Threats
Data breaches in 2026: what they cost, how long they hide, and the clocks that start
The expensive part of a breach is rarely the intrusion. It is the eight months nobody noticed, and the fact that several legal deadlines began running on the day you found out rather than the day you understood.
Last reviewed August 25, 2026
- The clock starts at discovery, not understanding. An incomplete notification filed on time is treated far better than a complete one filed late.
- Stolen credentials add roughly three months to the timeline. An intruder who logs in produces the same telemetry as the employee whose login it is.
- Close to half of breaches now involve a third party, up from about one in seven two measurements earlier. Your inventory of who holds your data is a security control.
- Speed is the lever that moves cost. The interventions that shorten detection and containment beat any single preventive purchase.
What actually counts as a breach?
A wider set of events than most incident plans anticipate. The regulatory definition turns on unauthorised access to or disclosure of personal data, and it makes no distinction between an intruder who worked for it and an accident that handed it over. A storage bucket left readable, a spreadsheet sent to the wrong distribution list, a departing employee copying a client database — each is a breach with the same duties attached as a sophisticated intrusion.
That breadth catches organisations twice. The first time is procedural: incident plans written against attackers rarely have a path for the marketing coordinator who realises at four on a Friday that the attachment went to the wrong list. The second is cultural. Somebody has to volunteer that they made a mistake, quickly, to people who might be annoyed, and no notification duty is ever met by a team that punishes the disclosure.
The practical consequence is that the reporting route matters more than the technology. An organisation where anyone can raise a possible breach in one step, to a named person, without needing to be certain, finds out in hours. One where the route runs through a line manager and a form finds out in weeks, if at all — and the clocks were running the whole time.
The average is real and nearly useless
Five million dollars is the figure everyone quotes, and it is accurate as an average across a global sample. As a planning input it is close to worthless, because the distribution behind it is enormously wide and the position of any one organisation within it is determined by things that are knowable in advance.
Geography moves it more than most people expect: a breach in the United States runs to more than double the global figure, driven by litigation exposure and by the cost of notifying under fifty separate state regimes. Sector moves it further. Healthcare has been the most expensive place to lose data for fourteen years running, at around half again the global average, and the reasons are structural rather than a failure of effort — regulated data, decades of retention, and clinical systems that cannot be taken down for patching on a Tuesday afternoon.
Size cuts the other way, and it cuts harder. Smaller organisations report costs nearer one and a half million, which sounds like relief until it is expressed as a share of revenue. The same incident that a large enterprise absorbs as a bad quarter is, for a firm of forty people, an event the business may not survive.
What the averages do reveal is which variables actually matter, and the strongest single one is time. Cost tracks the length of the incident closely enough that shortening detection and containment is the most reliable way to move the number. That is a more useful finding than the average itself, because it points at something you can change.
Why does it take eight months to notice?
Because most intrusions do not look like anything. The mental model of a breach — alarms, obvious damage, systems behaving strangely — describes ransomware at the moment of detonation and almost nothing else. An attacker whose goal is data does not want to be noticed, and being unnoticed is not difficult when the activity resembles ordinary work.
The figures have improved and remain uncomfortable. About six months to identify, a further two to contain, roughly eight months in total. That combined figure is the lowest in nine years, which is a genuine achievement and still means an intruder with access in January is plausibly still there in September.
Credentials make it substantially worse. Where the breach begins with a login rather than an exploit, the timeline stretches by around three months, to something close to eleven. Nothing is broken, no signature fires, no unusual binary appears. The account is real, the session is legitimate, the access is authorised. Detecting that requires asking whether the behaviour fits the person — which is a harder question than whether the software is patched, and one most monitoring is not set up to ask.
This is where the initial access data lands with force. Credential abuse is now the leading entry route at around a fifth of breaches, ahead of vulnerability exploitation and well ahead of phishing as a standalone category. The most common way in is also the slowest to find, and those two facts compound.
How long a breach lives before it is closed
Two bars, each split into the time spent undetected and the time spent containing it once found. The difference between them is the entire cost of an intruder who logs in rather than breaks in.
Which clocks start the moment you find out
Most organisations discover their notification obligations during the incident, which is the worst possible time to read a statute. Tick the regimes that apply and the deadlines sort themselves into the order they will actually arrive.
First deadline72 hoursfrom becoming aware
- ImmediatelyPCI DSS — acquirer and card brandsfrom suspicion — Contractual rather than statutory, and typically the fastest clock in the room.
- 72 hoursGDPR — supervisory authorityfrom becoming aware — Applies wherever the personal data of people in the EU or UK is involved, regardless of where you are.
- 4 business daysSEC — listed companiesfrom determining materiality — The clock starts at the materiality decision, and delaying that decision is itself scrutinised.
- Without undue delayGDPR — affected individualsfrom becoming aware — Required when the risk to people is high. No fixed number, which in practice means justify anything past a week.
- 30 days typicalUS state laws — affected residentsfrom discovery — Fifty regimes with different triggers. Several say only 'without unreasonable delay'; a few are shorter than 30 days.
- 60 daysHIPAA — affected individualsfrom discovery — Breaches affecting 500 or more people also require notice to the regulator and the media on the same clock.
These are the deadlines commonly cited for each regime, shown so you can see which ones overlap. They are orientation for planning, not legal advice — the triggers, the exemptions and the definition of "discovery" all vary, and several of these clocks start before anyone understands what happened.
The detail that causes the most damage is the trigger. Under GDPR the 72 hours run from becoming aware, and awareness does not require understanding. Teams routinely assume the clock waits for forensics to conclude. It does not, and regulators have been consistent that a partial notification submitted on time, updated later, is the expected behaviour rather than a fallback.
Overlap is the second trap. An organisation holding health records of people in the EU, listed on a US exchange and taking card payments is inside four regimes at once, each with a different trigger and a different recipient. The earliest deadline governs the whole timetable, and working out which one that is takes minutes when prepared and hours when improvised.
Is your biggest exposure somebody else's network?
Increasingly, yes, and the measurement has kept moving. Third-party involvement went from about one incident in seven, to nearly one in three, to close to half by 2026. One jump can be a bad year; three consecutive readings in the same direction describe something structural, and what they describe is that the average organisation now hands data to more outside parties than it can readily list, and reviews far fewer of them than it hands data to.
The exposure is rarely the marquee supplier with the security team and the annual audit. It is the analytics tool a department signed up for with a corporate card, the payroll processor inherited in an acquisition, the marketing platform holding a customer export from a campaign in 2023 that nobody remembered to delete. Each of those holds real data and none appears on the risk register.
The uncomfortable part is that the notification duty does not follow the data. If a processor loses records you are responsible for, the obligation to tell the regulator and the affected people is generally yours, on your clock, using facts you have to extract from somebody else's incident team. Organisations that have lived through this describe the delay in getting straight answers from a supplier as the single biggest threat to meeting the deadline.
The work that helps is unglamorous and mostly clerical. An inventory of who holds what, refreshed on a schedule rather than at renewal. A contractual notification window measured in hours. And, before signing anything, one question that separates prepared suppliers from the rest: what does your breach notification to us look like, and can we see the template?
What actually reduces the cost?
Time, and the things that buy it. Because cost tracks the length of the incident, every hour removed from detection or containment shows up in the final number. That reframes the investment question usefully: the winning purchases are the ones that shorten an interval, not the ones that promise prevention.
Behavioural detection on identity. Given that credential abuse leads the entry routes and produces the longest timelines, monitoring what accounts do — rather than what software is running — attacks the exact overlap of most common and slowest to find.
Knowing where regulated data sits. When the notification clock is running, the difference between answering "which records were exposed" in hours versus weeks is the difference between a controlled disclosure and a sequence of corrections that erodes every audience's confidence.
A response that has been run, not written. The rehearsal finds the things the document cannot: that the out-of-hours number is a desk phone, that the forensics retainer needs a purchase order, that nobody has authority to take production offline without a director who is on a plane.
Deleting what you no longer need. The cheapest record to lose is the one that was disposed of on schedule three years ago. Retention discipline is the only control on this list that reduces the size of the incident rather than its duration, and it is consistently the least funded.
Do you know where your data actually is?
Most organisations answer yes and mean something narrower: they know where the systems of record live. That is a different question. The customer export sitting in a shared drive since a 2023 campaign, the anonymised research extract that turned out to be re-identifiable, the test environment seeded from production because it was the fastest way to reproduce a bug — none of those appear on an architecture diagram and all of them are notifiable.
This matters at exactly the wrong moment. Once a breach is confirmed, the question that governs everything downstream is which records were exposed, and the answer determines who must be told, under which regime, and on what clock. An organisation that can produce that answer in hours runs a controlled disclosure. One that cannot spends the first week discovering its own estate under a deadline, publishing a figure, and then revising it — and each revision costs more confidence than the original number ever bought.
The useful exercise is smaller than a full data-mapping programme and produces most of the benefit. Take the categories of regulated data you hold, and for each one write down every place a copy could plausibly exist, including the ones that are somebody's laptop. Then check three at random. The gap between the list and the checks is a fair estimate of how wrong the rest of it is.
Retention is the companion discipline and the one that actually shrinks the problem. Every record disposed of on schedule is a record that cannot be part of an incident, cannot appear in a notification and cannot be produced in litigation. It is the only intervention on this page that makes future breaches smaller rather than shorter.
Two habits keep an inventory honest once it exists. Tie it to procurement, so a new supplier cannot be onboarded without declaring what data will cross the boundary. And revisit it whenever a department reorganises, because that is when ownership of a dataset quietly becomes nobody's — the manager who understood why a particular export existed moves on, the export keeps running, and it surfaces years later in an incident nobody expected it to touch. Neither habit requires a tool, and both fail quietly the moment nobody owns them, which is the ordinary fate of governance work that lives outside somebody's objectives.
How disclosure went from optional to enforced
The obligations that now dominate breach response are recent, and the trade press recorded each step as it landed. In the middle of the last decade a large breach was a corporate embarrassment with an uncertain legal tail — the response to the Anthem disclosure in early 2015 was still largely a question of how to handle the announcement.
Equifax, in September 2017 changed the register. The volume, the sensitivity and the handling of the announcement combined into something that reached legislatures rather than just headlines, and it arrived as GDPR was months from application. The pairing set the template for everything since: a statutory clock, a named regulator, and penalties expressed as a share of global turnover.
Capital One in 2019 moved the conversation again, this time about where the boundary of responsibility sits when the data lives in someone else's infrastructure and the misconfiguration is your own. And SolarWinds, from early 2021 made supplier compromise a legislative subject rather than a procurement one.
The direction across all of it is consistent. Each incident narrowed the space between discovering a breach and having to say so, and widened the set of people who must be told. Nothing in the current trajectory suggests that reverses.
Writing the notification before you need it
The message to affected people gets drafted under the worst conditions available: incomplete facts, exhausted staff, legal counsel and communications pulling in opposite directions, and a deadline measured in hours. Almost every notification that reads badly was written that way, and the fix is to write most of it months earlier.
A usable draft covers four things and leaves gaps for the specifics. What happened, in language that does not require the reader to know what an endpoint is. What data was involved, listed plainly. What the organisation is doing. What the reader should do, with steps rather than advice to remain vigilant.
Two failures recur often enough to design against. The first is the passive construction that removes the organisation from its own sentence — data "was accessed", systems "were compromised" — which readers correctly hear as evasion. The second is discovering during the incident that nobody can send an email to every affected customer, because the marketing platform holds a subset and the billing system holds a different one.
Rehearsing the send is as valuable as rehearsing the containment. Producing the list, getting approval, dispatching at volume without tripping a rate limit — each of those has failed for real organisations under a real deadline, and all three are testable on an ordinary Wednesday.
The first hour, in order
The opening sequence of a breach response is where irreversible mistakes happen, and most of them come from acting fast in the wrong order. Three things belong at the front, and none of them is technical.
Preserve before you fix. The instinct to rebuild the affected server is strong and destroys the evidence needed to establish what was taken — which is the fact the entire notification rests on. Snapshot first, then remediate. An hour spent preserving state saves a fortnight of arguing about scope.
Start the legal clock consciously. Somebody has to record, in writing, when the organisation became aware and of what. That timestamp is the anchor for every deadline that follows, and reconstructing it afterwards from memory and message history is a poor substitute that regulators notice.
Open a channel that is not the compromised one. Coordinating an incident over the email system the intruder may still be reading has happened often enough to be a known failure mode. Agree the out-of-band route in advance, and make sure the people who need it have installed whatever it is before they need it at midnight.
Everything after those three follows the plan you already have. What separates organisations that recover well is rarely the sophistication of the response — it is that the first hour was spent on preservation, timing and communications rather than on a well-intentioned rebuild that removed the only copy of the evidence.
One further caution about who gets told internally, and when. Widening the circle early feels collaborative and creates two problems: it raises the chance the intruder learns they have been spotted, and it puts people who will later be witnesses inside conversations they cannot unhear. Decide the initial circle in advance, keep it deliberately narrow, and write down who has the authority to expand it.
Common questions
What counts as a data breach?
Unauthorised access to, or disclosure of, personal or confidential data. That definition is broader than most people assume: a misdirected email, a misconfigured storage bucket and a laptop left on a train all qualify, and all three carry the same notification duties as an intrusion.
How long do breaches usually go unnoticed?
About six months to identify and a further two to contain — roughly 241 days in total, which is the shortest that combined figure has been in nine years. Breaches that start with stolen credentials run substantially longer, closer to eleven months.
Why do credential-driven breaches take so much longer to find?
Because nothing about them looks wrong. An intruder using a valid login generates the same telemetry as the employee whose login it is. Detection has to rest on behaviour — what that account is doing, from where, at what hour — rather than on anything being obviously broken.
What does a breach cost?
The global average sits near five million dollars and has risen about a tenth in a year. In the United States it is more than double that. Smaller organisations land closer to one and a half million, which is a smaller number and a larger share of the business.
Which sector has it worst?
Healthcare, and it has held that position for fourteen consecutive years. Regulated data, long retention, complex estates and clinical systems that cannot be taken offline for patching combine into the most expensive incidents anywhere.
How fast do we have to tell the regulator?
Under GDPR, 72 hours from becoming aware — not from understanding what happened. Listed companies in the United States face four business days from determining materiality. Health data in the US runs to 60 days. Card data is contractually immediate.
Does the clock start when we find it or when we understand it?
When you find it, for most regimes. That is the detail that catches organisations out: the 72-hour clock is running while the forensics are still inconclusive, and an incomplete notification made on time is treated far better than a complete one made late.
How much of our exposure comes from suppliers?
More than it did, and it has moved three years running: about one breach in seven, then nearly one in three, and close to half by the 2026 measurement. A single jump can be a run of bad luck; three consecutive rises describe how organisations now hold data. An inventory of who holds yours is a security control, not an administrative record.
What actually reduces the cost?
Speed, mostly. Organisations that identify and contain quickly pay substantially less, and the levers that shorten those two intervals — behavioural detection on identity, a rehearsed response, knowing where regulated data sits — do more than any single preventive control.
Do we have to tell the people affected?
Usually, and on a different clock from the regulator. GDPR requires it without undue delay where the risk to people is high; US state laws commonly set thirty days; health data in the US allows sixty. Where the regimes overlap, the shortest one governs your timetable.
What are the penalties?
Under GDPR, up to four per cent of global annual turnover or twenty million euros, whichever is greater. US health regulators can reach into the millions per violation category per year. Securities regulators have fined companies in the millions for late or misleading disclosure.
Is a misconfigured cloud bucket really a breach?
If personal data was accessible to people who should not have it, yes, and it is one of the most common causes. The absence of an attacker does not change the notification duty, and 'we found it ourselves' is a mitigating factor rather than an exemption.
Breach coverage
1,609 reports on breaches and exposures, newest first.
- More technology is not always the answer to cybersecurity headaches
November 17, 2021 · computing.co.uk
- Gauging Cybersecurity Resiliency and Why It Matters
November 17, 2021 · informationweek.com
- 90% of IT Decision Makers Believe Organizations Compromise on Cybersecurity in Lieu of Other Goals
November 16, 2021 · channelfutures.com
- Stellar Cyber integrates security platform with Barracuda Networks
November 12, 2021 · securitybrief.asia
- Why the biggest cyber-attacks go undetected
November 12, 2021 · securitybrief.asia
- Is This Top Artificial-Intelligence-Powered Cybersecurity Stock a Buy?
November 12, 2021 · fool.com
- Securing ‘Digital India’ With a Zero Trust Approach
November 10, 2021 · cisomag.eccouncil.org
- A diverse cybersecurity ecosystem is critical for network security
November 10, 2021 · c4isrnet.com
- How Facebook’s Outage Could Shape Public Preferences on Cybersecurity Policy
November 10, 2021 · lawfareblog.com
- SA businesses take action to stave off cyber attacks
November 8, 2021 · indaily.com.au
- Younger generations care little about cybersecurity
November 8, 2021 · helpnetsecurity.com
- U.S. Looks to Coordinate Global Cybersecurity
November 8, 2021 · eetasia.com
- 40% of organizations suffered a cloud-based data breach in the past 12 months
November 2, 2021 · helpnetsecurity.com
- Navigating the cybersecurity implications of remote work
November 1, 2021 · crainscleveland.com
- AI Phishing Defense Leader SlashNext Closes $26 Million Series B Funding
October 29, 2021 · prnewswire.com
- Overcoming Cybersecurity Challenges in a Multi-Cloud Era
October 29, 2021 · cxotoday.com
- Bringing Cybersecurity To The Forefront Of The Boardroom
October 28, 2021 · forbes.com
- Why the time has come to embrace the Zero-Trust model of cybersecurity
October 28, 2021 · weforum.org
- How to protect your business from cybersecurity threats
October 28, 2021 · businessreport.com
- What is an SQL Injection Attack and How to Prevent it?
October 27, 2021 · cisomag.eccouncil.org
- Nearly all UK health organizations have been hit by cyberattacks
October 26, 2021 · itproportal.com
- Multi-target breaches can end up costing far more than imagined
October 25, 2021 · itproportal.com
- Stolen data spreading even faster on the dark web
October 25, 2021 · securitybrief.asia
- What exactly is 5G security, and why is it essential?
October 22, 2021 · securitybrief.asia
- Why Every Business Needs a Cybersecurity Incident Response Team
October 22, 2021 · cisomag.eccouncil.org
- Cybersecurity blind spot: AI’s inherent vulnerabilities
October 22, 2021 · gcn.com
- Increased activity surrounding stolen data on the dark web
October 21, 2021 · helpnetsecurity.com
- Allocators and Managers Remain Vulnerable to Cybersecurity Threats
October 21, 2021 · institutionalinvestor.com
- Zero trust and the role of least privilege for securing cloud workloads
October 20, 2021 · securitymagazine.com
- Remote work leaving businesses exposed to cyber attack
October 20, 2021 · securitybrief.asia