Insider Threats Now Cost $19.5M a Year, and 73% of Them Aren’t Even Malicious
Your biggest data breach this year probably won’t come from a hacker in another country. It’ll come from someone on your payroll who misconfigured a bucket, emailed the wrong client, or got their credentials phished. According to Ponemon Institute’s newly released 2026 Cost of Insider Risks: Global report, the average organization now spends $19.5 million a year cleaning up after insiders, and nearly three-quarters of those incidents involve no malice at all.
That number matters if you’re the one signing off on next year’s security budget. It means the “disgruntled employee stealing secrets” story that shaped a decade of insider-threat programs is, statistically, the minority case. The majority case is a lot more boring, and a lot harder to staff against: ordinary people, doing ordinary work, making ordinary mistakes at scale.
The Real Number (and Why $17 Billion Is Wrong)
Let’s clear up the confusion first, because a lot of it is floating around online. There is no credible $17 billion aggregate insider-threat figure anywhere in the current research. That number appears to be a “million” that got mistyped as “billion” somewhere in the content-mill chain, and it’s been repeated enough times that it now shows up in AI Overviews and half-sourced listicles as if it were fact.
The real figure, straight from the Ponemon and DTEX Systems study, is $19.5 million per organization, per year, up from $17.4 million the year before. That’s a 12% jump in a single year, and a 20% climb over two years. Ponemon surveyed 8,750 IT and security practitioners across 354 organizations worldwide, all of which had experienced at least one material insider incident, spanning industries from banking to healthcare to manufacturing.
Who’s Actually Causing These Incidents
Here’s the breakdown that should reshape how security teams think about budget. Negligent insiders, the employee who cc’d the wrong recipient, left an S3 bucket open, or ignored a patch notice, account for 53% of all incidents. Credential theft, where an outsider gets in using a legitimate employee’s stolen login, accounts for another 20%. That leaves 27% for what most people picture when they hear “insider threat”: someone deliberately stealing data or sabotaging systems.
| Incident type | Share of incidents | Avg. cost per incident |
|---|---|---|
| Negligent insider | 53% | $747,107 |
| Malicious/criminal insider | 27% | $4.7 million |
| Credential theft | 20% | $842,462 |
Notice what that table actually shows. Malicious insiders are rare but ruinous per incident. Credential theft is the single costliest category per event, even pricier than outright malice, because attackers using a real employee’s login tend to move further before anyone notices. Negligence, meanwhile, is cheap per incident but happens so often (an average of 13.8 negligent incidents per organization per year) that it adds up to $10.3 million annually on its own, the single biggest line item in the whole report.
Verizon’s independently produced 2026 Data Breach Investigations Report backs this up from a completely different dataset. Analyzing confirmed breaches from November 2024 through October 2025, Verizon found convenience, not financial gain, was the leading motive behind insider misuse, at 60% versus 33%. Two separate research teams, two separate methodologies, same conclusion: most insider risk is a people-and-process problem, not a villain problem.
Why Containment Speed Is the Whole Game
If there’s one number CISOs should tape to their monitor, it’s this one: incidents contained within 30 days cost an average of $14.2 million. Incidents that drag past 90 days cost $21.9 million. Same incident type, same organization size, nearly an $8 million swing based purely on how fast the team catches and shuts it down.
The industry is getting faster, if not fast enough. Average containment time fell to 67 days in 2025, down from 86 days in 2023. But only 13% of incidents get contained inside that critical 30-day window. Containment itself, not detection, not escalation, is where the money actually goes: $247,587 average containment cost per incident versus $39,728 for escalation. That’s a six-to-one ratio, and it tells you exactly where a security budget should be pointed.
Which Regions and Industries Are Bleeding the Most
Geography matters more than most breach reports admit. North American organizations posted the highest average annual cost at $24 million, ahead of Europe’s $18.6 million. On the industry side, healthcare and pharmaceutical companies topped the list at $28.8 million, with tech and software close behind at $24.2 million, both sectors where a single insider incident can touch either patient data or proprietary source code.
If your organization sits in one of those two buckets, US-based, or health/tech, the $19.5 million “average” understates your actual exposure. Worth checking where your industry and region land before you present this stat to your board as a baseline.
The New Variable: Shadow AI
Every edition of this study since 2018 has told roughly the same story: negligence beats malice as the dominant driver of insider cost. What’s genuinely new in 2026 is the AI layer sitting on top of that old story.
Verizon’s DBIR found that shadow AI, employees pasting proprietary code or data into unauthorized AI tools, is now the third most common non-malicious insider action showing up in data loss prevention telemetry, a fourfold increase over the prior year. Source code is the single most common data type submitted to those unauthorized platforms. More than 15% of users in Verizon’s sample had unauthorized AI browser extensions installed on their machines, often without IT ever knowing.
Separately, Cybersecurity Insiders’ 2026 Insider Risk Report found that 94% of organizations believe rapid AI adoption is increasing their insider risk exposure, with 74% calling that increase moderate to significant.
“Insider risk has become one of the most consequential and underestimated threats facing organizations today, not just because of the data loss it causes, but because attackers are increasingly exploiting insiders as a deliberate entry point to bypass perimeter defenses entirely.” Leslie Nielsen, CISO, Mimecast
There’s a sharper, less comfortable version of this argument too. Lina Dabit, Executive Director of the CISO Office at Optiv Canada, points out that the old framing of insiders as willing bad actors is already outdated.
“We’ve always had malicious insiders, but now we have coerced insiders. I think it’s just a matter of time before a threat actor shows up at someone’s home or someone’s children’s school.” Lina Dabit, Executive Director, CISO Office, Optiv Canada, via CSO Online
That’s an uncomfortable line to read as a CISO. It reframes insider risk programs from “catch the bad employee” to “protect the good employee from being turned into one.”
Why Scale, Not Intent, Is the Real Problem
Aviv Nahum, CEO and co-founder of Above Security, made a related point writing in Forbes Technology Council in July 2026: at enterprise scale, no security team can personally vet tens of thousands of employees, and even well-intentioned staff make mistakes fast enough to overwhelm a security model built on trusting the badge. It’s a fair diagnosis for why insider risk keeps climbing even as security budgets grow. You can’t background-check your way out of a scale problem.
The Case for Reading These Numbers Skeptically
Now the part most coverage of this report skips. The 2026 Cost of Insider Risks study is sponsored by DTEX Systems, a company that sells insider-risk detection software. Ponemon conducted the fieldwork independently, and the survey methodology is disclosed and reasonably rigorous, but a vendor with a product to sell has an obvious interest in a headline number that justifies buying more detection tooling. That’s worth flagging the same way you’d flag any vendor-funded study, IBM’s Cost of a Data Breach report included.
There’s a second, quieter issue: sampling. The study only surveyed 354 organizations that had already experienced at least one material insider incident. Companies with zero incidents, or minor ones that never got escalated, aren’t in the sample at all. That means the reported $19.5 million average is really the average cost among already-affected companies, not a representative figure across all enterprises. It’s a real number, but it’s not the number an unaffected company should expect to pay.
And some of the year-over-year increase might reflect better detection rather than worse behavior. The report notes that 68% of organizations logged between 21 and 40-plus incidents this year, up from 57% in 2024. Is that more insider incidents happening, or more incidents finally getting caught? The study doesn’t fully separate the two, and neither does most breach-cost research in this genre.
What Actually Reduces the Bill
The report isn’t only diagnostic. It models cost avoidance for specific controls, and the results give security leaders something concrete to point to in a budget meeting.
- Privileged access management (PAM): organizations using it avoided an average of $6.1 million in insider-related costs.
- User behavior analytics (UBA): avoided an average of $5.1 million.
- Faster containment workflows: the single biggest lever available, given the $7.7 million gap between 30-day and 90-plus-day containment.
None of that is exotic. It’s behavioral monitoring, tighter standing access, and faster incident response, not a bigger vetting process at hiring time. If your program is still built primarily around background checks and disgruntled-employee profiling, the data says you’re aiming at the 27% slice while the 73% slice quietly costs you more.
FAQ
Organizations spent an average of $19.5 million per year on insider-related incidents in 2025, up from $17.4 million the year before, according to Ponemon’s 2026 Cost of Insider Risks: Global report. North American companies spent the most, averaging $24 million annually.
No. Ponemon’s 2026 research found 53% of insider incidents stem from employee negligence and 20% from credential theft, meaning about 73% are non-malicious. Only 27% involve deliberate, malicious insider action, making careless mistakes the more common, and costlier in aggregate, root cause.
Negligent insiders are the most common type, responsible for 53% of incidents according to Ponemon’s 2026 research, things like misconfigured cloud storage, sending data to the wrong recipient, or unpatched devices, rather than deliberate data theft or sabotage.
Average containment time fell to 67 days in 2025, down from 86 days in 2023, per Ponemon’s 2026 report. Speed matters financially: incidents contained within 30 days cost organizations an average of $14.2 million, versus $21.9 million when containment takes longer than 90 days.
Yes. 94% of organizations say rapid AI adoption is increasing their insider risk exposure, per Cybersecurity Insiders’ 2026 report. Verizon’s 2026 DBIR separately found shadow AI use is now the third most common non-malicious insider action in DLP data, a fourfold year-over-year increase.
Where This Goes Next
Here’s what you now know that most coverage of this topic still gets wrong: the $17 billion figure doesn’t exist, the “75% non-malicious” stat is a year out of date, and the real story isn’t a villain hiding in your org chart. It’s scale, speed, and now, a new generation of AI tools that make it easier than ever for a well-meaning employee to leak something valuable without meaning to.
Watch three things over the next 6 to 18 months. First, whether shadow AI moves from a DLP footnote to its own line item in next year’s Ponemon report, given the fourfold jump already recorded. Second, whether containment times keep falling below the current 67-day average as UBA tooling matures. Third, whether regulators, especially under the EU AI Act, start treating unmonitored generative AI use as a compliance failure rather than just a security one.
If you’re building an insider risk program in 2026, the actionable move is straightforward: shift budget from vetting to behavioral monitoring, tighten standing access for contractors and third parties, and get a policy in place for generative AI tools before shadow AI becomes this time next year’s headline stat instead of this year’s footnote.
Sources: Ponemon-Sullivan, 2026 Cost of Insider Risks: Global · DTEX Systems / Ponemon report hub · Verizon 2026 Data Breach Investigations Report · Cybersecurity Insiders, 2026 Insider Risk Report · Forbes Technology Council, July 2026
