An economy built on data
Almost every organisation today is, in some sense, a data business. A law firm holds confidential case files. A healthcare provider holds medical records. A manufacturer holds intellectual property. Even a business that thinks of itself as small — a clinic, a bookkeeper, a trades outfit — is usually sitting on a meaningful pile of names, dates of birth, bank details and passwords.
Cloud computing, remote work and now AI tools have accelerated all of this. IDC estimates the amount of data the world creates each year will grow from 132.4 zettabytes in 2023 to 393.9 zettabytes by 2028 — near enough a tripling in five years. For a legitimate organisation, that data creates value. For a criminal, it creates opportunity.
Cybercrime has professionalised
The popular image is still someone in a hoodie, alone, in a dark room. The reality is closer to a supply chain. Different criminal groups specialise in different stages of an attack — one builds ransomware, another harvests stolen credentials, another sells "initial access" into a company that's already been quietly compromised.
This division of labour has lowered the skill required to launch an attack, and generative AI has lowered it further — producing convincing phishing emails, translating scams into other languages, and helping attackers research a target before they ever send the first message.
A record USD 4.99 million
IBM's Cost of a Data Breach Report, now in its 21st year, remains the closest thing the industry has to a benchmark — it measures the full business cost of a breach, not just the technical clean-up. The 2026 edition, based on 602 organisations breached between March 2025 and February 2026, found the global average had reached a record USD 4.99 million — a 12% jump on the year before, and the steepest annual rise since the pandemic.
Global average cost of a breach, 2026 — a 12% rise on 2025 and a record high.
IBM Cost of a Data Breach Report, 2026Average cost in the United States — more than double the global figure, for the 15th year running.
IBM Cost of a Data Breach Report, 2026Average cost in Australia — up 38% since 2019.
IBM Cost of a Data Breach Report, 2026 (AU)A single average always flattens the picture — a small number of very large, very public breaches pull the mean upward. But the trend line matters more than any one figure: costs have risen in nine of the last ten years.
Detection and lost business dominate the bill
Most people picture a breach as a single bill: new servers, a consultant's invoice, maybe a ransom. IBM's methodology splits the real cost into four categories, and the pattern has held for two decades.
How a typical breach's cost is split
The category that rarely shows up on an invoice — lost business — is consistently the most underestimated part of the bill.
Detection and escalation is usually the first big invoice: forensic investigators tracing how attackers got in. Notification covers the legal and communications work required once regulators and affected people need to be told. Post-breach response is the security upgrade that, ironically, would have cost less if it had happened before the breach. And lost business — customers moving to a competitor, stalled sales, staff pulled off their real jobs for weeks — rarely appears as a single line item, yet frequently becomes the largest cost of all.
AI is rewriting the economics of an attack
The 2026 report's central story isn't the dollar figure — it's how artificial intelligence is now shaping both sides of the fight. One in four malicious breaches IBM studied were AI-enabled: mostly deepfake impersonation and AI-generated malware. That's a 56% jump year over year, and those AI-enabled breaches cost an average of $6.04 million — roughly a million dollars more than a malicious breach without AI involved.
+56%
Year-over-year rise in AI-enabled malicious breaches.
$6.04M
Average cost of an AI-enabled breach — about $1M above the non-AI average.
~$2M saved
Cost reduction for organisations using AI and automation extensively in their own defences.
The other side of the ledger is more encouraging: organisations that use AI and automation extensively in their own security operations cut breach costs by close to $2 million and contained incidents roughly two months faster than those that don't. One thing hasn't changed, though — for the fourth year running, phishing remained the single most common way attackers first got in.
The human element
Verizon's 2026 Data Breach Investigations Report — the largest dataset in its 19-year history, covering more than 22,000 confirmed breaches across 145 countries — found the human element present in 62% of breaches. That's up slightly from 60% the year before, and within the margin of error, it hasn't really moved in three straight editions of the report, despite everything organisations have spent on technology in the meantime.
Social engineering was the third most common attack pattern, appearing in 16% of confirmed breaches. Voice and SMS-based phishing attempts had a 40% higher success rate in simulations than the same attempts sent by email — a channel most awareness programs still don't test.
Verizon 2026 Data Breach Investigations ReportMost workplace training still assumes the threat arrives as an email. Increasingly, it arrives as a phone call, a text message, or a voice that sounds exactly like someone's manager. The mechanics of "stop, check, then act" don't change — but the moment people need to remember to apply them is moving off the screen and into their pocket.
Closer to home
The OAIC's Notifiable Data Breaches dashboard for the first half of 2025 shows malicious or criminal attacks still the largest source of breaches, at 59% of notifications (308 of them). But the sharper move was in human error, which jumped to 37% of all notifications (193) — a trend the regulator itself flagged as a growing concern.
IBM's Australian figures for 2026 tell a similar story from the cost side: the national average now sits at AU$4.22 million, up 38% since 2019. The gap between organisations that use AI well and those that don't is stark locally too — AU$3.46 million for extensive AI users, against AU$5.21 million for those with none.
The costliest way in for Australian organisations wasn't a software exploit — it was the abuse of valid accounts, followed by social engineering and IT-helpdesk impersonation, then plain phishing. All three are, at their core, attacks on a person's judgement rather than a system's defences.
What this means for your organisation
The invoice is the smallest part
Detection, lost business and months of disruption dwarf the cost of the technical clean-up.
AI cuts both ways
It's making attacks cheaper to launch, and — used well — defences meaningfully cheaper to run.
The human element hasn't moved
62% of breaches still involve a person, and mobile-based social engineering now outperforms email.
Australia is rising faster
Up 38% since 2019, with human-error breaches climbing fastest of all in the regulator's own data.
See how Mono addresses the human element directly.
Click or Flick is built on realistic simulations and behaviour-based training that moves the one variable three years of technology spend hasn't touched. If this resonated, the program page is the natural next step.