The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
IBM’s 2024 Cost of a Data Breach Report estimated the average total cost of a data breach involving an Indian organisation at ₹19.5 crore. The figure was 9% higher than in 2023 and 39% above 2020. It is an average economic-impact estimate—not a government fine, ransom payment, compensation amount or forecast for every Indian company.
The underlying incidents were studied between March 2023 and February 2024. IBM released the report on July 31, 2024. Because later reporting put the India figure for 2025 at about ₹22 crore, ₹19.5 crore should be treated as the 2024 India estimate, not the latest available number in 2026.
What the ₹19.5-crore figure includes
The IBM/Ponemon estimate represents the average total economic cost of a breach. It can include investigation, detection and escalation, containment, recovery, legal work, customer notification, business interruption, lost customers and reputational damage.
Free tools Windows power users keep installed
One-click scans. No signup required.
It does not mean that an organisation paid ₹19.5 crore to hackers or that the stolen data was worth that amount. It is also not a statutory penalty, a standard settlement or a guaranteed cost for the next breach. Costs vary with sector, company size, records affected, downtime, regulatory exposure, customer numbers and the complexity of the attack.
#1 Best Overall
IBM’s report covered 604 organisations globally. The available India coverage does not specify how many Indian organisations were included, how the sample was weighted or the precise cost-accounting formula. The India number should therefore be read as a study average, not a census of all Indian breaches.
Business Standard’s report of the findings and Scroll’s summary provide the reported India figures.
Why the average rose
The largest reported change was in lost-business costs, which rose by about 45% year over year. This category includes operational downtime, lost customers, reputational harm and related revenue effects—not simply money stolen from an account.
Notification costs increased 19%, reflecting the expense of identifying affected parties, communicating with them and managing the consequences. Detection and escalation costs rose 7% and remained the largest portion of the India breach-cost breakdown reported in the coverage.
These movements point to several pressures: more disruptive incidents, increasingly complicated cloud and hybrid environments, greater communications obligations and security teams that must investigate attacks while keeping business operations running. The report does not establish that any one factor alone caused the 9% increase.
Common entry points are not always the costliest
IBM’s findings are easier to use when frequency and severity are kept separate:
| Measure | Reported India finding |
|---|---|
| Common initial attack types | Phishing: 18%; stolen or compromised credentials: 18%; cloud misconfiguration: 12% |
| Highest average costs among listed root causes | Compromised business email: ₹21.5 crore; social engineering: ₹21.3 crore; phishing: ₹20.9 crore |
Thus, phishing and compromised credentials were frequent, while compromised business email had the highest average cost among the listed categories. A business-email compromise can enable fraudulent payment instructions, invoice diversion, executive impersonation and access to supplier or customer conversations. Attackers may also use an email foothold to move into cloud identities and other systems.
Recommended Free Tools
Which Indian sectors had the highest averages?
| Sector | Average breach cost |
|---|---|
| Industrial | ₹25.5 crore |
| Technology | ₹24.3 crore |
| Pharmaceutical | ₹22.1 crore |
Industrial organisations had the highest average among the Indian sectors listed in the coverage. That does not mean they experienced the most incidents; the evidence supports a higher average cost, not a ranking by breach count. Globally, IBM also identified healthcare, financial services, industrial, technology and energy as critical-infrastructure categories with high breach costs.
Cloud exposure and long investigations
Thirty-four per cent of the India breaches studied involved data stored on a public cloud. Twenty-nine per cent involved multiple environments, such as public cloud, private cloud and on-premises infrastructure. Public-cloud incidents had the highest reported average cost, ₹22.7 crore.
Breaches spanning multiple environments took 327 days to identify and contain. The lesson is not that using cloud causes breaches. Rather, public exposure, excessive permissions, weak identity controls, incomplete logging and inconsistent policies can make an incident harder to see and investigate across several platforms.
Does faster detection reduce losses?
Organisations that identified and contained incidents in under 200 days recorded an average cost of ₹18.4 crore, compared with ₹20.5 crore when the lifecycle exceeded 200 days. Faster response can plausibly limit attacker dwell time, data extraction, downtime, the number of affected customers and forensic work.
However, this is an association in the IBM study, not a controlled experiment proving that every additional day causes a fixed increase. A small breach that remains hidden may cost less than a rapidly discovered ransomware attack, while a major incident can be expensive even when detected quickly.
Security AI and automation
Twenty-eight per cent of Indian organisations in the study had extensively deployed security AI and automation, up from 20% in 2023. Thirty-five per cent reported limited use and 37% reported none.
IBM associated extensive use with a breach lifecycle 112 days shorter and an average cost ₹13 crore lower. That should not be interpreted as a guaranteed saving or return on investment: the study was sponsored and analysed by IBM, and organisations that automate extensively may also have stronger overall security programmes, better staffing or more mature processes. Automation can introduce false positives, poor tuning, sensitive-data exposure and overreliance on machine decisions.
What the findings mean under India’s regulatory environment
IBM’s India commentary connected the results with the rollout of the Digital Personal Data Protection Act, 2023 and urged organisations to assess regulatory implications and end-to-end compliance. Companies should distinguish that policy context from the report’s economic estimate.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Practical preparation includes mapping personal-data stores and processors, documenting detection and escalation, preserving evidence, coordinating legal and communications teams, and testing customer and regulator communications. CERT-In reporting requirements may apply depending on the incident and organisation, while sector-specific rules and contracts can add obligations. Exact deadlines, penalties and DPDP implementation requirements should be checked against the current legislation, rules and official regulator guidance; they should not be inferred from IBM’s ₹19.5-crore estimate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A practical priority list for companies
- Protect identity first: enforce phishing-resistant MFA for privileged and high-risk accounts, remove stale access and apply least privilege.
- Harden email and payments: require independent verification for payment-detail changes, use strong anti-phishing controls and monitor executive impersonation.
- Review cloud exposure: find public assets, excessive permissions and unprotected secrets; centralise cloud, identity and endpoint logs.
- Improve detection: measure mean time to detect, contain and recover. Use EDR, SIEM or managed detection where internal coverage is insufficient.
- Prepare recovery: maintain tested, resilient backups, segmentation and recovery procedures for ransomware and availability attacks.
- Exercise the response plan: run tabletop exercises involving IT, executives, legal, communications, vendors and insurers; define escalation thresholds and evidence-handling procedures.
- Pre-arrange specialist help: consider an incident-response or forensic retainer before an emergency. Cyber-insurance can transfer some financial risk but cannot prevent downtime and normally requires evidence of baseline controls.
Centralised logging, stricter access controls, cloud-security tooling and outsourced monitoring all involve trade-offs in cost, complexity, user friction, licensing and vendor dependence. Buying a large platform without good telemetry, staffing and response processes will not solve slow containment.
Best Value
How representative is ₹19.5 crore?
There is no basis in the available material to apply this number equally to a small business, a bank, a manufacturer and a national technology platform. A smaller company may face a lower absolute bill but much greater proportional damage. A third-party breach can create costs for an organisation that did not operate the compromised system; a business-email compromise may cause payment fraud without a large personal-data leak; and encrypted data may be accessed but not usable, depending on key management.
Insurance reimbursement, if available, should not be confused with a lower gross breach cost. Contractual, sectoral and regulatory consequences can also arise even when the final financial loss remains uncertain.
Currentness and methodology
The ₹19.5-crore result is the India figure in IBM’s 2024 report, based on incidents from March 2023 to February 2024. Subsequent reporting put the India average for 2025 at approximately ₹22 crore, so readers should not describe ₹19.5 crore as the latest estimate in 2026. The research was conducted by the Ponemon Institute and sponsored and analysed by IBM. Because the retrieved coverage does not provide the Indian sample size or full sampling and costing details, comparisons should be treated as directional rather than a universal benchmark.
For general cybersecurity control categories, IBM discusses identity and access management, attack-surface management, threat detection and response, and disaster recovery in its cybersecurity overview.
The Bottom Line
IBM’s ₹19.5-crore figure shows how quickly breach costs can spread from technical remediation into downtime, customer loss, communications and reputation. It is a study average, not a fine or prediction. Indian organisations should use it to prioritise identity and email protection, cloud governance, faster detection, tested recovery and documented regulatory response.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

