0:00
/

The Real Price Tag On Cyber Breaches

What breaches actually cost organizations, from the team behind the DBIR

In this episode, I sit down with Alex Pinto, who leads the Data Breach Investigations Report team at Verizon, to discuss the team’s new Breach Impact Study and what data breaches actually cost, including why the study measures insurable loss as a floor rather than a ceiling, why medians beat averages, and what the claims data does and does not tell us about AI.

If you missed it, I did a deep dive blog into the report titled “The Real Price Tag on Breaches”.

I’ve spent a lot of time pushing back on the fear-based statistics that dominate this industry, so a study built on roughly 70,000 real cyber insurance claims is exactly the kind of grounding the conversation has been missing. Alex and his team put concrete numbers behind questions we usually answer with anecdotes, and they were careful about what those numbers can and cannot say.

We chatted about:

  • How the Breach Impact Study came together and why the DBIR team finally landed a cyber insurance claims dataset through CyberAcuView

  • Why insurable loss is a floor and not a ceiling, and why reputational damage barely moved the numbers

  • The decision to report medians instead of averages, including the footnote about not publishing the average so LLMs don’t spread it around

  • The rise of business interruption and contingent business interruption, and the sub-limits that hid the real damage

  • Whether an $83,000 median breach impact hands the wrong argument to a skeptical CFO

  • The SMB paradox, where small companies can lose up to 7% of revenue while large enterprises rarely cross 2%

  • Where AI actually shows up in the data, and why offense is running ahead of defense

  • Third-party risk as the industry’s persistent blind spot


Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.



Prefer to listen?

Spotify

Apple Podcasts

Please be sure to leave a rating and review, as it truly helps the show!


A few takeaways:

Insurable loss is a floor, and business interruption is what moves the needle

The study only counts dollars paid through real policies, which Alex is upfront about calling a floor rather than a ceiling of the true economic impact. The team tried to measure reputational damage a few years back by cross-referencing known breaches against stock movements and found almost nothing.

As Alex put it, from the consumer side “nobody cares anymore,” and he probably has a couple lifetimes of credit monitoring to prove it. What actually changes behavior is downtime. “The thing that will move decision making is business interruption,” he said, and the data backs him up, with business interruption landing at roughly a third of all known losses in 2024. That is the number that gets an organization to treat this as a real problem.

The average is meaningless, the distribution is the point

Alex is blunt about why the team reports medians and refuses to publish an average. “It’s just that the information is meaningless for decision making,” he said. A five million dollar average headline, like the one making the rounds from another report, tells a company nothing about the risk it is actually accepting.

The percentiles do. For companies above $250 million in revenue, the top 2.5% of cases exceeded $22 million, which is the kind of figure an operational risk team can take to a board and decide how much of the distribution they want to be covered against. The single number is comfortable. The distribution is useful.

An $83K median does not mean breaches are cheap

I raised a concern I have heard from others, that dropping a median of around $83,000 in front of an executive invites the response that breaches are survivable and it might be cheaper to just eat the cost.

Alex did not hedge. “I think that’s a bad CFO,” he said, and made the point that the person reading that figure should be someone who understands what a distribution like that means. Any large company that looks at the median and ignores that its size alone puts it in the extreme tail is not doing operational risk properly. The report’s whole argument is to plan against the extreme cases, not the midpoint.

Small companies take the hardest proportional hit

The most uncomfortable finding for me is that SMBs can lose up to 7% of revenue in the extreme cases while large enterprises rarely cross 2%. The median SMB loss is a modest $38,000, but measured against revenue and thin cash flow it becomes existential, especially since an insurance payout is not automatic and you have to survive long enough to receive it.

Alex connected this to Wendy Nather’s cybersecurity poverty line and made a point I care about deeply. Ransomware crews moved down market a long time ago and industrialized the work, so being small is no longer a defense. It just changes the size of the ask.

AI is real, but offense is ahead of defense

I told Alex I could not find AI as an obvious fingerprint anywhere in the loss numbers, and he agreed the claims data simply does not carry that detail yet. The bigger problem is structural, since the DBIR anonymizes each dataset independently and cannot cross-correlate AI-assisted attacks with claims. What he is confident about is the direction.

“Offensive AI augmentation is way, way ahead of the curve than the defensive one,” he said, and everyone assuming a tidy AI versus AI showdown is ignoring that one fighter has a mean left hook and the other has not found its footing. His practical read is to stop waiting and rethink architecture. On taking flat networks and internet-exposed edge devices seriously, his line stuck with me. “The best time to do that was fifteen years ago. Maybe the second best time is now.”

If there is one thing to do on Monday, Alex pointed at third-party risk. Supply chain incidents are the single most likely to fully exhaust a policy, which means the recorded loss is a coverage cap and not the real number. His takeaway was direct. “Do not underestimate the impact that your third party can have.” Even the insurers, who understand risk better than most of us, have been caught off guard by it.

Thanks to Alex for coming on and for putting real numbers behind a conversation the industry usually runs on vibes. Follow his work through the Verizon DBIR and the new Breach Impact Study, and find him on LinkedIn.

Discussion about this video

User's avatar

Ready for more?