🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Average Cost of a Data Breach by Industry: What the Numbers Actually Tell You

September 24, 2026 · PlayCISO

The global average cost of a data breach reached $4.88M in 2024, according to IBM's Cost of a Data Breach Report 2024. But that single number hides enormous variation by industry: a breach in a heavily regulated sector like healthcare or finance carries costs that dwarf those in retail or hospitality, driven by regulatory penalties, litigation exposure, and — the part most people underestimate — lost customers. If you're a CISO trying to justify a control budget, the industry breakdown matters far more than the global average, because it tells you what a breach actually costs your business, not the theoretical median company.

Why industry is the biggest cost variable

Breach cost is not driven primarily by the number of records lost or the technical sophistication of the attack. It's driven by what happens after — and that's where industry defines the outcome. IBM's report consistently ranks healthcare as the most expensive sector, followed by financial services, then pharmaceuticals, technology, and energy. The pattern holds year over year because the underlying drivers are structural, not random:

  • Regulatory density. Healthcare carries HIPAA exposure; finance carries GLBA, PCI DSS, and sector-specific regulators. More regulation means more mandatory notification, more investigation, and more fines.
  • Data sensitivity. A stolen medical record or a compromised bank account has a longer, more damaging tail than a leaked loyalty-program email.
  • Customer switching cost. When trust breaks in finance or healthcare, customers leave — and that churn is expensive in ways a technical team rarely sees on a dashboard.

This is why comparing yourself to the $4.88M global average is a mistake. If you're a regional bank, your realistic exposure sits well above that line. If you run a low-regulation SaaS product with non-sensitive data, it may sit below.

The cost category almost everyone gets wrong

Here's the most useful and most counterintuitive finding in IBM's Cost of a Data Breach Report 2024: the single largest cost category is lost business — roughly 40% of the total breach cost — not incident response. IBM breaks total cost into four centres: detection and escalation, notification, post-breach response, and lost business. Lost business (customer churn, reputation damage, and the cost of acquiring replacement customers) outweighs the money you spend on forensics and remediation.

The implication for budgeting is direct. Security teams tend to justify spend on tooling that reduces the technical cost of a breach — faster detection, cheaper cleanup. But if 40% of the damage is customers walking away, then the controls that preserve trust and limit the scope of exposed data (segmentation, encryption, minimizing what you collect) protect the largest cost bucket. When you present a business case, tie your ask to lost-business exposure, not to hours of analyst time saved.

How to translate the average into your own number

The industry average is a starting anchor, not an estimate for your organization. To get a defensible number you can put in front of a board:

  • Start with your industry's average from IBM's report, not the global $4.88M figure.
  • Adjust for your record volume and data sensitivity. IBM reports per-record cost, so multiply against a realistic worst-case exposed record count for your most sensitive data store — not your entire database.
  • Layer in your regulatory regime. Estimate notification obligations and likely fine ranges under the regulations that actually apply to you (GDPR, HIPAA, state breach laws).
  • Weight the lost-business component heavily. If you operate in a high-trust, high-switching-cost sector, expect the 40% lost-business share to run higher.

This gives you a range, not a point estimate — and a range framed around your own drivers is far more credible in a budget conversation than quoting a headline figure from a press release.

The 1-10-60 rule and why speed changes the math

One of the most practical levers on breach cost is detection and response speed, and the 1-10-60 rule is the benchmark security teams use to measure it. It defines target times for handling an intrusion:

  • 1 minute to detect an intrusion.
  • 10 minutes to investigate and understand it.
  • 60 minutes to contain and remediate it.

The rule matters because IBM's data consistently shows that breaches with shorter lifecycles cost dramatically less. The longer an attacker dwells, the more records are exposed, the wider the notification obligation, and — critically — the larger the lost-business hit. The 1-10-60 rule isn't a magic threshold; it's a forcing function that pushes you toward the capabilities that shorten the lifecycle: real-time detection, an actual runbook rather than an ad-hoc scramble, and pre-authorized containment actions so you're not waiting on approvals during an active breach. Cutting your breach lifecycle is one of the few interventions that reduces cost across all four IBM cost centres at once.

Breach cost vs. breach payout — two different questions

People searching for the "average payout for a data breach" are usually conflating two things: the cost a company absorbs, and the payout either from a ransomware demand or from a legal settlement to affected individuals. These are not the same as IBM's $4.88M total-cost figure.

  • Total breach cost (the IBM number) is everything the organization spends and loses — response, notification, fines, and lost business combined.
  • Ransom or extortion payouts are a subset that only apply if you're hit by ransomware and choose to pay. Paying does not reduce total cost; it typically adds to it, and IBM's data shows organizations that pay ransoms rarely come out ahead.
  • Class-action settlement payouts are per-affected-individual figures negotiated after the fact, and they feed into the litigation portion of the post-breach response cost centre.

When you model risk, keep these separate. Budgeting against a ransom figure understates your real exposure, because it ignores the lost-business share that dominates the actual cost.

What to do with this

Use the industry average as a floor, not a forecast. Build your own range using your record volumes, your regulatory exposure, and — most importantly — a lost-business estimate weighted for your sector's switching costs. Then prioritize the controls that attack the biggest cost drivers: shrinking the exposed data footprint, and shortening the breach lifecycle toward something like the 1-10-60 targets. Those two moves hit the 40% lost-business bucket harder than any amount of after-the-fact forensic spend.

If you want to skip the manual math, PlayCISO's free Breach Cost Calculator lets you plug in your industry, record volume, and regulatory context to produce a defensible cost range you can take straight into a board conversation.

Ready to practise the decisions these articles describe?

Run a free War Room →