Skip to main content
CybersecurityHacking

Cyber-Attacks Inflict $52,000 Average Cost on Organizations

Busy office reception area with employees working and a customer service representative speaking with a client.

"Downtime doesn’t just mean being locked out of computers, it means disruption to service, disruption to employees and their ability to perform their jobs, plus disruption to customers because they are unable to access the services or goods an organization provides to them," Keven Knight, CEO of Talion Cyber Security, said in response to newly released findings.

Hiscox: scale and frequency of successful attacks

The Hiscox Cyber Readiness Report 2026, published on September 15, finds that nearly a third (29%) of organizations globally experienced at least one successful cyber-attack in the past 12 months. Among those that were hit, the average victim reported four incidents over the period. The survey behind the report sampled 6,800 security decision-makers across the UK, Europe and the US.

Financial and operational toll: $52,000 and 32.8 hours

On average, cyber incidents during the past 12 months cost organizations about $52,000. Costs were not evenly distributed geographically: Italy recorded the highest average cost per incident at $134,138. Operationally, downtime was significant — the global average downtime following an incident was 32.8 hours.

Strategic damage and human cost among victims

Hiscox documents a range of strategic and human impacts reported by victims of cyber-attacks. Among those hit:

  • 32% reported delays to growth and expansion or new business initiatives
  • 31% cited increased staffing or external expertise costs
  • 30% said there was a negative impact on financial performance, valuation or credit rating
  • 29% reported losing business opportunities or partnerships
  • 28% were impacted by financial penalties
  • 26% suffered negative publicity

The report also highlights the human toll: over two-thirds (69%) of victims reported employee burnout, high stress or a toxic workplace culture after an incident.

Corporate investments and the survey sample

Against that backdrop, the Hiscox study finds businesses are investing to strengthen cyber resilience. Firms are spending on average around $51,000 a year on these efforts. The most common measures reported were updating employee cybersecurity training (62%), hiring additional cybersecurity personnel (55%), and purchasing new software and tools (51%). The survey also found that 32% of respondents revealed their organization is linking executive compensation or performance metrics directly to cybersecurity outcomes.

How board members, security teams, and employees are responding

Hiscox reports specific actions companies are taking with regard to the AI tools they are deploying and the risks those tools bring. Reported measures include upskilling employees in AI and cybersecurity (33%), expanding AI awareness and training programs (33%), reviewing cyber insurance arrangements to ensure AI risks are covered (32%), and planning regular AI audits (31%). The insurer summed up the outlook on AI: "Businesses are less concerned about speculative future AI scenarios than practical risks that already exist today, including corrupted training data, vulnerable third-party tools and reduced human oversight."

Keven Knight framed the stakes succinctly: “Every second of downtime costs the business money. This is when cyber has a very tangible impact on organizations and it is something board members and business leaders should never overlook.”

Hiscox’s numbers paint a clear, narrowly defined picture: successful attacks are common, their costs and disruptions measurable, and many organizations are reallocating funds, personnel and performance incentives to reduce future harm. The concrete questions the report leaves in view are equally concrete: will the roughly $51,000 average annual investment, the expanded training and the shift to tying executive pay to cyber outcomes be sufficient to reduce the one-in-three risk that a firm will suffer a breach in the coming year?

Original story