Ditch Microsoft & Google Today!

Cost of a Data Breach 2026: $4.99M Global Average

The cost of a data breach reached a global average of $4.99 million in IBM’s 2026 report, up 12%, and an average of $11.5 million in the United States. Breaches also took longer to find and contain, at a mean of 247 days. This guide walks through the latest figures, how they changed from the 2025 edition, and what they imply for a business with a small team.

Last reviewed: October 6, 2026. The figures come from published summaries of IBM’s reports. This is general information.

Key takeaways

  • IBM’s 2026 report puts the global average cost of a breach at $4.99 million, up 12% from $4.44 million in 2025.
  • The US average reached $11.5 million in 2026, up 11% from $10.22 million.
  • Mean time to identify and contain a breach rose to 247 days, from 241.
  • Healthcare remains among the costliest sectors, at $6.64 million in 2026.
  • Phishing was the most common way in during the 2025 edition, at about 16% of breaches.

The average cost of a data breach, edition by edition

IBM’s annual Cost of a Data Breach report analyzes real breaches at hundreds of organizations. The 2025 edition, published July 30, 2025 and covering 600 organizations, reported a global average of $4.44 million, down 9% from $4.88 million, and a US average of $10.22 million. The 2026 edition, published July 30, 2026 and covering 602 breaches, reported a global average of $4.99 million and a US average of $11.5 million. Figure 1 shows the three editions.

Cost of a data breach bar chart of IBM average costs: global 4.88 million dollars in 2024, 4.44 million in 2025, 4.99 million in 2026, and US 9.36 million, 10.22 million and 11.5 million
Figure 1. Average cost of a data breach, global and US. Source: IBM, via published summaries.

The US average is more than double the global figure in every edition. The 2025 dip in global cost reversed in 2026, so the improvement did not last.

How long breaches go undetected

Cost grows with time. IBM measures the mean time to identify and contain a breach. It was 241 days in the 2025 edition, a nine-year low, and 247 days in 2026, the first increase in five years. Healthcare organizations took 279 days in 2025.

Horizontal bar chart of mean days to identify and contain a data breach: healthcare 2025 279 days, global 2025 241 days, global 2026 247 days
Figure 2. Mean days to identify and contain a breach. Source: IBM, via published summaries.

More than eight months is a long time for an intruder to sit in a network. During that time they can copy files, read email and prepare a second attack.

What the figures mean for a small business

These averages are weighted toward large organizations, and IBM has not recently published a breakout for small ones, so a company with 20 employees should not expect an $11.5 million bill. The useful signals are the direction and the causes. Phishing was the most common initial vector in the 2025 edition, at about 16% of breaches and an average cost of about $4.8 million. Long detection times point to a gap that small firms share, which is that nobody is watching the logs. The table below matches the causes with a first control.

Driver of cost First control
Credentials and phishing Multi-factor authentication, filtering and training
Unpatched software Scheduled updates and vulnerability monitoring
Slow detection Logging, alerts and managed monitoring
Slow recovery Tested offsite backups and a written incident plan

Three ways to lower breach risk and cost

1. Reduce the chance of a break-in

Multi-factor authentication, prompt patching and email filtering address the most common initial routes. Our cybersecurity services cover monitoring, hardening and incident response for small businesses.

2. Shorten the time to detect

Switch on logging for email, servers and your website, and send alerts to a person who will read them. A long dwell time is what turns a contained incident into a costly one.

3. Plan the recovery

Keep tested backups, and write down who does what in the first day of an incident. A restore that works turns a data-loss event into an inconvenience. See our backup and disaster recovery service for how that looks in practice.

Frequently asked questions about the cost of a data breach

What is the average cost of a data breach?

IBM’s 2026 Cost of a Data Breach report puts the global average at $4.99 million, up 12%, and the US average at $11.5 million, up 11%. The 2025 edition reported $4.44 million globally and $10.22 million in the US.

How long does it take to find and contain a breach?

IBM’s 2026 report puts the mean time to identify and contain a breach at 247 days, the first rise in five years. The 2025 figure was 241 days, and 279 days for healthcare.

Which industry has the costliest breaches?

Healthcare has led IBM’s list for years. The 2025 report put its average at $7.42 million, and the 2026 report put it at $6.64 million.

Is phishing a common cause of breaches?

Yes. In IBM’s 2025 report phishing was the most common initial access vector, at about 16% of breaches, with an average cost of about $4.8 million.

Does IBM publish figures for small businesses?

Not recently. A third-party tracker reports that IBM dropped its size breakouts from the 2024 to 2026 editions, with the last published figure being $3.31 million for organizations under 500 employees in 2023. We have not confirmed that claim with IBM, so treat it as unverified.

Sources