Data-breach costs jumped nearly 10% from an average of $3.86 million to $4.24 million per incident over the past year, according to IBM’s latest Cost of a Data Breach Report. It marks the highest average total cost in this report’s 17-year history and the largest single-year increase in the last seven years. 

The 2021 Cost of a Data Breach Report is based on analysis of 537 real-world data breaches in 17 different industries across 17 countries and regions that occurred between May 2020 and March 2021.

Despite the overall cost growth, organizations with more mature security postures that deployed tools including artificial intelligence (AI), automation, zero trust, and cloud security saw significantly lower costs.

IBM’s report indicates that around 35% of the surveyed organizations had implemented a zero-trust security approach, and 48% of those were in the mature stage. The average data breach cost for companies with a mature zero-trust strategy was $3.28 million, which was $1.76 million less than the ones without zero trust.

“We're seeing that there's definitely a correlation,” said Limor Kessem, executive security advisor at IBM Security. “The more zero trust was implemented, the more they saved in data-breach costs, which was really awesome proof to see that [zero trust is] actually working in real-world data breaches.”

The bottom line is that the companies that adopted some level of zero trust are in a better position to deal with data breaches, she said. Not only can zero trust help secure distributed IT environments, but it also can help contain the breach so it doesn’t have to spill over to the other parts of the networks, she added. 

For the 11th consecutive year, health care organizations experienced the highest average cost of a data breach by industry ($9.23 million), followed by the financial sector and pharmaceuticals. The report found that the health care sector saw a $2 million (180%) increase over the previous year. 

During the pandemic, health care becomes a lot more critical, so the attackers target these organizations more, Kessem told SDxCentral. To reduce breach costs in the future, the industry can benefit from using automation to reduce human error and implementing zero-trust enabling technologies to modernize their infrastructure.

Remote Work Led to More Expensive Data Breaches

According to Kessem, IBM reported a 1.5% decline in average breach costs over a “normal year” of 2019. Many organizations encouraged or required remote work last year. According to the report, the average cost of a data breach was $1.07 million higher when remote work was indicated as a factor in the event.

Sixty-percent of surveyed organizations moved further into cloud-based activities during the pandemic. However, companies with mature cloud modernization were able to identify and contain breaches 77 days faster than those in the early stages of modernization, which can save more breach costs, Kessem said.

This year’s report found that the average time to detect and contain a data breach was 287 days (212 to detect, 75 to contain), which is one week longer than the previous year.

Compromised Credential Found as a Leading Cause

Compromised credentials proved the most common initial attack vector responsible for 20% of the breaches. It was followed by phishing (17%) and cloud misconfigurations (15%). “Interestingly, the costliest factor was business email compromise, but that was only 4% of the cases,” Kessem said.

Kessem suggests CISOs and organizations look chronologically at how data breaches begin and how they deploy their security technologies. If they see numbers indicating zero-trust enabling technologies mitigated costs more than other security tools, for example, then “I want to go and start really getting into zero trust if I haven't already,” Kessem said. 

Reports from other security companies echoed IBM’s findings. According to the data presented by the Atlas VPN, ransomware has already cost victims $45 million in 2021.