IBM report on data breaches: cost to firms is up by 12% over five years, reaching $3.92M on average; hacked firms with <500 staff suffer $2.5M losses on average
Charlie Osborne / ZDNet :
Context & Ripple Effects
This is the 2019 installment of IBM's annual Cost of a Data Breach series, which had already put the global average at $3.86M in its 2018 study. The new figure of $3.92M extends a five-year climb, and the standout finding is the small-business exposure: firms with fewer than 500 staff lose $2.5M per breach on average.
The series has become the de facto annual benchmark for breach economics — each July release resets the baseline, with the following year's 2020 report holding near-flat before costs resume climbing through the 2020s.
First-order effects
- Firms under 500 staff now carry a quantified worst-case of $2.5M per incident — a loss scale that hits a small company's balance sheet far harder than the $3.92M average hits an enterprise, sharpening the case for managed security over in-house teams.
- Security vendors and cyber-insurance underwriters gain a fresh, citable dataset for pricing products against breach severity by company size.
Second-order effects
- As the published cost floor rises year after year — $3.86M in 2018, $3.92M here, then $4.35M by the 2022 study — insurers reprice premiums upward and boards treat breach reserves as a standing budget line rather than a contingency.
- Small firms facing $2.5M exposure but lacking detection capability push demand toward outsourced monitoring and response providers, shifting security spend from tools to services.
Third-order effects
- If the pattern holds — and it does across the series, reaching $4.45M in the 2023 survey where only about a third of breaches were caught in-house — breach cost benchmarks harden into the standard metric regulators and boards use to justify mandatory disclosure rules and minimum security investment.
- Persistent SMB exposure at multi-million-dollar averages points toward consolidation of security functions into platform and service providers, with small companies buying protection rather than staffing it.
The trend: IBM's annual breach-cost series is turning security economics into a steadily compounding line item, with each year's higher average ratcheting up insurance pricing, board expectations, and regulatory pressure.