IBM and the Ponemon Institute publish the Cost of a Data Breach Report every year, now in its 21st edition, and it's the report most commonly quoted whenever you see a headline about the "average cost of a data breach." The 2026 edition puts that global average at nearly USD 5 million, and Australia at USD 2.96 million. Before you take either number to your board or your bank manager, it's worth understanding what the study actually measures, and which parts of it genuinely apply to a business our size.
The Honest Read on the Headline Number
The global average breach cost rose 12% this year to USD 4.99 million, and the Australian average rose from USD 2.55 million to USD 2.96 million. Those figures come from 602 organisations studied across 16 countries, and the breaches examined ranged from 2,590 to 115,380 compromised records, organisations with the scale, and the maturity, to participate in a detailed research interview in the first place.
That's not the profile of most Perth SMBs. If your business holds a few thousand customer records, not tens of thousands, these dollar figures aren't a realistic estimate of what a breach would cost you directly. What they are useful for is the trend: breach costs are rising faster than they're falling, largely driven by detection, escalation, and lost business costs, and that pressure applies regardless of your size.
What Actually Moves the Needle
More useful than the absolute dollar figures is what IBM found actually raises or lowers breach costs, since those effects are relative and apply whether your breach costs thousands or millions.
- Cost reducers: a DevSecOps approach (building security into software development rather than adding it later) was the single biggest cost reducer, followed by identity and access management and use of a managed security service provider. Encryption and employee training also featured in the top factors.
- Cost increasers: a breach caused by a compromised business partner or vendor ("supply chain" or third-party compromise) was the single most expensive factor, ahead of security system complexity and noncompliance with regulations.
The pattern is consistent with what we covered in Verizon's 2026 breach report: knowing what your vendors and partners can access, keeping identity controls tight, and not letting your security setup become so complex nobody fully understands it, are the levers that actually move your risk, not your company's size.
Phishing Is Still Number One, and Voice Phishing Is the Costliest
For the fourth year running, phishing was the top initial attack vector into breached organisations. The most expensive variant wasn't email, it was voice and SMS phishing, used in 17% of attacks and leading to average breach costs of USD 5.29 million, ahead of help desk-style social engineering (including MFA fatigue attacks) at USD 5.23 million. Both point to the same weakness: attacks that bypass the inbox entirely are harder for staff to recognise and for technical filters to catch, which is why staff training and verifying unusual requests through a known channel matter more as these tactics spread.
One more basic finding is worth calling out on its own: 53% of breached organisations hadn't encrypted sensitive data at rest and in motion at the time of the breach. That's not an advanced control, it's a default most business software already supports.
Ransomware Is Shifting From "Pay to Decrypt" to "Pay or We Go Public"
39% of breached organisations were hit by ransomware this year, continuing a four-year climb from 24% in 2023. What's changed is the pressure attackers apply: 41% of ransomware attacks threatened brand reputation, through public shaming or leaking data to the media, ahead of the 23% that relied on encrypting operational systems alone. Encryption used to be the whole threat. Now it's one option among several.
There's a genuinely positive finding here too: 42% of organisations fully recovered from their breach, up from 35% the year before, and the share taking more than 150 days to recover shrank from 26% to 19%. Recovery is improving, but for most organisations it still isn't fast, which is exactly why a tested restore process and cyber insurance that actually pays out matter well before an incident happens.
The AI Thread Continues
Consistent with the other 2026 reports we've covered, IBM found AI-driven attacks rose 56% on last year, adding an average of USD 1 million to the cost of a malicious breach, with deepfake impersonation driving the largest share of those incidents. It's the same pattern we wrote about in AI Is Reshaping Cybercrime, now showing up in a third, independently run dataset.
What This Means for a Perth Business
- Ignore the dollar figure, use the ranking. DevSecOps, identity and access management, and managed security support reduced costs the most; third-party compromise, complexity, and noncompliance increased them the most. Focus there first.
- Treat voice and text requests with the same suspicion as email. The costliest attack vector this year didn't come through the inbox.
- Check whether your sensitive data is actually encrypted. Over half of breached organisations hadn't done this basic step.
- Plan for a ransomware demand that isn't just about encryption. A tested backup handles a locked server. It doesn't handle a threat to leak stolen data, that needs an incident response plan and insurance that covers extortion.
- Know what your vendors can access. Third-party compromise was the single most expensive factor in this year's report, for the second report running.
Frequently Asked Questions
Is the USD 2.96 million average Australian breach cost realistic for a small business?
Almost certainly not as a literal figure. IBM's study covered breaches ranging from 2,590 to 115,380 compromised records at organisations with mature enough security and privacy programs to take part in a detailed research interview, which skews toward larger organisations. Treat the dollar figure as evidence that breach costs are trending upward, not as a number to budget a small business breach against.
What's the single cheapest thing that reduces breach costs according to IBM's data?
A DevSecOps approach, building security into software development rather than bolting it on afterward, was the top cost-reducing factor in this year's report, followed by identity and access management and use of a managed security service provider. None of these require enterprise budgets to start on at a smaller scale.
Why do voice and SMS phishing cost more than email phishing?
IBM's report found voice and SMS phishing led to the costliest breaches of any attack vector, averaging USD 5.29 million, ahead of email-based social engineering. These channels tend to bypass the training and technical filters staff are used to relying on for email, which is why verifying unusual requests through a second, known channel matters more as these tactics grow.
Is ransomware now more about data theft than encryption?
It's shifting that way. IBM found 41% of ransomware attacks in this year's report included threats to leak data or publicly shame the victim, ahead of the 23% that relied on encrypting operational systems. Attackers are increasingly using the threat of exposure as leverage, not just locking files.
Identity and access management and managed security support were two of the top three cost reducers in IBM's data - both are things we handle every day for Perth businesses.
Cybersecurity Services →Not sure how your business would actually recover from a breach?
Call 0433 087 091 for a free, no-obligation conversation about where the gaps are.
Book a Free ConsultationFor related reading, see Verizon's 2026 Data Breach Report, Ransomware Recovery, and Cyber Insurance for Perth Businesses.
Source: IBM Cost of a Data Breach Report 2026, researched and produced by the Ponemon Institute for IBM. Statistics referenced in this article belong to IBM and the Ponemon Institute; for the full dataset, methodology, and industry and regional breakdowns, refer to the report directly at ibm.com/reports/data-breach. This article is general information only, not a formal risk or financial assessment of your business.