Cybersecurity Market Statistics (2026)

Updated July 2026

The short answer

Worldwide spending on information security reached about $213 billion in 2025 and Gartner forecasts roughly $240 billion in 2026. The global average cost of a data breach fell to $4.44 million in 2025, but the US average hit a record $10.22 million. Cybercrime losses reported to the FBI hit a record $16.6 billion in 2024, and researchers estimate total global cybercrime costs near $10.5 trillion a year. The market is fragmented: no single vendor holds a double-digit share.

$213B
Global security spending
2025, Gartner
~$240B
2026 forecast
up ~12.5%, Gartner
$4.44M
Avg breach cost (global)
2025, IBM
$10.22M
Avg breach cost (US)
record high, IBM
$16.6B
Cybercrime losses (FBI)
2024, record
~4.8M
Workforce gap
unfilled roles, ISC2
Key takeaways
  • Worldwide end-user spending on information security reached about $213 billion in 2025, up from $193 billion in 2024, and Gartner forecasts roughly $240 billion in 2026 (Gartner).
  • The global average cost of a data breach fell 9% to $4.44 million in 2025, but the US average rose 9% to a record $10.22 million (IBM).
  • Healthcare was the costliest sector for the 14th straight year at $7.42 million per breach; the mean time to identify and contain fell to 241 days, a nine-year low.
  • Cybercrime losses reported to the FBI's IC3 hit a record $16.6 billion in 2024 across 859,532 complaints, up 33% year over year (FBI IC3).
  • Ransomware appeared in 44% of breaches Verizon analyzed in 2025, up 37%, though the median payout fell to $115,000 and 64% of victims refused to pay (Verizon DBIR).
  • The market stays fragmented: Palo Alto Networks leads with an estimated 9% share, ahead of Fortinet (7%) and Microsoft (6%), and no vendor has yet reached double digits.

The security market by the numbers

Cybersecurity is now one of the largest line items in enterprise technology. Gartner puts worldwide end-user spending on information security at about $213 billion in 2025, up from $193 billion in 2024, roughly a 10% jump in a single year (see the chart below).

That is the software, services, and network-security tooling organizations buy to defend themselves. Broader research firms that also count internal staff, hardware, and consumer products cite even larger figures, from roughly $200 billion to $270 billion for 2025, depending on scope.

Worldwide information security spending by year

Gartner end-user spending on information security. 2022-2023 are Gartner prior-year forecasts; 2026 is a forecast.

Where the security dollars go

Spending splits into three big buckets. Security software is the largest and fastest-growing at about $106 billion in 2025, followed by security services at roughly $84 billion and network security at about $23 billion (see the table below).

Software leads because companies keep moving from on-premises systems to the cloud, which opens new attack surfaces. Gartner flags cloud security posture management and cloud access security brokers as the main drivers, with cloud security growing nearly 29% into 2026.

Worldwide security spending by segment (Gartner)
Segment20242025Growth
Security software$94.96B$105.94B+11.6%
Security services$77.13B$83.81B+8.7%
Network security$21.32B$23.27B+9.2%
Total information security$193B$213B+10.4%

Growth is 2024 to 2025. Security software is the fastest-growing segment, led by cloud security. Source: Gartner information security spending forecast (July 2025)

The 2026 spending outlook

Growth is accelerating, not slowing. Gartner forecasts information security spending will rise about 12.5% in 2026 to roughly $240 billion, and a later 2026 update lifted the estimate toward $244 billion, up 13.3% (Gartner via Software Strategies).

AI is the swing factor on both sides. Gartner estimates the AI-amplified security market at roughly $49 billion in 2025, while spending to secure AI systems themselves is just $2.8 billion, meaning organizations spend about 17 times more on AI tools than on protecting them.

The cost of a data breach

For the first time in years, the global average breach cost fell, dropping 9% to $4.44 million in 2025 as faster AI-assisted detection trimmed the damage (see the tables below). IBM's report draws on 600 organizations across 16 countries and 17 industries.

The cost depends heavily on what is stolen: intellectual property runs about $178 per record, employee personal data $168, and customer data $160. That is why breaches that expose sensitive records, rather than just anonymized data, drive the headline totals.

Average cost of a data breach: global vs US
Measure20242025Change
Global average$4.88M$4.44M-9%
United States average$9.36M$10.22M+9%
Mean days to identify + contain2582419-year low
Organizations refusing ransom59%63%+4 pts

Based on 600 organizations across 16 countries and 17 industries, March 2024 to February 2025. Source: IBM Cost of a Data Breach Report 2025

Data breach cost per record, by data type
Data typeCost per record
Intellectual property$178
Employee PII$168
Customer PII$160
Anonymized customer data$115

Figures are IBM's per-record averages, republished by an aggregator (flagged as secondary). Source: IBM Cost of a Data Breach Report 2025 (via DataBreachCost.com)

Why a US breach costs more than double

The global decline hides a sharp US divergence. The US average breach cost rose 9% to a record $10.22 million in 2025, more than double the global figure, driven by higher regulatory fines plus steep detection and escalation costs (IBM).

It is a reminder that averages travel badly across borders. Stricter US disclosure rules, larger settlements, and heavier litigation exposure all inflate the final bill, so a US organization budgeting off the global $4.44 million number would badly underestimate its risk.

Where breaches cost the most

Some industries bleed far more than others. Healthcare topped the list for the 14th consecutive year at $7.42 million per breach, ahead of the financial sector at about $5.56 million, with industrial, energy, and technology rounding out the priciest five (see the chart below).

Healthcare stays expensive because patient records are highly regulated, hard to re-secure, and valuable to attackers, and because downtime in a hospital carries direct safety costs. Financial firms face similar regulatory weight plus the direct value of the accounts involved.

Average data breach cost: US vs global vs top sectors

IBM Cost of a Data Breach 2025. US and global are overall averages; healthcare and financial are sector averages.

How breaches happen and what each costs

Attackers overwhelmingly get in through people and credentials. Phishing was the single most common root cause at 16% of breaches, followed by supply-chain compromise at nearly 15% and denial-of-service at about 13%. Roughly 51% of breaches trace to malicious attacks, 26% to human error, and 23% to IT failure.

The most expensive entry points are not always the most common. Malicious-insider breaches cost the most at $4.92 million, just ahead of supply-chain compromises at $4.91 million and phishing at $4.80 million (see the chart and table below), so both frequency and per-incident cost matter when prioritizing defenses.

Average breach cost by initial attack vector

Global average cost by initial attack vector, IBM Cost of a Data Breach 2025.

Average breach cost by initial attack vector
Initial attack vectorAvg costShare of breaches
Malicious insider$4.92M-
Supply chain compromise$4.91M~15%
Phishing$4.80M16%
Credential theft$4.67M-
Denial-of-service$4.41M~13%
Vulnerability exploitation$4.24M-

Phishing was the single most common root cause at 16% of breaches. Cost figures are global averages. Source: IBM Cost of a Data Breach Report 2025

Detection and containment time

Speed is money in a breach. The mean time to identify and contain an incident fell to 241 days in 2025, a nine-year low, helped by security AI and automation that IBM credits with cutting the breach lifecycle by up to 80 days.

That gap between fast and slow responders is expensive: breaches contained in under 200 days averaged $3.87 million, versus $5.01 million when they dragged past 200 days, a roughly 24% premium for slow detection. Internal security teams found breaches fastest, at about 172 days.

Ransomware by the numbers

Ransomware remains the defining threat. Verizon's 2025 DBIR found it present in 44% of breaches, up 37% year over year, and involved in a striking 88% of breaches at small and mid-sized businesses (Verizon).

Victims are pushing back, though. The median ransom payment fell to about $115,000, 64% of victims refused to pay at all (up from 59% the prior year in IBM's data), and IBM's ransomware recovery cost excluding any ransom dropped 44% to $1.53 million as organizations got better at restoring from backups.

AI on both sides of the fight

AI is now central to the breach story. Organizations that deployed security AI and automation extensively saved about $1.9 million per breach, but the flip side is emerging fast: IBM found 13% of organizations reported breaches of AI models or applications, and nearly two-thirds had no AI governance policy at all.

Unsanctioned tools add cost. Breaches involving so-called shadow AI carried a $670,000 penalty over the average, and Verizon reported that AI-generated phishing emails have roughly doubled, so the same technology cutting defenders' costs is also lowering the bar for attackers.

Cybercrime losses keep climbing

Reported losses are hitting records. The FBI's IC3 logged $16.6 billion in cybercrime losses across 859,532 complaints in 2024, a 33% jump from the prior year, with investment fraud (mostly crypto) accounting for more than $6.5 billion and business email compromise for $2.7 billion (see the table below).

Zoom out and the estimates get staggering. Cybersecurity Ventures, a research firm, projects total global cybercrime costs of about $10.5 trillion a year in 2025, rising toward $12.2 trillion by 2031. That figure is a widely cited projection, not a measured total, and should be read as an order-of-magnitude estimate rather than a hard number.

Cybercrime losses reported to the FBI IC3 (2024)
CategoryFigure
Total reported losses$16.6B
Complaints filed859,532
Year-over-year loss increase+33%
Investment fraud (mostly crypto) losses$6.5B+
Business email compromise losses$2.7B
BEC complaints21,442

US-reported figures only; actual global cybercrime is far larger and largely unreported. Source: FBI IC3 2024 Internet Crime Report

Breaches, victims, and the talent gap

Breach counts have plateaued even as exposure explodes. The ITRC tracked 3,158 US data compromises in 2024, down about 1% from 2023's record, yet victim notices surged 312% to more than 1.7 billion, driven by six mega-breaches that each exposed at least 100 million people (ITRC).

Defenders remain badly outnumbered. ISC2's 2025 Workforce Study, based on a record 16,029 professionals, found 95% reporting at least one skills gap and 59% calling those gaps critical or significant, up from 44% a year earlier, against a talent shortage the group has previously pegged near 4.8 million unfilled roles worldwide.

The vendor landscape

No one dominates. Palo Alto Networks leads with an estimated 9% market share, ahead of Fortinet at 7% and Microsoft at 6%, and industry analysts note that no vendor has yet reached a double-digit share (see the table below). Palo Alto reported about $8.2 billion in FY2025 revenue and Fortinet $5.96 billion in 2024.

The fast growth is in platform consolidation and recurring revenue. CrowdStrike's annual recurring revenue reached roughly $4.4 billion, while Zscaler, CyberArk, and SentinelOne each run subscription revenue in the low billions, and Microsoft's security business alone has been reported above $20 billion, blurring the line between pure-plays and incumbents.

Largest cybersecurity vendors (share and scale)
VendorEst. market shareLatest revenue / ARR
Palo Alto Networks~9%$8.2B revenue (FY2025)
Fortinet~7%$5.96B revenue (2024)
Microsoft (security)~6%>$20B security revenue (reported)
CrowdStrike-~$4.4B ARR
Cisco (incl. Splunk)-Multi-billion security segment
Zscaler / CyberArk / SentinelOne-$0.8-2.6B ARR each

Market-share percentages are secondary research estimates and vary by source. Revenue figures span different fiscal years. Source: Company filings; market-share estimates via industry research

What it means for investors

Cybersecurity is a structural-growth theme: spending compounds at low double digits, breach costs keep rising in the US, and AI is expanding the attack surface as fast as it improves defense. That secular demand is why the sector has drawn steady investor interest through market cycles.

The catch is that the market is fragmented and richly valued, with dozens of specialists across endpoint, network, identity, and cloud security. Rather than pick a single winner, many investors gain exposure through a diversified basket of cybersecurity leaders or a sector ETF. Walnut is a tracking and research tool, not an investment adviser, and none of this is a recommendation to buy any specific security.

Frequently asked questions

How big is the cybersecurity market?

Gartner puts worldwide information security spending at about $213 billion in 2025, up from $193 billion in 2024, with a forecast near $240 billion in 2026. Broader research estimates that also count staff, hardware, and consumer products run higher, roughly $200 billion to $270 billion for 2025.

What is the average cost of a data breach in 2025?

IBM's Cost of a Data Breach 2025 puts the global average at $4.44 million, down 9% from 2024, as AI-assisted detection sped up response. The US average, however, hit a record $10.22 million, more than double the global figure, on higher fines and detection costs.

Which industry has the most expensive data breaches?

Healthcare, for the 14th straight year, at about $7.42 million per breach in 2025. Financial services followed near $5.56 million, with industrial, energy, and technology rounding out the five costliest sectors, according to IBM.

How much does cybercrime cost globally?

Reported US losses to the FBI's IC3 hit a record $16.6 billion in 2024, up 33%. The often-cited $10.5 trillion global annual cost for 2025 is a projection from Cybersecurity Ventures, not a measured figure, so treat it as an order-of-magnitude estimate.

Who are the biggest cybersecurity companies?

Palo Alto Networks leads with an estimated 9% market share, followed by Fortinet (7%) and Microsoft (6%). CrowdStrike, Cisco (with Splunk), Zscaler, CyberArk, and SentinelOne are other major players. The market is fragmented, and no vendor has yet reached double-digit share.

How large is the cybersecurity workforce gap?

ISC2 has estimated a global shortage near 4.8 million unfilled cybersecurity roles. In its 2025 study of 16,029 professionals, 95% reported at least one skills gap and 59% called those gaps critical or significant, up from 44% a year earlier.

Sources

Figures are compiled from the primary sources above and reflect the most recent data available at the time of writing. This page is informational and not investment advice.

Related statistics

Browse all investing statistics.

Walnut lets you connect your brokerage and analyze your real holdings against benchmarks with AI, read-only by default.

Try Walnut
    Cybersecurity Market Statistics (2026), Walnut