Updated May 2026 · IBM CODB 2025 · Ponemon 2025 · PagerDuty 2024

What does a business incident actually cost?

$4.44M
Average data breach cost
IBM CODB 2025
$5.75M
Average ransomware cost
Resilience Cyber Risk 2025
$794K
Average P1 IT incident
PagerDuty 2024

This site documents what every type of business incident costs, and why. Vendor-neutral, fully cited, updated with 2025 data.

2026 Incident Cost Index

See full index

A consolidated reference table aggregating per-incident costs across all major incident types. No other resource publishes this cross-category view.

Incident TypeAvg Cost Per IncidentYoY ChangeSource
Data breach (global)$4.44M-9%IBM CODB 2025
Data breach (US)$10.22M+6%IBM CODB 2025
Ransomware attack$5.75M+17%Resilience 2025
Insider threat (credential theft)$779K+15%Ponemon 2025
P1 IT incident$794Kn/aPagerDuty 2024

Showing 5 of 17 rows. View complete index.

Browse by Incident Type

Every major category of business incident documented with cost data, cost components, and industry comparisons.

How Incident Cost Is Calculated

Incident cost is not just the ransom payment or the downtime bill. It has four components, all of which compound:

1
Direct Costs
Forensics, remediation, system rebuild, legal retainer, PR agency, notification.
2
Revenue Loss
Customer-facing downtime revenue per hour times outage duration, plus lost contract revenue and customer churn.
3
Productivity Loss
Affected employees times fully loaded hourly cost times hours lost. Averages $100-$125/hr for senior staff.
4
Second-Order Costs
Regulatory fines, legal settlements, credit monitoring for victims, reputation damage, and insurance premium increases.

Cost by Industry

Full breakdown
IndustryAvg Breach CostRansomware RiskKey Regulatory Exposure
Healthcare$7.42MHighHIPAA
Finance$6.08MVery HighGLBA/SEC
Technology$5.47MHighReputational
Retail$3.48MModeratePCI DSS
Public Sector$2.70MModerateOperational

Source: IBM Cost of a Data Breach Report 2025. Showing top 5 industries by breach cost.

Cost by Company Size

Full breakdown
SMB (<100 employees)
$120K-$1.24M

60%+ of SMBs that suffer a major incident close within 6 months. Fixed forensics and legal costs hit small orgs disproportionately.

Mid-Market (100-1000)
$2.5M-$4M

Rising target profile, under-resourced security teams relative to enterprise. Regulatory exposure increasing as they hold more regulated data.

Enterprise (1000+)
$4.88M-$10.22M

US enterprises average $10.22M per breach. Cross-subsidiary blast radius and board-level regulatory scrutiny multiply costs.

IncidentCost.com is an independent educational resource. All cost figures are drawn from published industry research including IBM's Cost of a Data Breach Report, Ponemon Institute Cost of Insider Risks Report, Verizon Data Breach Investigations Report, Atlassian incident management research, and PagerDuty incident surveys. This site is not affiliated with IBM, Ponemon Institute, Verizon, Atlassian, PagerDuty, or any security vendor. Figures are for educational and planning purposes only.