Skip to content

    Breach Cost Benchmarks

    What a data breach actually costs, by industry, from the IBM Cost of a Data Breach Report 2026. This tool reports published benchmarks for the profile you describe. It does not predict what a breach would cost you.

    1
    2
    3

    Your Profile

    Pick the industry category IBM would place you in, and roughly how many records could be exposed.

    Industry

    These are the 17 categories IBM uses, with their own definitions. Hover a category to see how IBM defines it.

    Records that could be exposed

    This does not scale the figures. It tells you whether your scenario sits inside the range of breaches IBM actually studied.

    Select an industry and a record range to continue

    How to read these numbers

    The global average total cost of a data breach reached $4.99M in 2026, a record, and organizations took a mean of 247 days to identify and contain one. That total is a whole-breach figure: it covers the investigation, the notification, the response, and the business lost while systems were down.

    It is not a cost per record, and it cannot be turned into one. IBM studied breaches of between 2,590 and 115,380 compromised records, excluding very small and very large events, and says in its own methodology that the per-record figure must not be used to size a breach involving millions of records. Any tool that multiplies a per-record cost by your record count is doing arithmetic the source rejects.

    Where the money goes

    IBM splits the global average of $4.99M into four categories. These are the published figures for that global average, not a split of the industry number above, because IBM does not publish the split per industry. Regulatory fines are inside post-breach response; they are not a separate category.

    • Detection and escalation $1.64MForensic and investigative activities, assessment and audit services, crisis management, and communications to executives and boards
    • Lost business $1.54MBusiness disruption and revenue lost to system downtime, the cost of losing and replacing customers, and reputational damage
    • Post-breach response $1.36MHelp desk and inbound communications, credit monitoring, issuing new accounts or cards, legal expenditures, product discounts, and regulatory fines
    • Notification $0.45MNotifying data subjects and regulators, determining regulatory requirements, and engaging outside experts

    Average cost of a breach by industry

    All 17 IBM industry categories, highest first, with the previous year for direction. Healthcare has been the costliest industry for 13 consecutive years, though it is the one industry whose average fell this year.

    Average total cost of a data breach by industry, 2026 compared with 2025, in millions of US dollars
    Industry20262025
    Healthcare$6.64M$7.42M
    Financial$6.29M$5.56M
    Industrial$5.50M$5.00M
    Technology$5.50M$4.79M
    Entertainment$5.38M$4.43M
    Pharmaceuticals$5.25M$4.61M
    Energy$5.24M$4.83M
    Professional services$5.08M$4.56M
    Communications$4.71M$3.75M
    Transportation$4.50M$3.98M
    Media$4.49M$4.22M
    Hospitality$4.33M$4.03M
    Consumer$4.31M$3.72M
    Education$4.15M$3.80M
    Research$3.99M$3.79M
    Retail$3.80M$3.54M
    Public sector$3.50M$2.86M

    Every figure on this page is transcribed from the IBM Cost of a Data Breach Report 2026. Nothing here is modeled, estimated, or adjusted.

    Data breach cost questions

    How much does a data breach cost on average in 2026?

    The global average total cost of a data breach is $4.99 million in the IBM Cost of a Data Breach Report 2026, up from $4.44 million the year before. The United States was the costliest country in the study at $11.5 million. These are whole-breach averages, not predictions for any single organization.

    Which industry has the most expensive data breaches?

    Healthcare breaches were the costliest in the 2026 study at $6.64 million on average, followed by Financial at $6.29 million. The full table for all 17 industries IBM tracks is published on this page.

    Can I estimate breach cost per record?

    No. IBM studied breaches of between 2,590 and 115,380 compromised records and states in its methodology that per-record figures must not be used to size breaches involving millions of records. Any tool that multiplies a per-record cost by your record count is doing arithmetic the source rejects.

    How long does it take to identify and contain a data breach?

    Organizations in the 2026 study took a mean of 183 days to identify a breach and 64 more days to contain it, 247 days in total.

    Where do these numbers come from?

    Every figure on this page is transcribed from the IBM Cost of a Data Breach Report 2026, researched by Ponemon Institute: 602 organizations across 16 countries and regions, breached between March 2025 to February 2026. IBM describes the sample as nonstatistical, so no margins of error apply.

    Does this tool predict what a breach would cost my organization?

    No. It reports published industry benchmarks for the profile you describe, for education and planning. Actual costs vary with incident scope, response time, jurisdiction, and readiness; a benchmark is not a risk assessment.

    Most of that list is work you can start now

    IBM found organizations took a mean of 247 days to identify and contain a breach, and that offensive security testing, identity and access management, and employee training were among the largest measured cost reducers. Those are engagements, not aspirations. Let us scope one.