Skip to content

Guide · breach cost

Data breach cost calculator

The baseline numbers

The most cited breach figures come from IBM's annual Cost of a Data Breach study. They are useful anchors — but averages, not destinies. A handful of catastrophic breaches pull the mean far above what a typical small or mid-sized organization would face.

Metric Figure Note
Global average$4.44MIBM Cost of a Data Breach 2025.
United States average$10.22MHighest of any region.
Cost per record~$160 – $200Higher for regulated PII / health data.
Healthcare (highest sector)$7M – $10M+Regulation + sensitivity premium.

Figures are study averages; medians for smaller organizations are substantially lower.

What drives breach cost

Total cost is the sum of several drivers, some fixed and some that scale. Understanding which ones you can influence is the point — most of the controllable cost lives in detection and response speed.

Driver Effect Can you control it?
Records exposedScales cost roughly linearly for small/mid breaches.Partly — data minimization helps.
Detection & containment timeLonger dwell = more exposure & cleanup.Yes — top lever
Data sensitivity / regulationHealth & financial data carry premiums.No — structural.
Ransomware involvementAdds ransom, downtime, and recovery cost.Partly — backups & segmentation.
Business interruptionLost revenue during downtime.Partly — resilience planning.

How to estimate your exposure

You don't need the IBM dataset to size your own downside. A defensible estimate stacks five components, then brackets the result with a fast- and slow-detection scenario:

  1. Records × per-record cost. Count the sensitive records you hold; multiply by a per-record figure for your data type ($160–$200 is a reasonable starting band).
  2. Fixed incident costs. Forensics, legal counsel, and breach notification run from tens of thousands at the low end into the hundreds of thousands.
  3. Business interruption. Estimate revenue lost per day of downtime × expected days to recover.
  4. Ransomware (if in scope). Add a plausible demand plus recovery cost — and note that paying does not guarantee clean recovery.
  5. Detection bracket. Model a fast-contained case (strong detection) and a slow-contained case. The gap between them is the dollar value of your detection investment.

"The headline breach average is the wrong number for budgeting — it's a mean dragged up by mega-breaches. Estimate your own exposure, then spend to shrink the slow-detection tail. That tail is where breaches turn catastrophic."

— SecurityBudget Research Team

Frequently asked questions

How much does a data breach cost on average?

Per IBM's Cost of a Data Breach 2025, the global average is $4.44M and the United States average is $10.22M — the highest of any region. Averages are dominated by large incidents; the median breach for a small or mid-sized business is far lower, often in the tens to low hundreds of thousands.

What is the cost per record in a data breach?

Cost per compromised record commonly falls in the range of roughly $160–$200, though it varies by data type and industry. Regulated records (health, financial, PII) sit at the high end. Per-record figures are most useful for smaller breaches; very large breaches show economies of scale per record.

Why are US data breaches so expensive?

The US combines high regulatory and legal exposure (state breach-notification laws, class actions), expensive incident-response and forensics labor, and large customer-notification and credit-monitoring obligations. Healthcare and financial breaches in the US are especially costly.

How does detection time affect breach cost?

Strongly. Breaches that take longer to identify and contain cost materially more — the longer an attacker dwells, the more data is exposed and the bigger the cleanup. Organizations with strong detection (and increasingly, security AI and automation) contain incidents faster and pay significantly less.

How can I estimate my own breach exposure?

Start from the records you hold and a per-record cost for your data type, then layer on fixed incident costs (forensics, legal, notification), business interruption, and — if relevant — a ransomware demand. Stress-test detection time: model both a fast-contained and a slow-contained scenario to bracket your range.

References

Turn risk into a budget

Exposure is the denominator; controls are the spend. Build a defensible budget against your own risk profile.

Open the budget calculator

Estimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.