← Back to blog

What a US data breach really costs (CCPA to SEC)

· TinyX · 5 min read

What a US data breach really costs (CCPA to SEC)

When a U.S. company leaks data, the public sees the headline and a year of credit monitoring. What finance and the board see is a longer bill: forensics, multi-state notification, class-action exposure, harder insurance renewals — and, for public companies, a four-business-day disclosure clock.

IBM's Cost of a Data Breach Report 2025 puts a hard number on that shadow. In the United States, it is not the global average.

The U.S. number that actually matters

The 2025 global average cost of a data breach fell 9% year over year, from $4.88 million to $4.44 million. The United States moved the other way. The U.S. average hit a record $10.22 million, driven by higher regulatory fines and detection costs. Healthcare remained the costliest industry studied, at $7.42 million per breach.

That total is not just IT overtime. IBM breaks it into detection and escalation, notification, post-breach response, and lost business. Lost business is often the largest share: customers leave, renewals stall, and procurement starts asking harder questions about how you handle files.

Lifecycle still matters. The 2025 global average time to identify and contain a breach fell to 241 days — roughly eight months of exposure and follow-up. Organizations that used security automation extensively shortened that lifecycle by about 80 days and saved roughly $1.9 million versus those that did not.

In the first 72 hours the costs are visceral: forensic firms, outside counsel, a war room, systems taken offline. For a retailer that can mean card rails that stop. For a manufacturer it can mean a line paused because the industrial network cannot be trusted.

A mosaic, not one federal privacy law

There is no single U.S. federal privacy statute equivalent to GDPR. The mosaic is still expensive.

All 50 states (plus D.C. and several territories) have breach-notification statutes. Most demand notice in the most expedient time possible — often 30 to 90 days. Running a multi-state notification program under legal review is its own project, with credit monitoring, call centers, and counsel on the clock.

California adds two sharp edges under CCPA/CPRA. Regulators can pursue civil penalties on the order of $2,500 per unintentional violation and $7,500 per intentional one (amounts are inflation-adjusted). Separately, Californians have a limited private right of action for certain breaches of non-encrypted, non-redacted personal information, with statutory damages around $100–$750 per consumer per incident. At 100,000 records, that is class-action math measured in tens of millions.

Encryption is not a cure-all. Under CCPA's private right of action, and in many notification analyses, non-encrypted or non-redacted data is what triggers the sharpest exposure. A stolen file that arrives with intact key custody is a different event from a cleartext dump.

Cases that still set expectations

  • T-Mobile (2021). After a breach affecting tens of millions of people, T-Mobile agreed to a $350 million class settlement plus a $150 million incremental security spend commitment (SEC 8-K).
  • Anthem. After the 2014–15 breach of about 79 million records, Anthem paid $16 million to HHS OCR (2018) and later $39.5 million in a multistate AG settlement (2020).
  • Equifax (2017). Cumulative breach costs have been reported above $1.4 billion, including a global settlement with the FTC, CFPB, and states of at least $575 million (up to $700 million if claims exhausted the fund) — see the FTC announcement.

These are not edge cases. They are the reference points plaintiffs' firms, insurers, and boards still use when sizing exposure.

The SEC 8-K clock

Public companies face another timer. Since December 2023, the SEC cyber disclosure rules require a Form 8-K for a material cybersecurity incident within four business days of determining materiality. Late or misleading disclosure can turn a security incident into a securities investigation. Plaintiffs' firms often file within days of an 8-K. Even when a case is dismissed, defense costs are substantial.

Costs that never show up on a purchase order

Fines and forensics are quantifiable. The deeper costs are reputational and strategic: customer trust, defense counsel, harder cyber-insurance renewals after a claim, and engineering teams diverted into remediation for quarters.

That is why the budget conversation should not start with "what did IBM say globally." For U.S. operators, start with $10.22 million, then layer state clocks, CCPA class-action math, and — if you are public — the 8-K path.

Three circles, one U.S. budget conversation

Think of breach cost as three concentric circles.

  1. Inner circle — containable costs. Incident-response retainers, logging, backup tests, data minimization, and how you move files when someone outside the company needs them. Relatively cheap. High return.
  2. Middle circle — regulatory and litigation costs. Multi-state notification, CCPA exposure, credit monitoring, legal defense.
  3. Outer circle — existential costs. Loss of ability to process payments if PCI status collapses, a corrective action plan that blocks health-data handling, or a disclosure failure that becomes a securities problem.

Organizations that spend on the inner circle are the ones that usually avoid living in the outer two.

Practical pressure that still holds up:

  • A tested incident-response plan mapped to U.S. state notification clocks — and to the SEC four-business-day path if you are public.
  • Data minimization. You cannot leak what you do not hold.
  • Encryption where it changes the legal and practical outcome — especially where CCPA's private right of action turns on non-encrypted, non-redacted data.
  • Controlled sharing. Permanent "anyone with the link" URLs are a quiet way breaches and leaks keep compounding years later. See share links that never expire for that failure mode in plain language.

For the EU ledger — GDPR fines, NIS2 clocks, and Article 33/34 notification — see What a GDPR data breach really costs.

Controlled sharing as an inner-circle mitigation

Who can open a shared file — and whether that link is still live next quarter — is one of the cheapest levers in the inner circle. It does not replace MFA, logging, or an incident plan. It does cut a common way sensitive files keep circulating after a deal, a contractor, or a campaign ends.

TinyX is built for that handoff. Free covers outgoing file share with expiry and passwords; upload drops start on Pro+. Caps and plans are on pricing; the product surface is on features.

The cheapest breach is the one that never happens. The second cheapest is the one you were already set up to contain.