{"id":3462,"date":"2020-10-16T15:49:46","date_gmt":"2020-10-16T12:49:46","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=3462"},"modified":"2026-03-25T17:23:25","modified_gmt":"2026-03-25T14:23:25","slug":"the-cost-of-a-data-breach-in-2020","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/the-cost-of-a-data-breach-in-2020\/","title":{"rendered":"The Cost of a Data Breach in 2020"},"content":{"rendered":"<p>The global average cost of a data breach decreased slightly in 2020, reaching $3.86 million\/breach, down 1.5% from 2019, according to the <a href=\"https:\/\/www.ibm.com\/security\/digital-assets\/cost-data-breach-report\/#\/\" target=\"_blank\" rel=\"noopener noreferrer\">Cost of a Data Breach report 2020<\/a> released by IBM and the Ponemon Institute. Companies in the United States had the highest average total cost at $8.64 million\/breach, followed by the Middle East at $6.52 million. Lost business continued to be the biggest contributing cost factor, accounting for 39.4% of the average total cost, and included business disruption and revenue loss from system downtown, loss of existing and new customers as well as reputational damage.<\/p>\n<p>Customers\u2019 personally identifiable information (PII), which falls under the incidence of <a href=\"https:\/\/www.endpointprotector.com\/blog\/data-protection-in-canada-pipeda\/\">data protection<\/a> regulations, was compromised in 80% of all data breaches, making it the type of record most often lost or stolen. Customer PII was also the costliest type of data compromised in a data breach, averaging $150\/record. Intellectual property came close behind, costing $147\/stolen or lost record.<\/p>\n<p>The average time it took to detect and contain a data breach was 280 days, with over 200 days needed for an organization to identify that a breach had taken place. Germany showed the highest efficiency in dealing with data breaches: it takes a German company only 160 days on average to detect and contain a data breach. Meanwhile, Brazil is on the other end of the spectrum with a staggering 380-day average. It remains to be seen if the coming into force of the <a href=\"https:\/\/www.endpointprotector.com\/blog\/brazils-lgpd-is-now-in-effect\/\" target=\"_blank\" rel=\"noopener noreferrer\">Lei Geral de Prote\u00e7\u00e3o de Dados<\/a> (LGPD), Brazil\u2019s answer to the EU\u2019s\u00a0<a href=\"https:\/\/www.endpointprotector.com\/epp\/gdpr-the-most-in-depth-guide-to-stay-compliant\" target=\"_blank\" rel=\"noopener noreferrer\">General Data Protection Regulation<\/a>\u00a0(GDPR), will help reduce companies\u2019 reaction time in the coming years.<\/p>\n<p>Covering the period between August 2019 and April 2020, the report does not touch on the full impact of the COVID-19 pandemic and remote work on the cost of a data breach. However, participants in the research were asked about the potential impact of longer-term remote workforces on costs. 70% agreed that working from home would increase the cost of a data breach and 76% said it would extend the time it took to detect and react to a potential data breach, a key factor in reducing data breach costs.<\/p>\n<h2>Root Causes of Data Breaches<\/h2>\n<p>The report showed that 52% of data breaches were caused by malicious attacks, with system glitches coming in second with 25% and human error being responsible for the remaining 23% of data breaches. For the first time, malicious attacks were broken down by threat vector, giving us a good overview of the most targeted data access points.<\/p>\n<p>Compromised credentials and cloud misconfiguration were at the top of the list, being responsible each for 19% of data breaches. Third-party software vulnerability accounted for another 16%. Social engineering and phishing attacks, that target employees directly, trying to trick them into revealing sensitive information, accounted for 17% and malicious insiders for a further 7%.<\/p>\n<p>When it comes to human error, the Entertainment industry proved to have the most careless employees, with 34% of data breaches in the sector being attributed to them. In the public and consumer products sectors, 28% of data breaches were caused by human error, with healthcare following closely behind with 27%.<\/p>\n<h2>Costs by industry<\/h2>\n<p>Companies subject to more rigorous regulatory requirements had higher average data breach costs. The healthcare industry continued to average the highest data breach costs of any industry, reaching $7.1 million\/breach, a 10.5% increase from 2019. The energy sector overtook the financial industry, reaching the second-highest data breach cost with $6.39 million\/breach, registering a worrying 14.1% increase from the previous year. The finance sector came in third, with $5.85 million\/breach, recording a small 0.2% decrease from 2019.<\/p>\n<p>The public sector had the lowest average data breach cost with $1.08 million\/breach, a 16.3% decrease from last year. However, the success story of 2020 was the media sector that managed to reduce its data breach costs by an impressive 26.3%, reaching an average cost of $1.65 million\/breach.<\/p>\n<p>The reaction time to data breaches also varied greatly by industry, with the healthcare sector taking 329 days on average to identify and contain a breach, while the financial sector only took 233 days.<\/p>\n<h2>Cost-saving practices<\/h2>\n<p>Incident response plans were the biggest cost saver when it came to the average cost of a data breach. Businesses that had appointed an incident response team and extensively tested their incident response plan had an average data breach cost of $3.29 million\/breach, while those that didn\u2019t have either of them had an average cost of $5.29 million\/breach, an impressive $2 million difference.<\/p>\n<p>Data breaches with a lifecycle of less than 200 days had an average cost of $3.21 million, $1.12 million less than those that take over 200 days to be identified, and contained and cost $4.33 million\/breach. Security automation was shown to have a significant impact on the data breach lifecycle, helping to reduce it by as much as 74 days on average.<\/p>\n<p>Data loss prevention is also a key factor in cost-saving, helping companies save on average approximately $165,000\/data breach through the direct protection of sensitive data. Extensive encryption can reduce data breach costs by a further $237,000.<\/p>\n<h2>In conclusion<\/h2>\n<p>No data protection strategy is foolproof and even the strictest cybersecurity framework cannot guarantee that a company will not suffer a data breach. Whether it\u2019s a new vulnerability that hasn\u2019t been discovered and patched yet or a tired employee making a careless mistake, companies can suddenly find themselves having to deal with a data breach and the significant costs that come with it. As shown in the IBM and Ponemon Institute\u2019s Data Breach Report 2020, there are a number of ways organizations can help reduce the costs of data breaches and it all comes down to foresight and the right tools.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The global average cost of a data breach decreased slightly in 2020, reaching $3.86 million\/breach, down 1.5% from 2019, according to the Cost of a Data Breach report 2020 released by IBM and the Ponemon Institute. Companies in the United States had the highest average total cost at $8.64 million\/breach, followed by the Middle East &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/the-cost-of-a-data-breach-in-2020\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The Cost of a Data Breach in 2020&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":3464,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3462","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-loss-prevention","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=3462"}],"version-history":[{"count":4,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3462\/revisions"}],"predecessor-version":[{"id":8289,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/3462\/revisions\/8289"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/3464"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=3462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=3462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=3462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}