Breach Cost Benchmarks
What a data breach actually costs, by industry, from the IBM Cost of a Data Breach Report 2026. This tool reports published benchmarks for the profile you describe. It does not predict what a breach would cost you.
Your Profile
Pick the industry category IBM would place you in, and roughly how many records could be exposed.
These are the 17 categories IBM uses, with their own definitions. Hover a category to see how IBM defines it.
This does not scale the figures. It tells you whether your scenario sits inside the range of breaches IBM actually studied.
How to read these numbers
The global average total cost of a data breach reached $4.99M in 2026, a record, and organizations took a mean of 247 days to identify and contain one. That total is a whole-breach figure: it covers the investigation, the notification, the response, and the business lost while systems were down.
It is not a cost per record, and it cannot be turned into one. IBM studied breaches of between 2,590 and 115,380 compromised records, excluding very small and very large events, and says in its own methodology that the per-record figure must not be used to size a breach involving millions of records. Any tool that multiplies a per-record cost by your record count is doing arithmetic the source rejects.
Where the money goes
IBM splits the global average of $4.99M into four categories. These are the published figures for that global average, not a split of the industry number above, because IBM does not publish the split per industry. Regulatory fines are inside post-breach response; they are not a separate category.
- Detection and escalation $1.64MForensic and investigative activities, assessment and audit services, crisis management, and communications to executives and boards
- Lost business $1.54MBusiness disruption and revenue lost to system downtime, the cost of losing and replacing customers, and reputational damage
- Post-breach response $1.36MHelp desk and inbound communications, credit monitoring, issuing new accounts or cards, legal expenditures, product discounts, and regulatory fines
- Notification $0.45MNotifying data subjects and regulators, determining regulatory requirements, and engaging outside experts
Average cost of a breach by industry
All 17 IBM industry categories, highest first, with the previous year for direction. Healthcare has been the costliest industry for 13 consecutive years, though it is the one industry whose average fell this year.
| Industry | 2026 | 2025 |
|---|---|---|
| Healthcare | $6.64M | $7.42M |
| Financial | $6.29M | $5.56M |
| Industrial | $5.50M | $5.00M |
| Technology | $5.50M | $4.79M |
| Entertainment | $5.38M | $4.43M |
| Pharmaceuticals | $5.25M | $4.61M |
| Energy | $5.24M | $4.83M |
| Professional services | $5.08M | $4.56M |
| Communications | $4.71M | $3.75M |
| Transportation | $4.50M | $3.98M |
| Media | $4.49M | $4.22M |
| Hospitality | $4.33M | $4.03M |
| Consumer | $4.31M | $3.72M |
| Education | $4.15M | $3.80M |
| Research | $3.99M | $3.79M |
| Retail | $3.80M | $3.54M |
| Public sector | $3.50M | $2.86M |
Every figure on this page is transcribed from the IBM Cost of a Data Breach Report 2026. Nothing here is modeled, estimated, or adjusted.
Data breach cost questions
How much does a data breach cost on average in 2026?
The global average total cost of a data breach is $4.99 million in the IBM Cost of a Data Breach Report 2026, up from $4.44 million the year before. The United States was the costliest country in the study at $11.5 million. These are whole-breach averages, not predictions for any single organization.
Which industry has the most expensive data breaches?
Healthcare breaches were the costliest in the 2026 study at $6.64 million on average, followed by Financial at $6.29 million. The full table for all 17 industries IBM tracks is published on this page.
Can I estimate breach cost per record?
No. IBM studied breaches of between 2,590 and 115,380 compromised records and states in its methodology that per-record figures must not be used to size breaches involving millions of records. Any tool that multiplies a per-record cost by your record count is doing arithmetic the source rejects.
How long does it take to identify and contain a data breach?
Organizations in the 2026 study took a mean of 183 days to identify a breach and 64 more days to contain it, 247 days in total.
Where do these numbers come from?
Every figure on this page is transcribed from the IBM Cost of a Data Breach Report 2026, researched by Ponemon Institute: 602 organizations across 16 countries and regions, breached between March 2025 to February 2026. IBM describes the sample as nonstatistical, so no margins of error apply.
Does this tool predict what a breach would cost my organization?
No. It reports published industry benchmarks for the profile you describe, for education and planning. Actual costs vary with incident scope, response time, jurisdiction, and readiness; a benchmark is not a risk assessment.
Most of that list is work you can start now
IBM found organizations took a mean of 247 days to identify and contain a breach, and that offensive security testing, identity and access management, and employee training were among the largest measured cost reducers. Those are engagements, not aspirations. Let us scope one.