IBM Cost of a Data Breach Report 2026: the global headline numbers

2nd August 2026BlogAJ Thompson

Are you ready to get in touch?

Request a Call back

Key takeaways

  • The global average cost of a data breach has climbed to $4.99 million, up 12% year-on-year and a new record, according to IBM’s 2026 Cost of a Data Breach report.
  • UK organisations are paying £3.13 million per breach on average, a slight improvement on last year, but supply chain attacks remain the single biggest cost driver.
  • AI-generated attacks are up 56%, yet 92% of organisations that suffered an AI-related breach had no AI access controls in place.
  • Ransomware has evolved beyond encryption: 41% of attacks now involve reputational threats and public shaming alongside data theft.
  • Just 26% of organisations have started planning for post-quantum cryptography, despite the long-term risk of “harvest now, decrypt later” attacks.

Every year, IBM’s Cost of a Data Breach report gives businesses a reality check on what a breach actually costs, not just in headlines, but in hard numbers. The 2026 edition, based on research from the Ponemon Institute covering 602 organisations across 16 countries and regions and 17 industries, shows costs climbing to a new high. Here’s what the findings mean for organisations in the UK and beyond.

“These figures show just how much the threat landscape has shifted in the last twelve months,” says AJ Thompson, Chief Commercial Officer at Northdoor. “Supply chain risk in particular has moved from a compliance checkbox to one of the costliest attack routes UK businesses face, and that’s before you factor in what AI and quantum computing are about to do to the threat landscape.”

A new record globally

The global average cost of a data breach now stands at $4.99 million, a 12% increase on last year and the highest figure the report has ever recorded. Higher detection rates, longer escalation processes and lost business are all pushing the number upward, meaning breaches are becoming more expensive even where organisations are getting faster at spotting them.

The UK’s supply chain problem

UK organisations reported an average breach cost of £3.13 million, a slight year-on-year improvement, but the picture is far from reassuring. Several of the UK’s most damaging attacks in the past year, including those affecting Jaguar Land Rover, M&S, Co-op and Harrods, didn’t start with the target at all. Instead, attackers exploited weaknesses in third-party suppliers to work their way in. Jaguar Land Rover’s 2025 breach alone is reported to have cost the business around £1.9 billion.

IBM’s data backs up the trend: a supply chain breach was the costliest single factor for UK businesses, adding an average of £241,620 to the cost of an incident. For any organisation relying on third-party vendors and suppliers, which is to say nearly all of them, supply chain risk deserves as much attention as internal defences.

AI: a growing target, and a growing defence

AI-generated attacks rose by 56% over the past year, and criminals aren’t just using AI as a tool to break in. They’re increasingly targeting the AI models and applications businesses now depend on. Attacks aimed at manipulating AI models through inversion techniques carried an average cost of $6 million, well above the norm.

The gap in preparedness is stark: 92% of organisations that suffered an AI-related breach had no AI-specific access controls in place. Those that had invested in AI and automation for their own defences saw a real payoff, cutting breach lifecycles by 65 days and saving an average of $1.93 million per incident.

Awareness is growing, at least. When asked whether they’d increase security spending following a breach, 64% of organisations said yes, a figure that jumped to 85% once they learned more about the scale of AI-driven threats.

Ransomware’s new playbook

Ransomware tactics are shifting. Where attackers once simply encrypted data and demanded payment for its return, many are now threatening to expose stolen data publicly and target an organisation’s reputation directly, whether or not a ransom is paid. This approach now accounts for 41% of ransomware attacks.

Ransomware itself remains a major threat: 39% of breached organisations were hit by it this year, up from 24% in 2023, a rise of over 60% in three years.

Recovery is improving, but still too slow

Given how likely a breach now is, recovery speed matters as much as prevention. Of the organisations breached, 42% were able to fully recover their data, up from 35% the year before. That’s progress, but it still leaves more than half unable to recover everything they lost.

Speed remains a challenge. Only 4% of organisations recovered fully within 50 days, while 29% took between 101 and 125 days, and 19% took more than 150 days. That said, the proportion taking over 150 days has fallen from 26% the previous year, suggesting incident response processes are gradually maturing.

Quantum: a future risk with present-day consequences

Quantum computing isn’t yet capable of breaking modern encryption at scale, but the threat is closer than many organisations are prepared for. Criminals are already harvesting encrypted data today with a view to decrypting it once quantum capability catches up.

Despite this, only 26% of organisations have a post-quantum cryptography project underway; 69% have none, and 5% aren’t sure. More broadly, 61% say they lack the controls needed to monitor and secure cryptographic assets such as keys, certificates and algorithms, a gap that will matter more, not less, as quantum capability develops.

How costs vary by sector

Globally, healthcare remains the most expensive sector for a breach at $6.64 million on average, though that’s a significant drop from $7.42 million the previous year. Financial services follows at $6.29 million (up from $5.56 million), with industrial close behind at $5.50 million (up from $5 million).

In the UK, the ranking looks a little different: financial services leads at £5.46 million, followed by services at £4.23 million and energy at £4.03 million. The energy figure is particularly concerning given the potential knock-on impact of a breach on critical infrastructure.

Where specialist support fits in

The report makes one thing clear: the cost and complexity of cyber risk is increasing across every sector, whether the threat comes directly or via the supply chain. For many organisations, closing the gap between the threats they face and the expertise they have in-house means bringing in outside support to strengthen defences, train staff, and prepare for what’s coming next from AI and quantum alike.

If you’d like to talk through what these findings mean for your organisation’s security posture, get in touch with the Northdoor team.


AJ Thompson All Author's Posts
1

Our Awards & Accreditations