Cybersecurity Statistics at a Glance (2024)
| Metric | Value | Primary Vector / Impact | Year | Source |
|---|---|---|---|---|
| Global Cybercrime Cost | $9.22 trillion/yr | All categories combined | 2024 | Cybersecurity Ventures |
| Avg. Cost of a Data Breach | $4.88 million | Stolen credentials, phishing | 2024 | IBM Security |
| U.S. Avg. Breach Cost | $9.36 million | Highest globally, 14th consecutive year | 2024 | IBM Security |
| Median Ransomware Payment | $1.5 million | RaaS groups, double extortion | 2024 | Sophos |
| Avg. Ransom Demand | $2.7 million | Enterprise targets, critical infrastructure | 2024 | CrowdStrike Global Threat Report |
| Breaches Involving Human Element | 68% | Phishing, errors, misuse | 2024 | Verizon DBIR |
| Mean Time to Identify Breach | 194 days | Attacker dwell time | 2024 | IBM Security |
| Mean Time to Contain Breach | 64 days | Post-detection containment | 2024 | IBM Security |
| BEC Losses (FBI IC3) | $2.95 billion | Business Email Compromise | 2023 | FBI IC3 Annual Report |
| Global Cybersecurity Workforce Gap | 4 million jobs | Unfilled security positions | 2024 | ISC2 Workforce Study |
What Is Cybersecurity?
The U.S. National Institute of Standards and Technology (NIST) defines cybersecurity as the ability to protect or defend the use of cyberspace from cyber attacks. The European Union Agency for Cybersecurity (ENISA) frames it as the collection of tools, policies, and practices needed to protect the cyber environment from attack.
Understanding cybersecurity statistics requires a clear grasp of what is being measured. Terms like "breach," "incident," and "attack" are used loosely in media coverage, which distorts comparisons between reports. The definitions below are technical and legal standards used by security researchers and regulatory bodies.
A data breach (confirmed unauthorized exfiltration) is not the same as a data leak (accidental exposure), a security incident (any integrity event), or a ransomware attack (extortion-focused malware). These definitions affect legal obligations, insurance claims, and regulatory fines. Many published statistics conflate these categories, which inflates or misrepresents actual confirmed breach counts.
A confirmed incident where sensitive, protected, or confidential data is viewed, stolen, or used by an unauthorized party. Requires exfiltration evidence under most legal definitions (GDPR, HIPAA).
Unintentional public exposure of sensitive data, typically through a misconfigured cloud storage bucket, unsecured database, or exposed API. No malicious actor need be confirmed.
Any event that compromises the confidentiality, integrity, or availability of an information asset. Includes denial-of-service attacks, unauthorized login attempts, and system crashes.
Malware that encrypts files or threatens to publish stolen data, demanding cryptocurrency payment for decryption keys or non-disclosure. Modern attacks combine both threats (double extortion).
Psychological manipulation designed to trick individuals into revealing credentials, downloading malware, or authorizing fraudulent transfers. The most common initial access method in confirmed breaches.
Global Cybercrime Damages and Market Forecasts
Global cybercrime has grown into one of the largest economic damage categories on earth. Cybersecurity Ventures, which analyzes data from government agencies, breach databases, and security vendor telemetry, estimated global cybercrime damages at $9.22 trillion in 2024, up from $8 trillion in 2023 and $3 trillion in 2015. At the projected growth rate, annual damages will surpass $10.5 trillion by 2025.
To place the scale in context: if cybercrime were measured as a national economy, its $9.22 trillion annual output would make it the third largest economy on earth after the United States and China. The FBI Internet Crime Complaint Center (IC3) recorded $12.5 billion in total reported cybercrime losses in the United States alone in 2023, a 22% increase from the prior year. These IC3 figures represent confirmed, reported losses and are widely acknowledged to undercount total damages because many incidents go unreported.
| Year | Estimated Global Cybercrime Cost | Year-over-Year Change | Source |
|---|---|---|---|
| 2015 | $3.0 trillion | Baseline | Cybersecurity Ventures |
| 2017 | $3.5 trillion | +17% | Cybersecurity Ventures |
| 2018 | $5.0 trillion | +43% | Cybersecurity Ventures |
| 2020 | $6.0 trillion | +20% | Cybersecurity Ventures |
| 2021 | $6.9 trillion | +15% | Cybersecurity Ventures |
| 2023 | $8.0 trillion | +10% | Cybersecurity Ventures |
| 2024 | $9.22 trillion | +15% | Cybersecurity Ventures |
| 2025 (projected) | $10.5 trillion | +14% | Cybersecurity Ventures |
Evolution of Cyber Threats and Attack Vectors (1990s to Present)
The threat landscape has shifted dramatically over three decades, from hobbyist-driven virus experiments to industrialized Ransomware-as-a-Service operations, nation-state advanced persistent threats (APTs), and AI-assisted spear phishing at scale. Understanding this progression helps security teams assess which threat generation they face and what defenses apply.
Cost of a Data Breach: Global Averages and Financial Impact
IBM Security's annual Cost of a Data Breach Report, published since 2004, is the most widely cited source for breach cost benchmarking. The 2024 report analyzed 604 organizations across 17 industries and 16 countries that experienced breaches between March 2023 and February 2024. Each organization's costs were tracked across four categories: detection and escalation, notification, post-breach response, and lost business.
The global average cost of a data breach in 2024 was $4.88 million per incident, a 10% increase from 2023 and the highest figure recorded in 20 years of IBM Security reporting. In the United States, the average reached $9.36 million. Healthcare sector breaches averaged $9.77 million per incident for the 14th consecutive year as the most expensive industry.
| Country / Region | Average Breach Cost (2024) | Rank | Change vs 2023 |
|---|---|---|---|
| United States | $9.36 million | #1 | +13% |
| Middle East | $8.75 million | #2 | +4% |
| Canada | $5.13 million | #3 | +3% |
| Germany | $4.90 million | #4 | +2% |
| Japan | $4.19 million | #5 | +22% |
| United Kingdom | $3.58 million | #6 | -2% |
| Global Average | $4.88 million | — | +10% |
Impact of Security AI and Automation on Breach Cost
One of the most consistent findings in IBM's research is the measurable cost reduction from security automation. Organizations with full AI and automation deployment detected and contained breaches significantly faster than those with no automation, translating directly into cost savings.
| Security Automation Level | Avg. Breach Cost | Avg. Breach Lifecycle | Cost vs No Automation |
|---|---|---|---|
| Full AI / Automation Deployed | $3.84 million | 168 days | $1.76M saved |
| Partial Automation | $4.55 million | 233 days | $1.05M saved |
| No AI / Automation | $5.72 million | 306 days | Baseline |
Organizations with an Incident Response (IR) team that regularly tested their response plan saved an average of $1.49 million compared to organizations with no IR plan. This figure provides one of the clearest returns on investment calculations available in enterprise security research. The mathematical logic behind comparing these mean costs is covered in our mean calculation guide.
Ransomware Statistics: Demands, Payments, and Extortion Trends
Ransomware is a category of malware that encrypts an organization's files or exfiltrates data, then demands cryptocurrency payment in exchange for decryption keys or a promise not to publish stolen data. Modern ransomware operations run as Ransomware-as-a-Service (RaaS) cartels, where developers license malware kits to affiliate operators who carry out attacks and split ransoms.
A critical statistical note: ransomware payment figures require careful reading. The median payment of $1.5 million (Sophos 2024) is the more useful benchmark for most organizations because a small number of massive enterprise payouts inflate the mean. Reporting the mean without context misrepresents typical risk exposure for mid-sized organizations. See the mean vs median vs mode guide for the statistical reasoning behind this.
| Ransomware Metric | Value | Year | Source |
|---|---|---|---|
| Organizations experiencing a ransomware attack | 59% | 2024 | Sophos State of Ransomware |
| Median ransom payment | $1.5 million | 2024 | Sophos |
| Average ransom demand | $2.7 million | 2024 | CrowdStrike Global Threat Report |
| Organizations that paid ransom | 56% | 2024 | Sophos |
| Organizations recovering all data after paying | 31% | 2024 | Sophos |
| Attacks using double extortion | 83% | 2024 | Palo Alto Networks Unit 42 |
| Average downtime from a ransomware event | 21 days | 2024 | Coveware Q4 2023 Report |
| Healthcare organizations attacked by ransomware | 67% | 2024 | Sophos |
Of organizations that paid a ransom in 2024, only 31% recovered all of their data, according to Sophos. A further 35% recovered most data. Total recovery is rare. Additionally, paying a ransom does not prevent the attacker from using or selling exfiltrated data on dark web markets, which is why CISA and FBI guidance consistently advises against payment.
Phishing, Business Email Compromise (BEC), and Social Engineering
The 2024 Verizon Data Breach Investigations Report (DBIR), which analyzed 30,458 security incidents and 10,626 confirmed breaches, found that 68% of all confirmed breaches involved a non-malicious human element. That category covers employees falling for phishing, misconfiguring systems, and mishandling data. Social engineering and phishing were the most frequent pathways into enterprise networks.
| Phishing / BEC Metric | Value | Year | Source |
|---|---|---|---|
| Breaches involving non-malicious human element | 68% | 2024 | Verizon DBIR |
| BEC losses reported to FBI IC3 | $2.95 billion | 2023 | FBI IC3 Annual Report |
| Phishing emails sent per day (estimated) | 3.4 billion | 2023 | AAG IT / Statista |
| Employees who click on phishing simulations | ~17% | 2024 | KnowBe4 Phishing Benchmark |
| Spear phishing as percentage of targeted attacks | 65% | 2024 | Symantec / Broadcom ISTR |
| Vishing (voice phishing) year-over-year increase | +442% | H1 2022 vs H1 2021 | Agari / HelpSystems |
Generative AI and Spear Phishing
Generative AI models eliminated one of the most reliable ways employees used to identify phishing: poor grammar and awkward phrasing. Research from IBM and multiple university cybersecurity programs found that AI-generated phishing emails achieve open rates 14-26% higher than manually written phishing emails in controlled simulations. AI can ingest publicly available information from LinkedIn, company websites, and press releases to construct hyper-personalized spear phishing lures targeting specific executives or employees at a scale that was previously impossible for human attackers.
This connects directly to the statistical discipline of probability and distribution analysis: security teams can use Bayesian models to score incoming email risk based on behavioral signals, since traditional text-based indicators have become less reliable.
Cloud Security, API Vulnerabilities, and Infrastructure Misconfigurations
Cloud adoption has created a new attack surface that many organizations have been slow to properly instrument and defend. The Verizon 2024 DBIR found that cloud infrastructure was involved in 60% of system intrusion incidents, reflecting both the shift of enterprise workloads to cloud and the relative ease of exploiting misconfigurations compared to hardened on-premises systems.
| Cloud Security Metric | Value | Source |
|---|---|---|
| Organizations storing sensitive data in public cloud | 80%+ | IBM / Ponemon 2024 |
| Data breaches caused by cloud misconfiguration | 21% of all breaches | Verizon DBIR 2024 |
| Average cost of a cloud-originated breach | $5.17 million | IBM Security 2024 |
| Shadow IT assets undiscovered by security teams | 30-40% of total assets | Gartner / CyCognito |
| Organizations with multi-cloud environments | 87% | Flexera 2024 State of the Cloud |
| API attacks increase year-over-year | +37% | Salt Security State of API Security 2024 |
Artificial Intelligence in Cybersecurity: Defense and Threats
AI plays a dual role in the current threat landscape. Defenders use it to analyze vast volumes of security telemetry, correlate alerts, and automate containment actions that would take human analysts hours or days. Attackers use it to generate convincing phishing content, scan targets for vulnerabilities at speed, and adapt malware to evade signature-based detection.
Security AI and automated SOAR (Security Orchestration, Automation, and Response) platforms reduced the average breach lifecycle from 306 days (no automation) to 168 days (full automation) in IBM's 2024 study, a 45% reduction. The corresponding cost saving of $1.76 million per breach represents the strongest documented ROI in enterprise security investment. For more on AI trends, see our AI statistics reference.
Insider Threats and Human Error Statistics
Insider threats include both negligent employees who accidentally expose data and malicious insiders who deliberately exfiltrate information. Ponemon Institute's 2023 Cost of Insider Risks Report analyzed 1,803 insider risk incidents across 311 organizations and found that the average total annual cost of an insider program had risen to $16.2 million per organization.
| Insider Threat Metric | Value | Year | Source |
|---|---|---|---|
| Average annual cost of insider threats per organization | $16.2 million | 2023 | Ponemon / DTEX |
| Negligent insider incidents (as share of all insider incidents) | 55% | 2023 | Ponemon Institute |
| Malicious insider incidents | 25% | 2023 | Ponemon Institute |
| Third-party / credential theft incidents | 20% | 2023 | Ponemon Institute |
| Average cost per negligent insider incident | $505,113 | 2023 | Ponemon Institute |
| Average cost per malicious insider incident | $648,062 | 2023 | Ponemon Institute |
| Average days to contain an insider incident | 85 days | 2023 | Ponemon Institute |
Compromised Credentials, Passwords, and Identity Attacks
The most common initial access vector in confirmed breaches is not a sophisticated zero-day exploit but a stolen or reused password. Verizon's 2024 DBIR found that credentials were involved in over 44% of all confirmed breach incidents. MFA adoption has grown substantially but remains far from universal, and attackers have responded with sophisticated MFA-bypass techniques.
| Identity / Credential Metric | Value | Source |
|---|---|---|
| Breaches involving compromised credentials | 44%+ | Verizon DBIR 2024 |
| Passwords found in dark web data dumps (est.) | 24 billion+ | Digital Shadows / ReliaQuest 2024 |
| Enterprise MFA adoption rate | ~90% (large enterprise) | Microsoft Security Intelligence 2024 |
| SMB MFA adoption rate | ~38% | HYPR 2024 State of Passwordless |
| MFA-bypass attacks year-over-year increase | +146% | Microsoft Digital Defense Report 2024 |
| Password spray attacks per day (Microsoft cloud) | 7,000+ | Microsoft Digital Defense Report 2024 |
Cybersecurity Threat Profiles by Industry Vertical
Breach costs, attack frequency, and attacker motivations vary substantially by industry sector. Healthcare organizations hold the most sensitive personal data and face the strictest regulatory requirements, which drives both attacker interest and cost per incident. Financial services are targeted for direct financial gain. Manufacturing and critical infrastructure are increasingly targeted by ransomware for operational disruption leverage.
Regional Cybercrime Statistics
| Region | Avg. Breach Cost | Primary Threat | Distinguishing Factor |
|---|---|---|---|
| North America (U.S.) | $9.36M | Ransomware, BEC, credential theft | Highest breach costs globally for 14th consecutive year. SEC and HIPAA requirements drive notification and legal costs upward. |
| Middle East | $8.75M | Nation-state APTs, critical infrastructure | Energy sector concentration and geopolitical targeting elevate costs. Second highest globally. |
| Europe | $3.58M (UK) | Regulatory enforcement, data theft | GDPR Article 83 fines (up to 4% of global annual turnover) are a major cost multiplier. ENISA reports 24% increase in DDoS attacks on EU infrastructure in 2023. |
| Asia-Pacific | $4.19M (Japan) | Supply chain attacks, high-volume DDoS | Rapid escalation in advanced persistent threats targeting semiconductor and defense supply chains. Highest volume of DDoS attacks globally by count. |
Cybersecurity Job Market, Skills Gap, and Workforce Trends
The cybersecurity workforce gap represents one of the most significant structural vulnerabilities in organizational security. ISC2's 2024 Cybersecurity Workforce Study found a global gap of approximately 4 million unfilled security positions, while the total cybersecurity workforce reached 5.5 million workers globally. A team cannot defend what it cannot staff.
| Role | Avg. U.S. Salary Range (2024) | Key Certifications |
|---|---|---|
| CISO (Enterprise) | $350,000 – $500,000+ (total comp) | CISSP, CISM |
| Security Architect (Lead) | $155,000 – $220,000 | CISSP, AWS / Azure Security Specialty |
| SOC Manager | $120,000 – $170,000 | CISM, CompTIA CySA+ |
| Penetration Tester (Senior) | $130,000 – $185,000 | OSCP, CEH, GPEN |
| SOC Analyst (Tier II / III) | $90,000 – $140,000 | CompTIA Security+, CySA+ |
| Cloud Security Engineer | $140,000 – $200,000 | CCSK, AWS / Azure Security |
Cybersecurity Risk: Small and Medium Businesses vs Enterprise
SMBs are disproportionately targeted relative to their security investment capacity. The Verizon 2024 DBIR found that 43% of all cyberattacks targeted small businesses, while Accenture's Cyber Resilience Research found that 43% of SMBs have no cybersecurity plan in place. A breach that represents a manageable cost at enterprise scale can be existential at SMB scale.
| Metric | SMBs (<500 employees) | Enterprise (>5,000 employees) |
|---|---|---|
| Percentage targeted by cyber attacks | 43% | 57% |
| Avg. cost of a data breach | $3.31 million | $5.54 million |
| SMBs that close within 6 months of a major breach | 60% | N/A |
| Security budget as % of IT spend | 4 – 8% | 10 – 15% |
| Average time to recover from a major incident | 279 days avg. | 180 – 200 days avg. |
Regulatory Compliance, SEC Disclosure Rules, and Legal Fines
Regulatory consequences compound breach costs significantly. The EU's General Data Protection Regulation (GDPR) permits fines of up to 20 million euros or 4% of a company's global annual turnover, whichever is higher. The U.S. Securities and Exchange Commission's rules, effective December 2023, require public companies to disclose material cybersecurity incidents within four business days of determining materiality.
| Regulation | Jurisdiction | Max Fine | Disclosure Requirement |
|---|---|---|---|
| GDPR | European Union | €20M or 4% global turnover | 72 hours to supervisory authority |
| HIPAA (Health Data) | United States | $1.9M per violation category / yr | 60 days (individuals); annual HHS report (500+) |
| SEC Cybersecurity Rules | United States (public cos.) | Enforcement varies | 4 business days post-materiality determination |
| NIS2 Directive | European Union | €10M or 2% global turnover | 24 hours (early warning); 72 hours (formal) |
| CCPA / CPRA | California, U.S. | $7,500 per intentional violation | Disclosure to affected consumers |
The largest GDPR fine on record remains Meta's 1.2 billion euro penalty in May 2023 for illegal transfer of EU user data to the United States. Amazon received a 746 million euro GDPR fine in 2021. These figures represent the regulatory ceiling for major breaches in addition to operational recovery costs. Understanding how to interpret legal and regulatory risk probability connects directly to conditional probability and statistics in risk management.
Incident Response: Mean Time to Detect (MTTD) and Contain (MTTC)
Breach lifecycle metrics are among the most actionable statistics in cybersecurity because they have a direct, measurable relationship to total financial loss. IBM Security's 2024 data confirms that shorter breach lifecycles correlate with lower costs at a statistically significant level.
Breach lifecycle figures (194 days to detect, 64 days to contain) are arithmetic means. A handful of catastrophic incidents with multi-year dwell times pull these figures upward. When comparing your organization to benchmarks, the 75th percentile figure is often more representative of reasonable preparedness than the mean alone. This is the same concept covered in our guides on mean calculations and percentile analysis.
| Breach Lifecycle Metric | Global Average (2024) | Financial Impact |
|---|---|---|
| Mean Time to Identify (MTTI) | 194 days | Baseline breach cost exposure period |
| Mean Time to Contain (MTTC) | 64 days | Post-detection remediation costs |
| Full breach lifecycle (MTTI + MTTC) | 258 days | Average total exposure: $4.88M |
| Savings when breach contained in under 200 days | $1.12M saved | Compared to breaches exceeding 200 days |
| Savings with IR team plus tested plan | $1.49M saved | Versus no IR plan |
| Savings with full AI / automation deployed | $1.76M saved | Lifecycle reduced to avg. 168 days |
Why Cybersecurity Statistics Differ Across Reports
A researcher comparing the IBM breach cost figure ($4.88 million average) with the FBI IC3's total reported losses ($12.5 billion across all U.S. incidents) might wonder why the numbers look so different. The answer is that these sources measure entirely different things using entirely different methodologies.
- What is the unit of measurement? Cost per incident (IBM) vs total sector losses (IC3) vs attack attempt count (firewall telemetry) produce incomparable figures.
- Who is in the sample? A survey of 604 large organizations (IBM) differs from a survey of 5,000 IT managers across company sizes (Sophos). Check sample composition before comparing.
- Is this a confirmed breach or an attack attempt? Firewalls block millions of connection attempts daily. These are not breaches. Reports that count blocked probes produce figures 100x higher than confirmed exfiltration databases.
- Self-reported vs telemetry-sourced? Executive surveys produce memory-based estimates. Automated telemetry from EDR agents, SIEM platforms, and email gateways produces empirical data with lower recall bias.
- Is the reporting year clearly stated? Threat data ages rapidly. A ransomware payment median from 2021 is not comparable to 2024 data. Always check publication and data collection dates separately.
- What does "average" mean statistically? When large outliers exist (billion-dollar mega-breaches), the arithmetic mean is distorted. Look for median, quartile, or percentile breakdowns. See our guides on mean, mean vs median vs mode, and percentiles.
Primary Data Sources and Methodology
| Source | Focus Area | Sample / Telemetry Scope | Publication Frequency |
|---|---|---|---|
| IBM Security CDBR | Data breach financial costs | 604 organizations, 17 industries, 16 countries (2024) | Annual (since 2004) |
| Verizon DBIR | Breach actors, vectors, and patterns | 30,458 incidents, 10,626 breaches (2024 edition) | Annual (since 2008) |
| FBI IC3 | Reported cybercrime financial losses (U.S.) | Public complaint submissions; 880,418 complaints in 2023 | Annual |
| CISA | Critical infrastructure threats, advisories | U.S. government and critical infrastructure reporting | Continuous advisories; annual threat assessments |
| CrowdStrike Global Threat Report | Adversary intelligence, eCrime, APTs | Anonymized telemetry from CrowdStrike Falcon platform (millions of endpoints) | Annual |
| Mandiant M-Trends | Incident response findings, dwell time | Confirmed IR investigations across Mandiant client base | Annual |
| Sophos State of Ransomware | Ransomware payments, recovery, impact | 5,000 IT/security leaders, 14 countries (2024) | Annual |
| ENISA Threat Landscape | EU threat environment, sector analysis | ENISA member state reporting, CERT/CSIRT data | Annual |
Strategic Takeaways for CISOs, CIOs, and Corporate Boards
Cybersecurity statistics serve a practical function beyond informing threat models: they justify capital allocation, insurance premiums, vendor contracts, and board-level risk reporting. The following takeaways translate aggregate research into actionable security program guidance.
Quantify breach risk in dollar terms before budget conversations
IBM's MTTD/MTTC savings data ($1.49M for IR planning, $1.76M for AI automation) provides defensible ROI calculations for security investment. Use industry-specific breach cost averages (healthcare: $9.77M; manufacturing: $4.64M) to anchor board-level risk discussions in financial reality rather than abstract threat descriptions.
Credential security and MFA deployment address the most common attack vector
Compromised credentials are involved in 44%+ of confirmed breaches. Full MFA deployment at enterprise scale (currently ~90% in large enterprise, 38% in SMBs) directly reduces the probability of successful initial access from the most prevalent attack category. Prioritize phishing-resistant MFA (FIDO2/passkeys) over SMS-based OTP, which is vulnerable to SIM swapping and adversary-in-the-middle attacks.
Test your incident response plan, not just its existence
IBM's data shows a $1.49M cost difference between organizations with a tested IR plan and those without one. Organizations that had an IR plan but had never tested it performed only marginally better than those with no plan at all. Tabletop exercises and red team simulations are the testing mechanisms with the clearest documented cost reduction evidence.
Use median ransomware statistics, not averages, for SMB risk planning
The median ransomware payment ($1.5M) better represents typical exposure for mid-market organizations than the mean (inflated by large enterprise payouts). SMBs should also factor in the 60% closure rate within 6 months of a serious breach when modeling total existential risk, not just recovery costs. The distinction matters and is covered in our mean vs median vs mode guide.
SEC disclosure rules create new legal exposure for public company executives
The SEC's December 2023 cybersecurity rules require public companies to disclose material breaches within 4 business days of determining materiality. Boards must now have documented processes for breach materiality assessment, not just incident response. Legal and governance costs are the fastest-growing component of enterprise breach costs in IBM's 2024 data.
Cloud security requires active measurement, not inherited assumptions
Cloud providers secure the infrastructure layer. Organizations are responsible for securing their configurations, access controls, data classification, and API security. Misconfigurations account for 21% of data breaches and produce a $5.17M average breach cost, above the global average. Continuous cloud security posture management (CSPM) tooling is the control with highest coverage efficiency per dollar in cloud environments.
Frequently Asked Questions
Global cybercrime damages reached an estimated $9.22 trillion in 2024, according to Cybersecurity Ventures, which aggregates data from government reports, breach databases, and security vendor telemetry. That figure is projected to reach $10.5 trillion annually by 2025. If measured as a national economy, cybercrime would rank as the world's third-largest after the United States and China. FBI IC3 reported $12.5 billion in confirmed U.S. losses in 2023 alone, a figure acknowledged to represent a fraction of total actual damages because most incidents go unreported.
The global average cost of a confirmed data breach in 2024 was $4.88 million per incident, according to IBM Security's Cost of a Data Breach Report 2024, which analyzed 604 organizations across 17 industries and 16 countries. In the United States the average was $9.36 million, the highest national figure globally and the fourteenth consecutive year the U.S. led this category. The healthcare sector averaged $9.77 million per breach, the highest industry cost for 14 straight years due to the sensitivity of protected health information (PHI) and strict HIPAA regulatory requirements.
The 2024 Verizon Data Breach Investigations Report found that 68% of all confirmed breaches involved a non-malicious human element, including employees falling victim to phishing, making configuration errors, or mishandling data. Within that, phishing and stolen or compromised credentials were the two most frequent specific initial access methods, with credentials involved in more than 44% of confirmed incidents. Cloud misconfigurations accounted for approximately 21% of breaches. Technical controls alone are insufficient without robust security awareness training and strong identity access management.
IBM Security's 2024 data put the global average at 194 days to identify a breach and 64 days to contain it once identified, for a full breach lifecycle of 258 days. These are arithmetic means pulled upward by a small number of incidents with very long attacker dwell times. Organizations that identified and contained breaches in under 200 total days saved an average of $1.12 million compared to those that took longer. Organizations with a fully deployed Security AI and automation platform reduced their average lifecycle to 168 days, saving $1.76 million per breach on average.
Verizon's 2024 DBIR found that 43% of all cyberattacks targeted small businesses. SMBs are attractive targets because they hold valuable data, process payment cards, and sit in the supply chains of larger organizations, while typically having less sophisticated defenses. Research from the U.S. National Cyber Security Alliance found that 60% of SMBs that suffer a major cyberattack close within six months. The average breach cost for an SMB was $3.31 million in 2024, which while lower than the enterprise average, represents a far larger portion of total revenue and reserves for a small business.
Cybersecurity statistics are empirically collected, quantitative measurements of the frequency, financial impact, technical characteristics, and trends in cyber threats, data breaches, and security investments. They come from multiple source categories: government law enforcement databases (FBI IC3, CISA), primary research with organizations (IBM Security, Ponemon Institute, Verizon DBIR), automated threat telemetry from security platforms (CrowdStrike, Microsoft MSTIC), and workforce studies (ISC2). Valid cybersecurity statistics specify their measurement period, sample scope, and definition of the metric being measured, allowing direct comparison across time periods and organizations.