The 2026 Incident Cost Index: Every Type of Business Incident Priced
Published data on incident costs is fragmented across six or more annual reports from different research organisations, each covering a different incident type. This index aggregates those figures into a single, citation-grade reference table.
Every row cites its primary source. Methodology notes explain what each figure includes and excludes. For interactive scenario modeling, use incidentcostcalculator.com.
The Master Index Table
| Incident Type | Avg Cost Per Incident | Annual Org Impact | YoY | Source | Notes |
|---|---|---|---|---|---|
| Data breach (global avg) | $4.44M | Varies | -9% | IBM CODB 2025 | See /types/data-breach |
| Data breach (US avg) | $10.22M | Varies | +6% | IBM CODB 2025 | Record high for US |
| Data breach (Healthcare) | $7.42M | Varies | -24% | IBM CODB 2025 | Still highest industry |
| Data breach (Finance) | $6.08M | Varies | +3% | IBM CODB 2025 | Heavily regulated |
| Ransomware attack | $5.75M | Varies | +17% | Resilience 2025 | See /types/ransomware |
| Ransomware - ransom demand avg | $2.20M | n/a | +8% | Coveware Q4 2024 | Actual payment often lower |
| Insider threat (credential theft) | $779K | $17.4M total org | +15% | Ponemon 2025 | Per-incident figure |
| Insider threat (malicious) | $715K | Included above | +2% | Ponemon 2025 | 25% of insider incidents |
| Insider threat (negligence) | $677K | $8.8M total org | +1% | Ponemon 2025 | 55% of insider incidents |
| P1 IT incident (avg) | $794K | $19.85M (25 P1s/yr) | n/a | PagerDuty 2024 | 25 P1 incidents/yr average |
| Service outage (mid-market+) | $14K/min | Varies | n/a | Various | See outagecost.com |
| Service outage (large enterprise) | $23,750/min | Varies | n/a | Various | $1.425M/hr |
| Manufacturing downtime avg | $260K/hr | Varies | n/a | Various | OT/ICS environments |
| Automotive downtime | $3M/hr | Varies | n/a | ABB 2025 | Assembly line stoppage |
| Supply chain attack | $4.76M | Varies | n/a | IBM CODB 2025 | Longest detection time |
| DDoS attack | $120K-$2M | Varies | n/a | Various | See /types/ddos |
| Compliance violation (HIPAA Tier 4) | $73K-$2.19M | n/a | n/a | HHS 2025 | Per violation |
| Compliance violation (GDPR max) | 4% global revenue | n/a | n/a | GDPR Art. 83 | See gdprfine.com |
| Compliance violation (PCI DSS) | $5K-$100K/month | + card brand fines | n/a | PCI SSC | Plus mandatory forensics |
Sources: IBM Cost of a Data Breach Report 2025, Ponemon Cost of Insider Risks 2025, PagerDuty State of Digital Operations 2024, Resilience Cyber Risk Report 2025, Coveware Q4 2024 Ransomware Report, ABB 2025 Manufacturing Report. Updated April 2026.
Methodology: What Each Figure Includes and Excludes
The term "average cost" means different things across primary sources. Understanding the methodology is essential for correct interpretation.
IBM uses a 4-activity cost model: detection and escalation, notification, post-breach response, and lost business. Lost business includes customer churn, reputational impact, and revenue lost during breach. Notably, IBM CODB excludes ransom payments from breach cost figures, as the report focuses specifically on breach costs. The 2025 figure of $4.44M is based on 604 organisations across 17 industries and 16 countries.
Ponemon surveys report an annual organisational total cost ($17.4M average) that includes monitoring tools, investigation, escalation, incident response, and containment costs. The per-incident figures ($779K credential theft, $715K malicious, $677K negligent) are derived by dividing total costs by incident frequency data.
PagerDuty's $794K per P1 incident figure includes revenue loss during downtime, productivity cost of personnel responding, customer impact, SLA penalties, and post-incident review costs. The 25 P1 incidents per year average is based on survey data from DevOps and SRE practitioners across mid-market and enterprise organisations.
Resilience's $5.75M ransomware cost figure is a total-cost figure that includes ransom payment (where paid), restoration and rebuild costs, forensics, legal counsel, PR, regulatory notification, and downtime revenue loss. This is notably higher than IBM's CODB breach figures because ransomware incidents typically involve all four cost categories simultaneously.
Year-over-Year Trends
Key trend signals from 2020-2025 primary source data.
How to Use This Index
Use the per-incident figures as a starting point for risk budget conversations. Multiply by the estimated probability of each incident type for your industry to derive an expected annual loss.
The consolidated index table is formatted for board-level presentations. Cite the source column alongside the figure to establish credibility with non-technical audiences.
Cyber insurers ask for incident history and risk profile. Use the industry and size breakdown pages to benchmark your organisation's expected cost profile versus the index average.
Use the index as an input to FAIR (Factor Analysis of Information Risk) or ALE (Annualised Loss Expectancy) models. Each row provides a Loss Magnitude estimate for the corresponding threat scenario.
Frequently Asked Questions
What is the Incident Cost Index?
How often is the index updated?
Why did global data breach costs drop in 2025?
Are these figures averages or medians?
Primary Source Citations
IBM Cost of a Data Breach Report 2025. IBM Security, 2025. Annual global study covering 604 organisations across 17 industries and 16 countries. The primary source for data breach cost figures globally and by industry.
Ponemon Institute Cost of Insider Risks Global Report 2025. Ponemon Institute, sponsored by DTEX Systems, 2025. Annual survey of 1,000+ IT and security practitioners covering insider threat cost by type, industry, and containment time.
Verizon Data Breach Investigations Report 2025. Verizon Business, 2025. Annual breach statistics covering threat actors, attack vectors, and industry breakdown based on real incident data.
PagerDuty State of Digital Operations 2024. PagerDuty, 2024. Survey-based study of DevOps and SRE practitioners on incident frequency, cost, and business impact. Source for the $794K per P1 incident figure.
Resilience Cyber Risk Report 2025. Resilience, 2025. Annual analysis of cyber insurance claims data. Source for the $5.75M ransomware total cost figure and the 17% year-over-year increase.
Coveware Q4 2024 Ransomware Marketplace Report. Coveware, January 2025. Quarterly analysis of ransomware payment trends, ransom demand data, and recovery costs based on incident response case data.
Mandiant M-Trends 2025. Mandiant (Google), 2025. Annual threat intelligence report including breach dwell time benchmarks and attack lifecycle data.