Cybersecurity Statistics by Sector and Company Size
Cybersecurity statistics are useful when they answer a specific business question. A security leader choosing recovery priorities needs different evidence from a finance team estimating loss exposure. An incident count can identify patterns within a dataset, but it cannot tell an individual company its probability of suffering an attack.
The distinction becomes especially important when comparing industries and business sizes. Sector reports often count contributed incidents. Insurance studies measure losses among covered organizations. Complaint systems record reports submitted by victims and other complainants. Each captures a different part of the problem.
The figures below keep those populations separate. They show what the sources observed, explain where comparisons stop, and provide a practical way to use the evidence in budgeting and operational reviews. No single number is treated as a universal risk score.
Key Statistics and Data
Two datasets provide complementary views of exposure and financial impact. Their figures should remain in separate tables because their units and populations differ.
- Manufacturing: Verizon’s 2026 DBIR executive summary reports 3,627 incidents and 2,713 confirmed data disclosures in its contributed manufacturing data.
- Finance and insurance: The same summary reports 3,809 incidents and 1,300 confirmed disclosures for this sector.
- Smaller revenue band: The 2026 Breach Impact Study places approximate median ground-up loss at $38,000 for the analyzed nonzero insured losses associated with companies below $25 million in annual revenue.
- Larger revenue band: That approximate median reaches $283,000 above $250 million in annual revenue. It is a loss-severity comparison within the study, not an estimate of annual attack probability.
What the Sector Counts Measure
Verizon’s incident and breach counts distinguish security incidents from confirmed data disclosures. The broader incident category and the narrower disclosure category answer different questions. Combining them would count some events twice and destroy the distinction that makes the dataset useful.
| Sector | Incidents | Confirmed Data Disclosures | Source Edition |
|---|---|---|---|
| Education | 1,302 | 1,252 | 2026 DBIR executive summary |
| Finance and insurance | 3,809 | 1,300 | 2026 DBIR executive summary |
| Healthcare | 1,492 | 1,438 | 2026 DBIR executive summary |
| Manufacturing | 3,627 | 2,713 | 2026 DBIR executive summary |
| Public administration | 3,634 | 2,410 | 2026 DBIR executive summary |
| Retail | 997 | 806 | 2026 DBIR executive summary |
These are observations contributed to an international research dataset. They are not a census of every event experienced by every organization in each industry. The table also lacks the number of organizations operating in each sector and their time at risk. Without that denominator, a higher count does not establish that a randomly selected company in one sector faces a higher attack probability than a company in another.
Consider a manufacturing business comparing its priorities with those of a financial institution. The manufacturing figure can support a discussion about the kinds of incidents represented in the research. It cannot justify multiplying a factory’s security budget by the ratio of the two sector counts. That calculation would turn differences in observed volume into an unsupported estimate of relative exposure.
Use the sector categories to start questions about your own environment. Which systems support revenue? Which services cannot tolerate extended interruption? Where does sensitive information reside? The useful comparison is between the business process and its controls, with external evidence supplying context.
Reading Company Size Through Loss Severity
Company size requires a separate measurement. The Breach Impact Study uses revenue-based company-size bands, not employee counts, in its loss comparison. Converting those bands into headcount categories would introduce assumptions the study does not make.
| Annual Revenue | Approximate Median Ground-Up Loss | Scope |
|---|---|---|
| Below $25 million | $38,000 | Analyzed nonzero US insured cyberclaim losses |
| $25 million to $250 million | $96,000 | Same study and loss definition |
| Above $250 million | $283,000 | Same study and loss definition |
The figure uses 24,873 loss observations. Ground-up loss includes the deductible and total incurred amounts, including reserves. These figures therefore do not mean that an insurer paid the stated amount, that every claim had closed, or that the business had already spent all of the recorded loss.
The source examines US insured cyberclaims associated with incidents from 2019 through October 2025. It excludes zero-dollar claims from this comparison. Uninsured organizations and losses outside the relevant coverage are not represented in the same way. The median describes the middle of the analyzed observations; it does not describe the worst plausible event for a particular company.
This is where cybersecurity statistics can inform a financial conversation without becoming a budget formula. A business can compare the study’s loss definition with the costs it tracks internally, then identify what remains outside the comparison. That exercise is more useful than selecting the median for its revenue band and calling it the expected cost of a future incident.
Keep Incidents, Breaches, and Complaints Separate
A single attack may generate several different records. A security team might investigate an incident, confirm unauthorized disclosure, notify affected parties, file an insurance claim, and submit a complaint. Those records do not become five independent attacks simply because five systems contain them.
The distinction between confirmed breaches and exposed records matters when an executive asks how many people or organizations were affected. Event counts, record counts, and notification counts describe different units. A high number of exposed records can arise from a small number of large events, while repeated notices can concern the same person.
The FBI’s IC3 report, meanwhile, records reported complaints and losses. Complaint-based data reflects what was submitted to that system under its reporting definitions. It should not be relabeled as a complete count of successful attacks against businesses. It also should not be added to an incident research dataset without a defensible method for removing overlap.
The same caution applies to loss categories. Ransomware recovery costs may include restoration work and operational disruption under one study’s definition, while a complaint dataset may use a narrower reported-loss measure. An insurance figure may include reserves. Similar dollar symbols do not make the underlying amounts comparable.
For a management report, write the counting unit beside every number. “Contributed incidents,” “confirmed disclosures,” “nonzero insured claim losses,” and “submitted complaints” are compact labels that prevent large interpretive mistakes. Keep the source edition and population in the same row or footnote so they survive when a chart is copied into a presentation.
Turn External Evidence Into an Internal Review
The strongest use of cybersecurity statistics is to challenge a decision, not to replace it. Start with a decision your team can make: improving recovery for a critical service, reducing privileged access, funding incident response coverage, or testing an important dependency.
First, identify the business service and its owner. A broad industry category cannot reveal whether payroll, customer ordering, manufacturing control, or internal collaboration would create the greatest interruption cost in your organization. Map the systems, people, and suppliers required to restore that service.
Second, distinguish available controls from demonstrated capability. A backup subscription does not establish that a usable recovery point exists. An incident response contract does not establish that the right people can invoke it. Ask for recent evidence of the specific action the business expects to perform under pressure.
Third, separate frequency assumptions from severity assumptions. The sector table does not supply a defensible annual probability for your company. The insurance table does not supply a worst-case loss. If a financial model needs those inputs, identify them as organization-specific assumptions and show how the decision changes when they vary.
Finally, connect the proposed spending to an observable outcome. A recovery investment might be assessed through a successful restoration test and a documented dependency map. An access-control project might be assessed through removal of unnecessary privileges and verified handling of employee departures. Neither outcome needs an invented industry-wide return on investment to be meaningful.
Build a Comparison That Survives Review
A useful evidence record contains the source, edition, counting unit, population, collection period where established, financial definition, and intended use. It also records the inference the team is choosing not to make. That last field is valuable when statistics move between technical, finance, and executive audiences.
For the sector table, the prohibited inference is a population-wide industry risk ranking. For the revenue-band comparison, it is a universal loss forecast or an employee-size conversion. For complaint data, it is a complete estimate of all cybercrime harm. These boundaries make the information more dependable, not less useful.
Treat changes between report editions carefully. A larger count can reflect changes in contributions, reporting practices, definitions, or the underlying activity. Before describing a trend, establish that the two editions measure sufficiently similar populations and units. If that comparison is unavailable, report each observation with its own date and avoid a growth claim.
The same approach improves discussions of reported cybercrime losses. A finance audience may reasonably want a single total, but the total needs a clearly defined scope. Broader business interruption, uninsured costs, and indirect consequences should not be silently assumed to be included.
Keep the final executive view short. Show the relevant observation, the limitation that changes its interpretation, the internal evidence, and the proposed decision. Detailed methodology belongs in the supporting record, but material limits belong beside the claim.
Use the Numbers to Set Priorities
Useful cybersecurity statistics connect an external observation to an internal question that someone owns. The figures here support separate discussions about contributed sector events and the severity of analyzed insured losses. They do not support a single league table of which businesses are safest.
A practical next step is to select one important service, document its dependencies, and review whether the team can demonstrate detection, containment, and restoration for that service. Use the external figures to explain why the review matters, then judge the proposed work by the evidence it produces.
That approach gives executives a defensible decision rather than a dramatic number. It also makes future updates easier: when a source changes, the team can replace the observation without rebuilding its entire risk argument.
Consider a planning meeting where a finance lead asks whether the revenue-band median should become the incident reserve. The answer should begin with the study population and loss definition, then turn to the company’s own exposure. Which costs would the reserve cover? Does the business have an estimate for interruption of its most important service? Are supplier dependencies included? The external median can challenge an implausibly low assumption, but it cannot supply the missing internal analysis.
The security team can make that meeting more productive by bringing a short service-level scenario. Identify the affected process, the restoration dependencies, the cost categories, and the assumptions that remain uncertain. Finance can then assess the financial treatment while the operational owners validate the recovery work. The resulting estimate will still have uncertainty, but it will have a traceable basis.
Retain the external source separately from the internal scenario. When the next report edition arrives, the team can update the contextual figure and reconsider the assumptions without implying that the organization’s exposure changed in direct proportion to the published median.
Frequently Asked Questions
These answers clarify how sector counts and insured losses can inform a business review.
Which Industry Has the Most Cyberattacks?
There is no universal answer in the sector table. It shows incidents contributed to one research dataset, not every attack across all organizations. Different industry sizes, reporting practices, and contributor coverage prevent a simple population-wide ranking from these counts alone.
Do Larger Companies Always Lose More?
The analyzed insured-loss medians increase across the stated revenue bands. That does not mean every large company loses more than every small company. Individual outcomes depend on the event, business dependencies, response, coverage, and what the loss measure includes.
Can These Figures Set a Security Budget?
They can inform the discussion, but they cannot determine a budget by themselves. Build the decision around critical services, demonstrated control gaps, contractual obligations, recovery requirements, and organization-specific financial assumptions. Use external evidence to test those assumptions and explain their limits.
Why Do Different Reports Give Different Totals?
They often count different things. Complaints, incidents, confirmed disclosures, insurance claims, and affected records are separate units. Before comparing these figures, check the population, reporting period, event definition, and loss definition. Differences in those fields can explain apparently conflicting figures.
Resources
The sector comparison uses the 2026 Verizon DBIR executive summary, printed pages 13–16. The company-size comparison uses Figure 11 of Verizon’s 2026 Breach Impact Study. Complaint terminology follows the FBI’s 2025 IC3 Annual Report. Each source is linked at its first substantive use above.
