...
26/03/2024
IBM Announces EMEA Geography Winners of the 2024 IBM Partner Plus Awards
London, UK, March 26, 2024 Today, IBM (NYSE: IBM) announced the EMEA geography winners of the 2024 IBM Partner Plus Awards, which celebrate IBM partners who a...
21/02/2024
IBM Report: Cybercriminals Intensify Attacks on User Identities in the UK, Complicating Recovery Efforts for Enterprises
LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligen...
06/02/2024
New IBM LinuxONE 4 Express to Offer Cost Savings and Client Value through a Cyber Resilient Hybrid Cloud and AI Platform
LONDON, U.K., February 6, 2024 IBM (NYSE: IBM) today announced IBM LinuxONE 4 ...
18/01/2024
IBM to Acquire Application Modernization Capabilities from Advanced
Today, IBM is announcing that it has signed a definitive agreement to acquire application modernization capabilities from Advanced, bringing a combination of ta...
10/01/2024
UK Lags Leading Asian Economies on Enterprise AI Adoption - New IBM Study
LONDON and ARMONK, N.Y., January 10, 2024 New research commissioned by IBM (NYSE: IBM) found that more than a third of UK organisations with over 1,000 employ...
13/12/2023
NATO Selects IBM to Further Enhance Alliance's Cybersecurity Resilience
LONDON, UK, December 13, 2023 - Today, IBM (NYSE: IBM) signed a contract with the NATO Communications and Information Agency (NCI Agency) to help strengthen the...
05/12/2023
AWS Announces IBM Winner of the 2023 Global Systems Integrator Partner of the Year Award
LONDON, UK, 5 December, 2023 Amazon Web Services, Inc. (AWS), an Amazon.com co...
30/11/2023
IBM Advances Geospatial AI to Address Climate Challenges
LONDON, UK, Nov 30, 2023 IBM (NYSE: IBM) today announced new efforts that apply its geospatial AI technologies, including IBM's geospatial foundation mode...
22/11/2023
IBM Commits to Train 2 Million in Artificial Intelligence in Three Years, with a Focus on Underrepresented Communities
DUBLIN, 22 November, 2023 - To help close the global artificial intelligence (AI...
08/11/2023
New IBM Study Explores the Changing Role of Leadership as UK Businesses Embrace Generative AI
Wednesday 8 November, London: Today, IBM launched its new report Leadership in ...
27/10/2023
The Sunday Times: Why Big Blue is betting on an AI reboot
Arvind Krishna, Chairman and CEO of IBM, met recently with one of the UK's leading business editors in New York for a major profile interview. The Sunday T...
18/10/2023
IBM Expands Relationship with AWS to Bring Generative AI Solutions and Dedicated Expertise to Clients
LONDON, UK, October 18, 2023: IBM (NYSE: IBM) today announced an expansion of it...
13/09/2023
IBM Announced as Sponsor of 2023 U.N. Climate Change Conference (COP28)
LONDON, UK, September 13, 2023 IBM (NYSE: IBM) today announced its role as an Associate Pathway Partner of the 2023 United Nations Climate Change Conference (...
17/08/2023
IBM Consulting Collaborates with Microsoft to Help Companies Accelerate Adoption of Generative AI
LONDON, UK, August 17, 2023 - Today, IBM (NYSE: IBM) is expanding its collaborat...
14/08/2023
IBM Study: AI Drives Massive Shifts in Jobs and Skills as Employees Prioritise Meaningful Work
LONDON, UK, August 14, 2023 - Executives in the UK estimate that 41% of their wo...
24/07/2023
IBM Security Report: Cost of a Data Breach for UK Businesses Averages 3.4m
LONDON, UK. 24 July 2023 IBM Security today released its annual Cost of a Data Breach Report,1 which revealed that UK organisations pay an average of £3.4m fo...
20/07/2023
Crown Commercial Service and IBM Sign 3-Year Memorandum of Understanding to Boost Public Sector Services
The Crown Commercial Service (CCS) has announced a new 3-year Memorandum of Unde...
18/07/2023
Digital Realty Selects IBM Sustainability Software to Transform Data into Insights Across its Global Data Centers and Offices
LONDON, UK; July 18, 2023London, UK; July 18, 2023 - IBM (NYSE:IBM) today announ...
27/06/2023
IBM Study: CEOs Embrace Generative AI as Productivity Jumps to the Top of their Agendas
LONDON, UK, June 27, 2023 A new study by the IBM (NYSE: IBM) Institute for Bus...
21/06/2023
IBM Brings Generative AI Commentary and AI Draw Analysis to the Wimbledon Digital Experience
LONDON, U.K. and ARMONK N.Y., June 21, 2023 IBM (NYSE: IBM) and The All Englan...
19/05/2023
Diageo partners with IBM Consulting and SAP to drive its digital transformation initiative
IBM Consulting has been selected to revolutionise Diageo's IT environment by...
23/04/2023
IBM statement on the Confederation of British Industry
You may have seen recent media coverage relating to the Confederation of British Industry (CBI), the largest business association in the UK. IBM agrees with th...
17/04/2023
New IBM Study Reveals Inadequate Data Hinders Progress Against Environmental, Social and Governance Goals
LONDON, UK, April 17, 2023 - A new global IBM (NYSE: IBM) Institute for Business...
03/04/2023
IBM Statement on UK Government's AI Regulation White Paper
IBM is pleased to see the UK government making progress on its plans to develop a pro-innovation approach to AI regulation. Like similar approaches in Singapore...
14/03/2023
IBM launches RFP to help accelerate global water management solutions for vulnerable populations
LONDON, UK, March 1, 2023 - IBM (NYSE: IBM) announced today that it is accepting...
01/03/2023
IBM and Chief Study Finds Women in Leadership Pipeline has Hollowed Out in the Middle
LONDON, UK, March 1, 2023 - The leadership pipeline for women has hollowed out i...
22/02/2023
IBM Report: Vulnerable UK energy system among top targets for cybercriminals as businesses face growing extortion threat
ARMONK, N.Y. and LONDON, UK, FEBRUARY 22, 2023 IBM Security (NYSE: IBM) today ...
14/02/2023
New IBM survey reveals the greatest perceived barrier to professional or technical skill development is that programs are too expensive
London, 14th February 2023 Job seekers, students, and career changers around t...
09/01/2023
Nicola Hodson named Chief Executive, IBM in the UK and Ireland
London, 9 January 2023 IBM today announced that Nicola Hodson has been named Chief Executive, IBM in the UK and Ireland. Dr Hodson succeeds Sreeram Visvanatha...
28/11/2022
East and North Hertfordshire NHS Trust Launches New Virtual Assistant with IBM Watson to Support Human Resources and Bolster Employee Services
Stevenage, UK, November 28th 2022: East and North Hertfordshire NHS Trust is tod...
25/10/2022
IBM Grants $500,000 in-kind to City of Dublin Education Training Board To Boost Cybersecurity Preparedness
October 25, 2022 - As schools become more dependent on technology, ransomware at...
28/09/2022
UK Business Leaders Say Hybrid Cloud is Critical to Modernisation, Yet Security, Skills and Compliance Concerns Impede Success
ARMONK, N.Y., September 28, 2022 New market research from IBM (NYSE: IBM) reve...
31/08/2022
REPROCELL, IBM and STFC harness the power of AI in drug discovery and precision medicine
Glasgow, UK and Daresbury, UK: REPROCELL Europe Ltd, IBM Research and STFC today...
27/07/2022
IBM Report: Consumers Pay the Price as Data Breach Costs Reach All-Time High
CAMBRIDGE, Mass., July 27, 2022 IBM Security today released the annual Cost of a Data Breach Report,[1] revealing costlier and higher-impact data breaches tha...
21/06/2022
IBM Reveals New AI and Cloud Powered Fan Experiences for Wimbledon 2022
London, 21st June, 2022 IBM (NYSE: IBM) and the All England Lawn Tennis Club today unveil new ways for Wimbledon fans around the world to experience The Champ...
18/05/2022
IBM Study: Skills Shortage Stalls UK's AI Adoption as Europe Accelerates
London, 18th May 2022 A global study from IBM (NYSE: IBM) has revealed UK businesses are not progressing their use of artificial intelligence (AI) at the same...
10/05/2022
IBM Study: Sustainability Ranks Among Highest Priorities on CEO Agendas, Yet Lack of Data Insights Hinders Progress
IBM Study: Sustainability Ranks Among Highest Priorities on CEO Agendas, Yet Lac...
13/07/2020
From Studio to Screen: How IBM Developed a Digital Showcase for Final-Year Students at University of the Arts London
From Studio to Screen: How IBM Developed a Digital Showcase for Final-Year Stude...
25/09/2019
CICS 50th Anniversary
CICS 50th Anniversary 19 September, 2019 | Written by: Nick Garrod...
18/09/2019
Rugby Football Union, IBM delivering a refreshed digital experience
Rugby Football Union, IBM delivering a refreshed digital experience 16 August, 2019 | Written by: John Kaduthodil Staying relevant, maintaining and exceedin...
18/09/2019
IBM's Internship program is helping Marwell Zoo improve its recycling with smart technology
IBM's Internship program is helping Marwell Zoo improve its recycling with s...
09/07/2019
IBM Closes Landmark Acquisition of Red Hat for $34 Billion; Defines Open, Hybrid Cloud Future
London - 09 Jul 2019: - Acquisition positions IBM as the leading hybrid cloud p...
03/07/2019
Moorfields Eye Hospital launches first virtual assistant to connect with patients
London - 02 Jul 2019: Moorfields Eye Hospital NHS Foundation Trust (Moorfields)...
13/06/2019
Wimbledon & IBM Herald The Role of AI to Maintain a Competitive Advantage in Sports Landscape
London, UK - 13 Jun 2019: The All England Lawn Tennis Club (AELTC) and IBM toda...
14/02/2019
SPF Private Clients introduces its First AI Mortgage Advisor Built on IBM Watson and IBM Cloud
London, UK - 14 Feb 2019: Ava was created to handle the significant increase in...
07/12/2018
University of Liverpool and IBM sign a Joint Study Agreement for Research and Innovation
London, UK - 28 Nov 2018: A major part of this new relationship is the Joint St...