Every year IBM and the Ponemon Institute put a price on getting breached in their Cost of Data Breach Report. This year's number is £3.74 million (USD 4.99 million) - the highest on record, up 12% on last year. That figure alone should earn a line in the board pack.
But the number that matters more to a board isn't the average. It's what's driving it, and how much of that driver sits outside IT's control.
*Figures below are converted from the report's USD amounts at approximately £1 = $1.33 (£0.75 = $1), the mid-market rate as of late July 2026. Original USD figures are shown in brackets for reference.
Read this years Cost of Data Breach report closely and a pattern emerges: the costs that grew fastest this year - detection and escalation, and lost business - made up 63% of total breach cost. Those are not forensic or patching costs. They're the cost of confusion: how long it takes to understand what happened, how well the organisation communicates through it, and how much trust and revenue leak out in the process.
The report's own root-cause data backs this up. AI-related breaches weren't caused by sophisticated model attacks in the main - they were caused by identity and access management failures, the kind of governance gap a board should be asking about at the next audit committee, not discovering after the fact.
IBM's own recommendation is to treat identity as "mission-critical infrastructure," not a technical afterthought.
Two findings deserve particular board attention, because they point at the same underlying weakness: the ability to communicate and coordinate once the primary network is no longer trustworthy.
These attack vectors specifically target the accounts and credentials leadership relies on to communicate - email, helpdesk access, MFA.
When those channels are the attack surface, they can't simultaneously be the crisis response tool. Yet in practice, most organisations still coordinate their breach response over email and Teams - the same systems the attacker may already control.
The past 12 months has seen the ransomware groups take a new direction in their attacks , reputation extortion. Specifically public shaming, leaked data, media pressure - precisely because it forces a fast, public leadership response under conditions where the leadership can least afford to be slow, uncoordinated, or overheard.
A board that can't convene securely and immediately when the ransom note lands is negotiating from a weaker position before a single word is exchanged.
This is the gap an out-of-band communications capability exists to close. Not a technical nice-to-have, but the mechanism that lets the CEO, CFO, general counsel, and crisis lead actually reach each other, agree a position, and brief the regulator or the market - independent of whatever the attacker has already compromised.
The report's own numbers on breach lifecycle cost make the business case directly: organisations that identify and contain faster save close to a third of the average breach cost. Speed is a function of coordination. Coordination requires a channel the attacker doesn't control.
IBM's recommendations to security teams are about identity, AI governance, and post-quantum readiness - all fair, all technical. But the board's own exposure sits one layer up: when the systems your executive team normally uses to talk to each other are the same systems in question, how do you make the decisions that determine whether this costs £3.24 million or £4.24 million?
That's not a question for the incident response plan buried in the security team's wiki. It's a question for the board to have answered - and rehearsed - before the attack, not during it.