Cybersecurity6 min read

Understanding the Cost of Data Breaches

Key insights from IBM's Cost of a Data Breach report: healthcare leads at $10.1M per breach, while AI platforms, DevSecOps, and incident response teams can significantly cut costs.

Marco Cavani

Marco Cavani

Cybersecurity Analyst

|
Understanding the Cost of Data Breaches

Businesses must recognise the cybersecurity risks they face and implement strategies to prevent data breaches, which can lead to significant disruptions and financial losses. By understanding the factors that influence costs, companies of all sizes can effectively reduce their expenditures related to data breaches.

This analysis draws from IBM’s Cost of a Data Breach report, based on data from 604 organisations and feedback from 3,556 cybersecurity and business leaders affected by breaches, compiled by IBM and the Ponemon Institute.


Cost by Industry Sector

The report highlights significant variation in breach costs across different industries. Healthcare continues to lead as the most expensive sector for the 12th consecutive year:

Sector2021 Cost2022 CostChange
Healthcare$9.23M$10.10M+9.4%
Financial$5.72M$5.97M+4.4%
Pharmaceutical$4.97M$5.01M+0.8%
TechnologyN/AN/A↑ slight
EnergyN/AN/A↑ slight

Healthcare’s high cost reflects the sensitivity of patient data and the operational impact of system downtime.


Factors That Reduce Breach Costs

Organisations can significantly reduce breach costs by implementing the following controls:

PracticeAverage Cost Reduction
AI security platformLargest reduction
DevSecOps approachSignificant
Incident Response (IR) teamSignificant
Extensive encryption$252,088
Employee training$247,758
Regular IR plan testing$246,889
Identity & Access Management$224,396
Security analytics$217,317
Multifactor Authentication$186,765
Red team testing$204,375

Factors That Increase Breach Costs

Conversely, certain factors contribute to rising breach costs:

FactorAverage Cost Increase
Security system complexity$290,655
Cloud migration challenges$284,292
Third-party involvement$247,624
Compliance failures$258,293
Lost or stolen devices$227,420
Shortage of security skills$206,843
IoT/OT environment challenges$201,354
Remote work issues$152,465

Key Takeaways

This analysis emphasises the importance of adopting proactive cybersecurity measures and continuous investment in both technology and human resources.

By prioritising:

  • AI security platforms
  • Employee training
  • Encryption
  • Incident response readiness

…organisations can significantly mitigate the financial impact of data breaches.

Addressing issues like system complexity, compliance failures, and third-party risks is equally crucial in an increasingly digital and interconnected world.

#Data Breach#IBM#Cost Analysis#Healthcare#AI Security#DevSecOps#Incident Response
Marco Cavani

Written by

Marco Cavani

Cybersecurity analyst and IT governance professional. Author of digital reports on threat intelligence, critical infrastructure security, and IT audit frameworks.

Related articles

Boss of The SOC V3 Timeline
Tutorial6 min read

Boss of The SOC V3 Timeline

A chronological account of the BOTSv3 security incident on 20 August 2018, categorised by MITRE ATT&CK tactics, from initial access and phishing through to exfiltration and a Memcached DDoS attack.

Read more →
MITRE ATT&CKBOTSv3Incident Response

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.

ITGC Audit Tool

Streamline Your IT General Controls Audits

The RACM ITGC SaaS platform helps audit professionals manage IT General Controls assessments, from risk and control mapping to workpaper generation and evidence tracking.