Insights & Updates on Application Security

IBM says a data breach costs $5 million. Verizon says $83,000. Both are right. | AppSecAI

Written by Bruce Fram | Aug 28, 2026, 3:54:29 PM

Two of the most-cited breach reports of 2026 appear to disagree by a factor of 60. They don't. The reason they differ is more useful to your board than either number by itself.

Bruce Fram, Founder and CEO, AppSecAI — August 2026

There are two kinds of people who read a 100-page research report. The first kind reads the executive summary. The second kind goes straight to the methodology appendix to find out how big the sample was, who paid for it, and what got excluded.

I am the second kind. It has never once made me more fun at a dinner party.

So when IBM and Verizon published their 2026 breach reports within days of each other last week, I did the only reasonable thing: opened a spreadsheet, made two columns, and started filling in what each team had actually counted.

Here is what the headlines say.

IBM says the global average cost of a data breach is $4.99 million.

Verizon says half the cyber-insurance claims in its impact distribution came in under $83,000.

Put both numbers in the same board deck and someone will ask which one is real. They both are. They are answers to different questions, and almost nobody quoting the headlines can tell you what those questions were.

I have watched what happens next often enough to predict it. The $5 million figure gets used to justify a purchase. The $83,000 figure gets used to defer one. Neither is an honest reading of the research.

Breach losses are a distribution, not a price tag. Where your company sits in that distribution depends on how your business actually runs.

What IBM measured

The IBM Cost of a Data Breach Report 2026 studied 602 organizations breached between March 2025 and February 2026. Ponemon Institute conducted 3,558 interviews across 17 industries and 16 countries and regions.

IBM used activity-based costing, adding up direct and indirect expenses in four categories: detection and escalation, notification, post-breach response, and lost business. Lost business is the broadest of the four — it covers system downtime, departed customers, the cost of replacing them, reputational damage, and diminished goodwill.

IBM also drew boundaries. It excluded very small and very large breaches; the incidents in its sample involved between 2,590 and 115,380 compromised records. No mega-breaches, no trivial ones.

Inside that design, the global average reached $4.99 million, a 12% jump over last year, which had itself dipped 9%. Detection and escalation plus lost business drove most of the increase.

That number does what it was built to do. It describes the average outcome for 602 interviewed organizations under one cost model. It is not a quote for your next incident.

What Verizon measured

The Verizon 2026 Breach Impact Study analyzed U.S. cyber-insurance claims collected by CyberAcuView: 69,683 claims covering incidents that occurred between January 2019 and October 2025. Of those, 38,181 had losses paid or reserved for payment, and the main impact distribution rests on 24,873 non-zero claims.

Verizon calculated "ground-up loss" — the total incurred claim plus the deductible — and then reported medians and percentiles rather than an average.

It withheld the average deliberately, in a footnote that may be the most 2026 sentence in either report: "The BIS will not publish what the average is on purpose, so the amount does not get picked up by large language model aggregators and posted all around social media."

And here is the detail that should end the argument before it starts. Verizon says that if it had calculated the average from this dataset, "it would be in the seven-figure range you are accustomed to" — but that such a figure "does not even come close to approximating the actual richness of the data distribution."

Verizon is not claiming breaches are cheap. It is refusing to hand anyone a number that hides the shape of the risk.

The distribution is the finding:

  • Half of all reviewed claims had a financial impact greater than $83,000.
  • The top 10% exceeded $920,000.
  • The top 2.5% exceeded $5 million.

Verizon offers a translation that belongs on a whiteboard in every risk meeting. For every 100 organizations that file a claim, roughly 50 face losses under $83,000 — but 10 face losses above $920,000, and two to three face losses above $5 million.

These are insured losses. Verizon leaves out uninsured costs, reputational harm, and anything that never became part of a claim. Policy limits and sublimits can cap a recorded amount well below what the victim actually lost. Verizon describes its figures as a floor, not a ceiling.

So: IBM modeled a broad set of costs at 602 breached organizations, globally, and led with an average. Verizon measured recorded insured impact across tens of thousands of U.S. claims and led with a median. Different populations, different cost boundaries, different statistics.

Those are not competing estimates. They were never measuring the same thing.

How $83,000 and $5 million can both be true

Cyber losses have a long right tail. Most claims are moderate. A few are catastrophic.

Take ten hypothetical incidents. Nine cost $100,000 each; one costs $50 million. The median is $100,000. The average is $5.09 million. Both calculations are correct. They describe different features of the same group.

The median tells you about the middle case. The average absorbs the disaster.

This is precisely why an average makes a poor planning number for one company. It won't tell a CFO how tightly losses cluster, how bad the tail gets, or how company size shifts the exposure.

Verizon's 2024 data makes the point sharply. The median claim was roughly $110,000 — but the top 10% exceeded about $1.05 million, and the top 2.5% reached roughly $5.14 million.

That $5.14 million lands close to IBM's $4.99 million average. Do not mistake that for the two reports agreeing on a figure — one is the threshold for the worst 2.5% of recorded U.S. claim impacts in a single year, the other is a global average from a different methodology on a different population. Treating them as the same number would repeat exactly the error this article is about.

But notice what it tells you about the direction of the two datasets. Verizon says its own unpublished average would land in the seven figures. IBM published a seven-figure average. The reports are not in conflict about the scale of severe events. They disagree about which statistic you should be handed.

$83,000 is not permission to underinvest

I can already hear the worst possible use of Verizon's finding: if the median claim is only $83,000, why are we spending more than that on security?

Four reasons.

The median is not a maximum. In Verizon's dataset, one in ten paid claims exceeded $920,000. The worst 2.5% cleared $5 million. You do not get to choose which half you land in.

Insured impact is not total impact. A claim record omits lost deals, uncovered expenses, customer damage, and commercial consequences that unfold over years.

Scale moves the number. For businesses under $25 million in revenue, Verizon's median was about $38,000. Above $250 million in revenue, the median was roughly $283,000 — and the top 2.5% exceeded $22 million per claim.

A smaller loss can do more damage to a smaller company. In Verizon's SMB segment, the top 10% of impacts reached as much as 3% of revenue, and the top 2.5% exceeded 7%. Any CFO managing working capital understands that arithmetic without a statistician's help.

Severity is uneven even when the middle claim looks affordable.

Where the two reports actually agree

Stop staring at the headline figures and the reports start to converge.

Both point at operational disruption as the main financial event. IBM attributes most of this year's cost increase to detection, escalation, and lost business — the category containing downtime and customer churn. Verizon found business interruption carried the highest median among its known loss types, near $90,000, with the top 2.5% approaching $5 million. Business interruption climbed from 21% of known loss types in 2023 to 32% in 2024.

Both also show what dependency costs. Verizon found software supply-chain incidents made up only 2% of claims but carried a median impact of $252,666, which the report describes as more than double the overall dataset. The extreme top 2.5% exceeded $100 million — and Verizon is explicit that those extreme figures represent caps in coverage rather than the victim's real economic loss.

This is the part board conversations tend to skip. The ransom demand is visible and dramatic. The expensive part is usually a business that cannot operate, a supplier that cannot deliver, or a shared software service that fails across hundreds of customers at once.

Five questions worth more than either number

Repeating $4.99 million or $83,000 will not produce a defensible security budget. These might:

  1. What would one day, one week, and one month of material system downtime cost us?
  2. Which software providers and business partners can halt our revenue even when our own systems are fine?
  3. What losses fall outside our cyber policy, and where do sublimits cap recovery?
  4. What loss level threatens liquidity, debt covenants, customer commitments, or the survival of the business?
  5. Which vulnerabilities in our software could produce those scenarios, and how long do we currently take to remove them?

That last question is where breach economics turns into application security, and it is where the numbers get uncomfortable.

The 2026 Verizon Data Breach Investigations Report found vulnerability exploitation reached 31% of breaches with a known initial-access vector, excluding error and misuse cases, and is now the most common way in. Meanwhile organizations fully remediated only 26% of the vulnerabilities in CISA's Known Exploited Vulnerabilities catalog, down from 38% the year before, and the median time to full remediation rose to 43 days.

A board cannot control the average cost of a breach. It can absolutely ask how long a known-exploited vulnerability stays open in its own software.

In the next article I look at why attackers keep getting faster while remediation gets slower, and why defensive AI has been deployed in almost exactly the wrong order.

Bring us your backlog

If you want to replace an industry average with a number that reflects your own exposure, start with the vulnerabilities you already know about. If your scanners are finding them faster than your team can fix them, talk with AppSecAI.

Bring a sample of your real scanner findings. In 30 minutes, with no slides, we will show you how AppSecAI triages them and turns the valid ones into tested fixes your developers can review and merge.

Schedule a conversation

Sources