The Cybersecurity Bill Is Getting Too Big to Pay

A record $4.99 million average cost per breach, bloated tool stacks, and AI spending that outpaces its own savings are squeezing smaller businesses toward a breaking point.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge overhead photoreal view of a dark security operations center desk at night, multiple monitors glowing with abstract telemetry graphs and
Share

Key points

  • The global average cost of a data breach hit a record $4.99 million in 2025, a 12 percent rise over 2024, according to IBM's 2026 Cost of a Data Breach Report.
  • Global cybersecurity spending is projected to reach $239.8 billion in 2025, up from $193.4 billion in 2024, according to Gartner.
  • A 1Password study found that AI-generated security fixes made things worse, not better, 53.9 percent of the time on average.
  • Small and medium-sized businesses face the sharpest risk: one breach can generate costs they simply cannot absorb.
  • Security experts are calling for a shift from counting security alerts to measuring actual risk reduction.

A data breach no longer just costs a company its secrets. It costs an eye-watering amount of money.

The global average price tag for a single breach reached $4.99 million in 2025, equivalent to roughly $1,100 every hour, according to IBM's 2026 Cost of a Data Breach Report. That figure, first highlighted by Dark Reading, represents a 12 percent jump in a single year. For context: that is enough to wipe out a small business entirely.

Who gets hurt most?

Small and medium-sized businesses, the kind that run on tight margins and rarely employ a full-time security team, absorb the sharpest blow. Large companies have reserves. Smaller ones often do not.

Criminals know this. Bryson Byrd, a cybersecurity advisor at security firm Huntress, explains that attackers deliberately go after smaller businesses because budget constraints make them easier targets. The problem extends beyond any single company: smaller businesses are deeply embedded in the supply chains of larger ones, meaning a breach at a small supplier can ripple outward.

The market, Byrd argues, does not reflect that systemic risk. Venture-backed security vendors, under pressure to chase profitable contracts with large enterprises, build products too expensive or too complex for a business without a dedicated security department. "When you have millions of small businesses that exist, what ends up happening is disproportionately we are less secure," Byrd says.

Is AI making the cost problem worse?

Yes, at least for now. Organizations rushed to adopt artificial intelligence tools to help their security teams process more work without hiring more staff. The savings did not materialise as expected.

Syed Ghayur, vice president of solution engineering at security platform ArmorCode, points to a structural mismatch. The average large enterprise already runs 40 separate security scanning tools, and broader security stacks span 83 tools from 29 vendors, citing research from Palo Alto Networks and IBM. That overlap floods security teams with duplicate alerts, a problem sometimes called "alert fatigue," where staff become so overwhelmed by warnings that real threats get missed.

Layering AI on top of that does not automatically fix things. A 1Password study found that patches, meaning software fixes for security flaws, generated by AI-powered large language models (programs trained on vast amounts of text to produce human-like output) actually failed to fix the original problem, introduced a new one, or did both in 53.9 percent of cases on average.

"Without prioritisation and cost governance, spending can scale with the number of findings, rather than the amount of actual risk being reduced," Ghayur warns.

What should organisations actually do?

The answer is not simply to spend less. Ghayur recommends measuring success differently: not by how many security alerts a tool generates, but by how much genuine risk it removes. Signisys, a consulting firm, recommends most businesses direct 8 to 12 percent of their total technology budget toward security, rising to 10 to 15 percent for healthcare, financial services, and government organisations.

Ghayur draws a comparison to "FinOps," a management practice that helped companies control runaway cloud computing costs by setting clear policies for where money goes. He believes cybersecurity needs the same discipline, applied to tools, staff hours, and AI spending alike.

For ordinary customers and employees, the practical takeaway is straightforward. If a company you deal with suffers a breach, watch for unusual activity on any account linked to that company, change your password there, and be suspicious of follow-up emails asking for personal information, since criminals sometimes use stolen data to run convincing follow-on scams, known as phishing.

Common questions

Does this mean my data is less safe than it used to be?

Breaches are more expensive partly because attackers are more sophisticated and data is more valuable, not necessarily because every company is ignoring security. The concern is that rising costs are making strong protection harder for smaller organisations to sustain.

Should small business owners be doing something different right now?

Experts suggest reviewing what security tools you actually use and whether they overlap, setting a deliberate budget target for security (around 8 to 12 percent of your total technology spend is the guidance), and making sure staff know how to spot a phishing email, since human error remains one of the most common ways criminals get in.

© 2026 Threat Vectr