Cybersecurity · Threat Landscape

The true cost of a data breach

Written by the Mono training team · · 11 min read Share
Executive summary The global average cost of a data breach has reached a record USD 4.99 million — a 12% jump in a single year, driven mostly by detection costs and lost business rather than technical clean-up. AI is now reshaping the economics on both sides: attacks are getting cheaper to launch, while organisations that use AI well in their own defences are cutting breach costs substantially. Meanwhile the human element — the fact that most breaches still start with a person, not a system — hasn't moved in three years of research, and Australia's own numbers are rising faster than the global average.
Data sources
IBM Cost of a Data Breach Report (2026)·Verizon Data Breach Investigations Report (2026)·OAIC Notifiable Data Breaches statistics (Jan–Jun 2025)·IDC Global StorageSphere Forecast
Figures reflect publicly reported research as of August 2026. Findings evolve — verify current studies before citing externally.
01Every organisation is a data business

An economy built on data

Almost every organisation today is, in some sense, a data business. A law firm holds confidential case files. A healthcare provider holds medical records. A manufacturer holds intellectual property. Even a business that thinks of itself as small — a clinic, a bookkeeper, a trades outfit — is usually sitting on a meaningful pile of names, dates of birth, bank details and passwords.

Cloud computing, remote work and now AI tools have accelerated all of this. IDC estimates the amount of data the world creates each year will grow from 132.4 zettabytes in 2023 to 393.9 zettabytes by 2028 — near enough a tripling in five years. For a legitimate organisation, that data creates value. For a criminal, it creates opportunity.

02Not a lone hacker anymore

Cybercrime has professionalised

The popular image is still someone in a hoodie, alone, in a dark room. The reality is closer to a supply chain. Different criminal groups specialise in different stages of an attack — one builds ransomware, another harvests stolen credentials, another sells "initial access" into a company that's already been quietly compromised.

This division of labour has lowered the skill required to launch an attack, and generative AI has lowered it further — producing convincing phishing emails, translating scams into other languages, and helping attackers research a target before they ever send the first message.

03The number that makes the headlines

A record USD 4.99 million

IBM's Cost of a Data Breach Report, now in its 21st year, remains the closest thing the industry has to a benchmark — it measures the full business cost of a breach, not just the technical clean-up. The 2026 edition, based on 602 organisations breached between March 2025 and February 2026, found the global average had reached a record USD 4.99 million — a 12% jump on the year before, and the steepest annual rise since the pandemic.

$4.99M

Global average cost of a breach, 2026 — a 12% rise on 2025 and a record high.

IBM Cost of a Data Breach Report, 2026
$11.5M

Average cost in the United States — more than double the global figure, for the 15th year running.

IBM Cost of a Data Breach Report, 2026
AU$4.22M

Average cost in Australia — up 38% since 2019.

IBM Cost of a Data Breach Report, 2026 (AU)

A single average always flattens the picture — a small number of very large, very public breaches pull the mean upward. But the trend line matters more than any one figure: costs have risen in nine of the last ten years.

04Where it actually goes

Detection and lost business dominate the bill

Most people picture a breach as a single bill: new servers, a consultant's invoice, maybe a ransom. IBM's methodology splits the real cost into four categories, and the pattern has held for two decades.

How a typical breach's cost is split

Total ≈ $4.44M
Lost business$1.47M · 33%
Detection & escalation$1.47M · 33%
Post-breach response$1.11M · 25%
Notification$0.39M · 9%
Figures are IBM's most recently published category breakdown (2025 report). In the 2026 report, detection & escalation and lost business together made up 63% of the newer $4.99M total.

The category that rarely shows up on an invoice — lost business — is consistently the most underestimated part of the bill.

Detection and escalation is usually the first big invoice: forensic investigators tracing how attackers got in. Notification covers the legal and communications work required once regulators and affected people need to be told. Post-breach response is the security upgrade that, ironically, would have cost less if it had happened before the breach. And lost business — customers moving to a competitor, stalled sales, staff pulled off their real jobs for weeks — rarely appears as a single line item, yet frequently becomes the largest cost of all.

05Cutting both ways

AI is rewriting the economics of an attack

The 2026 report's central story isn't the dollar figure — it's how artificial intelligence is now shaping both sides of the fight. One in four malicious breaches IBM studied were AI-enabled: mostly deepfake impersonation and AI-generated malware. That's a 56% jump year over year, and those AI-enabled breaches cost an average of $6.04 million — roughly a million dollars more than a malicious breach without AI involved.

+56%

Year-over-year rise in AI-enabled malicious breaches.

$6.04M

Average cost of an AI-enabled breach — about $1M above the non-AI average.

~$2M saved

Cost reduction for organisations using AI and automation extensively in their own defences.

The other side of the ledger is more encouraging: organisations that use AI and automation extensively in their own security operations cut breach costs by close to $2 million and contained incidents roughly two months faster than those that don't. One thing hasn't changed, though — for the fourth year running, phishing remained the single most common way attackers first got in.

06The variable that hasn't moved

The human element

Verizon's 2026 Data Breach Investigations Report — the largest dataset in its 19-year history, covering more than 22,000 confirmed breaches across 145 countries — found the human element present in 62% of breaches. That's up slightly from 60% the year before, and within the margin of error, it hasn't really moved in three straight editions of the report, despite everything organisations have spent on technology in the meantime.

Social engineering was the third most common attack pattern, appearing in 16% of confirmed breaches. Voice and SMS-based phishing attempts had a 40% higher success rate in simulations than the same attempts sent by email — a channel most awareness programs still don't test.

Verizon 2026 Data Breach Investigations Report

Most workplace training still assumes the threat arrives as an email. Increasingly, it arrives as a phone call, a text message, or a voice that sounds exactly like someone's manager. The mechanics of "stop, check, then act" don't change — but the moment people need to remember to apply them is moving off the screen and into their pocket.

07The view from Australia

Closer to home

The OAIC's Notifiable Data Breaches dashboard for the first half of 2025 shows malicious or criminal attacks still the largest source of breaches, at 59% of notifications (308 of them). But the sharper move was in human error, which jumped to 37% of all notifications (193) — a trend the regulator itself flagged as a growing concern.

IBM's Australian figures for 2026 tell a similar story from the cost side: the national average now sits at AU$4.22 million, up 38% since 2019. The gap between organisations that use AI well and those that don't is stark locally too — AU$3.46 million for extensive AI users, against AU$5.21 million for those with none.

The costliest way in for Australian organisations wasn't a software exploit — it was the abuse of valid accounts, followed by social engineering and IT-helpdesk impersonation, then plain phishing. All three are, at their core, attacks on a person's judgement rather than a system's defences.

Abuse of valid accounts — AU$4.87M Social engineering / IT impersonation — AU$4.78M Phishing — AU$4.48M
Key takeaways

What this means for your organisation

01

The invoice is the smallest part

Detection, lost business and months of disruption dwarf the cost of the technical clean-up.

02

AI cuts both ways

It's making attacks cheaper to launch, and — used well — defences meaningfully cheaper to run.

03

The human element hasn't moved

62% of breaches still involve a person, and mobile-based social engineering now outperforms email.

04

Australia is rising faster

Up 38% since 2019, with human-error breaches climbing fastest of all in the regulator's own data.

Enjoyed this article?

See how Mono addresses the human element directly.

Click or Flick is built on realistic simulations and behaviour-based training that moves the one variable three years of technology spend hasn't touched. If this resonated, the program page is the natural next step.