top of page

The numbers don't lie — we just keep ignoring them

A data-driven postscript to "We are still managing security like it's 2006"


In my previous post I made the case on principle: that information security has been recycling the same failed approaches for a quarter century, and that only a coherent architectural rethink will break the cycle. Several people asked, reasonably, for the numbers. Fair enough. Let's look at them.

The data comes primarily from two sources that between them represent the most rigorous annual measurement of breach economics available: the IBM Cost of a Data Breach Report, now in its nineteenth year, and the Verizon Data Breach Investigations Report. Neither is perfect, but together they paint a picture that should be uncomfortable reading for any CISO still running a 2006-vintage security operating model.


The baseline cost of failure is accelerating

IBM's 2024 report puts the average cost of a data breach in the financial sector at $6.08 million per incident — 22% above the global cross-industry average and up 3% from the prior year. Financial services has held the second most expensive position across industries for years, trailing only healthcare.


Financial sector avg. breach cost (2024)



What is less often discussed is the trajectory. In 2021 the financial sector average was $5.72 million. By 2022 it had reached $5.97 million. The 2024 figure of $6.08 million represents a sustained upward trend with no sign of reversing under legacy operating models. The 2025 IBM report brings a partial reprieve globally — but the United States bucked that trend entirely, hitting a record $10.22 million per breach. If your institution operates primarily in the US, the global improvement is not your number.


The programme you run determines what you pay

This is the finding that deserves far more attention than it gets. IBM's data is unambiguous: organisations running legacy security programmes — static controls, manual processes, no meaningful AI or automation — paid an average of $5.72 million per breach. Organisations with extensive AI and automation deployment averaged $3.84 million. A $1.88 million difference per incident. IBM has replicated this finding for five consecutive years. It is not noise. It is signal.




The mechanism is not mysterious. Modern programmes detect and contain breaches faster — nearly 100 days faster on average per IBM's 2024 data. Time is money in breach economics: the longer an attacker has dwell time, the more data is exfiltrated, the higher the regulatory exposure and remediation cost. For prevention specifically, organisations deploying AI across prevention workflows incurred $2.22 million less per breach than those that hadn't. The investment case is not ambiguous.


The expected loss model compounds brutally over time

A single breach cost is a useful data point but a misleading frame for decision-making. The correct question is not "what does a breach cost?" but "what is my expected loss over a five-year planning horizon, given my current programme maturity?" Those are very different questions, and the answer to the second one is what should be landing on the board's desk.



Working from IBM's per-breach cost data and conservative breach probability assumptions grounded in historical breach rates for comparable financial institutions, the five-year picture is stark. A legacy programme generates cumulative expected losses in the range of $15 million over that window. A modern, architecture-led programme generates roughly $7 million over the same period. The gap is $8 million — before you account for the $375 million tail risk of a catastrophic breach.


The Verizon data shows exactly where legacy programmes fail

The IBM numbers tell you what breaches cost. The Verizon DBIR tells you how they happen — and the patterns map with uncomfortable precision onto the legacy disciplines I described in the previous post.




Credential theft and the 292-day dwell time is the direct, measurable cost of failing to implement dynamic, behavioural identity controls. Static entitlement tables and annual access certifications do not catch credential abuse. They were never designed to.

Vulnerability exploitation nearly tripling year-on-year is the scan-ticket-patch cycle failing in real time, at scale. The organisations being breached via vulnerability exploitation are the ones that did not destroy and rebuild from known-good baselines.

Third-party breach involvement doubling to 30% in a single year is what happens when your third-party risk programme is a point-in-time questionnaire applied to a continuously changing supplier ecosystem. One year. A doubling. The risk is dynamic. The measurement is static. The breaches are the predictable result.


The business case is not actually close

Aggregate the IBM programme-maturity savings of $1.88 million to $2.22 million per breach against realistic breach frequency for a mid-to-large financial institution, and the investment case for modern, architecture-led security is not a marginal one. It is overwhelming. The five-year expected loss differential of roughly $8 million dwarfs the cost of the architectural transformation required to close the gap. And that calculation excludes regulatory fines, reputational damage, customer attrition, and the tail-risk scenario of a catastrophic breach.

The insurance actuaries have reached their own conclusions, somewhat ahead of the security industry. Cyber insurance premiums have risen substantially and persistently, underwriters are requiring increasingly specific evidence of security controls maturity before quoting, and exclusions for legacy technology environments are appearing in policy language. The market is applying expected loss logic to the same underlying data — and pricing legacy programme risk accordingly.

The industry does not have a data problem. The data has been available, consistent, and directionally unambiguous for years. What it has is a habits problem — the institutional inertia of programmes built for a 2006 environment, staffed by teams organised around 2006 disciplines, reporting to boards that have been reassured for two decades that the current approach is adequate.

The numbers say otherwise. They have been saying otherwise for quite some time.



Joël Van Dyk is a cybersecurity architect and strategist with three decades of experience at systemically important financial institutions. He writes about enterprise security architecture, risk economics, and the transition to post-quantum cryptography at joelvandyk.com.


 
 
 

Recent Posts

See All
We Are Still Managing Security Like It’s 2006

And we should be embarrassed about it. Mark Twain once observed that history may not repeat itself, but it sure does rhyme. In information security, we have taken that as a design principle. Let me be

 
 
 

Comments


bottom of page