According to IBM’s Cost of a Data Breach 2025 report, the global average cost of a data breach is USD 4.44 million. While organizations of every size and kind are vulnerable to breaches, the severity of these breaches and the costs to remediate them can vary.
For example, the average cost of a data breach in the United States is USD 10.22 million, about 4 times the cost of a breach in India (USD 2.51 million).
Breach consequences tend to be especially severe for organizations in highly regulated fields like healthcare, finance and the public sector, where steep fines and penalties can compound the costs. For example, according to the IBM report, the average cost of a healthcare data breach in 2025 is USD 7.42 million, the highest average breach cost among industries for the 14th consecutive year.
Data breach costs arise from several factors, with IBM’s report noting four key ones: lost business, detection and escalation, post-breach response and notification.
The loss of business, revenue and customers resulting from a breach costs organizations USD 1.38 million on average. The price of detecting and escalating the breach is even higher at USD 1.47 million. Post-breach expenses—including fines, settlements, legal fees, providing free credit monitoring to affected customers and similar expenditures—cost the average breach victim USD 1.20 million.
Notification costs, which include reporting breaches to customers, regulators and other third parties, are the lowest at USD 390,000. However, reporting requirements can still be onerous and time-consuming.
The US Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) requires organizations in national security, finance and other designated industries to report cybersecurity incidents affecting personal data or business operations to the Department of Homeland Security within 72 hours.
US organizations subject to the Health Insurance Portability and Accountability Act (HIPAA) must notify the US Department of Health and Human Services, affected individuals and sometimes the media if protected health information is breached.
All 50 US states also have their own data breach notification laws.
The General Data Protection Regulation (GDPR) requires companies doing business with EU citizens to notify authorities of breaches within 72 hours.