$4.88M
Global average cost of a data breach in 2024, the highest figure ever recorded.
Up 10% year-over-year. The report aggregates 604 organisations across 17 countries and 17 industries.
IBM — Cost of a Data Breach Report 2024 (2024)Curated from Verizon DBIR, IBM Cost of a Data Breach, Sophos State of Ransomware, CrowdStrike Global Threat Report, Microsoft Digital Defense Report, CERT-In, RBI, and Infilux AppSec field data. Every stat has a one-click citation in APA-ish format.
What a single data breach actually costs in 2024 — global averages, sector variance, detection and containment time.
$4.88M
Global average cost of a data breach in 2024, the highest figure ever recorded.
Up 10% year-over-year. The report aggregates 604 organisations across 17 countries and 17 industries.
IBM — Cost of a Data Breach Report 2024 (2024)$9.77M
Healthcare remains the costliest sector for breaches — fourteenth consecutive year on top.
IBM — Cost of a Data Breach Report 2024 (2024)₹19.5 Cr
Average breach cost in India — approximately ₹19.5 crore (US$2.35M), up 28% since 2020.
IBM — Cost of a Data Breach Report 2024, India edition (2024)258 days
Average time to identify AND contain a breach worldwide. 194 days to identify, 64 to contain.
IBM — Cost of a Data Breach Report 2024 (2024)$4.81M
Stolen or compromised credentials remain the costliest initial-attack vector — and the slowest to detect.
IBM — Cost of a Data Breach Report 2024 (2024)$4.66M
Breaches that originate in the supply chain cost on average 11.8% more than internally-caused breaches.
IBM — Cost of a Data Breach Report 2024 (2024)$2.22M
Organisations that deployed security AI and automation extensively saved an average $2.22M per breach versus those that didn't.
IBM — Cost of a Data Breach Report 2024 (2024)10,626
Confirmed data disclosures analysed in Verizon's 2024 DBIR — across 30,458 real-world security incidents.
Verizon — Data Breach Investigations Report 2024 (2024)Frequency, payment behaviour, recovery rates, and which sectors take the heaviest hit.
59%
Of surveyed organisations were hit by ransomware in the past year.
Sophos — State of Ransomware 2024 (2024)$2.0M
Average ransom payment in 2024 — five times the 2023 figure of $400K.
Sophos — State of Ransomware 2024 (2024)$2.73M
Average cost to recover from a ransomware attack (excluding ransom paid), up 50% YoY.
Sophos — State of Ransomware 2024 (2024)32%
Of ransomware attacks started with an exploited vulnerability — the most common initial vector.
Sophos — State of Ransomware 2024 (2024)62 minutes
Average eCrime adversary breakout time — how fast attackers move from initial access to lateral compromise.
CrowdStrike — Global Threat Report 2024 (2024)+75%
Year-over-year increase in cloud-based intrusions tracked by CrowdStrike threat-intelligence telemetry.
CrowdStrike — Global Threat Report 2024 (2024)29%
Of ransomware victims paid the ransom in Q4 2024 — historic low, down from 85% in 2019.
Coveware — Q4 2024 Ransomware Marketplace Report (2024)How attackers actually get in — the human-element story across recent DBIRs.
68%
Of breaches in 2024 involved a non-malicious human element — error, mis-routing, or social-engineering victim.
Verizon — Data Breach Investigations Report 2024 (2024)32%
Of breaches involved stolen credentials, making them the most common entry tactic for the third consecutive year.
Verizon — Data Breach Investigations Report 2024 (2024)2x
Pretexting incidents (business email compromise) doubled year-over-year, with median loss of $50,000.
Verizon — Data Breach Investigations Report 2024 (2024)21 minutes
Median time from receipt of a phishing email to the first click by a user.
Verizon — Data Breach Investigations Report 2024 (2024)33.2%
Baseline phish-prone percentage across untrained employees — one in three clicks on a simulated phishing email.
KnowBe4 — Phishing By Industry Benchmarking Report 2024 (2024)↓ to 4.6%
Phish-prone rate drops to ~4.6% after 12 months of consistent security-awareness training and simulations.
KnowBe4 — Phishing By Industry Benchmarking Report 2024 (2024)600M/day
Identity attacks blocked daily by Microsoft Entra ID across the global Microsoft cloud — a 10× year-over-year increase.
Microsoft — Digital Defense Report 2023 (2023)How EASM, cloud misconfiguration, and shadow IT show up in the real-world breach record.
99%
Of cloud security failures through 2025 will be the customer's fault — primarily misconfiguration.
Gartner — Public Cloud Security forecasting analysis (2023)69%
Of organisations have experienced a cyber incident from an internet-facing asset they didn't know they owned.
Forrester — The State of Attack Surface Management 2024 (2024)8M+
Critical services (databases, RDP, exposed admin panels) found on the public internet in routine scans.
Censys — State of the Internet 2024 (2024)12.8M
Secrets (API keys, passwords, tokens) discovered in public GitHub repositories in a single year.
GitGuardian — State of Secrets Sprawl 2024 (2024)30%
Of an enterprise's external attack surface is, on average, undocumented in the CMDB at the start of an EASM engagement.
Infilux AppSec — Field observation across 110+ enterprise engagements (2024)+13 days
Multi-cloud environments take 13 days longer to identify and contain a breach than single-cloud environments.
IBM — Cost of a Data Breach Report 2024 (2024)1,200+
Vulnerabilities listed in the CISA Known Exploited Vulnerabilities (KEV) catalog — actively exploited in the wild.
CISA — Known Exploited Vulnerabilities Catalog (2024)Why identity is the new perimeter — and where access control still leaks.
99.9%
Reduction in account-compromise risk when multi-factor authentication is enabled on user accounts.
Microsoft — Security Engineering research (2024)15%
Of all web-application attacks involve credential stuffing — automated reuse of leaked username/password pairs.
Verizon — Data Breach Investigations Report 2024 (2024)+50%
Year-over-year increase in MFA-bypass attempts using social engineering, push-fatigue, and adversary-in-the-middle phishing.
Okta — Customer Identity Trends Report 2024 (2024)~80%
Of red-team engagements end with domain-admin compromise via Active Directory weaknesses — Kerberoasting, ACL abuse, GPO misconfiguration.
Infilux AppSec — Aggregated red-team engagement statistics 2023-2024 (2024)13.6B
Unique credentials known to have been exposed in public data breaches indexed by Have I Been Pwned.
Have I Been Pwned — Pwned Passwords v8 (2024)45:1
Median ratio of non-human identities (service accounts, automation, machine credentials) to human users in enterprise cloud estates.
Cloud Security Alliance — Non-Human Identity Report 2024 (2024)Regulatory cost, audit timelines, and where compliance overlaps with security outcomes.
6–12 months
Typical time from kickoff to first ISO/IEC 27001 certification for a mid-sized organisation.
Industry baseline — BSI, Bureau Veritas, ISACA guidance (2024)$40K–$150K
Total first-year cost for a SOC 2 Type 2 attestation — audit fees, tooling, and internal effort combined.
Industry benchmarks — AICPA, leading SOC 2 auditors (2024)€4.5B+
Cumulative GDPR fines issued since May 2018 — Meta, Amazon, TikTok, and Instagram top the list.
Enforcement Tracker / DLA Piper GDPR Data Breach Survey 2024 (2024)2023
Year India's Digital Personal Data Protection (DPDP) Act became law. Rules and enforcement are rolling out through 2025-2026.
Ministry of Electronics & Information Technology, Government of India (2023)2016
Year the RBI Cyber Security Framework became mandatory for all scheduled commercial banks operating in India.
Reserve Bank of India — Cyber Security Framework circular (2016)Jan 17, 2025
EU Digital Operational Resilience Act (DORA) enforcement date — applies to all financial entities and their ICT third-party providers.
European Banking Authority — DORA implementation timeline (2025)~70%
Control overlap between ISO/IEC 27001 Annex A and SOC 2 Trust Services Criteria — most evidence is reusable across both audits.
Mapping analyses — Drata, Vanta, Secureframe (industry consensus) (2024)How the cybersecurity threat picture looks for Indian and broader Asia-Pacific enterprises specifically.
15.9 lakh
Cyber incidents reported to CERT-In in 2023 — a 27% increase over 2022, driven by ransomware, phishing, and supply-chain attacks.
CERT-In — Annual Report 2023 (2023)78%
Of Indian organisations experienced at least one ransomware attack in the last 12 months.
Data Security Council of India (DSCI) — Annual Cybersecurity Survey (2024)1,500+
Co-operative banks in India subject to RBI cyber-security framework — a sector consistently ranked the most targeted by financial fraud.
Reserve Bank of India — co-operative banking statistics (2024)$3.23M
Average breach cost across ASEAN — lower than the global $4.88M average but climbing fastest in the world.
IBM — Cost of a Data Breach Report 2024 (2024)5+ frameworks
Compliance frameworks in India that explicitly mandate periodic VAPT — RBI, SEBI, IRDAI, NPCI, and CERT-In Empanelment.
Compendium of Indian cyber-security regulations (2024)70+
Indian co-operative banks securing their digital channels with Infilux AppSec's VAPT, GRC, and SOC services.
Infilux AppSec — Engagement portfolio 2020-2024 (2024)Quote any individual stat with the “Copy citation” button next to it. For an aggregate citation of the page itself:
Infilux AppSec (2025). Cybersecurity Statistics 2026. Retrieved from https://infilux.in/stats. 48+ curated, sourced data points.
Refreshed annually. Spot a stale stat? Email research@infilux.in.