A data breach could cost organizations millions of dollars, IBM and Black Kite researchers found in their recent studies. Both reports showed similar conclusions that data breaches have a “haunting effect,” and lacking the use of certain security technologies could lead to higher breach costs.

IBM’s 2022 Cost of a Data Breach Report is based on its analysis of data breaches experienced by 550 organizations globally between March 2021 and March 2022. It found the average cost of a data breach reached a record $4.35 million this year, slightly higher than last year’s average of $4.24 million.

While IBM’s annual report has comparisons year over year, Black Kite researchers analyzed 2,400 global data breach incidents for the past five years and found the overall average cost of a data breach after removing the outliers was $15 million.  

The cost numbers from the two reports are different “since breach costs can continue to aggregate over time, in many instances far longer than a year,” Black Kite CSO Bob Maley explained. 

IBM’s report also shed a light on the “haunting effect," which shows that the after-effect of those data breaches lingers long. Nearly half of the data breach costs are incurred more than a year after they occur and 83% of the studied organizations have experienced more than one breach, according to the report.

Black Kite researchers also found that 17% of the 1,700 breached companies they analyzed are highly susceptible to a ransomware attack, and 79% to a phishing attempt.  

Another impact of those incidents is their contribution to the rising costs of goods and services, as 60% of organizations in the IBM report raised their prices due to the breaches. 

"The true cost of a data breach is often not fully realized immediately following the event. Even after a few months, the full scope of the damage may not yet be understood,” Black Kite head of research Ferhat Dikbiyik wrote in the report. “Companies have to deal with the consequences in the eyes of regulators, courts, and civil society for years.” 

As one example of lingering costs of data breaches, last week T-Mobile revealed that it would pay $350 million to consumers impacted by its data breach as part of a settlement, and it expected to spend $150 million on data security over the next 18 months.

Zero-Trust Adoption Lags in Critical Infrastructure

IBM’s report showed that organizations with a mature zero-trust strategy observed $1.5 million lower data breach costs compared to those with early adoption of zero trust.

However, only 21% of the studied critical infrastructure organizations adopted a zero trust security model, even a year after President Biden’s cyber executive order.

Twenty-eight percent of the breaches those organizations experienced are ransomware and destructive attacks, while 17% of those incidents were caused by a business partner being initially compromised. This highlights the security risks that over-trusting environments pose, researchers pointed out. 

IBM’s report shows that “the right strategies coupled with the right technologies can help make all the difference when businesses are attacked," Charles Henderson, global head of IBM Security X-Force, said in a statement. 

Black Kite researchers also warned credential management and information disclosure are the top critical issues related to a data breach. To combat those susceptibilities, many organizations turn to zero-trust measures such as two-factor authentication.