The global average cost of a data breach hit $4.99 million in 2026 — a record, up 12% from the year before, according to the IBM Cost of a Data Breach Report 2026, produced annually with the Ponemon Institute. But the number that should worry most organizations more is this one: 53% of breached organizations had sensitive data unencrypted at rest or in transit at the time of the breach. The failure usually is not sophistication of the attacker. It is a control that was never enforced, sitting in a policy document nobody checked against reality.
This guide treats cybersecurity as an enterprise risk rather than an IT budget line — using NIST Cybersecurity Framework 2.0 as the operating structure, a worked method for pricing cyber exposure in dollars, and the specific control gaps that show up most often in 2026 breach data.
What Makes Cyber Risk Different From Other Enterprise Risks
Three properties separate cyber risk from the operational and financial risks covered elsewhere on this site, and each changes how it needs to be managed.
- Onset speed. A weather delay gives a construction project weeks of warning. A compromised credential can move laterally through a network in minutes. Detection speed is not a nice-to-have metric here — it is the primary lever on cost.
- Adversarial dynamics. Market risk does not adapt to your hedges. An attacker does adapt to your controls, in real time, and increasingly with AI assistance.
- Cascading failure. A single exposed credential can touch every system it has access to. Cyber risk does not stay contained to the department that owns the asset.
The economics changed materially in the past year. IBM’s 2026 report found AI-driven attacks increased 56% year over year and added roughly $1 million to the average cost of a breach compared to non-AI-driven incidents. Attackers’ costs to launch an attack are falling. Defenders’ costs to detect and contain one are rising. That asymmetry is the reason a framework-based approach now matters more than an ad hoc one.
NIST Cybersecurity Framework 2.0: The Six Functions
NIST CSF 2.0 was published on 26 February 2024 — the first major revision since the original 2014 framework. Two changes matter more than the rest: the framework now applies to organizations of any size or sector, not just critical infrastructure, and it adds a sixth function — Govern — that sits above the other five rather than alongside them.
| Function | What It Covers | Typical Owner |
|---|---|---|
| Govern | Risk strategy, policy, executive oversight, supply chain risk governance | Board / CISO / risk committee |
| Identify | Asset inventory, data mapping, risk assessment against business context | IT / risk management |
| Protect | Access control, encryption, awareness training, data security | Security engineering |
| Detect | Continuous monitoring, anomaly detection, logging | SOC / security operations |
| Respond | Incident response execution, communications, mitigation | Incident response team |
| Recover | Restoration, lessons learned, feeding findings back into Identify | IT operations / business continuity |
The functions sit inside a three-level structure: 6 functions, 22 categories, 106 subcategories. Categories group related outcomes within a function — asset management and supply chain risk both sit under Identify, for instance. Subcategories are the specific, checkable outcomes an organization actually implements.
Govern is the change that matters most, and it is directly relevant to how this site treats enterprise risk management generally. Under CSF 1.1, governance was scattered inside the Identify function — a subset of asset management, effectively. CSF 2.0 makes it a standalone function that sits above the other five, which is a structural statement: cybersecurity is not a technical control category, it is a board-level risk category with technical controls underneath it. An organization with strong Protect and Detect functions but no Govern function has excellent technical execution and no way to connect that execution to business risk tolerance or capital allocation decisions.
Quantifying Cyber Risk in Dollar Terms
Our Insurance Risk Management guide uses Annualized Loss Expectancy (ALE) to price exposure — the same method applies directly to cyber risk, and using one method across risk categories is what makes them comparable inside a single risk register.
ALE (Annualized Loss Expectancy) = SLE × ARO (Annual Rate of Occurrence)
The figures below are a constructed example for teaching the calculation — not a real organization’s data.
A mid-sized healthcare provider holds patient records worth an estimated $8,000,000 in breach-notification and remediation liability if fully compromised. Historical incident data across similar-sized providers suggests a ransomware exposure factor of roughly 25% of that value per incident, at an annual rate of occurrence of 0.15 (roughly one incident every 6–7 years, consistent with sector-wide ransomware frequency).
ALE = $2,000,000 × 0.15 = $300,000/year
That $300,000 figure is what should be compared against the cost of a cyber insurance premium, an EDR platform subscription, or an encryption-at-rest rollout — not the headline $8,000,000 worst case, and not a vague sense that “healthcare is a target.” IBM’s 2026 figures give a useful sanity check on the input assumptions: healthcare recorded the highest average breach cost of any sector at $6.64 million for the thirteenth consecutive year, and the US national average across all sectors was $11.5 million — more than double the global average of $4.99 million. If an organization’s own SLE estimate is far below these benchmarks without a specific reason (smaller data footprint, stronger existing controls), that is a signal to revisit the assumption rather than the framework.
Try It Yourself
The calculator below runs the same SLE × ARO = ALE method used above. Enter your own asset value, exposure factor, and annual rate of occurrence to see your organization’s estimated exposure.
Third-Party and Supply Chain Risk
This is the fastest-growing category in the 2026 data, and it is the one most risk registers still underweight. IBM’s report found supply chain compromise was the second most common initial attack vector, carried the longest average breach lifecycle at 258 days to identify and contain, and added $227,250 above the global average breach cost — the single largest cost increase of the 30 factors IBM tracked.
The reason is structural, not a failure of any one vendor’s security. Modern applications depend on open-source libraries, third-party APIs, CI/CD pipelines, and an increasing number of AI agents and plugins. Every dependency is a relationship the organization does not fully control, and a vendor with weaker controls than the organization’s own becomes the practical attack surface regardless of how strong internal controls are.
Three controls address most of this exposure without requiring a full vendor security programme on day one:
- Tier vendors by data access, not by contract size. A small vendor with database credentials is a bigger exposure than a large vendor with none.
- Require SOC 2 Type II reports (or equivalent) for any vendor in the top tier, renewed annually — not a one-time check at onboarding.
- Build a right-to-audit clause into contracts with top-tier vendors, even if it is rarely exercised. Its presence changes vendor behaviour on its own.
Building the Programme: Implementation Steps
1. Assign executive ownership. Cyber risk needs a named owner outside the IT department — typically a CISO or risk committee reporting to the board — and a documented risk appetite specific to cyber exposure, not inherited wholesale from general enterprise risk appetite.
2. Build the asset and data inventory. The same principle that governs data controls generally applies here: you cannot protect what you cannot see. This step routinely surfaces shadow IT and unsanctioned SaaS tools that were never part of any prior assessment.
3. Assess risk against the CSF categories rather than against a generic checklist. Mapping actual gaps to the 22 categories makes the assessment auditable and comparable year over year.
4. Prioritise controls by ALE, not by severity label. A “critical” finding with a low annual rate of occurrence may carry a smaller ALE than a “medium” finding that recurs constantly. Budget follows the dollar figure, not the adjective.
5. Build detection and monitoring with defined log retention and a documented escalation path — this connects directly to the audit trail principles in our Internal Controls guide.
6. Write and rehearse an incident response plan. A plan that has never been tested in a tabletop exercise is a draft, not a control. IBM’s data shows organizations with tested response plans consistently detect and contain breaches faster than those without.
7. Close the loop. Every incident and every near-miss feeds back into Identify. A recovery that does not update the risk register is a recovery that guarantees a repeat.
Where This Intersects With Regulation
Requirements vary by sector and jurisdiction, and this is not an exhaustive list — check the current text of any rule that applies to your organization before relying on it.
- Financial services (US): NYDFS Part 500 sets specific cybersecurity requirements for entities regulated by New York’s Department of Financial Services, including a designated CISO and periodic risk assessments.
- Healthcare (US): the HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic protected health information — overlapping substantially with CSF’s Protect function.
- Public companies (US): SEC rules require disclosure of material cybersecurity incidents on a defined timeline, and annual disclosure of the organization’s cybersecurity risk management approach.
For the broader compliance frameworks these sit alongside, our Internal Controls guide covers SOX and GDPR requirements that frequently apply to the same organizations.
Common Mistakes
- Treating cybersecurity as an IT budget line rather than an enterprise risk with a named executive owner and a defined risk appetite.
- An incident response plan that exists but has never been rehearsed. A tabletop exercise reveals gaps a document review never will.
- Partial encryption. IBM’s 2026 data found 53% of breached organizations had sensitive data unencrypted at rest or in transit — encrypting one and not the other closes half the gap and leaves the rest.
- Flat vendor risk treatment. Applying the same due diligence to every vendor regardless of data access wastes review capacity on low-risk vendors while under-scrutinising high-risk ones.
- Ungoverned AI tool use inside the organization. IBM found unapproved (“shadow”) AI tool use present in 43% of breached organizations in 2026, up from 20% the year before — and nearly seven in ten breached organizations lacked any governance policy for AI use at all.
Conclusion
The $4.99 million average breach cost is not primarily a story about sophisticated attackers. It is a story about controls that existed on paper and not in practice — unencrypted data, untested response plans, unmonitored vendors. NIST CSF 2.0 gives the structure; ALE gives the way to price what is actually at stake in dollar terms an executive team can act on. The same discipline that runs through the rest of this site’s risk coverage applies here: identify the exposure early, price it honestly, and decide deliberately rather than by default.
Frequently Asked Questions
What is the difference between cybersecurity and cyber risk management?
Cybersecurity is the set of technical controls — firewalls, encryption, access management. Cyber risk management is the broader discipline of identifying, pricing, and deciding how much of that exposure to accept, mitigate, transfer, or avoid, using cybersecurity controls as one of several response tools.
Do small businesses need to follow NIST CSF?
CSF 2.0 was explicitly expanded to apply to organizations of any size, not just critical infrastructure. A small business will not implement all 106 subcategories, but the six functions scale down — governance, an asset inventory, basic access controls, and a written incident response plan cover most of the practical risk at low cost.
How often should a cybersecurity risk assessment be conducted?
Annually at minimum, with a lighter review after any material change — a new major vendor, a significant system migration, or an actual incident. High-risk sectors such as finance and healthcare often run more frequent assessments to satisfy sector-specific regulatory requirements.
What is the difference between NIST CSF and ISO 27001?
NIST CSF is a flexible outcomes-based framework without formal certification. ISO 27001 is a certifiable information security management system standard, often required for enterprise contracts as external proof of controls. Many organizations run both — CSF for internal risk structure, ISO 27001 where a client or contract requires third-party certification.
Can AI tools help manage cybersecurity risk, or do they add risk?
Both, and the 2026 data shows the split clearly. Organizations using AI and automation in security operations cut breach costs by close to $2 million on average. At the same time, ungoverned AI tool use inside an organization — “shadow AI” — was present in 43% of breached organizations. The determining factor is governance: AI used deliberately inside a monitored security programme reduces risk; AI adopted informally without oversight increases it.
What industries face the highest breach costs?
Healthcare has led every year since IBM began tracking the metric, at $6.64 million per breach in 2026 — thirteen consecutive years at the top, driven by the value of patient data and the regulatory penalties attached to its loss. Financial services and industrial sectors follow closely behind.
