Skip to content
A red padlock on a computer keyboard
Research

IBM's Cost of a Data Breach report puts financial services as the second-most-expensive industry for breaches, behind only healthcare.

Data Breaches Cost Financial Services Firms $5.56 Million on Average

The average data breach cost financial services firms $5.56 million in IBM's 2025 report — 25% above the global average, though down from $6.08 million in 2024. Here's how the sector compares and why costs remain elevated.

PV

Parivestra Research Desk

22 July 2026 · 2 min read

Share

Cybersecurity economics remain a defining cost pressure for financial institutions in 2026, even as the aggregate numbers show modest improvement year-over-year.

The headline figure

The average cost of a data breach in financial services stood at $5.56 million in IBM's most recent Cost of a Data Breach report, based on 2025 data. That's 25% above the global cross-industry average of $4.44 million, cementing financial services as one of the most expensive sectors to secure — and to clean up after an incident.

Financial services ranks as the second most expensive industry overall, trailing only healthcare at $7.42 million — a position healthcare has now held for 14 consecutive years — and ahead of industrial ($5 million), energy ($4.83 million), and technology ($4.79 million).

The direction of travel

Encouragingly, the trend line points down, not up. Financial services' average breach cost fell 9% year-over-year, from $6.08 million in 2024 to $5.56 million in 2025 — tracking a broader global decline of 9% in the average breach cost across all industries. That's a meaningful reversal after several years of steadily climbing breach costs across the report's history, though it's worth noting the absolute dollar figures remain far above pre-2020 levels.

Why financial services stays expensive

IBM attributes the sector's persistent premium over the global average to three structural factors: regulatory compliance requirements that mandate specific notification and remediation processes, card reissuance economics — the direct operational cost of replacing compromised payment credentials at scale — and the inherently sensitive nature of the financial data institutions hold, which increases both legal exposure and customer-notification costs per record compromised.

Why this matters

For fintechs and banks budgeting security spend in 2026, the data supports two conclusions simultaneously: breach costs are trending favorably industry-wide, but financial services firms are still absorbing a structural premium over nearly every other sector, which argues for continued investment in prevention rather than assuming the declining trend does the work on its own.

Sources

Financial Services Data Breach Cost, DataBreachCost.com (IBM 2025 data), Data Breach Cost by Industry, DataBreachCost.com, Cost of a Data Breach 2025: IBM Report Analysis, DataFence.

Frequently asked questions

Financial services ranks second-highest at $5.56 million per breach on average, behind healthcare at $7.42 million and ahead of industrial ($5 million), energy ($4.83 million), and technology ($4.79 million), per IBM's 2025 report.

Falling, at least in IBM's most recent report — the average breach cost for financial services dropped 9% year-over-year, from $6.08 million in 2024 to $5.56 million in 2025, mirroring a broader 9% decline in the global average.

IBM attributes the premium — 25% above the global average — to regulatory compliance obligations, the cost of reissuing compromised cards, and the highly sensitive nature of financial data, all of which drive up post-breach remediation and notification costs.