According to IBM’s annual Data Breach report, the average cost of a data breach reached an all-time global high of $4.45 million, up 2.3% from 2022 and 15.3% since 2020.
While $4.45 million is the average across the 16 countries included in IBM’s survey of 553 organizations, breaches in the United States cost far more than the average. The 2023 average hit $9.48 million, according to the report.
Healthcare organizations saw even more of a jump—the average cost of a breach for the sector rose 53.3% in the same period, IBM said in its 2023 report. This year was the thirteenth in a row when the healthcare sector reported the highest average breach cost (now at $10.93 million). The average cost per breached record increased slightly to a new high—up to$165 per record from $164 one year ago. This has jumped from $146 in 2020, IBM noted. The survey assessed breach events with a range of 2,200 to 102,000 records.
In its survey, the firm highlighted breach investigation tactics that could either reduce costs or increase them. For example, organizations that didn’t call in law enforcement during ransomware attacks experienced an extra $470,000 in costs on average and faced longer recovery times.
“While 63% of respondents said they involved law enforcement, the 37% that didn’t paid 9.6% more and experienced a 33-day longer breach lifecycle,” IBM noted. Longer breaches, in general, produce higher than average costs—events stretching over200 high $4.95 million on average, while those at fewer than 200 days cost 23% less at $3.93 million.
Threat detection costs appeared to drive the average breach cost, rising 42% in the last three years, according to the report, suggesting cyber event investigations have become more complex. Just one in three respondents said their own security teams detected breaches—it was far more likely (67%) for third parties or attackers themselves to reveal intrusions. Organizations also faced nearly $1 million in extra costs when cyber threat actors disclosed breaches.
Cyber attackers also showed an increasing preference for infiltrating the cloud – 82% of the breaches evaluated involved cloud data in public, private, or hybrid environments. When threat actors could access multiple environments, breach costs skewed even higher, up to an average of $4.75 million.
Despite higher costs, just 51% of organizations said they planned to increase their cybersecurity spending. Instead, more than half (57%) said they would pass the costs through to customers. Nearly all (95%) surveyed organizations had experienced more than one breach.
One area where organizations may want to invest more is in artificial intelligence tools to help detect breaches. Businesses leveraging AI and automation tools extensively in their networks identified and contained breaches, on average, 108 days quicker than their less tech-forward counterparts and saw average costs of $1.76 million lower than other organizations.
“Time is the new currency in cybersecurity, both for the defenders and the attackers. As the report shows, early detection and fast response can significantly reduce the impact of a breach,” said Chris McCurdy, general manager, worldwide, IBM Security Services, in a statement. “Security teams must focus on where adversaries are the most successful and concentrate their efforts on stopping them before they achieve their goals. Investments in threat detection and response approaches that accelerate defenders’ speed and efficiency—such as AI and automation—are crucial to shifting this balance.”
Contact INSURICA for more healthcare resources.
The content of this News Brief is of general interest and is not intended to apply to specific circumstances. It should not be regarded as legal advice and not be relied upon as such. In relation to any particular problem which they may have, readers are advised to seek specific advice. © 2023 Zywave, Inc. All rights reserved.
About the Author
Share This Story
Related Blogs
Client Guidance: Understanding “Nuclear Verdicts” in Commercial Trucking
A Texas jury recently handed down a verdict of nearly $50 million against a trucking company most people have never heard of — and that's exactly the point.
Do Your Employee Benefit Plan Documents Reflect How Your Plan Actually Operates?
Most employers work hard to administer their employee benefit plans consistently. However, one of the most common compliance issues isn't how a plan is administered—it's whether the written plan documents accurately reflect what the employer is actually doing.
Lifestyle Spending Accounts (LSAs): The Fastest-Growing Benefit of 2026
Lifestyle Spending Accounts (LSAs) are becoming one of the fastest-growing benefits of 2026. Employers are adopting LSAs because they solve a problem traditional benefits have struggled with for years: personalization. Employees want benefits that fit their lives, not one-size-fits-all programs. LSAs give them that flexibility. And because July is a major decision month for 2027 plan design, many employers are evaluating LSAs right now.








