IBM Report: Consumers Pay the Price as Data Breach Costs Reach All-Time High
IBM's 2022 Cost of a Data Breach Report reveals the global average cost of data breaches has risen to $4.35 million, a 13% increase over the last two years. Notably, 60% of affected organizations increased product prices post-breach, contributing to inflation concerns. The report indicates 83% of organizations faced multiple breaches, with critical infrastructure entities lagging in zero trust adoption, incurring costs averaging $5.4 million. Additionally, organizations deploying security AI saw average savings of $3.05 million in breach costs.
- Organizations utilizing security AI and automation save an average of $3.05 million in breach costs.
- Hybrid cloud adopters face lower average breach costs of $3.8 million compared to $5.02 million for public cloud only.
- Healthcare sector breaches hit record costs at $10.1 million, indicating sector-specific concerns.
- Global average data breach cost increased by 13% to $4.35 million.
- 62% of organizations are inadequately staffed for security, incurring $550,000 more in breach costs.
- Critical infrastructure organizations that do not adopt zero trust strategies see average breach costs rise to $5.4 million.
CAMBRIDGE, Mass., July 27, 2022 /PRNewswire/ -- IBM (NYSE: IBM) Security today released the annual Cost of a Data Breach Report,1 revealing costlier and higher-impact data breaches than ever before, with the global average cost of a data breach reaching an all-time high of
The perpetuality of cyberattacks is also shedding light on the "haunting effect" data breaches are having on businesses, with the IBM report finding
The 2022 Cost of a Data Breach Report is based on in-depth analysis of real-world data breaches experienced by 550 organizations globally between March 2021 and March 2022. The research, which was sponsored and analyzed by IBM Security, was conducted by the Ponemon Institute.
Some of the key findings in the 2022 IBM report include:
- Critical Infrastructure Lags in Zero Trust – Almost
80% of critical infrastructure organizations studied don't adopt zero trust strategies, seeing average breach costs rise to$5.4 million – a$1.17 million increase compared to those that do. All while28% of breaches amongst these organizations were ransomware or destructive attacks. - It Doesn't Pay to Pay – Ransomware victims in the study that opted to pay threat actors' ransom demands saw only
$610,000 less in average breach costs compared to those that chose not to pay – not including the cost of the ransom. Factoring in the high cost of ransom payments, the financial toll may rise even higher, suggesting that simply paying the ransom may not be an effective strategy. - Security Immaturity in Clouds – Forty-three percent of studied organizations are in the early stages or have not started applying security practices across their cloud environments, observing over
$660,000 on average in higher breach costs than studied organizations with mature security across their cloud environments. - Security AI and Automation Leads as Multi-Million Dollar Cost Saver – Participating organizations fully deploying security AI and automation incurred
$3.05 million less on average in breach costs compared to studied organizations that have not deployed the technology – the biggest cost saver observed in the study.
"Businesses need to put their security defenses on the offense and beat attackers to the punch. It's time to stop the adversary from achieving their objectives and start to minimize the impact of attacks. The more businesses try to perfect their perimeter instead of investing in detection and response, the more breaches can fuel cost of living increases." said Charles Henderson, Global Head of IBM Security X-Force. "This report shows that the right strategies coupled with the right technologies can help make all the difference when businesses are attacked."
Over-trusting Critical Infrastructure Organizations
Concerns over critical infrastructure targeting appear to be increasing globally over the past year, with many governments' cybersecurity agencies urging vigilance against disruptive attacks. In fact, IBM's report reveals that ransomware and destructive attacks represented
Despite the call for caution, and a year after the Biden Administration issued a cybersecurity executive order that centers around the importance of adopting a zero trust approach to strengthen the nation's cybersecurity, only
Businesses that Pay the Ransom Aren't Getting a "Bargain"
According to the 2022 IBM report, businesses that paid threat actors' ransom demands saw
The persistence of ransomware, despite significant global efforts to impede it, is fueled by the industrialization of cybercrime. IBM Security X-Force discovered the duration of studied enterprise ransomware attacks shows a drop of
Hybrid Cloud Advantage
The report also showcased hybrid cloud environments as the most prevalent (
The report highlights that
Additional findings in the 2022 IBM report include:
- Phishing Becomes Costliest Breach Cause – While compromised credentials continued to reign as the most common cause of a breach (
19% ), phishing was the second (16% ) and the costliest cause, leading to$4.91 million in average breach costs for responding organizations. - Healthcare Breach Costs Hit Double Digits for First Time Ever– For the 12th year in a row, healthcare participants saw the costliest breaches amongst industries with average breach costs in healthcare increasing by nearly
$1 million to reach a record high of$10.1 million . - Insufficient Security Staffing – Sixty-two percent of studied organizations stated they are not sufficiently staffed to meet their security needs, averaging
$550,000 more in breach costs than those that state they are sufficiently staffed.
Additional Sources
- To download a copy of the 2022 Cost of a Data Breach Report, please visit: https://www.ibm.com/security/data-breach.
- Read more about the report's top findings in this IBM Security Intelligence blog.
- Sign up for the 2022 IBM Security Cost of a Data Breach webinar on Wednesday, August 3, 2022, at 11:00 a.m. ET here.
- Connect with the IBM Security X-Force team for a personalized review of the findings: https://ibm.biz/book-a-consult.
About IBM Security
IBM Security offers one of the most advanced and integrated portfolios of enterprise security products and services. The portfolio, supported by world-renowned IBM Security X-Force® research, enables organizations to effectively manage risk and defend against emerging threats. IBM operates one of the world's broadest security research, development, and delivery organizations, monitors 150 billion+ security events per day in more than 130 countries, and has been granted more than 10,000 security patents worldwide. For more information, please check www.ibm.com/security, follow @IBMSecurity on Twitter or visit the IBM Security Intelligence blog.
Press Contact:
IBM Security Communications
Georgia Prassinos
gprassinos@ibm.com
1 Cost of a Data Breach Report 2022, conducted by Ponemon Institute, sponsored, and analyzed by IBM
2 Average cost of
View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-report-consumers-pay-the-price-as-data-breach-costs-reach-all-time-high-301592749.html
SOURCE IBM
FAQ
What did the IBM 2022 report reveal about data breach costs?
How many organizations faced multiple data breaches according to IBM?
What is the cost-saving benefit of using security AI as per the IBM report?