The headlines from the 2026 edition of Cost of a Data Breach made for interesting reading, but does it actually demonstrate a better perspective of the state of resilience amongst cyber professionals?
In the 21st edition of the Cost of a Data Breach Report, the global average cost of a data breach was $4.99 million, a significant increase from $4.44 million in 2025. IBM, which sponsors the report, said this equates to around $1,100 per hour that the incident is ongoing, including everything from crisis management to disrupted operations and customer churn.
The report also found that the average time organisations took to identify and contain a breach had risen to 247 days. When breaches were identified by internal IT teams, this figure fell to 209 days on average. Where organisations remained unaware of a breach until attackers notified them, the average cost reached $5.12 million.
Of course, this is all useful to know, and there is a stack of research available offering statistics like these. But what do we actually learn from them? How can you measure your level of resilience based on how much a breach could cost you, and what actually determines the business impact of a cyber incident?
Following major attacks and breaches over the past year, organisations are increasingly being judged on how effectively they respond, recover and maintain trust, rather than simply whether they experience a cyber incident. When one incident saw the government bailout Jaguar Land Rover to the tune of £1.5 billion, it placed a greater emphasis on the company’s preparation, governance and resilience in the face of a cyber incident.
Business Impact
The business impact of a breach isn’t always measured by the size of a government bailout, but by how an organisation responds and how much trust it can retain through its actions towards customers, partners and shareholders.
Lisa Ventura, cybersecurity specialist and founder of Cyber Security Unity, says that ultimately, trust is earned during an incident, not after it, and is rebuilt through the quality and timeliness of communication, particularly while the situation remains uncertain: “and not just by the headline press statement that’s issued once everything has been resolved and is back up and running.”
She says customers will remember whether they were told early, whether what they were told was accurate, and whether the organisation kept them updated as the picture changed.
“I think a lot of people won’t mind the fact that they’ve got an incomplete message, they just don’t like nothing at all going out. So, I’d put a named person front and centre that can handle [things] from an external perspective and someone who’s comfortable with explaining what’s known and what isn’t.”
On top of this, it is worth considering how recognised frameworks such as ISO 27001 can support these foundations through incident response, business continuity and continual improvement, and how much they help organisations build these capabilities.
Prevention to Resilience
Looking at the report again, we need to consider what it tells us about governance and cyber resilience, and where that trend is heading. The evidence suggests that cybersecurity is moving from a prevention-first model towards one of resilience, where organisations assume that some attacks will get through and focus increasingly on limiting the blast radius, maintaining operations and recovering quickly.
If a company cannot guarantee that it will stop every intrusion, it can still reduce the cost by identifying incidents earlier, containing them faster, maintaining critical operations, testing incident response processes, recovering data and systems, and ultimately restoring customer confidence and learning from the incident. Resilience therefore becomes a measurable economic control rather than simply a disaster recovery concept.
On this point, 64% of organisations said that after experiencing a breach, they would increase security investment. That makes resilience a board-level issue, as attackers are increasingly targeting trust, public perception and long-term business impact. Organisations still need prevention, but they are increasingly recognising that prevention alone cannot provide certainty. Detection, containment, recovery and business continuity therefore become equally important measures of security effectiveness.
Resilience isn’t replacing prevention because organisations have given up on stopping attacks. It is becoming more important because the probability of preventing every attack is falling, while the cost of allowing an attack to persist is rising.
Quentyn Taylor, director of information security at Canon Europe, said he was aware of one instance where two companies were hit by the same actor. One was offline for a long period of time, while the other had carried out “incident simulations to the nth degree; everyone knew what their place was, and everyone knew what they should be doing.”
He said this display of resilience and governance is about accepting that bad things are going to happen and being prepared to deal with them, considering what the least-worst outcome could be and identifying the best way to recover.
“For me, resilience is about people understanding what it is they should be doing,” he said. “It’s not everyone working according rigidly to a plan, but everyone working according to the spirit of the plan. That’s true resilience.
“Everyone understanding what the big picture is, everyone’s saying what their piece in the big picture is, and everyone knowing that I am empowered to be able to make the right decisions if I need to.”
Quick Recovery
Ultimately, the business impact of a cyber incident can be determined long before the incident occurs. The difference between organisations that suffer prolonged disruption and those that recover quickly often comes down to governance, preparedness and the ability to make effective decisions under pressure.
Organisations who understand resilience and their critical processes, have clearly defined responsibilities, regularly test their response plans and empower people to act when circumstances change lead the example here of how to operate. They also recognise that resilience is not simply a technical capability, but an organisational one, shaped by leadership, communication and decision-making.
The cost of an incident therefore depends not only on what happens, but on how prepared an organisation is to respond and how much governance you have over your operations.
Expand Your Knowledge
Blog: The NVD Pullback Should Prompt A Resilience Approach To Vulnerability Management







