As of 2024, the average data breach cost in the United Kingdom (UK) was around **** million U.S. dollars. In the measured period, 2022 registered the highest cost for breached data, more than five million U.S. dollars. The figure, thus, has increased from *** million U.S. dollars since 2020.
Cyberattacks are potentially ruinous events for business owners. As of 2024, the average cost the most disruptive cyber security breach in the previous 12 months in the United Kingdom was ***** British pounds across all businesses, however, this figure becomes greater as the size of a business increases. The cost of a cyber attack is not only financial, with companies having to spend time on recovering from the attacks. Methods of attackWould-be cyber attackers have a large range of tools at their disposal, with which to get around a business’s digital defenses. Fraudulent emails or being directed to fraudulent websites was by far the most common method used during 2019, with ** percent of security breaches coming in that form. Preventing future attacks Investing in new security technology is a key focus for European and American businesses. Most forms, of all sizes are committed to increasing their spending on cyber security.
As of 2024, the average cost of a data breach in the United States amounted to **** million U.S. dollars, down from **** million U.S. dollars in the previous year. The global average cost per data breach was **** million U.S. dollars in 2024. Cost of a data breach in different countries worldwide Data breaches impose a big threat for organizations globally. The monetary damage caused by data breaches has increased in many markets in the past decade. In 2023, Canada followed the U.S. by data breach costs, with an average of **** million U.S. dollars. Since 2019, the average monetary damage caused by loss of sensitive information in Canada has increased notably. In the United Kingdom, the average cost of a data breach in 2024 amounted to around **** million U.S. dollars, while in Germany it stood at **** million U.S. dollars. The cost of data breach by industry and segment Data breach costs vary depending on the industry and segment. For the fourth consecutive year, the global healthcare sector registered the highest costs of data breach, which in 2024 amounted to about **** million U.S. dollars. Financial institutions ranked second, with an average cost of *** million U.S. dollars for a data breach. Detection and escalation was the costliest segment in data breaches worldwide, with **** U.S. dollars on average. The cost for lost business ranked second, while response following a breach came across as the third-costliest segment.
As of February 2024, the United States ranked first by the average cost of a data breach, **** million U.S. dollars. The average cost of data breaches in the Middle East is **** million U.S. dollars. Benelux followed in the ranking, with *** million U.S. dollars. In the measured period, the global average data breach cost was **** million U.S. dollars. Phishing scams in the U.S. Breached data often ends up in the hands of threat actors who use it for malicious purposes, including online scams. Phishing continues to be a major threat in North America, particularly on smartphones. In the second quarter of 2023, the region recorded the highest number of phishing and malicious attack attempts globally. The United States was particularly affected, with ** percent of U.S. citizens reporting being targeted by scam texts, e-mails, and calls on a daily basis. Additionally, phishing and spoofing were the most common types of cybercrime, impacting *** thousand individuals in 2023. These attacks led to financial losses, with U.S. victims reporting nearly ** billion U.S. dollars in damages throughout the year. U.S. users and data privacy Despite only ** percent of internet users in the United States being highly knowledgeable about data privacy and cybersecurity, a significant portion of users demonstrated caution and awareness in protecting their information. In fact, over half of surveyed U.S. users reported being somewhat confident in knowing the right steps to take in the event of a cyberattack. Furthermore, ** percent of U.S. users actively decline cookies on websites, reflecting their increasing concern for data protection. Many respondents also take additional steps to safeguard their digital privacy, such as limiting or avoiding clicking on ads as well as not answering phone calls due to cybersecurity risks.
The Government has surveyed UK businesses and charities to find out they approach cyber security and help them learn more about the cyber security issues faced by industry. The research informs Government policy on cyber security and how Government works with industry to make Britain one of the most secure places to do business online.
3 April 2019
Respondents were asked about their approach to cyber security and any breaches or attacks over the 12 months before the interview. Main survey interviews took place between October and December 2018. Qualitative follow up interviews took place in January and February 2019.
UK
The survey is part of the Government’s National Cyber Security Programme.
Cyber security guidance and information for businesses, including details of free training and support, can be found on the National Cyber Security Centre website and GOV.UK at: https://www.ncsc.gov.uk" class="govuk-link">www.ncsc.gov.uk and www.gov.uk.
The survey was carried out by Ipsos MORI and its partner, the Institute of Criminal Justice Studies (ICJS) at the University of Portsmouth.
This release is published in accordance with the Code of Practice for Statistics (2018), as produced by the UK Statistics Authority. The UKSA has the overall objective of promoting and safeguarding the production and publication of official statistics that serve the public good. It monitors and reports on all official statistics, and promotes good practice in this area.
The document above contains a list of ministers and officials who have received privileged early access to this release. In line with best practice, the list has been kept to a minimum and those given access for briefing purposes had a maximum of 24 hours.
The responsible statistician for this release is Rishi Vaidya. For any queries please contact 020 7211 2320 or evidence@culture.gov.uk.
A survey conducted in the United Kingdom (UK) between September 2023 and January 2024 revealed that the average long-term cost of the most disruptive breaches for medium and large businesses amounted to 3,550 British pounds. The survey was conducted among UK businesses that identified their most disruptive breach or attack in the last 12 months. In the case of micro and small businesses, the average long-term cost of the most significant breach or attack was 90 British pounds.
This statistic displays the average recovery cost of the most disruptive cyber security breach for businesses in the United Kingdom (UK) in 2020, by business size. Medium/large businesses reported that the average recovery cost of their most disruptive breaches amounted to 1090 British pounds, whereas micro and small businesses reported an average recovery cost of 580 British pounds.The average direct cost and recovery cost of the most disruptive security breaches and the average cost of all cyber security breaches depend heavily on the size of the business. Concerning the size of businesses, micro firms had two to nine employees, small firms had 10 to 49 employees, medium firms had 50 to 249 employees and large firms had 250 employees or more.
This statistic shows the average costs to businesses through cyber crime in the United Kingdom (UK) in 2016 by company size. This includes the average direct costs, average recovery costs and estimated long-term costs. There is a clear correlation between the size of a company and the overall costs of cyber breaches, with large companies seeing an average of ****** British pounds for a cyber attack while a micro/small company sees an average cost of ***** British pounds.
This statistic illustrates the per capita cost of three root causes of the data breach in the United Kingdom (UK) in 2015. In 2015, malicious or criminal attacks have a average per capita cost of *** GBP.
The largest reported data leakage as of January 2025 was the Cam4 data breach in March 2020, which exposed more than 10 billion data records. The second-largest data breach in history so far, the Yahoo data breach, occurred in 2013. The company initially reported about one billion exposed data records, but after an investigation, the company updated the number, revealing that three billion accounts were affected. The National Public Data Breach was announced in August 2024. The incident became public when personally identifiable information of individuals became available for sale on the dark web. Overall, the security professionals estimate the leakage of nearly three billion personal records. The next significant data leakage was the March 2018 security breach of India's national ID database, Aadhaar, with over 1.1 billion records exposed. This included biometric information such as identification numbers and fingerprint scans, which could be used to open bank accounts and receive financial aid, among other government services.
Cybercrime - the dark side of digitalization As the world continues its journey into the digital age, corporations and governments across the globe have been increasing their reliance on technology to collect, analyze and store personal data. This, in turn, has led to a rise in the number of cyber crimes, ranging from minor breaches to global-scale attacks impacting billions of users – such as in the case of Yahoo. Within the U.S. alone, 1802 cases of data compromise were reported in 2022. This was a marked increase from the 447 cases reported a decade prior. The high price of data protection As of 2022, the average cost of a single data breach across all industries worldwide stood at around 4.35 million U.S. dollars. This was found to be most costly in the healthcare sector, with each leak reported to have cost the affected party a hefty 10.1 million U.S. dollars. The financial segment followed closely behind. Here, each breach resulted in a loss of approximately 6 million U.S. dollars - 1.5 million more than the global average.
As of 2021, the average cost of a cyber incident to organizations in the UK was highest in the energy sector, with a median cost of ****** U.S. dollars per cyber event. The costs were significantly high in financial services, retail and wholesale, pharma and healthcare, and transport and distribution. The costs were lowest in the travel and leisure industry.
This statistic displays the share of cyber security breaches that businesses have experienced in the past twelve months in the United Kingdom (UK) in 2019, by type. Among all respondents, ** percent have had virus, spyware or malware breaches in the past 12 months, whereas ** percent had breaches of fraudulent emails or being directed to fraudulent websites.Around half of the businesses in the United Kingdom experienced cyber security breaches or attacks in the last 12 months. In addition, the average cost of all cyber security breaches varies with respect to the company's size.
As of January 2025, the most significant data privacy violation fine worldwide was for social media giant Meta. In May 2023, the Data Protection Commission (DPC) of Ireland decided to fine the company with 1.2 billion euros or 1.3 billion U.S. dollars. The Chinese vehicle-for rent company Didi Global ranked second. In July 2022, China's data privacy regulator fined the company 8.026 billion Chinese yuan, or 1.19 billion U.S. dollars. The 2021 Amazon fine issued by Luxembourg's data privacy regulation authorities was 877 million U.S. dollars and was the third-biggest data breach fine as of the measured month. The 2019 fine of 575 million U.S. dollars to Equifax followed. In this incident, because of unpatched vulnerabilities, nearly 150 million people were affected, which caused the American consumer credit reporting agency to pay at least 575 million U.S. dollars.
This statistic shows the market forecast for the public cyber security sector in the United Kingdom (UK) from 2010 to 2017, by segment. The estimated cyber security market size of the defense and intelligence sector in 2017 is 250 million British pounds (GBP).Cyber security, also often called IT security or computer security, is a vital part to any business. There are several types of cyber security such as: access controls, encryption technologies, data loss prevention tools, and many more. In 2015, advanced perimeter controls and firewall technologies saved companies an average of approximately 714 thousand British pounds.When it comes to cyber security breaches there is usually more at stake than a loss of money. However, monetary value is how most security breaches are measured. On average, business invested a total of 4,060 British pounds in cyber security measures in 2016. In early 2016, the average cost of of security breaches for business amounted to 3,480 British pounds. In terms of number of breaches, medium business experienced a total of 189 breaches, whereas the average across all business sizes was 66 breaches.
This statistic show the market forecast of the total cyber security sector in the United Kingdom (UK) from 2010 to 2017. The estimated market size of the total cyber security sector in 2017 is 3,489 million British pounds (GBP). Cyber security exists because the threats and costs are great enough to warrant these measure. When considering the average annual cyber crime costs by industry sector it is necessary to have cyber security in place.The total market size in this statistic is comprised and various different market segments, services, and solutions. When breaking down the solution types there is: governance, content, systems, and infrastructure. In terms of market segments, included are: defense and intelligence, other public sector, enterprises, and small & medium enterprises and consumers. Broken down by IT product/service there is: software, project services & outsourcing, hardware, network, and management consultancy.
Not seeing a result you expected?
Learn how you can add new datasets to our index.
As of 2024, the average data breach cost in the United Kingdom (UK) was around **** million U.S. dollars. In the measured period, 2022 registered the highest cost for breached data, more than five million U.S. dollars. The figure, thus, has increased from *** million U.S. dollars since 2020.