The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →IBM’s 2025 Cost of a Data Breach Report put the average cost of a breach for U.S. organizations at a record $10.22 million. That is a report-year study average, not a bill every company should expect after an incident. In the same edition, the global average was $4.44 million and fell for the first time in five years. IBM has since published a 2026 edition, so the $10.22 million figure should be read as the 2025 U.S. result—not as a current 2026 estimate.
What does a data breach cost a U.S. company?
According to IBM’s 2025 report, the average U.S. breach cost was $10.22 million. IBM described it as a record for the United States. The figure is an average for organizations represented in that study, not a median, a cost per exposed record, or a forecast for a particular company or incident.
The report drew on breach experiences at 600 organizations worldwide during March 2024 through February 2025. Ponemon Institute conducted the research, while IBM sponsored and analyzed it. The published announcement identifies the sample count, geography and experience period, but does not provide enough detail to explain the full sampling, weighting or cost-accounting methodology; those details should not be inferred from the headline figure.
How did the U.S. result compare with the global average?
| Measure | IBM 2025 report | What it means |
|---|---|---|
| United States average | $10.22 million | IBM reported a record average for U.S. organizations in this edition. |
| Global average | $4.44 million | IBM reported the first global decline in five years. |
These are different geographic averages from the same report, not competing estimates of one identical group. The U.S. result rose even as the worldwide average declined; neither number describes what every organization paid. IBM’s announcement reports the direction and values but does not establish a single cause for the gap.
What does the newer 2026 report change?
IBM’s 2026 Cost of a Data Breach Report gives a global average of $4.99 million, which IBM says is 12% above the prior year. That newer worldwide figure updates the global comparison for its edition; it does not replace or update the 2025 report’s U.S. average of $10.22 million. The two figures should not be compared as if they covered the same geography and report year.
#1 Best Overall
What other findings did IBM report for 2025?
- AI-related exposure: 13% of organizations reported breaches involving AI models or applications. Among organizations reporting that kind of compromise, 97% said they lacked AI access controls.
- Shadow AI: Organizations with high levels of shadow AI had an average breach cost $670,000 higher than organizations with low or no shadow AI. Shadow AI means unapproved AI tools used without organizational oversight; the reported difference is not an increment that applies to every company.
- Security automation: Organizations extensively using AI and automation in security operations had average breach costs $1.9 million lower, according to IBM. This is an observed association in the report, not proof that buying or deploying AI tools alone will produce that saving.
- Healthcare: IBM reported a $7.42 million average breach cost for healthcare organizations in the 2025 edition.
- Response time: The global average breach lifecycle was 241 days in the report.
- Post-incident plans: 49% of breached organizations said they planned to invest in security after the breach. This is a reported intention, not a guarantee that the investment was made.
These are findings from IBM’s study and carry the same limits as its broader averages. IBM is both sponsor and analyst; its report findings and security recommendations should be understood with that context. IBM’s X-Force commentary discusses organizational risks and security practices, including oversight of AI tools, in its analysis of the 2025 report.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should a business take from the figure?
The practical takeaway is not to budget exactly $10.22 million for every possible breach. The study average can signal that incidents may carry substantial organizational costs, but it cannot predict a specific company’s losses. Businesses should assess their own exposure, response capabilities and controls rather than treating a broad average as a personalized estimate. IBM’s reported findings point to AI oversight and access controls as areas to examine, particularly where employees use tools that have not been approved or governed.
Rank #2
IBM’s 2025 release quotes Suja Viswesan, IBM’s Vice President of Security and Runtime Products: “The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it.” This is a statement from an IBM executive, not an independent study conclusion.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




