Data breach costs on the rise, IBM study shows

The cost of a data breach has risen 12% over the past five years to £3.2m on average globally, with a 10.56% increase in the UK in the past year alone to £2.99m on average, a study reveals.
In the UK, the average size of a data breach has increased 3.6% and the per capita cost per lost or stolen record is £119, which represents an increase of 9.69% from 2018 and has nearly doubled in the past ten years, according to the annual Cost of a data breach report conducted by the Ponemon Institute and sponsored by IBM Security.
The rising costs are representative of the multiyear financial impact of breaches, increased regulation and the complex process of resolving criminal attacks, the report said.
The report based on in-depth interviews with more than 500 companies around the world who suffered a breach over the past year, including 45 in the UK, and takes into account hundreds of cost factors including legal, regulatory and technical activities to loss of brand equity, customers, and employee productivity.
The study found that data breaches in the US are the most expensive, costing $8.19m (£6.6m), or more than double the average for worldwide companies in the study, and that the cost for data breaches in the US has increased by 130% over the past 14 years from $3.54m (£2.8m) in the 2006 study.
The financial consequences of a data breach, the report said, can be particularly acute for small and midsize businesses. Globally, companies with fewer than 500 employees suffered losses of more than £2m on average, which is a potentially crippling amount for small businesses, which typically earn £40.1m or less in annual revenue.
The report also examined the longtail financial impact of a data breach, finding that the effects of a data breach are felt for years. While an average of 67% of data breach costs were realised within the first year after a breach, 22% accrued in the second year and another 11% accumulated more than two years after a breach.
The longtail costs were higher in the second and third years for organisations in highly regulated environments, such as healthcare, financial services, energy and pharmaceuticals.
“Cyber crime represents big money for cyber criminals, and unfortunately that equates to significant losses for businesses,” said Wendi Whitmore, global lead for IBM X-Force Incident Response and Intelligence Services.
“With organisations facing the loss or theft of over 11.7 billion records in the past three years alone, companies need to be aware of the full financial impact that a data breach can have on their bottom line –and focus on how they can reduce these costs,” she said.


