Severe business downtime can cost millions
Business downtime can also be significantly costly for a breached organization, depending on the level and extent of the downtime and how technology-dependent the firm is.
Nearly all the organizations studied suffered operational disruption, taking an average of 100 days to recover from a security incident.
Jason Hicks, field CISO at Coalfire, tells CSO: “Often a breach is not going to take a company completely offline, but it can happen. The more critical systems that are taken down, the more significant the cost.”
Manufacturing tends to have the best metrics around this, as it’s relatively simple to measure the cost per minute if an assembly line is down, Hicks says. “This can translate into millions of dollars a day for a large manufacturing company. This can be more nebulous for other industry verticals, but there are models to get a reasonable feel that can be applied to each vertical.”
Regulation and litigation add to data breach costs
Increasingly strict data protection and privacy laws along with litigation are seeing a growing number of companies issued large fines, paying hefty settlements, and stumping up for legal fees following data breaches and non-compliance.
“Regulated industries suffer not only the immediate cost of responding to, containing, and remediating vulnerabilities but also the long-term effects of additional penalties from their regulatory bodies and legal settlements,” Nick says. Highly regulated industries, such as healthcare and financial services, typically run one and two in order of cost per breach because they will pay more non-compliance fines than others, he adds.
“Investigation and adjudication often take years for the victim organization to reach a monetary settlement with affected parties.” Legal costs are one of the largest expenditures organizations face in data breaches, Nick states. “Organizations rarely have the legal and privacy expertise in-house. To ensure compliance, they must hire outside counsel to lead their reporting.”
The role of cyber insurance
Cyber insurance is one way that companies mitigate the cost risks of breaches. Sharp increases in cyber insurance premiums have been stabilizing of late, but even organizations covered by insurance can expect to dole out extra cash to make good after a breach. One definite cost hit will be a hike in their premiums, Guidehouse’s Nick says.
“Some organizations have reported post-breach increases in premiums of approximately 200%,” he adds.
Insurers are also implementing more coverage limitations, meaning that even with a policy in place, businesses could find themselves financially responsible for certain breach-related costs.
In fact, Forrester’s Mellen says any notion that policies will allow organizations to fully recover financially from a cyberattack is folly. “In reality, it’s not going to cover all of the costs associated with any type of cyberattack, and we see some insurance firms not even covering ransomware at this point as part of their payouts,” she adds.
Another factor to consider is that cyber insurance providers typically have a list of approved service providers such as lawyers and forensics firms, Hicks says.
“If your preferred provider is not on their list, you may have to work with them to get them included, or potentially have to change providers. This can be costly, as firms are often leveraging their existing service providers to secure the maximum discounts based on the volume of work done with the partners,” Hicks says.
Ransomware extortion on the rise
Reported ransomware incidents rose in the last 12 months compared to the year prior (39% vs. 34%) as attackers have abused AI technologies to automate and scale their attacks.
While disrupting operations through encrypting remains a key tactic (23%), attackers are shifting to higher-impact pressure methods, such as threatening to leak stolen data (a common feature of so-called double extortion attacks).
Insufficient security staffing leads to higher breach costs
According to IBM’s latest report, the security skills shortage is one of the biggest data breach cost amplifiers, with the average additional cost of data breach due to cyber skills shortage pegged at $180,000.
If insufficient security staff equates to greater data breach costs, organizations should heed Mellen’s warning about the impact a poorly handled data breach can have on employees.
“If they don’t feel like the organization is able to protect them or customers in the event of a breach, or that they blame their employees for a breach, then they’re likely going to start looking for jobs elsewhere because it creates a bit of a hostile environment for them,” she says. “It is very important for organizations to recognize that they need to accept responsibility and protect both their employees and their customers.”
Taking a DevSecOps approach to software development was the No. 1 factor that reduced breach costs, according to the report, ahead of use of identity and access management. Running key lifecycle management tools rounded out the top three factors.
Security incidents involving shadow or unsanctioned use of AI tools more than doubled to 43% this year compared to 20% in 2025. Shadow AI is starting to rival supply chain breaches and security system complexity as a leading factor in exacerbating breach costs, according to the report.
Preparedness is key to managing data breach costs
No matter the specific costs involved, experts agree that preparedness is key to mitigating the financial repercussions of a breach.
“Faster incident response continues to be a clear driver for lowering the cost of a breach,” UST’s Dutile says. “The worst losses are those that go undetected for an extended time or have a slow or ineffective response.”
To that end, more than half of organizations surveyed say they plan to invest in AI security and governance tools post-breach, an 88% increase from last year and a reaction to concerns over frontier AI model threats.
Modern cybersecurity requires a post-breach mindset which understands that, eventually, a successful data breach is going to occur, Forrester’s Mellen adds.
“Operating under those conditions, you need to figure out how you’re going to handle that and build your resiliency to respond better and faster. This isn’t just about the security function either, and it needs to be spread across an organization, considering what marketing is going to do, what sales is going to do, etc. — how, as a business, you can demonstrate you value your customers and that you want to make it right as quickly and effectively as possible,” she says.


