Updated April 2026 · Next review October 2026

The 2026 Incident Cost Index: Every Type of Business Incident Priced

Published data on incident costs is fragmented across six or more annual reports from different research organisations, each covering a different incident type. This index aggregates those figures into a single, citation-grade reference table.

Every row cites its primary source. Methodology notes explain what each figure includes and excludes. For interactive scenario modeling, use incidentcostcalculator.com.

The Master Index Table

Incident TypeAvg Cost Per IncidentAnnual Org ImpactYoYSourceNotes
Data breach (global avg)$4.44MVaries-9%IBM CODB 2025See /types/data-breach
Data breach (US avg)$10.22MVaries+6%IBM CODB 2025Record high for US
Data breach (Healthcare)$7.42MVaries-24%IBM CODB 2025Still highest industry
Data breach (Finance)$6.08MVaries+3%IBM CODB 2025Heavily regulated
Ransomware attack$5.75MVaries+17%Resilience 2025See /types/ransomware
Ransomware - ransom demand avg$2.20Mn/a+8%Coveware Q4 2024Actual payment often lower
Insider threat (credential theft)$779K$17.4M total org+15%Ponemon 2025Per-incident figure
Insider threat (malicious)$715KIncluded above+2%Ponemon 202525% of insider incidents
Insider threat (negligence)$677K$8.8M total org+1%Ponemon 202555% of insider incidents
P1 IT incident (avg)$794K$19.85M (25 P1s/yr)n/aPagerDuty 202425 P1 incidents/yr average
Service outage (mid-market+)$14K/minVariesn/aVariousSee outagecost.com
Service outage (large enterprise)$23,750/minVariesn/aVarious$1.425M/hr
Manufacturing downtime avg$260K/hrVariesn/aVariousOT/ICS environments
Automotive downtime$3M/hrVariesn/aABB 2025Assembly line stoppage
Supply chain attack$4.76MVariesn/aIBM CODB 2025Longest detection time
DDoS attack$120K-$2MVariesn/aVariousSee /types/ddos
Compliance violation (HIPAA Tier 4)$73K-$2.19Mn/an/aHHS 2025Per violation
Compliance violation (GDPR max)4% global revenuen/an/aGDPR Art. 83See gdprfine.com
Compliance violation (PCI DSS)$5K-$100K/month+ card brand finesn/aPCI SSCPlus mandatory forensics

Sources: IBM Cost of a Data Breach Report 2025, Ponemon Cost of Insider Risks 2025, PagerDuty State of Digital Operations 2024, Resilience Cyber Risk Report 2025, Coveware Q4 2024 Ransomware Report, ABB 2025 Manufacturing Report. Updated April 2026.

Methodology: What Each Figure Includes and Excludes

The term "average cost" means different things across primary sources. Understanding the methodology is essential for correct interpretation.

IBM Cost of a Data Breach Report (CODB)

IBM uses a 4-activity cost model: detection and escalation, notification, post-breach response, and lost business. Lost business includes customer churn, reputational impact, and revenue lost during breach. Notably, IBM CODB excludes ransom payments from breach cost figures, as the report focuses specifically on breach costs. The 2025 figure of $4.44M is based on 604 organisations across 17 industries and 16 countries.

Ponemon Cost of Insider Risks

Ponemon surveys report an annual organisational total cost ($17.4M average) that includes monitoring tools, investigation, escalation, incident response, and containment costs. The per-incident figures ($779K credential theft, $715K malicious, $677K negligent) are derived by dividing total costs by incident frequency data.

PagerDuty State of Digital Operations

PagerDuty's $794K per P1 incident figure includes revenue loss during downtime, productivity cost of personnel responding, customer impact, SLA penalties, and post-incident review costs. The 25 P1 incidents per year average is based on survey data from DevOps and SRE practitioners across mid-market and enterprise organisations.

Resilience Cyber Risk Report (Ransomware)

Resilience's $5.75M ransomware cost figure is a total-cost figure that includes ransom payment (where paid), restoration and rebuild costs, forensics, legal counsel, PR, regulatory notification, and downtime revenue loss. This is notably higher than IBM's CODB breach figures because ransomware incidents typically involve all four cost categories simultaneously.

Year-over-Year Trends

Key trend signals from 2020-2025 primary source data.

Data Breach Global Average (IBM)
2019$3.92M
2020$3.86M
2021$4.24M
2022$4.35M
2023$4.45M
2024$4.88M
2025$4.44M
US Data Breach Average (IBM)
2019$8.19M
2020$8.64M
2021$9.05M
2022$9.44M
2023$9.48M
2024$9.65M
2025$10.22M
AI Savings on Breach Lifecycle (IBM 2025)
Average breach lifecycle287 days
With AI tools207 days
Days saved80 days
Cost saved$1.9M
Ransomware Cost Trend (Resilience)
2021$3.01M
2022$4.12M
2023$4.54M
2024$4.91M
2025$5.75M

How to Use This Index

Budgeting

Use the per-incident figures as a starting point for risk budget conversations. Multiply by the estimated probability of each incident type for your industry to derive an expected annual loss.

Board Presentations

The consolidated index table is formatted for board-level presentations. Cite the source column alongside the figure to establish credibility with non-technical audiences.

Insurance Applications

Cyber insurers ask for incident history and risk profile. Use the industry and size breakdown pages to benchmark your organisation's expected cost profile versus the index average.

Risk Assessments

Use the index as an input to FAIR (Factor Analysis of Information Risk) or ALE (Annualised Loss Expectancy) models. Each row provides a Loss Magnitude estimate for the corresponding threat scenario.

Frequently Asked Questions

What is the Incident Cost Index?
The Incident Cost Index is a consolidated reference table aggregating the average per-incident cost across all major business incident types. It is the only resource that presents this cross-category comparison in a single table, drawn from IBM, Ponemon, PagerDuty, Resilience, and other primary sources.
How often is the index updated?
The index is updated twice per year, in April and October. Data sources (IBM CODB, Ponemon, Verizon DBIR, etc.) publish annually, typically in Q3-Q4 of each year. The April 2026 edition incorporates all 2025 primary source reports published to date.
Why did global data breach costs drop in 2025?
IBM's 2025 report attributes the 9% global drop to improved AI-assisted detection. Organisations using AI security automation identified and contained breaches 80 days faster, saving approximately $1.9M per incident. The US average rose 6% to $10.22M, suggesting the improvement is unevenly distributed geographically.
Are these figures averages or medians?
Most figures are means (averages), not medians. This matters because a small number of very large incidents significantly skew the average upward. Median costs are typically 30-50% lower than mean costs. IBM and Ponemon both report means. When using these figures for budgeting, consider whether your organisation's risk profile is closer to the average or to a lower-cost scenario.

Primary Source Citations

IBM Cost of a Data Breach Report 2025. IBM Security, 2025. Annual global study covering 604 organisations across 17 industries and 16 countries. The primary source for data breach cost figures globally and by industry.

Ponemon Institute Cost of Insider Risks Global Report 2025. Ponemon Institute, sponsored by DTEX Systems, 2025. Annual survey of 1,000+ IT and security practitioners covering insider threat cost by type, industry, and containment time.

Verizon Data Breach Investigations Report 2025. Verizon Business, 2025. Annual breach statistics covering threat actors, attack vectors, and industry breakdown based on real incident data.

PagerDuty State of Digital Operations 2024. PagerDuty, 2024. Survey-based study of DevOps and SRE practitioners on incident frequency, cost, and business impact. Source for the $794K per P1 incident figure.

Resilience Cyber Risk Report 2025. Resilience, 2025. Annual analysis of cyber insurance claims data. Source for the $5.75M ransomware total cost figure and the 17% year-over-year increase.

Coveware Q4 2024 Ransomware Marketplace Report. Coveware, January 2025. Quarterly analysis of ransomware payment trends, ransom demand data, and recovery costs based on incident response case data.

Mandiant M-Trends 2025. Mandiant (Google), 2025. Annual threat intelligence report including breach dwell time benchmarks and attack lifecycle data.

IncidentCost.com is an independent educational resource. All cost figures are drawn from published industry research including IBM's Cost of a Data Breach Report, Ponemon Institute Cost of Insider Risks Report, Verizon Data Breach Investigations Report, Atlassian incident management research, and PagerDuty incident surveys. This site is not affiliated with IBM, Ponemon Institute, Verizon, Atlassian, PagerDuty, or any security vendor. Figures are for educational and planning purposes only.