IBM Report: Escalating Data Breach Disruption Pushes Costs to New Highs
Rhea-AI Summary
IBM's 2024 Cost of a Data Breach Report reveals a significant increase in global average breach costs, reaching $4.88 million, up 10% from the previous year. Key findings include:
1. 70% of breached organizations reported significant disruption.
2. Security staffing shortages led to $1.76 million higher breach costs.
3. AI and automation in security reduced breach costs by $2.2 million on average.
4. 40% of breaches involved data stored across multiple environments.
5. Intellectual property theft increased by 27%.
6. The average data breach lifecycle decreased to 258 days.
The report emphasizes the growing importance of AI-driven defenses and addressing risks associated with generative AI in cybersecurity.
Positive
- Organizations using AI and automation extensively in security operations saved $2.2 million in breach costs
- 67% of organizations deployed security AI and automation, a 10% increase from the previous year
- Internal breach detection improved, shortening the data breach lifecycle by 61 days and saving nearly $1 million in costs
- 63% of organizations plan to increase security budgets, up from 51% last year
- The average data breach lifecycle hit a 7-year low of 258 days, down from 277 days the prior year
Negative
- Global average cost of a data breach increased by 10% to $4.88 million
- 70% of breached organizations reported significant or very significant disruption
- Organizations with severe staffing shortages faced $1.76 million higher breach costs
- Intellectual property theft increased by 27%, with costs per stolen record up 11% to $173
- 40% of breaches involved data stored across multiple environments, increasing complexity and costs
- 63% of organizations stated they would increase the cost of goods or services due to breaches
News Market Reaction 1 Alert
On the day this news was published, IBM declined 0.24%, reflecting a mild negative market reaction.
Data tracked by StockTitan Argus on the day of publication.
Intellectual property theft spiked; More than one-third of breaches involved shadow data
Yet use of AI/Automation cut breach costs by
Lost business and post-breach customer and third-party response costs drove the year-over-year cost spike, as the collateral damage from data breaches has only intensified. The disruptive effects data breaches are having on businesses are not only driving up costs, but are also extending the after-effect of a breach, with recovery taking more than 100 days for most of the small number (
The 2024 Cost of a Data Breach Report is based on an in-depth analysis of real-world data breaches experienced by 604 organizations globally between March 2023 and February 2024. The research, conducted by Ponemon Institute, and sponsored and analyzed by IBM, has been published for 19 consecutive years and has studied the breaches of more than 6,000 organizations, becoming an industry benchmark.
Some key findings in the 2024 IBM report include:
- Understaffed Security Teams – More organizations faced severe staffing shortages compared to the prior year (
26% increase) and observed an average of in higher breach costs than those with low level or no security staffing issues.$1.76 million - AI-Powered Prevention Pays Off – Two out of three organizations studied are deploying security AI and automation across their security operation center (SOC). When these technologies were used extensively across prevention workflows organizations incurred an average
less in breach costs, compared to those with no use in these workflows – the largest cost savings revealed in the 2024 report.$2.2 million - Data Visibility Gaps – Forty percent of breaches involved data stored across multiple environments including public cloud, private cloud, and on-prem. These breaches cost more than
on average and took the longest to identify and contain (283 days).$5 million
"Businesses are caught in a continuous cycle of breaches, containment and fallout response. This cycle now often includes investments in strengthening security defenses and passing breach expenses on to consumers – making security the new cost of doing business," said Kevin Skapinetz, Vice President, Strategy and Product Design, IBM Security. "As generative AI rapidly permeates businesses, expanding the attack surface, these expenses will soon become unsustainable, compelling business to reassess security measures and response strategies. To get ahead, businesses should invest in new AI-driven defenses and develop the skills needed to address the emerging risks and opportunities presented by generative AI."
Security staffing shortages drove up breach costs
More than half of the organizations studied had severe or high-level staffing shortages last year and experienced significantly higher breach costs as a result (
Mounting staffing challenges may soon see relief, as more organizations stated that they are planning to increase security budgets compared to last year (
Hacking the clock with AI
The report found that
Shorter breach lifecycles can also be attributed to the increase in internal detection:
Data insecurities fuel intellectual property theft
According to the 2024 report,
These data visibility gaps contributed to the sharp rise (
Other key findings in the 2024 Cost of a Data Breach Report include:
- Stolen credentials topped initial attack vectors – At
16% , stolen/compromised credentials was the most common initial attack vector. These breaches also took the longest to identity and contain at nearly 10 months. - Fewer ransoms paid when law enforcement is engaged – By bringing in law enforcement, ransomware victims saved on average nearly
in breach costs compared to those who didn't – that savings excludes the ransom payment for those that paid. Most ransomware victims ($1 million 63% ) who involved law enforcement were also able to avoid paying a ransom. - Critical infrastructure organizations see highest breach costs - Healthcare, financial services, industrial, technology and energy organizations incurred the highest breach costs across industries. For the 14th year in a row, healthcare participants saw the costliest breaches across industries with average breach costs reaching
.$9.77 million - Breach costs passed to consumers - Sixty-three percent of organizations stated they would increase the cost of goods or services because of the breach this year – a slight increase from last year (
57% ) – this marks the third consecutive year that the majority of studied organizations stated they would take this action.
Additional Sources
- Download a copy of the 2024 Cost of a Data Breach Report.
- Sign up for the 2024 IBM Security Cost of a Data Breach webinar on Tuesday, August 13, 2024, at 11:00 a.m. ET.
- Read more about the report's top findings in this IBM Security Intelligence blog.
About IBM
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. More than 4,000 government and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity and service. Visit ibm.com for more information.
Media Contact:
Georgia Prassinos
IBM
gprassinos@ibm.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs-302209290.html
SOURCE IBM