Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Prepare Your Organization For Data Breaches

Illustration showing a security team preparing an organization for a data breach through incident response planning, detection, and remediation

Quick answer: Preparing for a data breach means having a tested incident response plan, not just security tools, so your team can detect, contain, and report an incident within legal deadlines. It matters because the global average cost of a breach reached $4.44 million in 2025 (IBM), and organizations still take an average of 241 days to identify and contain one. The first action every organization should take is building and rehearsing a written incident response plan that names roles, defines escalation steps, and maps to applicable breach notification laws.

Key takeaways:

  • The global average cost of a data breach was $4.44 million in 2025, down from $4.88 million the year before, while the United States average hit a record $10.22 million (IBM Cost of a Data Breach Report 2025).
  • Organizations took an average of 241 days to identify and contain a breach in 2025, and detecting a breach internally, rather than learning about it from an attacker or a third party, saved roughly $900,000 per incident.
  • Third party involvement in confirmed breaches doubled to 30% in 2025, and credential abuse (22%) and exploited vulnerabilities (20%) remain the two leading entry points (Verizon 2025 DBIR).
  • Ransomware appeared in 44% of breaches analyzed in the 2025 DBIR, up 37% year over year, and in 88% of breaches at small and medium sized businesses specifically.
  • Preparedness is a plan plus practice: a written incident response plan, defined roles, tested detection, and a remediation checklist mapped to your breach notification obligations, not a single tool purchase.

Published: February 2022. Updated: August 2026. Reviewed by Encryption Consulting’s security advisory team.

What Does It Actually Mean to Be Prepared for a Data Breach?

Being prepared for a data breach means an organization has a documented, tested incident response plan, defined roles, and pre approved communication and notification steps, not just firewalls, endpoint tools, or a security team on staff. A data breach is an event in which sensitive, protected, or confidential information is accessed, disclosed, or stolen without authorization. That information is often personally identifiable information (PII), meaning any data that can identify a specific individual, such as a name paired with a Social Security number, account credentials, or health records.

Two terms come up constantly in preparedness planning and are worth defining precisely:

  • Incident response (IR) is the structured process an organization follows to detect, contain, eradicate, and recover from a security incident, then capture lessons learned. It is a documented plan and a trained team, not an ad hoc reaction after something goes wrong.
  • Breach notification laws are the legal requirements that dictate who an organization must tell, and how quickly, once a qualifying breach is confirmed. In the United States, there is no single federal breach notification statute; all 50 states, the District of Columbia, and several territories each maintain their own notification laws, layered with sector specific rules such as HIPAA for health data and GLBA for financial data. Outside the US, the GDPR requires notifying the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach.

An organization that owns every security control on the market but has never rehearsed who calls legal counsel, who notifies affected customers, and within what deadline is not prepared. Preparedness is measured by how the organization performs in the first hours and days after detection, not by the size of its security budget.

What Do the Latest Data Breach Statistics Show?

The two most cited primary sources on breach trends, IBM’s annual Cost of a Data Breach Report and Verizon’s Data Breach Investigations Report (DBIR), both published new editions in 2025, and the numbers show costs easing slightly while attack paths keep shifting toward third parties and credentials.

IBM Cost of a Data Breach Report 2025

  • Global average cost of a data breach: $4.44 million, down from $4.88 million in 2024.
  • United States average cost: $10.22 million, a record high and roughly double the next highest country.
  • Mean time to identify and contain a breach: 241 days, 17 days faster than the prior year.
  • Organizations that detected a breach internally, rather than being told by the attacker or a third party, saved roughly $900,000 compared to those that were not.
  • Healthcare remains the most expensive industry at $7.42 million per breach on average, with a longer identify and contain window of 279 days, even after a 17% year over year improvement.

Verizon 2025 Data Breach Investigations Report

  • The 2025 DBIR analyzed more than 22,000 security incidents and 12,195 confirmed data breaches.
  • Third party involvement in confirmed breaches doubled year over year to 30%, driven largely by supply chain and vendor access issues.
  • Credential abuse was present in 22% of breaches, and exploitation of vulnerabilities was present in 20%, a 34% year over year increase for the vulnerability path.
  • Ransomware appeared in 44% of all breaches studied, up 37% year over year, and in 88% of breaches specifically affecting small and medium sized businesses.
  • The median ransom payment was $115,000, and 64% of victim organizations chose not to pay, up from 50% two years earlier.

Read together, these two reports point to the same conclusion: attackers increasingly reach an organization through a vendor, a stolen credential, or an unpatched system, and the organizations that limit damage are the ones that already had a rehearsed plan for that exact scenario before it happened.

Enterprise PKI Services

Get complete end-to-end consultation support for all your PKI requirements!

Which Technologies and Data Types Are Most Commonly Targeted?

Attackers most often target credentials, email and collaboration systems, cloud storage, and unencrypted databases, because these give the fastest path to valuable data with the least resistance. The categories that recur across breach reports year after year are:

  1. Login credentials and session tokens. Stolen, reused, or weak passwords remain one of the most reliable ways into a network, which is why credential abuse still shows up in roughly a fifth of confirmed breaches (Verizon 2025 DBIR).

  2. Third party and vendor access. With third party involvement in breaches at 30% and rising, a partner’s weak access controls or an unpatched integration point is now a direct path into the primary organization.

  3. Unpatched, internet facing systems. Exploited vulnerabilities grew 34% year over year as an initial access vector, which is why unpatched VPN appliances, file transfer tools, and web applications remain a favorite entry point.

  4. Personally identifiable and financial information. Names, Social Security numbers, payment card data, and health records carry the highest resale value and trigger the strictest notification obligations under laws like HIPAA, GLBA, and state breach statutes. A data loss prevention (DLP) program is one of the more direct ways to catch this category of data leaving the network before it becomes a confirmed breach.

  5. Encryption keys and certificates. When private keys are stored improperly or certificates are mismanaged, an attacker who reaches them can decrypt protected data or impersonate a trusted system, turning a contained incident into a full scale breach.

What Is the Real Impact of a Data Breach on a Business?

The impact of a data breach shows up as direct financial cost, operational downtime, and reputational damage that outlasts the incident itself, and the 2025 data quantifies each of these more precisely than in past years.

  1. Direct financial cost. At $4.44 million globally and $10.22 million in the United States, breach costs include detection, escalation, notification, legal fees, regulatory fines, and post breach customer support, not just the immediate cleanup.

  2. Operational downtime. Containment and eradication often require taking systems offline. The longer the mean time to identify and contain (241 days on average, 279 days in healthcare), the longer that operational disruption compounds.

  3. Reputational and customer trust damage. Customers and partners are less willing to share data with an organization that has already been breached, and that hesitation shows up in churn and slower sales cycles long after the technical incident is closed.

  4. Regulatory and legal exposure. Missing a notification deadline under a state breach law, HIPAA, GLBA, or the GDPR’s 72 hour window can trigger penalties on top of the breach itself, independent of how the breach occurred.

How Do Organizations Typically Detect a Data Breach?

Most organizations detect a breach through internal security monitoring, such as SIEM alerts, anomaly detection, or an employee report, rather than being told by the attacker or by law enforcement, and internal detection is consistently the faster and less costly path. IBM’s 2025 data shows organizations that catch a breach internally save roughly $900,000 on average compared to those that learn about it from an attacker’s disclosure or a third party notification. Detection actions that shorten the 241 day average identify and contain window typically include:

  • Centralized log collection and a SIEM or equivalent monitoring platform tuned to the organization’s actual environment, not just default rules.
  • Continuous monitoring of authentication events for anomalies such as impossible travel, repeated failed logins, or access from unrecognized devices.
  • Vulnerability scanning and patch tracking on internet facing systems, given that exploited vulnerabilities grew 34% year over year as an entry point.
  • Third party and vendor access reviews, since third party involvement in breaches doubled to 30% in the most recent DBIR.
  • An employee reporting channel and regular phishing simulation, since staff are still often the first to notice something unusual before automated tools do.

What Should a Data Breach Response and Remediation Checklist Include?

A data breach response checklist should move an organization from detection to legal notification and long term remediation in a defined, rehearsed sequence. This is a preparedness level overview; for a full phase by phase breakdown of the response process itself, see our companion guide, Incident Response and Its Phases. Use the following as a working checklist, adapted to your incident response plan and legal obligations:

  1. Confirm and scope the incident. Verify the alert is a genuine breach, identify which systems and data types are affected, and preserve forensic evidence before making changes.

  2. Activate the incident response plan and team. Notify the predefined response team, including security, legal, communications, and executive leadership, and assign an incident commander.

  3. Contain the incident. Isolate affected systems, revoke compromised credentials and certificates, and block known attacker infrastructure without destroying evidence.

  4. Eradicate the root cause. Remove malware, close the exploited vulnerability, and rotate every credential or key that could have been exposed, not only the ones known to be used.

  5. Determine notification obligations. Work with legal counsel to identify which breach notification laws apply based on the data involved and the residency of affected individuals, and calculate the exact deadline (as short as 72 hours under the GDPR).

  6. Notify regulators, affected individuals, and partners. Send notifications that meet each jurisdiction’s required content and timing, and prepare a public statement if the breach is material.

  7. Restore operations. Bring systems back online from clean, verified backups or rebuilt images, and validate that the exploited weakness is actually closed before restoring full access.

  8. Conduct a post incident review. Document what worked, what did not, and update the incident response plan, detection rules, and vendor access policies accordingly.

How Do Common Breach Types Compare?

The table below maps the breach types that show up most often in 2025 primary source data to their typical root cause and the control that most directly reduces that risk.

Breach TypeTypical Root CausePrimary Defensive Control
Credential based breachWeak, reused, or phished passwords; missing multi factor authenticationMulti factor authentication and certificate based authentication in place of static passwords
Third party or supply chain breachExcessive vendor access, unmonitored integrations, weak partner security controlsLeast privilege vendor access reviews and continuous third party risk monitoring
Vulnerability exploitationUnpatched internet facing systems, delayed patch cyclesContinuous vulnerability scanning and enforced patch management SLAs
RansomwareInitial access via phishing, credentials, or exploited vulnerabilities followed by lateral movementNetwork segmentation, offline backups, and rapid detection and containment
Data exposed at rest or in transitUnencrypted databases, misconfigured cloud storage, unmanaged encryption keysEncryption of sensitive data at rest and in transit, backed by proper HSM based key management
Insider or human errorMisconfiguration, accidental disclosure, or misuse of legitimate accessRole based access control, data loss prevention, and regular security awareness training

Limitations

This guide is a general preparedness framework, not a substitute for legal advice or a tailored incident response plan built for your specific environment. Breach notification requirements vary by state, sector, and country, and only qualified legal counsel can confirm which laws apply to a specific incident and what deadlines they impose. Cost and timeline figures cited here are averages from IBM and Verizon’s global datasets; actual cost and recovery time for any single organization depend heavily on industry, breach size, existing security maturity, and how quickly the incident is detected. Organizations in heavily regulated sectors such as healthcare, financial services, or government should treat these figures as a baseline and consult sector specific guidance in addition to this framework.

What Would Encryption Consulting Recommend?

Most organizations we work with are not short on security tools, they are short on a tested plan and on encryption controls that limit how much a breach actually costs when one happens anyway. Our recommendation has three parts.

First, build and test the incident response plan itself, including notification workflows mapped to the breach notification laws that actually apply to your data footprint. Our Compliance Advisory services help organizations align their incident response and notification processes to GDPR, HIPAA, state breach laws, and other applicable frameworks before an incident forces the question. Our Encryption Advisory services assess where sensitive data actually lives and how well it is currently protected, which is the starting point for any credible preparedness program.

Second, treat encryption as a breach impact reduction control, not just a compliance checkbox. Data that is properly encrypted at rest and in transit, with keys protected in a FIPS validated hardware security module, often falls outside the strict notification requirements that many breach laws attach to exposed plaintext data. Our HSM as a Service gives organizations FIPS certified, quantum ready key protection without the overhead of running HSM infrastructure in house, so encryption keys stay isolated even if other systems are compromised.

Third, close the identity and access gaps that show up in the majority of breach reports. Our PKI as a Service replaces static, reusable credentials and passwords with certificate based authentication for users, devices, and workloads, directly addressing the credential abuse and unauthorized access patterns behind roughly a fifth of confirmed breaches. Together, a rehearsed response plan, encrypted data, and strong authentication do not prevent every attack, but they consistently reduce how far an attacker gets and how much the incident ultimately costs.

Frequently Asked Questions

How long do organizations typically have to notify people after a data breach? It depends on the law that applies. The GDPR requires notifying the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach. In the United States, deadlines vary by state, commonly ranging from about 30 to 60 days after discovery, with some sectors such as healthcare under HIPAA required to notify within 60 days. There is no single federal deadline that covers every organization, so legal counsel should confirm the specific requirements that apply to your data and your affected individuals’ locations.

What is the difference between a data breach and a security incident? A security incident is any event that threatens the confidentiality, integrity, or availability of systems or data, such as a blocked malware attempt or a failed login spike. A data breach is a specific type of incident in which unauthorized access to or disclosure of sensitive data is confirmed. Every data breach is a security incident, but not every security incident becomes a data breach.

Does encrypting our data remove our breach notification obligations? Often, yes, in part. Many breach notification laws, including several US state statutes, include a safe harbor provision that exempts organizations from notification if the exposed data was properly encrypted and the encryption keys were not also compromised. This makes strong key management just as important as the encryption itself; if an attacker gets both the encrypted data and the keys, the safe harbor typically does not apply.

How often should we test our incident response plan? Most security practitioners recommend testing an incident response plan at least once a year through a tabletop exercise, and more frequently, roughly every six months, for organizations in high risk or heavily regulated industries. A plan that has never been rehearsed against a realistic scenario usually breaks down in exactly the areas that matter most: who has authority to make decisions, and how fast legal and communications teams can move.

What is the single most cost effective step a mid sized organization can take to reduce breach impact? Based on the 2025 IBM and Verizon data, the two highest leverage steps are enforcing multi factor or certificate based authentication to cut off credential based access (present in 22% of breaches) and building a tested incident response plan that shortens detection and containment time, since internal detection alone saves organizations roughly $900,000 per incident compared to attacker disclosed breaches.

Conclusion

Preparing an organization for a data breach is less about buying more security tools and more about building and rehearsing the incident response plan, notification workflow, and remediation checklist that actually get used the day something goes wrong. The 2025 data from IBM and Verizon is consistent: breach costs remain high, detection still takes an average of 241 days, and credentials, third party access, and unpatched systems remain the most common way in. Organizations that pair a tested response plan with encrypted data, strong key management, and certificate based authentication are the ones that turn a potential $4.44 million incident into a contained, well managed event.

References