IBM Security survey of 533 global organizations in the year to March 2023: average data breach costs rose 15% YoY to $4.45M and only ~33% were detected in-house
A new report from IBM Security today finds that the relentless rise in data breach costs continues unabated in 2023 …
Context & Ripple Effects
This is one installment of IBM Security's annual breach-cost benchmark, which has tracked an unbroken climb since at least 2018: $3.86M that year, $3.92M in 2019, then $3.86M again in 2020 before the curve steepened to $4.24M in 2021 and $4.35M last year.
The 2023 reading of $4.45M extends that streak with the sharpest single-year jump in the series' recent history — 15% — but the more operationally telling number is that only about a third of surveyed organizations caught their own breaches, meaning most victims learn of incidents from outside parties.
First-order effects
- Security teams at the 533 surveyed organizations now budget against a $4.45M average incident cost, up 15% year over year, while two-thirds of breaches are surfaced by external parties rather than internal tooling.
Second-order effects
- The detection gap shifts spending toward outside help — managed detection and incident-response providers capture demand from buyers whose own stacks missed the breach, and cyber-insurers gain leverage to price premiums off these published benchmarks.
Third-order effects
- If in-house detection stays near one-third across successive editions of this survey, breach response structurally consolidates around external specialists and insurers, turning the annual IBM figure into a de facto reference rate for security budgets and underwriting.
The trend: IBM's annual benchmark shows breach costs compounding faster than most organizations' ability to detect incidents themselves, pushing detection and response toward external providers.