Report · Cost Analysis · 2026
Cost of a Data Breach vs. Cost of Controls (2026)
A vendor-neutral look at how the price of a typical mid-market security control program compares to the cost of a single breach.
- The global average breach now costs $4.44M, while the US average reaches $10.22M (IBM Cost of a Data Breach 2025).
- A full control program for an 800-person healthcare firm runs roughly $1.2M/yr — about one-eighth of a single average US breach.
- Phishing and stolen or reused credentials remain the leading initial-access vectors (Verizon DBIR 2025), so spend follows where attackers actually get in.
- Controls reduce expected loss; they do not eliminate it. Budget against probability-weighted risk, not against a promise of prevention.
Security budgets are easiest to defend when they are framed against the thing they exist to prevent: the cost of a breach. The figures below come from public, vendor-neutral sources — IBM’s Cost of a Data Breach study, the Verizon Data Breach Investigations Report (DBIR), and CISA’s Known Exploited Vulnerabilities catalog — and they point to a consistent conclusion. A complete control program for a mid-sized organization typically costs a fraction of one serious incident. This report walks through the numbers and, importantly, the way to reason about them without overclaiming what any tool can deliver.
The breach numbers, in plain terms
IBM’s 2025 Cost of a Data Breach study puts the global average breach at $4.44M. In the United States the figure is far higher — a $10.22M average — driven by larger regulatory penalties, higher legal exposure, and steeper detection-and-response costs. These are averages across thousands of incidents, so any single organization’s outcome can land well below or well above the line. The point of the average is not to predict your breach; it is to size the bet you are making when you fund — or defer — a control.
| Metric | Figure | Source |
|---|---|---|
| Global average breach | $4.44M | IBM Cost of a Data Breach 2025 |
| US average breach | $10.22M | IBM Cost of a Data Breach 2025 |
| Leading initial-access vectors | Phishing, stolen/reused credentials | Verizon DBIR 2025 |
| Large per-incident losses | Business email compromise (BEC) | FBI IC3 |
Two patterns matter for budgeting. First, the Verizon DBIR continues to identify phishing and stolen or reused credentials as the most common ways attackers get their first foothold. Second, the FBI’s Internet Crime Complaint Center (IC3) reports that business email compromise produces some of the largest dollar losses per incident of any category. Both point spending toward identity, email security, and awareness rather than exotic edge cases.
A worked example: the 800-person healthcare firm
Consider an 800-employee healthcare organization — a regulated environment with sensitive records and a real obligation to protect them. A full control program covering endpoint protection, identity and access management, email security, vulnerability management, an MDR service for 24/7 monitoring, security awareness training, and periodic penetration testing comes to roughly $1.2M per year at the scale and maturity this site models.
Set that against the US average breach of $10.22M. The annual program is about one-eighth the cost of a single average breach — and the program runs every year, covering many threats, while the breach figure is one event.
| Line | Approx. annual cost | What it addresses |
|---|---|---|
| Full control program (800 employees, healthcare) | ~$1.2M | Layered prevention, detection, response, training |
| Single US average breach | $10.22M | One incident, after the fact |
| Global average breach | $4.44M | One incident, after the fact |
The comparison is not “spend $1.2M to avoid $10.22M.” It is “spend $1.2M per year to meaningfully lower the probability and severity of an event whose average cost is $10.22M.” That distinction is the whole argument — and it is an honest one.
Expected loss, not guaranteed prevention
No control program prevents every breach, and no vendor can responsibly claim otherwise. The defensible way to justify a budget is expected loss: the cost of an incident multiplied by its annual probability.
Suppose, for illustration, an organization estimates a 10% annual chance of a material breach. At a US-average severity of $10.22M, the expected loss is roughly $1.0M per year before any controls. If a well-chosen program credibly cuts that probability — say, by half — the expected loss drops by about $500K/yr. Against a program that costs ~$1.2M, the math is not a slam-dunk on prevention alone; the case is strengthened by the controls that also reduce severity (faster detection shrinks dwell time and total cost), satisfy regulatory requirements, and lower cyber-insurance premiums. IBM’s data consistently shows that organizations with mature detection and response see materially lower per-breach costs.
The honest framing: controls shift the odds and shrink the damage. They do not buy certainty.
Where the dollars do the most work
Because the DBIR keeps pointing at phishing and credentials, the highest-leverage spend tends to cluster in a few places:
- Identity and access management / MFA — directly counters the stolen-credential vector that leads the DBIR.
- Email security and awareness training — addresses phishing and the BEC losses flagged by FBI IC3.
- Vulnerability and patch management — CISA’s Known Exploited Vulnerabilities (KEV) catalog lists flaws confirmed to be exploited in the wild; closing those is a high-signal, low-cost place to start.
- Managed detection and response (MDR) — compresses detection-and-response time, which IBM links to lower breach cost.
Aligning spend to CISA’s KEV list and the DBIR’s vector data means the budget tracks where attackers actually succeed, rather than chasing the threat that made the most headlines.
What this means for a budget
The takeaway is not that more spending is always better. Past a point, marginal controls deliver diminishing risk reduction, and a $1.2M program that is well-targeted will outperform a larger one that is scattered. Use the breach averages as a ceiling on rational spend — it rarely makes sense to spend more annually than a probability-weighted incident would cost — and use the DBIR and KEV data to direct the dollars you do commit toward the vectors that matter most.
How to use this
Plug your own headcount, industry, and current controls into the Cybersecurity Budget Calculator to estimate a control-program cost for your organization, then compare it against the breach averages above. Treat the result as an expected-loss conversation with leadership — not a guarantee — and revisit it as your risk profile and the threat data change.
Sources
Figures are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.
See it for your organization
Turn these benchmarks into a budget tailored to your risk profile — free and ungated.