What is the most common way attackers get in?
Exploiting a vulnerability is the largest single route, at roughly 31% of initial access and up from about 20% the year before. Grouped differently the answer changes: phishing, stolen credentials and pretexting together come to some 35%, all of them attacks on identity rather than on code.
Should we prioritise patching or identity?
Both, and the published rankings will not settle the argument for you because they answer a question about technique rather than about target. A more useful test is which of the two your own last five incidents involved, and which of the two you could measurably improve within a quarter.
How long do breaches go unnoticed?
Around 183 days to identify on average, with a further 64 to contain, for a mean lifecycle near 247 days. Detection is close to three times containment, which is worth holding in mind when spending is weighted toward response.
Does faster containment actually save money?
Materially. Breaches with lifecycles beyond 200 days average about $5.65m against $4.32m for shorter ones. The roughly $1.33m difference is larger than many detection programmes cost to operate for a year.
What does a data breach cost on average?
The 2026 global average landed near $4.99m, about 12% higher than the previous year, with the United States average considerably above that at around $11.5m. Averages across industries and jurisdictions are blunt instruments, and they are most useful as a scale check rather than as a forecast.
Are companies still paying ransoms?
Fewer of them. Payment rates fell to a record low around 28–31%, down from roughly 49% in 2024, and about 64% of organisations now refuse. Extortion attempts did not fall with them, which is why leaked-data pressure has grown relative to encryption.
Is ransomware getting more or less common?
More common as an event and less profitable as a business. Some 39% of breached organisations reported at least one ransomware incident, against 24% in 2023, over a period in which the share of victims paying dropped by roughly a third.
Why has security awareness training not reduced human-caused breaches?
The human element appears in about 62% of breaches, slightly up on the previous year, after two decades of training programmes. The reasonable reading is that the failure is in the design of systems that require people to make security decisions under time pressure, not in the people making them.
Where should a small team start?
With the two controls that touch the largest share of the data above: phishing-resistant authentication on everything reachable from the internet, and a known, tested path to notice that something is wrong. Those address the identity family and the 183-day detection gap respectively, and neither depends on buying a platform.
How should I read the statistics vendors publish?
Ask what population the sample came from before reading the percentage. A supplier's telemetry reflects the organisations that bought that supplier's product, which is a real population and a narrow one. Reports that state their sample size, window and population can be reasoned about; reports that give percentages with no denominator cannot.
Do the numbers on this page come from one source?
No, and where credible sources disagree the disagreement is stated rather than averaged away. Initial access shares, breach costs, lifecycle lengths and ransom payment rates come from different annual studies with different methods, and small differences between them are usually methodological rather than substantive.
What is the fastest way to find something specific here?
The search page covers every entry by title and source, section pages group them by subject, and the glossary defines the terms that get used inconsistently across the industry.