GirderGroup

What breach data says about response time

The annual breach-cost studies contain a consistent, actionable signal: the longer a breach goes undetected and uncontained, the more it costs. Detection and response are not only security concerns; they are financial ones.

Girder GroupSecurity Practice
October 22, 2025 · 5 min read

Key takeaways

  • The global average cost of a data breach reached USD 4.45 million in 2023 (IBM).
  • Organisations took an average of 277 days to identify and contain a breach (IBM, 2023).
  • Faster detection and containment correlate with materially lower breach costs.
  • Auditability and monitoring shorten the window, which is exactly where the cost accumulates.

A consistent signal

Security spending is often hard to justify because its return is the absence of an event. The annual breach-cost research is useful precisely because it turns that absence into numbers. IBM's Cost of a Data Breach report, conducted with the Ponemon Institute, put the global average cost of a breach at USD 4.45 million in 2023.

More useful than the headline is the mechanism behind it. The same research consistently finds that the cost of a breach is strongly related to how long it goes undetected and uncontained.

The cost of a breach accumulates in the window between compromise and containment. Shortening that window is one of the few security investments with a direct dollar return.

The window is where the cost is

In the 2023 report, organisations took an average of 277 days to identify and contain a breach. That window, around nine months on average, is where much of the damage accumulates: more records exposed, more systems reached, more regulatory and recovery cost incurred.

Organisations that detected and contained breaches faster reported materially lower costs. The lever, in other words, is not only prevention. It is the speed of detection and response.

Designing for a shorter window

Shortening the window is largely a matter of visibility. Systems that record consequential actions, monitor for anomalies, and make it possible to reconstruct what happened let a team detect a problem sooner and scope it faster once found.

This is where auditability earns its keep beyond compliance. The same audit trails that make a system explainable to a regulator are what let a responder answer, quickly, the only questions that matter during an incident: what was accessed, by whom, and when.

Sources

  1. 1.IBM Security & Ponemon Institute (2023). Cost of a Data Breach Report 2023.IBM
  2. 2.Ponemon Institute (annual). Cost of a Data Breach research series.Ponemon Institute

Girder Group · Security Practice

Senior engineers who build and operate the software they write about.

Talk to the team

Newsletter

Get new insights when we publish them.

Occasional writing on operational software and modernisation. We send something only when it is worth your time.

Unsubscribe anytime. We never share your email.

Enterprise engagement

Bring the problem. We will make the path clear.

Share the context, constraints, and timeline. We'll respond with a practical next step, even when the right answer is not to start a build yet.

info@girdergroup.com