2025 Cybersecurity Incident Trends Report
2025 Cybersecurity Incident Trends Report
Insights Study
It's About Time
IRIS
20
25
Introduction TABLE OF
CONTENTS
Q1
ARE SECURITY
INCIDENTS
“Time isn't a straight line... It's BECOMING
4
all bumpy wumpy.” 1 MORE COMMON?
Q2
~The Eleventh Doctor
DO INCIDENT
TRENDS DIFFER
AC R O S S
7
Welcome to the 2025 edition of the (roughly) biennial O R G A N I Z AT I O N S ?
Information Risk Insights Study (IRIS). The last one
Q3
was in 2022, so it’s about time we got this to you. IS THE
Thanks for your patience. PROBABILIT Y
OF INCIDENTS
12
Fittingly, time is of the essence in this IRIS. Not just INCRE ASING?
because it’s a tad overdue, but because it’s literally
Q4
about time—cyber risk trends over time, to be H AV E S E C U R I T Y
specific. INCIDENTS
GOT TEN MORE
Cybersecurity is ever-changing, and there’s an 16
C O S T LY ?
implicit assumption that risk is always increasing.
Q5
But is it?
Are cyber events occurring at greater frequency? Is DO TRENDS
DIFFER AMONG 20
an organization more likely to have a breach now E VENT T YPES?
than 15 years ago? Which types of incidents have
Q6
become more common over time? Have the financial
ARE INTRUSION
impacts of cyber events increased or decreased? Are METHODS
risk factors trending the same way for all sectors and C H A N G I N G OV E R
23
sizes of organizations? TIME?
Q7
We explore these questions and more by analyzing
W H AT A R E
a huge historical dataset of cyber events and losses WE MISSING
from 2008 through 2024. As always, our goal is to FROM CURRENT
27
dispel the fog of FUD surrounding cyber risk so EVENTS?
you can see it more clearly and manage it more
A
effectively. Thanks for reading!
M E T H O D O L O GY
& INCIDENT 32
PAT T E R N S
Acknowledgements
The Cyentia Institute wishes to acknowledge and
IRIS 202 5 IT'S ABOUT TIME
To many of you, the answer to this question seems so obvious that it’s hardly worth asking. But we’re not
ones to let any assumption go unchallenged. As it turns out, this one is solidly backed by historical data—at
least in terms of reported incidents 4. Figure 1 shows a 650% increase in the average number of incidents
added to the public record each quarter in 2024 (~3,000) versus the rate set 15 years ago (~450).
But there’s a lot more going on than simply “incidents are way up!”5 The proliferation of large-scale data
breaches combined with the rolling out of breach disclosure laws certainly drove the steady climb early in
this timeframe. The plateau beginning in 2013 corresponds with the emergence of advanced persistent
threats (APTs)6 that employed a “low and slow” rather than “smash and grab” strategy. The reacceleration
circa 2019 was spurred by the rapid rise of ransomware (see Figure 2) and exacerbated by the COVID-19
pandemic. We could go on, but you get the point. These trends have reasons.
Roaring '20s
3,500
2024: ~3K
2,500
Number of incidents
Reporting lag
2,000
in final quarter
1,500
1,000
2008: ~450
500
0
2008 2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)
1 “Actually, from a non-linear, non-subjective viewpoint, it's more like a big ball of wibbly-wobbly, timey-wimey stuff.” - The Tenth Doctor
2 We use the terms security incident, cyber event, and loss event interchangeably. This refers to actual incidents that compromised the confidentiality, integrity, or availability
of a firm’s information assets.
3 We use the terms losses or costs to refer to the financial consequences of incidents.
4 This entire report is based on analyzing incidents that make their way into the public record through outward signs or impacts, mandatory reporting, voluntary disclosure,
company filings, public lawsuits, etc.
5 Yes—we’re aware that the “incidents are way down” in the last quarter of 2024. But we’re fairly confident that number will go up once the reporting lag catches up and flushes
all those as-yet-unknown events into the open. Spoiler alert: we test (and confirm) this in Q7.
6 To be clear, we’re not saying APT attacks started in 2013. But that’s when Mandiant’s APT1 report published and community awareness of these events ballooned. This slowed
the rate of publicly reported incidents because attackers (even cybercriminals) were more discrete and much of the threat intel and incident response community was focused
on APTs rather than standard cybercriminals.
60%
System intrusion
40%
Percent of all incidents over the trailing year
Ransomware
20%
10%
DoS attack
5%
Accidental disclosure
Insider misuse
Scam or fraud
1%
Defacement
System failure
Physical threat
0%
2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)
Figure 2: Relative frequency of incident patterns over time (rolling 12mo. 2009-2024)
IRIS 202 5 IT'S ABOUT TIME
Now let’s also observe what has changed. The aforementioned rise of ransomware in recent years is,
in fact, unprecedented. So is accidental disclosure’s precipitous drop over roughly the same period.
We could go into far more detail on ransomware trends, but we’ve already done that in another IRIS.
~ Jack Freund
Executive Fellow | The Cyentia Insitute
THE C YENTIA INSTITUTE CYENTIA .COM 6
Q2
DO INCIDENT TRENDS
D I F F E R AC R O S S
O RG A N I Z AT I O N S ?
This seems like another obvious answer on the surface because it’s well known that certain organizations
make more attractive targets, some have poor defenses, and others are just plain unlucky. But what we’re
really after here is whether there are inherent differences between different types of firms. Figure 3 attempts
to open the door to that question by comparing trends across organizations grouped by their annual
revenue.
35%
30%
$10M to $100M
25%
20%
15%
$100M to $1B
10%
$1B to $10B
5%
$10B to $100B
More than $100B
0%
2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)
Figure 3: Proportion of all incidents in each revenue tier (rolling 12mo. 2009-2024)
IRIS 202 5 IT'S ABOUT TIME
1,000x
530x 620x
$10B to $10
0B
32x
17x
$100 M to $1B
10x
7.2x
2.1x
1.6x $10 M t o $100M
1x
0.53x
Less than $10M
0.24x
Figure 4: Relative number of incidents to number of firms in each revenue tier (rolling 12mo. 2009-2024)
8 We use data from Dun & Bradstreet for the number of organizations in each revenue tier.
9 The Small Business Administration estimates that 99.9% of all businesses are small. [Link]
business-2024/
Let’s turn next to frequency-based disparities among different industries. Since we’ve established the
importance of adjusting for the number of firms in each segment, we can skip to the punch line. Figure 5
groups sectors10 based on their relative event frequency.11
Figure 5: Relative number of incidents to number of firms in each sector (rolling 12mo. 2009-2024)
The Public and Management sectors are the only two that have historically exhibited a very high relative
incident frequency. For the former, we attribute that to mandatory disclosure requirements that typically
exceed those in the private sector.
IRIS 202 5 IT'S ABOUT TIME
10 Sectors throughout this report use the North American Industry Classification System (NAICS). Our labels are short versions of NAICS sectors—generally the first word of the
official sector name.
11 A multiple >1 indicates higher relative incident frequency based on the number of firms in a sector; <1 indicates the opposite (low relative frequency).
This question may initially sound similar to the previous two, but those involved tallying the total number of
incidents reported across many organizations. Here, we explore how the likelihood of a single organization
having an incident is changing over time. If that nuance isn’t quite clear, think of it like this: what are the
chances your firm will suffer a significant incident this year?
We’ll begin by changing our perspective from the past to the future—except how the future was modeled in
the past… over time. Jeepers, this timey-wimey stuff is confusing, isn’t it? Maybe a chart will help; Figure 6
tracks the modeled probability12 of a typical organization13 experiencing an incident in the next 12 months.
It is understandable if cybersecurity folks can’t hold back an “I told you so!” here because overall incident
probability has almost quadrupled over the last 15 years. We could stop there, issue a press release, and
bid you adieu until the next installment, but we’re just getting started.
Roaring '20s
9.0% 9.3%
The probability
that a typical
Likelihood of at least one incident
8.0%
firm will
7.0% experience
Mid-'10s plateau a significant
6.0%
security incident
6.1% has almost
5.0%
quadrupled over
the last 15 years.
4.0%
3.0%
2.5%
12 See appendix for details on our approach to modeling annualized incident probability.
13 We use “typical” to remind readers that this model doesn’t account for the many factors that would make incidents more
or less likely for a particular organization. We’ll look at some of those later.
What if we told you that the probability of a <$100M firm suffering a security incident has more than doubled,
while the chance of a $100B+ megacorporation suffering an incident has dropped by a third over the same
time frame? Well, that’s exactly what Figure 7 tells us.
Figure 7: Annualized incident probability for firms in each revenue tier (rolling 12mo.)
Unfortunately, our dataset is silent on the underlying factors behind these trends, so all we can offer is some
IRIS 202 5 IT'S ABOUT TIME
speculation. Perhaps cybercriminals have shifted to more volume-oriented (“low-hanging fruit”) strategies
over time. Maybe the pace of digitalization has outpaced SMBs’ ability to defend their growing attack
surfaces, while the bigger enterprise security budgets offset that. Maybe increased regulatory pressures on
large corporations are gradually hardening enterprise security architectures. Whatever the cause(s), these
are important trends that are worth further research by our industry.
Allow us to briefly describe what you’re looking at. Sectors are sorted in descending order by the latest
probability estimate. So, a typical manufacturing firm has an 11% chance of having a security incident in
the next 12 months—up from ~2% 15 years ago.
6.8%
evolving business models,
4%
changes in the threat
Public Financial landscape, shifting adversary
0%
goals, etc.). That's intuitive,
12%
but perhaps seeing this
9.1%
confirmed will help validate
8%
the need to incorporate such
4.5% factors into your cyber risk
4%
assessments.
0%
Healthcare Utilities
4.1%
4%
0%
Information Entertainment
'08 '10 '12 '14 '16 '18 '20 '22 '24 '08 '10 '12 '14 '16 '18 '20 '22 '24
Source: IRIS 2025 (Cyentia Institute) IRIS 202 5 IT'S ABOUT TIME
Visit [Link]/iris to
get additional analysis of multi-
incident probabilities.
We’ve covered the evolving frequency and likelihood of cyber events—now it’s time to talk dollars and cents.
Let’s begin by establishing the distribution of financial losses from cyber events using Figure 9, which
reproduces a classic IRIS chart with the latest and greatest data.14
Figure 9: Distribution of reported losses for security incidents from 2015 to 2024
The typical (median15) incident costs about $600K, while more extreme (95th percentile) losses swell to $32
million. Note that Figure 9 is plotted on a log scale, so the tail of large losses is longer than it appears. If it’s
not too much to “shoulder,” also note the bump in the lower half of the distribution. We’ll explore that later.
NOTE: Losses analyzed in this study tend to reflect direct losses that are easier to quantify (e.g., response
costs or lost revenue) and/or identify from public records (e.g., class action suits or U.S. Securities and
Exchange Commission (SEC) filings). Indirect and intangible impacts often aren’t captured. Thus, this
IRIS 202 5 IT'S ABOUT TIME
14 All loss amounts considered in this report have been converted to 2024 dollars to adjust for inflation.
15 Prior IRIS used the geometric mean for a typical loss. Since the growing “shoulder” in lower part of the distribution pulls the geomean down, the median is better central
measure for the updated distribution.
h
95t Having seen that, we imagine you’re anxious to see
117.23% (1.15x)
102.27% how these costs are trending for firms like yours.
While we can’t drill down quite that far, we can show
these loss distribution parameters for organizations
of different types and sizes. We’ll start with the latter.
0.65% (7.84x)
It’s a no-brainer that larger firms would experience
50th
larger losses, and we’ve shown that in prior studies.
0.08%
2008 2012 2016 2020 2024
We include Table 1 to reconfirm that fact and arm you
Source: IRIS 2025 (Cyentia Institute)
with the most recent stats to inform loss estimates
that are better sized to your organization. Note that
the size-based differences in loss magnitude are
Figure 11: Trend analysis of median and 95th
especially prominent for extreme (95th percentile)
percentile losses as a percent of revenue
events. There’s a longer tail for larger organizations.
16 You may notice that we switch between the 95th and 90th percentile for losses to represent the concept of extreme events. We generally use the 95th for long, fixed time periods.
However, we found that in the specific context of time series models, data availability in the tails wax & wane such that estimates of the 95th percentile became unreliable. Using
the 90th percentile is merely a small concession in consistency to ensure that we're confident that the percentile is being estimated reliably.
90th
That deserves an entire study of its own, but
$6.5M
we suspect the push for Payment Card Industry
$6.0M (0.04x)
(PCI) compliance and the rollout of Chip-and-
50th
Pin technology may have helped to limit the
amount of data that can be easily exfiltrated from
$142.3K (0.02x) retailers. Since larger breaches generally (but
2008 2012 2016 2020 2024 not linearly18) correspond with higher losses, this
Source: IRIS 2025 (Cyentia Institute) would help cap potential losses. But Retail is not
alone; Information Services and Management
firms also show declining loss distributions.
Figure 12: Trend analysis of median and 90th
percentile event losses for example sectors.
IRIS 202 5 IT'S ABOUT TIME
17 Don’t fret if your favorite sector is missing. Appendix C includes a table that gives median and extreme loss values for all sectors similar to the IRIS 2022.
18 Prior IRIS have conclusively demonstrated that losses do not follow a flat cost-per-record formula.
Sectors Include:
• Financial
IRIS 202 5 IT'S ABOUT TIME
• Healthcare
• Hospitality
• Transportation
• And more!
Remember how we said to pay attention to the overall shape of the distribution in Figure 9 at the beginning
of the last section? If not, feel free to jump back and refresh your memory. We’ll wait.
We weren’t pulling one of your lower extremities when we said that would be important. There is a
pronounced “shoulder” in the lower half of the distribution. Whenever a bimodal tendency like this exists
in a distribution, it’s worth investigating what’s behind it. So, we did—and discovered that the shoulder has
grown over time, as evidenced by Figure 13.
No shoulder
2008-2017
2009-2018
2010-2019
2011-2020
2012-2021
2014-2023
2015-2024
$1K $10K $100K $1M $10M $100M $1B
Losses
Source: IRIS 2025 (Cyentia Institute)
Figure 13: Ridge plot showing loss distribution shape in successive 10-year windows
The reason we’re belaboring this technical detail is that it turns out the underlying cause highlights the
importance of distinguishing different types of incidents when assessing loss magnitude. Note what
happens when we plot separate loss distributions for each of our incident patterns in Figure 14.
IRIS 202 5 IT'S ABOUT TIME
Median
95th percentile
DoS/System failure
Ransomware
System intrusion
Scam or fraud
Physical threat
Insider misuse
Accidental disclosure
$1K $10K $100K $1M $10M $100M $1B
Losses
Source: IRIS 2025 (Cyentia Institute)
A possible explanation is that the growing shoulder reflects the rollout of regulations over the years that
require public disclosure of even relatively minor data loss events. Thus, comparing loss trends specific to
these different incident patterns could provide helpful context. We do just that in Figure 15.
$150.2K 50th
$6.9K (0.05x)
2008 2012 2016 2020 2024
System intrusion
$221.3M
90t h
$7.4M (0.03x)
$1.3M (1.97x)
$645.0K 50th
2008 2012 2016 2020 2024
Ransomware
$27.6M (5.52x)
90th
$5.0M
$3.2M (20.49x)
50t h
$155.5K
2008 2012 2016 2020 2024
Source: IRIS 2025 (Cyentia Institute)
Let’s say for a moment that the probability and loss estimates for your own organization mirror some of the
upswings observed in prior sections. Assuming that trend is climbing above your risk tolerance, you’ll want
to do something to flatten the curve. But what?
Choosing the best risk treatment strategy has never been easy and likely never will be. But organizations
make those decisions even harder when they attempt to jump all the way from high-level assessments
down to specific measures to mitigate risk. Discerning whether BlinkyBox1 vs. BestPractice2 vs. the latest
[enter acronym] solution is the most effective option strongly depends on the maturity of your security
program and the particular threats driving your risk exposure upward.
Exploit
2nd Hardware Additions 35% 31% 29% 38% 34% Public-Facing
Application
5th Trusted Relationship 12% 16% 15% 15% 10% Hardware Additions
Exploit
6th Public-Facing 5% 5% 14% 9% 10% External
Services
Remote
Application
Figure 16: Prevalence of ATT&CK Initial Access techniques observed in incidents over time
Figure 16 presents trends in ATT&CK Initial Access techniques observed over the last nine years, according
to the percentage of incidents19 associated with each. Overall, the shifts seen here largely reflect the
never-ending cat-and-mouse game played between attackers and defenders. A few trends are particularly
noteworthy.
Cyber threats are ever-changing, which makes it even more remarkable when TTPs don’t change all that
much. Using Valid Accounts to gain illicit access (e.g., by compromising user credentials) has held the pole
position for the entire time period. Phishing—a popular means of obtaining those credentials—has also
consistently ranked among the top techniques. To be fair, there are many different schemes by which
attackers abuse user accounts as well as many sub-techniques for phishing. But that doesn’t change the
overall lesson here regarding the longevity of these methods.
The “moving-up-the-charts” award among intrusion methods goes to Exploit Public-Facing Applications
(i.e., web application attacks) and External Remote Services (i.e., misconfigured remote access tools).
IRIS 202 5 IT'S ABOUT TIME
Both techniques have surged from single-digit percentages to heights of 38% and 30%, respectively. This
likely reflects the expansion of enterprise attack surfaces over the last decade. These external points of
presence are intended to serve customers, third parties, and remote employees, but attackers increasingly
take advantage of them as well.
19 Percentages are based on incidents for which at least one ATT&CK technique was identified.
But upon closer inspection, interesting variations become apparent. Abusing Valid Accounts is trending
down over the last few years for organizations below $10B in annual revenue, but rising sharply for
the largest corporations. Phishing and exploiting applications are most prevalent among incidents
affecting smaller firms (<$100M) and progressively less in higher revenue tiers. Attacks targeting Trusted
Relationships disproportionately affect larger organizations, which makes sense given their extensive
portfolio of third-party vendors.
60%
50%
Percent of incidents
40%
30%
20%
10%
2016 2018 2020 2022 2024 2016 2018 2020 2022 2024 2016 2018 2020 2022 2024
Figure 17: Prevalence of ATT&CK Initial Access techniques observed by revenue tier
These seemingly contradictory takeaways are reasonable based on the historical attack trends specific to
each class of organizations. The point is that the adversary TTPs trending for *waves hand* them aren’t
necessarily the ones shaping your risk posture.
We’ll close with a reminder that Initial Access is only one of more than a dozen tactics in MITRE ATT&CK.
While trending techniques within each tactic are possible, this is already a long report, and we have one
last question we’d like to explore.
20 Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk (with SecurityScorecard).
21 The State of Third-Party Risk Management (with RiskRecon).
Since the beginning of the IRIS series, we’ve tried to be open about the shortcomings and potential biases
in our dataset of publicly reported incidents. One point often mentioned is the reporting lag that stems
from the time it takes for details to make their way into the public record.22 Another is that some types of
cyber events (or attack details) are underrepresented because they don’t have immediate visible impacts
or don’t trigger mandatory disclosure laws. That’s why we’re especially grateful to Feedly, a real-time threat
graph, for allowing us to analyze cyberattacks collected via their intelligence capabilities for this section.
To derive the Feedly data analyzed in this study, we started with events identified by Feedly’s Cyber Attacks
AI model from 2024. The model was developed by Feedly to discover and research emerging threats, which
makes it more of an “ear-to-the-ground” signal of current cyber events than our historical loss database.
We’ll state up front that this isn’t an attempt to determine who’s right and who’s wrong. As the lead question
implies, we’re concerned with what our core incident dataset might be missing from recent media coverage
that hasn’t yet made (and may never make) it into the official public record.
2,500
Number of incidents
2,000
1,500
1,000
500
IRIS 202 5 IT'S ABOUT TIME
0
2008 2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)
Figure 18: Number of security incidents publicly reported or discovered each quarter. Feedly was used for
incident discovery in Q4-2024 to compensate for the lag in the historical dataset.
22 This is why many charts in this report show an apparent downturn in 2024; we’ll still be learning of 2024 incidents long after this report is published in 2025.
It’s worth noting that the incidents in both datasets show a similar representation of affected industries.
Each attributes the highest number of events to Healthcare and Finance. Feedly rounds out the top three
with the Public sector, while our data has Professional Services in third place (Public is #4). That’s a good
indication that the comparisons in this section are based on samples that are reasonably similar in nature.
Speaking of near-term trends, you may have noticed that we rarely include analysis of the latest threat actor
campaigns in the IRIS series. That’s partially due to our focus on risk management vs. threat intelligence.
But it’s also because public disclosures and filings that comprise our dataset usually don’t delve into
attribution. Media outlets, on the other hand, love a good “whodunnit?” story, and Feedly… well… feeds
off those stories.
Table 2 lists the top three threat actors behind the most incidents affecting the Finance, Healthcare, and
Public sectors, according to Feedly’s collections during 2024. Since this isn’t a threat intel report, we won’t
dive into the backstory of these groups—other resources are better suited to that. We include this simply to
make the point that adversaries often have unique goals and targets. Keep that in mind if you’re looking to
incorporate specific threat actors into your risk scenarios and assessments.
Table 2: Top threat actors associated with 2024 security incidents by sector (via Feedly)
It’s hard to talk about threat actors without the conversation turning to the TTPs they use. So, let’s go there
next. Table 3 lists the top five ATT&CK techniques observed by Feedly and two different date ranges for our
historical incident dataset. We do that to enable comparisons based on both time period and source.
IRIS 202 5 IT'S ABOUT TIME
We chalk the disparity around the ranking of Trusted Relationship primarily up to Cyentia’s classification
choices. MITRE’s definition strictly refers to external third parties for that technique, while we traditionally
broaden it to also apply to certain types of insider and contractor misuse. We plan to revisit this in the
future in light of MITRE’s Insider Threat TTP Knowledge Base project.
The disparate ranking of Hardware Additions is threefold. First, that technique was much more prevalent
among incidents a decade ago, but has been declining ever since (see Figure 16). Second, even in
its heyday, this technique was mostly related to skimmers added to payment terminals rather than
network taps and other more advanced threat scenarios that ATT&CK seems to have in view. Third, this
technique tends to be a bit “in the weeds” for media coverage of events and is described in ways that
maket echnique extraction difficult.
We suspect one of the key reasons for this disparity is that supply chain security is hot of late, and media
outlets are more motivated to dig for such details than companies are to include them in official reports.
The aforementioned time lag of incident disclosure could be another factor; perhaps details will soon
emerge that retroactively bump this technique higher in recent years. Thus, Feedly’s collections may grant
a forward-looking, headline-driven view of the most common techniques, while our legacy data offers
more of an actuarial perspective. Both views are informative for assessing risk and developing mitigation
strategies.
The median loss for Feedly-sourced cyber events stands at $28.5M, which is 30x higher than that of our
historical dataset ($603K). The 95th percentile for the two sources shows a disparity of almost $750M!
Typical Extreme
One of my favorite
things about my time
on Verizon's DBIR
team was working
with the scores
of external organizations
that contribute data for
analysis in that report. It's
something I'm glad we've
been able to continue in our
research at Cyentia.
Data Collection
The IRIS research draws heavily upon Zywave’s Cyber Loss Data, which contains over 150,000 security
incidents and associated losses spanning decades. The data is compiled from publicly available sources,
such as breach disclosures, company filings, litigation details, and Freedom of Information Act requests. It
is the most comprehensive source of cybersecurity incidents and losses available.
That said, we’re not claiming this dataset is all-inclusive. We can only analyze incidents that make their
way into the public record through outward signs or impacts, mandatory reporting, voluntary disclosure,
etc. That’s not all the events that occurred over the timeframe, of course, but we have high confidence that
significant cyber events are well represented.
Additionally, Cyentia does extensive processing of Zywave’s base dataset to extend and enrich it for
cyber risk analysis use cases. This is done using a combination of classification models, natural language
processing (NLP), taxonomy mapping, malware behavioral analysis, and manual tagging by our analysts.
Incident and loss data collected by Feedly is used for the last section to study trends we might be missing
from current events. We started with 2024 events identified by Feedly’s Cyber Attacks AI model. We further
refined this by focusing on “memes,” which is Feedly’s method of clustering articles and information on a
trending topic. The point is that we’re not simply counting articles in this analysis. Finally, we reviewed the
identified events to train a classification model to distinguish successful incidents affecting organizations
from other threats and trends that aren’t comparable to our core dataset.
Though we don’t delve into it in this edition, readers of prior IRIS may recall that we have modeled the
frequency of security incidents over a fixed 10 year time period, allowing for the fact that organizations can
have more than one in a single year. We took the same approach in this edition, expanding the model to
include a time component. Ultimately, we present estimates as the annual probability of an organization
experiencing at least one event.
To do this, we divide our historical dataset into 12-month rolling windows and count the number of incidents
for each organization. This gives us a large number of observations that allow us to more confidently model
the annualized loss event frequency.
We then treat these observations as samples from an underlying probability distribution and use random
effects models to estimate the parameters both overall and within specific slices like industry and revenue
bands over time. The result is a closed-form representation of the probability that an organization will
experience a certain number of incidents in a given year that can change over time.
Additionally, in prior IRIS reports we reported both upper and lower bound estimates for incident likelihood.
We’ve dropped that distinction in this edition in favor of exclusively using the more risk-averse upper bound
estimate.
In a nutshell, the difference between these approaches stems from the count of organizations used as the
denominator for the calculation. We don’t know how many exist throughout the world, so the upper bound
uses the total number of organizations that exist in our historical incident database. While it’s true that this
approach excludes some extremely secure or lucky firms, the fact is that those prone to incidents in the
future have probably had one at some point in the past. The result is a more conservative estimate that we
believe is more suitable for risk management.
Financial Losses
Financial losses tend to be less reported than other data points for cyber events. There are many reasons
for this, but the result is that the majority of incidents in our dataset do not include anything about losses.
Those that do tend to reflect direct losses that are easier to quantify (e.g., response costs or lost revenue)
and/or identify from public records (e.g., class action suits or SEC filings). Indirect and intangible impacts
usually aren’t captured.
The good news, from a data standpoint, is that the record of losses from major security incidents—like
those we analyze in this study—is more complete than for minor events due to increased visibility and
reporting. Thus, we hold that our loss dataset is sufficient to form a well-supported model of cyber events
IRIS 202 5 IT'S ABOUT TIME
Note that all financial loss values presented in this report have been adjusted for inflation.
All security incidents in our historical dataset are assigned one of these mutually exclusive23 patterns using
a combination of natural language processing techniques and human expert assessment.
DOS ATTACK: Any attack intended to render online systems, applications, or networks
unavailable, typically by consuming processing or bandwidth resources.
FRAUD OR SCAM: Any incident that primarily employs various forms of deception to
defraud the victim of money, property, identity, information, and so on.
PHYSICAL THREATS: Threats that occur via a physical vector, such as device tampering,
snooping, theft, loss, sabotage, and assault.
RANSOMWARE: A broad family of malware that seeks to encrypt data with the promise to
unlock upon payment or seeks to completely eradicate data/systems without the pretense
of collecting payment.
SYSTEM FAILURE: All unintentional service disruptions resulting from system, application,
or network malfunctions or environmental hazards.
subverting logical access controls, elevating privileges, deploying malware, and so on.
23 Yes, it’s true that an incident could involve more than one of these (e.g., system intrusion and ransomware). However, the purpose of these patterns is to represent the primary
nature of the event.
This appendix contains up-to-date versions of selected figures from IRIS 2022 that provide probability and
loss comparisons among sectors and revenue bands. If there are other figures you'd like to see from an IRIS
of yesteryear, let us know!
Education (1.60x)
Information (1.55x)
Professional (1.50x)
Financial (1.44x)
Healthcare (1.34x)
Public (1.34x)
Retail (1.19x)
Hospitality (1.15x)
Management (1.08x)
Manufacturing (1.03x)
Trade (0.97x)
Entertainment (0.94x)
Relative to median sector
Figure A1: Relative probability of one or more loss events among sectors (Figure 5 in IRIS 2022). The point
of comparison is the overall median across all organizations.
Figure A2: Relative probability of one or more loss events among annual revenue tiers. The point of
comparison is the overall median across all organizations.
Figure A4: Distribution of reported cyber event losses by annual revenue of affected firms (Figure 7 in IRIS
2022)
IRIS 202 5 IT'S ABOUT TIME