The Cybersecurity Bill Is Getting Too Big to Pay

A record $4.99 million average cost per breach, bloated tool stacks, and AI spending that outpaces its own savings are squeezing smaller businesses toward a breaking point.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
A small business owner's desk surrounded by bills and invoices marked with cybersecurity costs, with a large '$4
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The global average cost of a data breach hit a record $4.99 million in 2025, a 12 percent rise over 2024, according to IBM's 2026 Cost of a Data Breach Report.
  • Global cybersecurity spending is projected to reach $239.8 billion in 2025, up from $193.4 billion in 2024, according to Gartner.
  • A 1Password study found that AI-generated patches failed to fix the original flaw, introduced a new one, or did both in 53.9 percent of cases on average.
  • Small and medium-sized businesses face the sharpest risk: one breach can generate costs they simply cannot absorb.
  • Security experts are calling for a shift from counting alerts to measuring actual risk reduction.

A data breach no longer just costs a company its secrets. It costs a staggering amount of money.

The global average for a single breach reached $4.99 million in 2025, roughly $1,100 every hour, according to IBM's 2026 Cost of a Data Breach Report. That's a 12 percent jump in a single year, enough to wipe out a small business entirely.

Who gets hurt most?

Small and medium-sized businesses, the kind that run on tight margins and rarely employ a full-time security team, absorb the sharpest blow. Large companies have reserves. Smaller ones often don't.

Criminals know this. Bryson Byrd, a cybersecurity advisor at Huntress, told Dark Reading that attackers deliberately target smaller businesses because budget constraints make them easier marks. Their vulnerability extends beyond their own walls: smaller businesses are deeply embedded in the supply chains of larger ones, so a breach at a small supplier can ripple outward fast.

Venture-backed security vendors, under pressure to chase profitable contracts with large enterprises, build products too expensive or too complex for a business without a dedicated security department. "When you have millions of small businesses that exist, what ends up happening is disproportionately we are less secure," Byrd says. We've tracked this dynamic across four small-business stories since July, and the market hasn't corrected it yet.

Is AI making the cost problem worse?

Yes, at least for now. Organisations rushed to adopt artificial intelligence tools to help their security teams process more work without hiring more staff. The savings didn't materialise as expected.

Syed Ghayur, vice president of solution engineering at security platform ArmorCode, points to a structural mismatch. The average large enterprise already runs 40 separate security scanning tools, and broader security stacks span 83 tools from 29 vendors, according to research from Palo Alto Networks and IBM. That overlap floods security teams with duplicate alerts, a problem called "alert fatigue," where staff become so overwhelmed by warnings that real threats get missed.

Layering AI on top doesn't automatically fix things. A 1Password study found that patches generated by AI-powered large language models (programs trained on vast amounts of text to produce human-like output) failed to resolve the original flaw, introduced a new one, or did both in 53.9 percent of cases. That figure sits alongside a related finding we reported on 18 August: Rapid7 warned that the old model of fixing software flaws on a fixed schedule is breaking down as new vulnerabilities accumulate faster than teams can respond.

For smaller organisations without specialist staff to review what AI produces, that failure rate isn't a statistic. It's a liability.

"Without prioritisation and cost governance, spending can scale with the number of findings, rather than the amount of actual risk being reduced," Ghayur warns.

What should organisations actually do?

The answer isn't simply to spend less. Ghayur recommends measuring success differently: not by how many alerts a tool generates, but by how much genuine risk it removes. Consulting firm Signisys recommends most businesses direct 8 to 12 percent of their total technology budget toward security, rising to 10 to 15 percent for healthcare and financial services or government organisations.

Ghayur draws a comparison to "FinOps," a management practice that helped companies control runaway cloud computing costs by setting clear policies for where money goes. He believes cybersecurity needs the same discipline, applied to tools, AI spending and staff hours alike.

For ordinary customers and employees, the practical implication is straightforward. If a company you deal with suffers a breach, watch for unusual activity on any linked account, change your password there, and treat follow-up emails asking for personal information with suspicion. Criminals routinely use stolen data to run convincing follow-on scams, known as phishing.

Common questions

Does this mean my data is less safe than it used to be?

Breaches are more expensive partly because attackers are more sophisticated and data is more valuable, not necessarily because every company is ignoring security. The concern is that rising costs are making strong protection harder for smaller organisations to sustain.

Should small business owners be doing something different right now?

Review which security tools you actually use and whether they overlap. Set a deliberate budget target (8 to 12 percent of your total technology spend is the benchmark). Make sure staff can spot a phishing email, since human error remains one of the most common ways criminals get in.

© 2026 Threat Vectr