
According to a report by IBM, the average cost of a data breach in India reached an all-time high of Rs 195 million ($2.35 million) in the financial year 2024 (FY24), up by around 7 per cent over a year ago with the local industrial sector being the most impacted.
The report added, escalating data breach disruption pushes average cost of a data breach in India to all-time high of Rs 195 million in 2024, breach costs jumped 39 per cent since 2020 and 9 per cent from the prior year, as breaches grow more disruptive and further expand demands on cyber teams. Globally, 70 per cent of breached organisations reported that the breach caused significant or very significant disruption.
Further, it added, most common initial attack types in India were phishing and stolen or compromised credentials, accounting for 18 per cent of incidents each, followed by cloud misconfiguration (12 per cent). Business email compromise was the costliest root cause at an average total cost of Rs 215 million per breach, followed by social engineering (Rs 213 million) and phishing (Rs 20.9 million) as the next highest costs. The Indian industrial sector faced the highest impact from data breaches, with average cost reaching Rs 255 million, followed by the technology industry at Rs 243 million and the pharmaceutical sector at Rs 221 million.
India ranked at 15 in terms of the average cost of a data breach while the US topped the number at $9.36 million, which declined by 1.3 per cent from previous year’s cost at $9.38 million. This was followed by Middle East ($8.75 million), Benelux ($5.90 million), Germany ($5.31 million) and Italy ($4.73 million).
According to the report, 34 per cent of data breaches studied in India involved data stored on public clouds and 29 per cent across multiple environments (including public cloud, private cloud and on prem). Breached data stored on public clouds represented the highest costs (Rs 227 million), while incidents spanning multiple environments took the longest to identify and contain at 327 days.
Moreover, the report found that organisations which took less than 200 days to identify and contain a data breach incurred an average cost of Rs 184 million. By contrast, organisations with a data breach lifecycle extending beyond 200 days incurred an average cost of Rs 205 million.