0% found this document useful (0 votes)
9 views36 pages

2025 Cybersecurity Incident Trends Report

The 2025 Information Risk Insights Study (IRIS) reveals a significant increase in cybersecurity incidents, with a 650% rise in reported events over the last 15 years, averaging 3,000 incidents per quarter. The study analyzes data from 2008 to 2024, highlighting trends such as the growing prevalence of cyber events among smaller businesses and the rising financial impact of these incidents. Key findings indicate that while the probability of incidents has nearly quadrupled since 2008, the nature of incidents and their frequency varies significantly across different organizational sizes and sectors.

Uploaded by

gtarioii
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views36 pages

2025 Cybersecurity Incident Trends Report

The 2025 Information Risk Insights Study (IRIS) reveals a significant increase in cybersecurity incidents, with a 650% rise in reported events over the last 15 years, averaging 3,000 incidents per quarter. The study analyzes data from 2008 to 2024, highlighting trends such as the growing prevalence of cyber events among smaller businesses and the rising financial impact of these incidents. Key findings indicate that while the probability of incidents has nearly quadrupled since 2008, the nature of incidents and their frequency varies significantly across different organizational sizes and sectors.

Uploaded by

gtarioii
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Information Risk

Insights Study
It's About Time

IRIS
20
25
Introduction TABLE OF
CONTENTS

Q1
ARE SECURITY
INCIDENTS
“Time isn't a straight line... It's BECOMING
4
all bumpy wumpy.” 1 MORE COMMON?

Q2
~The Eleventh Doctor
DO INCIDENT
TRENDS DIFFER
AC R O S S
7
Welcome to the 2025 edition of the (roughly) biennial O R G A N I Z AT I O N S ?
Information Risk Insights Study (IRIS). The last one

Q3
was in 2022, so it’s about time we got this to you. IS THE
Thanks for your patience. PROBABILIT Y
OF INCIDENTS
12
Fittingly, time is of the essence in this IRIS. Not just INCRE ASING?
because it’s a tad overdue, but because it’s literally

Q4
about time—cyber risk trends over time, to be H AV E S E C U R I T Y
specific. INCIDENTS
GOT TEN MORE
Cybersecurity is ever-changing, and there’s an 16
C O S T LY ?
implicit assumption that risk is always increasing.

Q5
But is it?
Are cyber events occurring at greater frequency? Is DO TRENDS
DIFFER AMONG 20
an organization more likely to have a breach now E VENT T YPES?
than 15 years ago? Which types of incidents have

Q6
become more common over time? Have the financial
ARE INTRUSION
impacts of cyber events increased or decreased? Are METHODS
risk factors trending the same way for all sectors and C H A N G I N G OV E R
23
sizes of organizations? TIME?

Q7
We explore these questions and more by analyzing
W H AT A R E
a huge historical dataset of cyber events and losses WE MISSING
from 2008 through 2024. As always, our goal is to FROM CURRENT
27
dispel the fog of FUD surrounding cyber risk so EVENTS?
you can see it more clearly and manage it more

A
effectively. Thanks for reading!
M E T H O D O L O GY
& INCIDENT 32
PAT T E R N S

Acknowledgements
The Cyentia Institute wishes to acknowledge and
IRIS 202 5 IT'S ABOUT TIME

thank the Cybersecurity Division and the Office


of the Chief Economist at the Cybersecurity and
Infrastructure Security Agency (CISA) for sponsoring
this study. It is our sincere hope that this research The Cyentia Institute is a research firm working
will aid community efforts to manage cyber risk. to improve cyber risk management through our
analytical services and data-driven research
publications. You can download the IRIS 2025 and
find related content at [Link]/iris.
THE C YENTIA INSTITUTE CYENTIA .COM 2
IRIS
20 KE Y FINDINGS

25 On average, 3,000 significant security incidents


are publicly reported or discovered each quarter.
That’s a 650% increase over the last 15 years.

Cyber events affecting smaller businesses are far more


common overall, but relative to population size, the
rate among the largest corporations is 620 times higher.
The IRIS research
draws heavily upon
Zywave’s (formerly The annual probability of any given
organization experiencing a cyber event
Advisen) Cyber Loss has almost quadrupled since 2008.
Data, which contains
over 150,000 security
The probability of a <$1B firm suffering an incident
incidents1 and has more than doubled, while the annual likelihood
associated financial for a $100B+ organization has fallen 50%.
losses3 spanning
decades. The data Losses from a typical security incident have
is compiled from absolutely exploded, rising 15-fold from a
publicly available median of $190K to almost $3 million!
sources, such as
breach disclosures, The cost of more extreme “tail loss” events is
public company also up 5-fold, ballooning to $32 million.
filings, litigation
details, and Freedom Cyber events aren’t just costing more—they’re hurting
of Information the bottom line more than ever before. We’ve seen an
Act requests. 8-fold increase in costs as a proportion of annual revenue.

Median losses for professional services firms are up


It is the most
25x over the last 15 years! Alternatively, there’s been
comprehensive source a huge decrease in loss magnitude among retailers.
of cybersecurity
incidents and losses Compromising user credentials remains the most
available. Additionally, common intrusion technique over the last decade,
Cyentia does extensive fluctuating between 43% and 60% of all incidents.
processing of this base
dataset to extend and Exploitation of web applications is up 6x for smaller
enrich it for cyber risk firms, while targeting third-party relationships
analysis use cases. has doubled among large organizations.
IRIS 202 5 IT'S ABOUT TIME

Like what you see? Join the vision!


We intend to continue the IRIS in the future to discover even more insights for managing information risk. If you’d
like to join in that effort by contributing relevant data or sponsoring research, please reach out to us via the
contact form at [Link]/iris.

THE C YENTIA INSTITUTE CYENTIA .COM 3


Q1 ARE SECURIT Y INCIDENTS
B E C O M I N G M O R E C O M M O N?

To many of you, the answer to this question seems so obvious that it’s hardly worth asking. But we’re not
ones to let any assumption go unchallenged. As it turns out, this one is solidly backed by historical data—at
least in terms of reported incidents 4. Figure 1 shows a 650% increase in the average number of incidents
added to the public record each quarter in 2024 (~3,000) versus the rate set 15 years ago (~450).

But there’s a lot more going on than simply “incidents are way up!”5 The proliferation of large-scale data
breaches combined with the rolling out of breach disclosure laws certainly drove the steady climb early in
this timeframe. The plateau beginning in 2013 corresponds with the emergence of advanced persistent
threats (APTs)6 that employed a “low and slow” rather than “smash and grab” strategy. The reacceleration
circa 2019 was spurred by the rapid rise of ransomware (see Figure 2) and exacerbated by the COVID-19
pandemic. We could go on, but you get the point. These trends have reasons.

Roaring '20s
3,500
2024: ~3K

3,000 Mid-'10s plateau

2,500
Number of incidents

Reporting lag
2,000
in final quarter

1,500

1,000
2008: ~450

500

0
2008 2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)

Figure 1: Number of security incidents publicly reported or discovered each quarter


IRIS 202 5 IT'S ABOUT TIME

1 “Actually, from a non-linear, non-subjective viewpoint, it's more like a big ball of wibbly-wobbly, timey-wimey stuff.” - The Tenth Doctor
2 We use the terms security incident, cyber event, and loss event interchangeably. This refers to actual incidents that compromised the confidentiality, integrity, or availability
of a firm’s information assets.
3 We use the terms losses or costs to refer to the financial consequences of incidents.
4 This entire report is based on analyzing incidents that make their way into the public record through outward signs or impacts, mandatory reporting, voluntary disclosure,
company filings, public lawsuits, etc.
5 Yes—we’re aware that the “incidents are way down” in the last quarter of 2024. But we’re fairly confident that number will go up once the reporting lag catches up and flushes
all those as-yet-unknown events into the open. Spoiler alert: we test (and confirm) this in Q7.
6 To be clear, we’re not saying APT attacks started in 2013. But that’s when Mandiant’s APT1 report published and community awareness of these events ballooned. This slowed
the rate of publicly reported incidents because attackers (even cybercriminals) were more discrete and much of the threat intel and incident response community was focused
on APTs rather than standard cybercriminals.

THE C YENTIA INSTITUTE CYENTIA .COM 4


We just mentioned the rise of ransomware,
which prompts a related question: Are all
types of incidents trending the same way? The
crisscrossed lines in Figure 2 are sufficient for Are all types of incidents
a definitive “nope,” but let’s highlight some
following the same trend?
of these trends that meaningfully impact
organizations’ security strategies. The data in our analysis is clear:

At the top of Figure 2, below, system intrusion "NO"


(unauthorized access to systems, applications,
or networks) has long reigned supreme among
incident patterns7. The particular techniques
attackers use to infiltrate networks and systems
have undoubtedly changed, but we’ll dig into that later (see Q6). For now, simply observe that the most
common category of incident experienced by organizations hasn’t really changed in the last 15 years.

60%

System intrusion

40%
Percent of all incidents over the trailing year

Ransomware

20%

10%

DoS attack

5%

Accidental disclosure
Insider misuse
Scam or fraud
1%
Defacement
System failure
Physical threat
0%
2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)

Figure 2: Relative frequency of incident patterns over time (rolling 12mo. 2009-2024)
IRIS 202 5 IT'S ABOUT TIME

Now let’s also observe what has changed. The aforementioned rise of ransomware in recent years is,
in fact, unprecedented. So is accidental disclosure’s precipitous drop over roughly the same period.
We could go into far more detail on ransomware trends, but we’ve already done that in another IRIS.

7 See Appendix B for definitions of these incident patterns.

THE C YENTIA INSTITUTE CYENTIA .COM 5


We’d love to think that “oopsies” as a major
cause of data disclosure are a thing of the past,
but we suspect human nature will reassert
itself at some point.
Key Risk Insight
Physical threats and insider misuse show
a marked downward trend over the years. If it seems like a lot more
Compared to more scalable remote incidents are happening these
alternatives, the “hands-on” approach to data days, it’s not just recency bias.
theft has fallen out of favor. Data handling
regulations and endpoint protections—such as
encryption at rest—have further contributed
The overall rate has seen more
to its decline. Insider misuse never rises above than a sixfold increase over the
fourth place among all incident patterns, which last 15 years.
goes against the long-standing “employees
are the enemy” mentality. Sure, employees
are often targeted in cyberattacks, but they’re
usually not acting with malicious intent.

The data shows how


fluid and contextual
the cyber threat
landscape really is
and how important
your firmographic footprint
is to that, as we will show
throughout this report.
Quantifying that risk,
especially at the board level,
means understanding these
patterns as time sensitive,
not timeless.
Today’s dominant risk may
be tomorrow’s footnote, and
cyber risk models need to
keep pace.
Further, if your security
IRIS 202 5 IT'S ABOUT TIME

strategy isn’t recalibrating


with these changes in risk,
you’re planning for a past
that no longer exists.

~ Jack Freund
Executive Fellow | The Cyentia Insitute
THE C YENTIA INSTITUTE CYENTIA .COM 6
Q2
DO INCIDENT TRENDS
D I F F E R AC R O S S
O RG A N I Z AT I O N S ?

This seems like another obvious answer on the surface because it’s well known that certain organizations
make more attractive targets, some have poor defenses, and others are just plain unlucky. But what we’re
really after here is whether there are inherent differences between different types of firms. Figure 3 attempts
to open the door to that question by comparing trends across organizations grouped by their annual
revenue.

45% Less than $10M

Reporting lags can


40% cause large swings
in this period
Percent of all incidents over the trailing year

35%

30%

$10M to $100M
25%

20%

15%

$100M to $1B
10%
$1B to $10B

5%
$10B to $100B
More than $100B
0%
2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)

Figure 3: Proportion of all incidents in each revenue tier (rolling 12mo. 2009-2024)
IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 7


Rebutting the “Who would attack little ‘ol
us?” argument, smaller businesses (<$100M
annual revenue) see the biggest overall
share of incidents. What’s more, that share is The data in our analysis is clear:
growing over time. The proportion of events smaller businesses—those under
affecting larger organizations (>$1B annual $100M in annual revenue—
revenue), on the other hand, appears to be account for the largest share of
declining over the last 15 years. incidents, countering the idea
that they're too minor to target.
There’s more to this story, however, as astute
readers have probably already discerned. The
obvious objection to the prior chart’s
depiction of trends is that it does not account
for the number of firms that exist in each revenue tier8. Sure, more incidents affect small businesses, but
they vastly outnumber large corporations.9 What happens when we factor in the relative number of firms in
each group? Figure 4 gives the answer—a complete reversal of fortune!

3,600x More tha


n $1 0 0B

1,000x

530x 620x
$10B to $10
0B

100x 110x $1B to


$1 0B
77x

32x
17x
$100 M to $1B
10x
7.2x

2.1x
1.6x $10 M t o $100M
1x

0.53x
Less than $10M
0.24x

2010 2012 2014 2016 2018 2020 2022 2024


Source: IRIS 2025 (Cyentia Institute)
IRIS 202 5 IT'S ABOUT TIME

Figure 4: Relative number of incidents to number of firms in each revenue tier (rolling 12mo. 2009-2024)

8 We use data from Dun & Bradstreet for the number of organizations in each revenue tier.
9 The Small Business Administration estimates that 99.9% of all businesses are small. [Link]
business-2024/

THE C YENTIA INSTITUTE CYENTIA .COM 8


The multiples shown in Figure 4 compare the number of incidents across a revenue tier with the number of
organizations within it. The higher the multiple, the higher the average rate of incidents per organization in
each tier. While larger organizations show a declining trend in the relative number of incidents, they remain
disproportionately affected by them. The $100B+ tier has experienced 620 times more incidents than the
number of megacorporations in this segment. Though the smallest firms experience the largest number of
incidents in absolute terms, only a fraction of them (0.53x) are actually affected.

Let’s turn next to frequency-based disparities among different industries. Since we’ve established the
importance of adjusting for the number of firms in each segment, we can skip to the punch line. Figure 5
groups sectors10 based on their relative event frequency.11

Figure 5: Relative number of incidents to number of firms in each sector (rolling 12mo. 2009-2024)

The Public and Management sectors are the only two that have historically exhibited a very high relative
incident frequency. For the former, we attribute that to mandatory disclosure requirements that typically
exceed those in the private sector.
IRIS 202 5 IT'S ABOUT TIME

10 Sectors throughout this report use the North American Industry Classification System (NAICS). Our labels are short versions of NAICS sectors—generally the first word of the
official sector name.
11 A multiple >1 indicates higher relative incident frequency based on the number of firms in a sector; <1 indicates the opposite (low relative frequency).

THE C YENTIA INSTITUTE CYENTIA .COM 9


The Management sector is a bit of an oddball
in NAICS, consisting mainly of holding
companies. We suspect part of what’s going
on here is that incidents affecting their
subsidiaries are being attributed to them as
the parent entity. Key Risk Insight
Moving to the upper-right panel, the Finance Incidents involving small and
sector has historically seen a high share of midsize businesses (SMBs) are far
incidents relative to the number of firms
more common overall, but the
that exist. But that rate has fallen over
relative incident frequency among
time, perhaps due in part to the industry’s
outsized security budgets. The Information
large enterprises is much higher.
sector continues to experience an elevated
incident rate, yet is currently well below its
high-water mark. Together, these industries
control money and data flowing through the
economy, so it’s no surprise they receive more
than their fair share of cyberattacks.

Energ y and supply chain


sectors are creeping up in
incident frequency—Utilities,
Mining, Manufacturing, and
Transpor tation are no longer
sitting safely below the line.

Industries with historically low relative


incident frequencies are split into two
groups—those likely to remain low for
the foreseeable future and those that will
soon cross over the line of demarcation.
We find it unsettling to see energy and
supply chain sectors such as Utilities,
Mining, Manufacturing, and Transportation
IRIS 202 5 IT'S ABOUT TIME

(which includes oil and gas pipelines in


NAICS) increasing in relative frequency. The
Professional sector has already crossed that
line, which is quite concerning given that they
offer advice and services to the rest of us.

THE C YENTIA INSTITUTE CYENTIA .COM 10


Q3 I S T H E PR O BA B I L I T Y O F
I N C I D E N T S I N C R E AS I N G?

This question may initially sound similar to the previous two, but those involved tallying the total number of
incidents reported across many organizations. Here, we explore how the likelihood of a single organization
having an incident is changing over time. If that nuance isn’t quite clear, think of it like this: what are the
chances your firm will suffer a significant incident this year?

We’ll begin by changing our perspective from the past to the future—except how the future was modeled in
the past… over time. Jeepers, this timey-wimey stuff is confusing, isn’t it? Maybe a chart will help; Figure 6
tracks the modeled probability12 of a typical organization13 experiencing an incident in the next 12 months.

It is understandable if cybersecurity folks can’t hold back an “I told you so!” here because overall incident
probability has almost quadrupled over the last 15 years. We could stop there, issue a press release, and
bid you adieu until the next installment, but we’re just getting started.

Roaring '20s
9.0% 9.3%
The probability
that a typical
Likelihood of at least one incident

8.0%
firm will
7.0% experience
Mid-'10s plateau a significant
6.0%
security incident
6.1% has almost
5.0%
quadrupled over
the last 15 years.
4.0%

3.0%
2.5%

2008 2012 2016 2020 2024


Source: IRIS 2025 (Cyentia Institute)
IRIS 202 5 IT'S ABOUT TIME

Figure 6: Historical probability of a firm having an incident in the next year

12 See appendix for details on our approach to modeling annualized incident probability.
13 We use “typical” to remind readers that this model doesn’t account for the many factors that would make incidents more
or less likely for a particular organization. We’ll look at some of those later.

THE C YENTIA INSTITUTE CYENTIA .COM 11


“But wait,” we hear you saying, “doesn’t the probability for different types
of cyber events change over time?”
You’re not wrong. We simply can’t cram everything into this one study.
New studies are always in the pipeline — we regularly publish extra analysis
like that on our website at [Link]/iris.

What if we told you that the probability of a <$100M firm suffering a security incident has more than doubled,
while the chance of a $100B+ megacorporation suffering an incident has dropped by a third over the same
time frame? Well, that’s exactly what Figure 7 tells us.

Figure 7: Annualized incident probability for firms in each revenue tier (rolling 12mo.)

Unfortunately, our dataset is silent on the underlying factors behind these trends, so all we can offer is some
IRIS 202 5 IT'S ABOUT TIME

speculation. Perhaps cybercriminals have shifted to more volume-oriented (“low-hanging fruit”) strategies
over time. Maybe the pace of digitalization has outpaced SMBs’ ability to defend their growing attack
surfaces, while the bigger enterprise security budgets offset that. Maybe increased regulatory pressures on
large corporations are gradually hardening enterprise security architectures. Whatever the cause(s), these
are important trends that are worth further research by our industry.

THE C YENTIA INSTITUTE CYENTIA .COM 12


So, an organization’s size matters when evaluating the likelihood of incidents. Now, let’s see what happens
when we treat industry as a feature of interest. Figure 8 paints that picture.

Allow us to briefly describe what you’re looking at. Sectors are sorted in descending order by the latest
probability estimate. So, a typical manufacturing firm has an 11% chance of having a security incident in
the next 12 months—up from ~2% 15 years ago.

We could spend oodles


12% 11.2% of time combing through
historical evidence behind
8% 7.3% the peaks and troughs
for certain industries, but
4% we’ll leave that to eager
Manufacturing Retail
readers. Suffice it to say that
0%
incident probability trends
12% 10.9% can be significantly different
depending on firmographics
8% (which are reflective of
Likelihood of at least one incident

6.8%
evolving business models,
4%
changes in the threat
Public Financial landscape, shifting adversary
0%
goals, etc.). That's intuitive,
12%
but perhaps seeing this
9.1%
confirmed will help validate
8%
the need to incorporate such
4.5% factors into your cyber risk
4%
assessments.
0%
Healthcare Utilities

12% Figure 8: Annualized incident


probability for firms in each
8.4%
8% sector (rolling 12mo.)

4.1%
4%

0%
Information Entertainment
'08 '10 '12 '14 '16 '18 '20 '22 '24 '08 '10 '12 '14 '16 '18 '20 '22 '24
Source: IRIS 2025 (Cyentia Institute) IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 13


Sorry to disappoint if you were hoping to
see updated versions of the old school IRIS
charts/tables for incident likelihood by sector
and revenue tier. Since this version of the IRIS
focuses on trends over time, Figures 7 and 8 Key Risk Insight
replaced those. But we recreated some of the
key figures and stuck them in Appendix C as a
Overall, the chances of any given
thank you to our loyal readers.
organization experiencing an
incident have gone up.

But that trend has flattened or


even reversed in some sectors
and size tiers.

Our analysis in this section


focuses on the likelihood of
experiencing at least one
security incident within a year.
It is possible, of course, for
organizations to suffer multiple
incidents, and veteran IRIS
readers may recall that we've
supplied probability tables for
two, three, or five incidents in a
12-month period.

We decided not to include that


in this edition because a) it's
already a long report, and b)
feedback suggested most cyber
risk models focused on single-
event likelihood. However, we
have not abandoned that concept
and will continue that research
outside of this study.
IRIS 202 5 IT'S ABOUT TIME

Visit [Link]/iris to
get additional analysis of multi-
incident probabilities.

THE C YENTIA INSTITUTE CYENTIA .COM 14


Q4 H AV E S E C U R I T Y I N C I D E N T S
G OT T E N M O R E C O S T LY?

We’ve covered the evolving frequency and likelihood of cyber events—now it’s time to talk dollars and cents.
Let’s begin by establishing the distribution of financial losses from cyber events using Figure 9, which
reproduces a classic IRIS chart with the latest and greatest data.14

$603K (median) $32M (95%)


$464K $14M
(Geometric mean) (mean)

$1K $10K $100K $1M $10M $100M $1B


Total losses
Source: IRIS 2025 (Cyentia Institute)

Figure 9: Distribution of reported losses for security incidents from 2015 to 2024

The typical (median15) incident costs about $600K, while more extreme (95th percentile) losses swell to $32
million. Note that Figure 9 is plotted on a log scale, so the tail of large losses is longer than it appears. If it’s
not too much to “shoulder,” also note the bump in the lower half of the distribution. We’ll explore that later.

NOTE: Losses analyzed in this study tend to reflect direct losses that are easier to quantify (e.g., response
costs or lost revenue) and/or identify from public records (e.g., class action suits or U.S. Securities and
Exchange Commission (SEC) filings). Indirect and intangible impacts often aren’t captured. Thus, this
IRIS 202 5 IT'S ABOUT TIME

represents a conservative view of financial losses associated with cyber events.

14 All loss amounts considered in this report have been converted to 2024 dollars to adjust for inflation.
15 Prior IRIS used the geometric mean for a typical loss. Since the growing “shoulder” in lower part of the distribution pulls the geomean down, the median is better central
measure for the updated distribution.

THE C YENTIA INSTITUTE CYENTIA .COM 15


An overall distribution like Figure 9 is useful for
$28.5M (4.75x)
illuminating the big picture, but it obscures any
90th
shifts in losses that may be happening over time. To
$6.0M visualize how the costs of cyber events have evolved,
$2.9M (15.20x) we’ll track two reference points—the median and
90th percentile—during the 15-year timeframe. The
results are shown in Figure 10.
50t h
Indeed, moving from a static distribution to a more
$189.9K
2008 2012 2016 2020 2024
dynamic view reveals some major shifts. Median
Source: IRIS 2025 (Cyentia Institute) losses from a security incident have absolutely
exploded over the last 15 years, rising 15-fold from
$190K to almost $3 million! The cost of extreme
Figure 10: Trend analysis of median and 90th events16 at the upper end of the distribution has also
percentile losses risen substantially (~5x). So, yeah—the financial toll of
cyber events is definitely getting bigger.
Losses (relative to firm revenue)

h
95t Having seen that, we imagine you’re anxious to see
117.23% (1.15x)
102.27% how these costs are trending for firms like yours.
While we can’t drill down quite that far, we can show
these loss distribution parameters for organizations
of different types and sizes. We’ll start with the latter.

0.65% (7.84x)
It’s a no-brainer that larger firms would experience
50th
larger losses, and we’ve shown that in prior studies.
0.08%
2008 2012 2016 2020 2024
We include Table 1 to reconfirm that fact and arm you
Source: IRIS 2025 (Cyentia Institute)
with the most recent stats to inform loss estimates
that are better sized to your organization. Note that
the size-based differences in loss magnitude are
Figure 11: Trend analysis of median and 95th
especially prominent for extreme (95th percentile)
percentile losses as a percent of revenue
events. There’s a longer tail for larger organizations.

That being said, a million-dollar loss is different


Loss percentile for a mom-and-pop shop versus a multinational
megacorporation. We need a way to normalize the
Revenue 50% 95%
relative impact to the firm. Measuring losses as a
More than $10B $2.2M $266.2M percentage of the victim firm’s annual revenue works
$1B to $10B $1.8M $61.8M well for this purpose.
$100M to $1B $466.7K $12.3M
Less than $100M $357.0K $9.1M Median losses fall well below 1% of revenue for the
Source: IRIS 2025 (Cyentia Institute) majority of incidents. But as Figure 11 attests, that
IRIS 202 5 IT'S ABOUT TIME

ratio has grown by nearly 8x over the last 15 years.


Table 1: Loss statistics by revenue tier The top 5% of loss events continue to exceed the
annual revenue of affected firms.

16 You may notice that we switch between the 95th and 90th percentile for losses to represent the concept of extreme events. We generally use the 95th for long, fixed time periods.
However, we found that in the specific context of time series models, data availability in the tails wax & wane such that estimates of the 95th percentile became unreliable. Using
the 90th percentile is merely a small concession in consistency to ensure that we're confident that the percentile is being estimated reliably.

THE C YENTIA INSTITUTE CYENTIA .COM 16


We’ll now briefly demonstrate that industry makes
Education a difference too. Rather than a plot crammed with
$5.4M (1.53x) all 20 NAICS sectors, we’ve done some pre-screening
$3.5M 90th
to highlight three industries that represent distinct
rising, flat, and falling trends that we see across all
sectors.17

When it comes to the escalating costs of security


$243.4K (1.06x)
incidents, no industry has been hit as hard as
$229.4K 50th
2008 2012 2016 2020 2024 Professional Services. Median losses for firms in
Source: IRIS 2025 (Cyentia Institute) that sector are up 25x over the last 15 years! Top
end (90th percentile) costs have seen a nearly four-
fold increase too. The Administrative, Financial,
Professional Healthcare, Manufacturing, and Public sectors also
$21.1M (3.72x)
exhibit increasing trends for loss magnitude.
90th
$5.7M
Event losses in the Education sector show a fairly
$1.5M (25.71x)
steady, albeit increasing, trajectory over the years.
Perhaps a side effect of the “ivory tower” insulating
50th it from cyber risk trends experienced by the rest of
$58.5K
the world?
2008 2012 2016 2020 2024
Source: IRIS 2025 (Cyentia Institute) And then there’s the Retail sector, which seems to
have figured out a way to cut the price tag of a security
incident. Current losses for both typical and extreme
Retail
events are a fraction of their starting points in 2008.
$147.1M

90th
That deserves an entire study of its own, but
$6.5M
we suspect the push for Payment Card Industry
$6.0M (0.04x)
(PCI) compliance and the rollout of Chip-and-
50th
Pin technology may have helped to limit the
amount of data that can be easily exfiltrated from
$142.3K (0.02x) retailers. Since larger breaches generally (but
2008 2012 2016 2020 2024 not linearly18) correspond with higher losses, this
Source: IRIS 2025 (Cyentia Institute) would help cap potential losses. But Retail is not
alone; Information Services and Management
firms also show declining loss distributions.
Figure 12: Trend analysis of median and 90th
percentile event losses for example sectors.
IRIS 202 5 IT'S ABOUT TIME

17 Don’t fret if your favorite sector is missing. Appendix C includes a table that gives median and extreme loss values for all sectors similar to the IRIS 2022.
18 Prior IRIS have conclusively demonstrated that losses do not follow a flat cost-per-record formula.

THE C YENTIA INSTITUTE CYENTIA .COM 17


For a seemingly simple leading question,
this section contains many "Yes, if..." and
"No, but..." answers. A quick recap of
what we've learned would be helpful:

- Overall, security incidents have


indeed gotten more costly. Key Risk Insight
- Losses relative to the affected firm's Not only do typical security
annual revenue have also grown. incidents cost more these days
(up 15x since 2008)—they hur t
- The absolute cost of incidents is higher a lot more too (up 8x relative to
in large organizations, but the relative annual revenue).
impact is worse for smaller businesses.

The magnitude and directionality of loss


trends differ substantially by sector.

Don't see your sector listed here


among the three examples we
chose?

Don' t despair because we've


done the analysis!

We just couldn't squeeze all the


charts into the pages of this
study.

You can get a version of these


cyber loss trendlines for your
sector from the IRIS page on our
website at [Link]/iris.

Sectors Include:

• Financial
IRIS 202 5 IT'S ABOUT TIME

• Healthcare
• Hospitality
• Transportation
• And more!

THE C YENTIA INSTITUTE CYENTIA .COM 18


Q5 D O LO S S T R E N D S D I F F E R
A M O N G E V E N T T Y PE S ?

Remember how we said to pay attention to the overall shape of the distribution in Figure 9 at the beginning
of the last section? If not, feel free to jump back and refresh your memory. We’ll wait.

We weren’t pulling one of your lower extremities when we said that would be important. There is a
pronounced “shoulder” in the lower half of the distribution. Whenever a bimodal tendency like this exists
in a distribution, it’s worth investigating what’s behind it. So, we did—and discovered that the shoulder has
grown over time, as evidenced by Figure 13.

No shoulder

2008-2017

2009-2018

2010-2019

2011-2020

2012-2021

2013-2022 Pronounced shoulder

2014-2023

2015-2024
$1K $10K $100K $1M $10M $100M $1B
Losses
Source: IRIS 2025 (Cyentia Institute)

Figure 13: Ridge plot showing loss distribution shape in successive 10-year windows

The reason we’re belaboring this technical detail is that it turns out the underlying cause highlights the
importance of distinguishing different types of incidents when assessing loss magnitude. Note what
happens when we plot separate loss distributions for each of our incident patterns in Figure 14.
IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 19


We can now see that the shoulder in the overall loss distribution actually results from a proliferation of
fairly small losses from accidental disclosure events. Incidents tied to physical threats and insider misuse
also contribute to lower losses, but those patterns are considerably less common.

Median

95th percentile

DoS/System failure

Ransomware

System intrusion

Scam or fraud

Physical threat

Insider misuse

Accidental disclosure
$1K $10K $100K $1M $10M $100M $1B
Losses
Source: IRIS 2025 (Cyentia Institute)

Figure 14: Distribution of reported losses by incident pattern (2008 to 2024)

A possible explanation is that the growing shoulder reflects the rollout of regulations over the years that
require public disclosure of even relatively minor data loss events. Thus, comparing loss trends specific to
these different incident patterns could provide helpful context. We do just that in Figure 15.

The trends seen here support our hypothesis.


Losses stemming from accidental disclosure
and insider misuse have indeed declined
over time, particularly for run-of-the-mill
While ransomware losses surge
events (now just 5% of median cost in 2008).
past $27M at the high end, top-
tier system intrusions have
dropped sharply—down to $7.4M
from over $200M. IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 20


Conversely, the median loss magnitude for
system intrusion and ransomware incidents
has risen, with the latter ballooning 20-fold!

The decline in costs associated with system


intrusions at the top end of the distribution is Key Risk Insight
both dramatic and curious. The interpretation
is clear, though: The biggest intrusions Both the magnitude and trend
nowadays are significantly less expensive
of losses from security incidents
than they used to be.
depend heavily on the type of
event. This suppor ts the need for
risk scenarios to specif y threats
Accidental disclosure/Insider misuse
$2.3M 90th $1.6M (0.68x)

$150.2K 50th

$6.9K (0.05x)
2008 2012 2016 2020 2024

System intrusion
$221.3M

90t h
$7.4M (0.03x)

$1.3M (1.97x)
$645.0K 50th
2008 2012 2016 2020 2024

Ransomware
$27.6M (5.52x)
90th
$5.0M
$3.2M (20.49x)

50t h
$155.5K
2008 2012 2016 2020 2024
Source: IRIS 2025 (Cyentia Institute)

Figure 15: Trend analysis of median and


90th percentile losses by incident pattern
IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 21


Q6 ARE INTRUSION METHODS
C H A N G I N G OV E R T I M E ?

Let’s say for a moment that the probability and loss estimates for your own organization mirror some of the
upswings observed in prior sections. Assuming that trend is climbing above your risk tolerance, you’ll want
to do something to flatten the curve. But what?

Choosing the best risk treatment strategy has never been easy and likely never will be. But organizations
make those decisions even harder when they attempt to jump all the way from high-level assessments
down to specific measures to mitigate risk. Discerning whether BlinkyBox1 vs. BestPractice2 vs. the latest
[enter acronym] solution is the most effective option strongly depends on the maturity of your security
program and the particular threats driving your risk exposure upward.

That’s why tracking common adversary


tactics, techniques, and procedures (TTPs)
behind cyber events can bridge the divide
between risk assessments and risk treatment.
MITRE ATT&CK offers a knowledge base of Tracking adversar y tactics,
TTPs that is convenient for this purpose. techniques and proceduers
Cyentia uses a combination of methods to (TTPs) is the missing link
identify ATT&CK techniques associated with that connects high-level risk
incidents, and we’ll use those capabilities assessments to effective action.
here to explore the titular question.

IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 22


1st Valid Accounts 57% 60% 54% 43% 46% Valid Accounts

Exploit
2nd Hardware Additions 35% 31% 29% 38% 34% Public-Facing
Application

Replication Through 30% 29% 19% 35% 28% Phishing


3rd Removable Media

4th Phishing 18% 25% 16% 30% 12% Trusted Relationship

5th Trusted Relationship 12% 16% 15% 15% 10% Hardware Additions

Exploit
6th Public-Facing 5% 5% 14% 9% 10% External
Services
Remote
Application

External Remote <1% <1% 8% 8% 9% Replication Through


7th Services Removable Media

8th Drive-by Compromise <1% <1% 5% 1% 1% Drive-by Compromise

Supply Chain <1% <1% <1% <1% <1% Supply Chain


9th Compromise Compromise

2016 2018 2020 2022 2024


Source: IRIS 2025 (Cyentia Institute)

Figure 16: Prevalence of ATT&CK Initial Access techniques observed in incidents over time

Figure 16 presents trends in ATT&CK Initial Access techniques observed over the last nine years, according
to the percentage of incidents19 associated with each. Overall, the shifts seen here largely reflect the
never-ending cat-and-mouse game played between attackers and defenders. A few trends are particularly
noteworthy.

Cyber threats are ever-changing, which makes it even more remarkable when TTPs don’t change all that
much. Using Valid Accounts to gain illicit access (e.g., by compromising user credentials) has held the pole
position for the entire time period. Phishing—a popular means of obtaining those credentials—has also
consistently ranked among the top techniques. To be fair, there are many different schemes by which
attackers abuse user accounts as well as many sub-techniques for phishing. But that doesn’t change the
overall lesson here regarding the longevity of these methods.

The “moving-up-the-charts” award among intrusion methods goes to Exploit Public-Facing Applications
(i.e., web application attacks) and External Remote Services (i.e., misconfigured remote access tools).
IRIS 202 5 IT'S ABOUT TIME

Both techniques have surged from single-digit percentages to heights of 38% and 30%, respectively. This
likely reflects the expansion of enterprise attack surfaces over the last decade. These external points of
presence are intended to serve customers, third parties, and remote employees, but attackers increasingly
take advantage of them as well.

19 Percentages are based on incidents for which at least one ATT&CK technique was identified.

THE C YENTIA INSTITUTE CYENTIA .COM 23


Recent Cyentia Institute studies have found that 99% of Global 2000 companies are connected to vendors
that have had recent breaches20 and that 90% of organizations consider third-party risk management a
growing priority.21 Those concerns appear to have merit, based on the persistence of actors leveraging
Trusted Relationships with external service providers to compromise target organizations. Though third-
party risk and Supply Chain Compromise events are often referred to interchangeably, MITRE has a more
narrow definition for the latter that’s relatively rare among publicly known incidents.

On the topic of evolving threat actor


strategies, we noticed an interesting trend
Web app exploits and remote when analyzing initial access techniques
access misconfigurations rise among organizations of varying sizes. At
from single digits to 38% and 30% a high level, one could rightly infer that
of intrusions. attackers use similar techniques regardless
of the size of the target entity. Valid Accounts
is firmly on top for all three size tiers, and the
others are similarly clustered below that.

But upon closer inspection, interesting variations become apparent. Abusing Valid Accounts is trending
down over the last few years for organizations below $10B in annual revenue, but rising sharply for
the largest corporations. Phishing and exploiting applications are most prevalent among incidents
affecting smaller firms (<$100M) and progressively less in higher revenue tiers. Attacks targeting Trusted
Relationships disproportionately affect larger organizations, which makes sense given their extensive
portfolio of third-party vendors.

Want more AT T&CKif ication


of incident s and losses?
Here are two Cyentia resources:
MULTI-SOURCE ANALYSIS OF TOP MITRE ATT&CK TECHNIQUES
(WITH TIDAL CYBER)
INFORMATION RISK INSIGHTS STUDY RANSOMWARE
EDITION (SPONSORED BY CISA)

Cyentia is also currently working on an update to the


IRIS 20/20 “Xtreme” that analyzed the largest incidents
from 2015-2019. The prior report did not incorporate
IRIS 202 5 IT'S ABOUT TIME

ATT&CK, but the next iteration most definitely will.


So, if you want to learn more about TTPs behind the
biggest loss events of the last five years, keep an eye
on the IRIS site for updates on that study.

THE C YENTIA INSTITUTE CYENTIA .COM 24


Less than $100M $100M to $10B More than $10B

60%

50%
Percent of incidents

40%

30%

20%

10%

2016 2018 2020 2022 2024 2016 2018 2020 2022 2024 2016 2018 2020 2022 2024

Exploit Public-Facing Application Trusted Relationship

Phishing Valid Accounts

Source: IRIS 2025 (Cyentia Institute)

Figure 17: Prevalence of ATT&CK Initial Access techniques observed by revenue tier

These seemingly contradictory takeaways are reasonable based on the historical attack trends specific to
each class of organizations. The point is that the adversary TTPs trending for *waves hand* them aren’t
necessarily the ones shaping your risk posture.

We’ll close with a reminder that Initial Access is only one of more than a dozen tactics in MITRE ATT&CK.
While trending techniques within each tactic are possible, this is already a long report, and we have one
last question we’d like to explore.

IRIS 202 5 IT'S ABOUT TIME

20 Global 2000: Industry Titans Battle the Beast of Supply Chain Cyber Risk (with SecurityScorecard).
21 The State of Third-Party Risk Management (with RiskRecon).

THE C YENTIA INSTITUTE CYENTIA .COM 25


Q7 W H AT A R E W E M I S S I N G
F RO M C U R R E N T E V E N T S ?

Since the beginning of the IRIS series, we’ve tried to be open about the shortcomings and potential biases
in our dataset of publicly reported incidents. One point often mentioned is the reporting lag that stems
from the time it takes for details to make their way into the public record.22 Another is that some types of
cyber events (or attack details) are underrepresented because they don’t have immediate visible impacts
or don’t trigger mandatory disclosure laws. That’s why we’re especially grateful to Feedly, a real-time threat
graph, for allowing us to analyze cyberattacks collected via their intelligence capabilities for this section.

To derive the Feedly data analyzed in this study, we started with events identified by Feedly’s Cyber Attacks
AI model from 2024. The model was developed by Feedly to discover and research emerging threats, which
makes it more of an “ear-to-the-ground” signal of current cyber events than our historical loss database.

We’ll state up front that this isn’t an attempt to determine who’s right and who’s wrong. As the lead question
implies, we’re concerned with what our core incident dataset might be missing from recent media coverage
that hasn’t yet made (and may never make) it into the official public record.

With that in mind, let’s get to it!


Roaring '20s Feedly Q4
3,500

3,000 Mid-'10s plateau

2,500
Number of incidents

2,000

1,500

1,000

500
IRIS 202 5 IT'S ABOUT TIME

0
2008 2010 2012 2014 2016 2018 2020 2022 2024
Source: IRIS 2025 (Cyentia Institute)

Figure 18: Number of security incidents publicly reported or discovered each quarter. Feedly was used for
incident discovery in Q4-2024 to compensate for the lag in the historical dataset.
22 This is why many charts in this report show an apparent downturn in 2024; we’ll still be learning of 2024 incidents long after this report is published in 2025.

THE C YENTIA INSTITUTE CYENTIA .COM 26


Remember that apparent Q4-2024 dip in security incidents back in Figure 1? It’s not real. Figure 18 plainly
shows that the 3,500+ incidents observed by Feedly during that timeframe fill the hole in our base historical
dataset. This corroborates our suspicion of a reporting time lag rather than a drop in frequency. It also
emphasizes the need for more real-time tracking of incidents if your risk analysis relies on near-term trends.

It’s worth noting that the incidents in both datasets show a similar representation of affected industries.
Each attributes the highest number of events to Healthcare and Finance. Feedly rounds out the top three
with the Public sector, while our data has Professional Services in third place (Public is #4). That’s a good
indication that the comparisons in this section are based on samples that are reasonably similar in nature.

Speaking of near-term trends, you may have noticed that we rarely include analysis of the latest threat actor
campaigns in the IRIS series. That’s partially due to our focus on risk management vs. threat intelligence.
But it’s also because public disclosures and filings that comprise our dataset usually don’t delve into
attribution. Media outlets, on the other hand, love a good “whodunnit?” story, and Feedly… well… feeds
off those stories.

Table 2 lists the top three threat actors behind the most incidents affecting the Finance, Healthcare, and
Public sectors, according to Feedly’s collections during 2024. Since this isn’t a threat intel report, we won’t
dive into the backstory of these groups—other resources are better suited to that. We include this simply to
make the point that adversaries often have unique goals and targets. Keep that in mind if you’re looking to
incorporate specific threat actors into your risk scenarios and assessments.

FINANCE HEALTHCARE PUBLIC

Lazarus Group Alpha Spider GhostEmperor

Shiny Hunters RansomHub Volt Typhoon

RansomHub Vanilla Tempest Flax Typhoon

Table 2: Top threat actors associated with 2024 security incidents by sector (via Feedly)

It’s hard to talk about threat actors without the conversation turning to the TTPs they use. So, let’s go there
next. Table 3 lists the top five ATT&CK techniques observed by Feedly and two different date ranges for our
historical incident dataset. We do that to enable comparisons based on both time period and source.
IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 27


All sources place Valid Accounts and Phishing in the top three spots, albeit in varied order. This further
substantiates these techniques as primary attack vectors for treating risk exposure. There’s also relative
agreement for several techniques that land in the middle of the pack. Beyond that, there are some notable
differences between the two sources.

We chalk the disparity around the ranking of Trusted Relationship primarily up to Cyentia’s classification
choices. MITRE’s definition strictly refers to external third parties for that technique, while we traditionally
broaden it to also apply to certain types of insider and contractor misuse. We plan to revisit this in the
future in light of MITRE’s Insider Threat TTP Knowledge Base project.

Frequency of MITRE ATT&CK Initital Access Techniques


Top ATT&CK initial access techniques identified by Cyentia (2014-2023 & 2024) and Feedly (2024)
Name Cyentia (2014-2023) Cyentia (2024) Feedly
Phishing (T1566) 2nd 3rd 1st
Valid Accounts (T1078) 1st 1st 2nd
Exploit Public-Facing Application (T1190) 6th 2nd 6th
Supply Chain Compromise (T1195) 9th 9th 3rd
Hardware Additions (T1200) 3rd 5th -
Drive-by Compromise (T1189) 8th 8th 4th
Replication Through Removable Media (T1091) 4th 7th 7th
Trusted Relationship (T1199) 5th 4th -
External Remote Services (T1133) 7th 6th 5th
Source: IRIS 2025 (Cyentia Institute)
Table 3: Comparison of top ATT&CK Initial Access techniques observed in incidents by source

The disparate ranking of Hardware Additions is threefold. First, that technique was much more prevalent
among incidents a decade ago, but has been declining ever since (see Figure 16). Second, even in
its heyday, this technique was mostly related to skimmers added to payment terminals rather than
network taps and other more advanced threat scenarios that ATT&CK seems to have in view. Third, this
technique tends to be a bit “in the weeds” for media coverage of events and is described in ways that
maket echnique extraction difficult.

IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 28


The relative prominence of Supply Chain Compromise in Feedly’s collections is very interesting to us
because very few public incident disclosures list this as an initial access technique (see Figure 16, where
it’s always in a distant last place).

We suspect one of the key reasons for this disparity is that supply chain security is hot of late, and media
outlets are more motivated to dig for such details than companies are to include them in official reports.
The aforementioned time lag of incident disclosure could be another factor; perhaps details will soon
emerge that retroactively bump this technique higher in recent years. Thus, Feedly’s collections may grant
a forward-looking, headline-driven view of the most common techniques, while our legacy data offers
more of an actuarial perspective. Both views are informative for assessing risk and developing mitigation
strategies.

Last but not least, we’ll examine a comparison of reported


financial losses in Figure 19. The statistics for the 10-year
and 2024 views of losses in our dataset are relatively
comparable. The loss magnitude of events identified by
Feedly-sourced cyber
Feedly in 2024, however, reveals major differences.
events show a median
loss of $28.5M—30
Note first that Feedly contains more 2024 events with times higher than the
identified financial losses than we found in our core data historical median.
source. This further corroborates the utility of monitoring
current events to help compensate for the reporting lag in
risk data.

The median loss for Feedly-sourced cyber events stands at $28.5M, which is 30x higher than that of our
historical dataset ($603K). The 95th percentile for the two sources shows a disparity of almost $750M!

Typical Extreme

Cyentia 2014-2023 $603K $31.6M

Cyentia 2024 $950K $40.6M

Feedly 2024 $28.5M $786.9M


IRIS 202 5 IT'S ABOUT TIME

$1K $10K $100K $1M $10M $100M $1B


Source: IRIS 2025 (Cyentia Institute)

Figure 19: Comparison of reported financial losses from incidents by source

THE C YENTIA INSTITUTE CYENTIA .COM 29


Much of what we see (or don’t see) here goes
back to sourcing methods. The primary source
of our historical loss data, Zywave, has a strong
focus on the insurance and reinsurance market.
They’re diligent in gathering datapoints on all
aspects of losses, both large and small. Minor Key Risk Insight
loss events might be interesting to insurers
managing risk across a large portfolio of
If your cyber risk analysis relies
organizations, but media outlets tend to focus
on major breaches or disruptions. Since such
on near-term trends, consider
events rarely go unnoticed, they’re ripe for incorporating sources that
open-source intel collection. If you’re focused emphasize current events to
on tail risk—which is what many execs are supplement historical event data.
most concerned with—closely tracking these
mega-loss events is essential.

One of my favorite
things about my time
on Verizon's DBIR
team was working
with the scores
of external organizations
that contribute data for
analysis in that report. It's
something I'm glad we've
been able to continue in our
research at Cyentia.

I'm grateful to all our data


partners and sponsors who
make it possible for us to do
impactful research for the
community. Reach out if
you have data that would
IRIS 202 5 IT'S ABOUT TIME

unlock new avenues of cyber


risk analysis!

~ Wade Baker PhD


Co- Founder | The Cyentia Insitute

THE C YENTIA INSTITUTE CYENTIA .COM 30


A1 M E T H O D O LO GY

Data Collection

The IRIS research draws heavily upon Zywave’s Cyber Loss Data, which contains over 150,000 security
incidents and associated losses spanning decades. The data is compiled from publicly available sources,
such as breach disclosures, company filings, litigation details, and Freedom of Information Act requests. It
is the most comprehensive source of cybersecurity incidents and losses available.

That said, we’re not claiming this dataset is all-inclusive. We can only analyze incidents that make their
way into the public record through outward signs or impacts, mandatory reporting, voluntary disclosure,
etc. That’s not all the events that occurred over the timeframe, of course, but we have high confidence that
significant cyber events are well represented.

Additionally, Cyentia does extensive processing of Zywave’s base dataset to extend and enrich it for
cyber risk analysis use cases. This is done using a combination of classification models, natural language
processing (NLP), taxonomy mapping, malware behavioral analysis, and manual tagging by our analysts.

Incident and loss data collected by Feedly is used for the last section to study trends we might be missing
from current events. We started with 2024 events identified by Feedly’s Cyber Attacks AI model. We further
refined this by focusing on “memes,” which is Feedly’s method of clustering articles and information on a
trending topic. The point is that we’re not simply counting articles in this analysis. Finally, we reviewed the
identified events to train a classification model to distinguish successful incidents affecting organizations
from other threats and trends that aren’t comparable to our core dataset.

GOT DATA FOR THE NEXT IRIS?


If you have information on security incidents
and losses and might be willing to contribute
anonymized data for analysis in a future IRIS,
please reach out! We’re especially keen to
incorporate insights from cyber insurance
IRIS 202 5 IT'S ABOUT TIME

claims and incident response investigations.

THE C YENTIA INSTITUTE CYENTIA .COM 31


Incident Likelihood

Though we don’t delve into it in this edition, readers of prior IRIS may recall that we have modeled the
frequency of security incidents over a fixed 10 year time period, allowing for the fact that organizations can
have more than one in a single year. We took the same approach in this edition, expanding the model to
include a time component. Ultimately, we present estimates as the annual probability of an organization
experiencing at least one event.

To do this, we divide our historical dataset into 12-month rolling windows and count the number of incidents
for each organization. This gives us a large number of observations that allow us to more confidently model
the annualized loss event frequency.

We then treat these observations as samples from an underlying probability distribution and use random
effects models to estimate the parameters both overall and within specific slices like industry and revenue
bands over time. The result is a closed-form representation of the probability that an organization will
experience a certain number of incidents in a given year that can change over time.

Additionally, in prior IRIS reports we reported both upper and lower bound estimates for incident likelihood.
We’ve dropped that distinction in this edition in favor of exclusively using the more risk-averse upper bound
estimate.

In a nutshell, the difference between these approaches stems from the count of organizations used as the
denominator for the calculation. We don’t know how many exist throughout the world, so the upper bound
uses the total number of organizations that exist in our historical incident database. While it’s true that this
approach excludes some extremely secure or lucky firms, the fact is that those prone to incidents in the
future have probably had one at some point in the past. The result is a more conservative estimate that we
believe is more suitable for risk management.

Financial Losses

Financial losses tend to be less reported than other data points for cyber events. There are many reasons
for this, but the result is that the majority of incidents in our dataset do not include anything about losses.
Those that do tend to reflect direct losses that are easier to quantify (e.g., response costs or lost revenue)
and/or identify from public records (e.g., class action suits or SEC filings). Indirect and intangible impacts
usually aren’t captured.

The good news, from a data standpoint, is that the record of losses from major security incidents—like
those we analyze in this study—is more complete than for minor events due to increased visibility and
reporting. Thus, we hold that our loss dataset is sufficient to form a well-supported model of cyber events
IRIS 202 5 IT'S ABOUT TIME

over the last 15 years.

Note that all financial loss values presented in this report have been adjusted for inflation.

THE C YENTIA INSTITUTE CYENTIA .COM 32


A2 I N C I D E N T PAT T E R N
DEFINITIONS

All security incidents in our historical dataset are assigned one of these mutually exclusive23 patterns using
a combination of natural language processing techniques and human expert assessment.

ACCIDENTAL DISCLOSURE: Data stores that are inadvertently left accessible to


unauthorized parties, typically through misconfigurations on the part of the data custodian.

DOS ATTACK: Any attack intended to render online systems, applications, or networks
unavailable, typically by consuming processing or bandwidth resources.

DEFACEMENT: Any unauthorized content modification to an organization’s website or


other online assets.

FRAUD OR SCAM: Any incident that primarily employs various forms of deception to
defraud the victim of money, property, identity, information, and so on.

INSIDER MISUSE: Inappropriate use of privileged access, either by an organization’s own


employees and contractors or a trusted third party.

PHYSICAL THREATS: Threats that occur via a physical vector, such as device tampering,
snooping, theft, loss, sabotage, and assault.

RANSOMWARE: A broad family of malware that seeks to encrypt data with the promise to
unlock upon payment or seeks to completely eradicate data/systems without the pretense
of collecting payment.

SYSTEM FAILURE: All unintentional service disruptions resulting from system, application,
or network malfunctions or environmental hazards.

SYSTEM INTRUSION: All attempts to compromise systems, applications, or networks by


IRIS 202 5 IT'S ABOUT TIME

subverting logical access controls, elevating privileges, deploying malware, and so on.

23 Yes, it’s true that an incident could involve more than one of these (e.g., system intrusion and ransomware). However, the purpose of these patterns is to represent the primary
nature of the event.

THE C YENTIA INSTITUTE CYENTIA .COM 33


A3 C H A R T S & TA B L E S F R O M
PR I O R I R I S S T U D I E S

This appendix contains up-to-date versions of selected figures from IRIS 2022 that provide probability and
loss comparisons among sectors and revenue bands. If there are other figures you'd like to see from an IRIS
of yesteryear, let us know!

Education (1.60x)
Information (1.55x)
Professional (1.50x)
Financial (1.44x)
Healthcare (1.34x)
Public (1.34x)
Retail (1.19x)
Hospitality (1.15x)
Management (1.08x)
Manufacturing (1.03x)
Trade (0.97x)
Entertainment (0.94x)
Relative to median sector

Real Estate (0.93x)


Administrative (0.92x)
Agriculture (0.92x)
Other (0.92x)
Construction (0.91x)
Transportation (0.78x)
Mining (0.76x)
Utilities (0.62x)

Source: IRIS 2025 (Cyentia Institute)

Figure A1: Relative probability of one or more loss events among sectors (Figure 5 in IRIS 2022). The point
of comparison is the overall median across all organizations.

More than $100B (3.46x)


$10B to $100B (2.49x)
$1B to $10B (1.20x)
$100M to $1B (0.80x)
$10M to $100M (0.67x)
Less than $10M (0.60x)
IRIS 202 5 IT'S ABOUT TIME

Source: IRIS 2025 (Cyentia Institute)

Figure A2: Relative probability of one or more loss events among annual revenue tiers. The point of
comparison is the overall median across all organizations.

THE C YENTIA INSTITUTE CYENTIA .COM 34


Education $226K $249K $6M
Entertainment $147K $282K $12M
Financial $951K $1M $194M
Healthcare $524K $557K $14M
Hospitality $687K $600K $62M
Losses observed per sector Losses observed
Information per sector
$783K $718K $217M
Sector Geometric mean Median 95th percentile Sector
Management Geometric mean Median
$343K $332K 95th percentile
$140M
Administrative $318K $529K $31M Manufacturing
Administrative $1M $529K
$318K $1M $42M
$31M
Agriculture $1M $2M $3M Mining
Agriculture $1M $1M $2M $2M
$3M
Construction $164K $189K Other services
$5M Construction $262K
$164K $189K$348K $41M
$5M
Education $226K $249K $6M Professional
Education $400K
$226K $736K$249K $17M
$6M
Entertainment $147K $282K $12M Public
Entertainment $234K
$147K $214K$282K $18M
$12M
Financial $951K $1M $194M Real Estate
Financial $244K
$951K $236K $1M $2M
$194M
Healthcare $524K $557K $14M Retail
Healthcare $872K
$524K $746K$557K $45M
$14M
Hospitality $687K $600K $62M Trade
Hospitality $902K
$687K $600K $1M $23M
$62M
Information $783K $718K $217M Transportation
Information $286K
$783K $490K$718K $23M
$217M
Management $343K $332K $140M Utilities
Management $113K
$343K $146K$332K $3M
$140M
Manufacturing $1M $1M $42M Manufacturing $1M IRIS$1M
Source: $42M
2025 (Cyentia Institute)
Mining $1M $1M $2M Mining $1M $1M $2M
Other services
Figure A3: Loss$262K $348Ksummary statistics
magnitude $41M Other services
by sector $262K
(Table 4 in IRIS 2022)$348K $41M
Professional $400K $736K $17M Professional $400K $736K $17M
Public $234K $214K $18M Public $234K $214K $18M
Real Estate $244K $236K $2M Real Estate Typical
$244K $236K
Extreme
$2M
Retail
More than $100B
$872K $746K $45M Retail $6M $872K $259M$746K $45M
Trade $902K $1M $23M Trade $902K $1M $23M
Transportation $286K $490K $23M Transportation $286K $490K $23M
Utilities
$10B to $100B $113K $146K $3M Utilities
$2M $113K $146K
$271M $3M
Source: IRIS 2025 (Cyentia Institute) Source: IRIS 2025 (Cyentia Institute)
$1B to $10B $2M $57M

$100M to $1B $446K $12M

$10M to $100M $325K $7M

Less than $10M $412K $11M

$1K $10K $100K $1M $10M $100M $1B


Source: IRIS 2025 (Cyentia Institute)

Figure A4: Distribution of reported cyber event losses by annual revenue of affected firms (Figure 7 in IRIS
2022)
IRIS 202 5 IT'S ABOUT TIME

THE C YENTIA INSTITUTE CYENTIA .COM 35


THE CYENTIA INSTITUTE IS A WIDELY-RESPECTED, RESEARCH AND DATA SCIENCE FIRM
WORKING TO ADVANCE CYBERSECURITY KNOWLEDGE AND PRACTICE.

We accomplish that goal through collaborative research publications like the


IRIS series and analytic services that help our clients manage cyber risk.
Visit [Link] for more information.

You might also like