Cybersecurity Statistics by Industry 2026
By Axis Intelligence Research
Co-author: Marcus Chen | Last updated: September 26, 2026 | License: CC BY 4.0
Retail is the most breach-exposed industry of 2026. Axis Intelligence Research’s Industry Breach Exposure Index (IBEX™) scores retail at 63.35 out of 100, ahead of education (60.95) and manufacturing (58.39), against an all-industry reading of 56.75. The drivers: 68% third-party involvement and 42% of breaches opened by exploited vulnerabilities, per Verizon’s 2026 DBIR.
Quick Answer
Healthcare still has the most expensive breaches ($6.64M average, IBM 2026), but it is not the most exposed industry. Combining four Verizon 2026 DBIR sector metrics, Axis Intelligence Research finds retail (IBEX™ 63.35) carries the highest breach exposure, followed by education (60.95). Cost and exposure rank industries differently — and budgets should follow both.
Key Findings
- Axis Intelligence Research’s IBEX™ baseline reading scores retail at 63.35/100, the highest of five industries profiled in Verizon’s 2026 DBIR sector data.
- According to Verizon’s 2026 DBIR, 96.4% of healthcare security incidents became confirmed data breaches (1,438 of 1,492), an Axis-calculated conversion rate.
- Exploitation of vulnerabilities opened 42% of retail breaches and 40% of public administration breaches in the 2026 DBIR, against 31% across all industries.
- IBM’s 2026 Cost of a Data Breach Report puts the average healthcare breach at $6.64 million — 33.1% above the $4.99 million global average, per Axis calculation.
- FBI IC3 logged 460 ransomware complaints from the U.S. healthcare sector in 2025 — 2.53 ransomware complaints for every data breach complaint, per Axis calculation.
Which Industry Is Most Targeted by Cyberattacks in 2026?
It depends on whose data you read, and that is the first thing a security leader should understand. The three largest public datasets count different things.
Verizon’s 2026 DBIR (incidents from November 1, 2024 to October 31, 2025) examined more than 31,000 incidents and 22,000 confirmed breaches across 145 countries. By raw volume in its sector breakdowns, public administration (3,634 incidents) and manufacturing (3,627 incidents) lead. Read the full dataset at Verizon’s 2026 Data Breach Investigations Report.
ENISA’s 2026 Threat Landscape, released September 22, 2026 and covering calendar 2025, finds public administration was targeted in 32% of EU incidents, followed by business services (8%), transport (8%), manufacturing (7%) and finance/banking (6%). But 82% of public-administration events were ideology-driven DDoS — noisy, rarely data-destroying.
The FBI’s IC3 2025 report counts U.S. complaints, and there healthcare and public health topped every critical infrastructure sector with 460 ransomware and 182 data breach complaints.
Most targeted industries: incidents vs. confirmed breaches (DBIR 2026)
| Industry (NAICS) | Incidents | Confirmed breaches | Incident→breach conversion (Axis) | Source |
|---|---|---|---|---|
| Public Administration (92) | 3,634 | 2,410 | 66.32% | Verizon DBIR 2026 |
| Manufacturing (31–33) | 3,627 | 2,713 | 74.80% | Verizon DBIR 2026 |
| Healthcare (62) | 1,492 | 1,438 | 96.38% | Verizon DBIR 2026 |
| Educational Services (61) | 1,302 | 1,252 | 96.16% | Verizon DBIR 2026 |
| Retail (44–45) | 997 | 806 | 80.84% | Verizon DBIR 2026 |
Marcus Chen’s read: Volume rankings are the least useful number on this page. Public administration logs the most incidents because it reports more incident types, in more detail, than anyone else — Verizon says so itself. The number I’d pin to a CISO’s wall is the conversion rate. When 96 of every 100 incidents at a hospital or a university end in confirmed data disclosure, the problem isn’t detection volume. It’s that the first compromise is usually the last line.
Which Industry Has the Highest Data Breach Cost?
Healthcare, for the 13th consecutive year. IBM’s 2026 report (602 organizations breached between March 2025 and February 2026) puts the global average breach at a record $4.99 million, per the IBM newsroom release of July 29, 2026.
Data breach cost by industry (IBM 2026)
| Industry | Avg. breach cost | Premium vs. global avg (Axis) | Source |
|---|---|---|---|
| Healthcare | $6.64M | +33.07% | IBM 2026, as reported by Becker’s Hospital Review |
| Financial services | $6.3M | +26.25% | IBM newsroom, 2026-07-29 |
| Energy | $5.2M | +4.21% | IBM newsroom, 2026-07-29 |
| All industries (global) | $4.99M | — | IBM newsroom, 2026-07-29 |
Healthcare’s average fell from $7.42 million a year earlier, even as the global mean rose. Mean time to identify and contain a breach across all industries climbed to 247 days. IBM also reports that 62% of AI-driven attacks in its study hit critical infrastructure sectors, with financial services and energy absorbing the heaviest concentration.
Marcus Chen’s read: Healthcare’s cost line dropped and finance’s climbed to within $340,000 of it. That gap is the closest I’ve seen those two lines. Finance won’t overtake on patient-record liability — it’ll overtake on the AI-driven fraud bill, if IBM’s concentration data holds next July.
How Do Hackers Get In? Initial Access Vectors by Industry
The single most important shift in the 2026 DBIR: exploitation of vulnerabilities (31%) replaced credential abuse (13%) as the top initial access vector across all breaches. By sector, the spread is wide.
Initial access vectors in breaches, by industry (DBIR 2026)
| Industry | Exploited vulns | Phishing | Credential abuse | Source |
|---|---|---|---|---|
| Retail | 42% | 9% | 14% | Verizon DBIR 2026 |
| Public Administration | 40% | 20% | 8% | Verizon DBIR 2026 |
| Manufacturing | 38% | 13% | 11% | Verizon DBIR 2026 |
| Educational Services | 34% | 22% | 8% | Verizon DBIR 2026 |
| Healthcare | 20% | 14% | 11% | Verizon DBIR 2026 |
| All industries | 31% | — | 13% | Verizon DBIR 2026 |
Patching cadence is where this breaks. Only 26% of CISA KEV-listed vulnerabilities were fully remediated in 2025, and the median time to full remediation rose to 43 days.
Marcus Chen’s read: Retail’s 42% is an edge-device story, not a zero-day story. Education is the outlier in the other direction: 22% phishing, the highest of the five, which tracks with a user population that turns over every September. Healthcare’s low exploitation share is not good news — its breaches skew toward misdelivery and misconfiguration, which no scanner finds.
Which Industries Are Most Exposed to Third-Party and Supply Chain Breaches?
Across all DBIR 2026 breaches, third-party involvement jumped to 48%, up from 30% a year earlier. Retail sits far above that.
| Industry | Third-party involvement | Human element | Source |
|---|---|---|---|
| Retail | 68% | 58% | Verizon DBIR 2026 |
| Manufacturing | 61% | 56% | Verizon DBIR 2026 |
| Educational Services | 40% | 68% | Verizon DBIR 2026 |
| Public Administration | 36% | 69% | Verizon DBIR 2026 |
| Healthcare | 32% | 54% | Verizon DBIR 2026 |
| All industries | 48% | 62% | Verizon DBIR 2026 |
Axis Industry Breach Exposure Index (IBEX™): Which Sector Is Most Exposed?
Cost tells you what a breach bills. Volume tells you who reports the most. Neither answers the question a board actually asks: if we get hit, how likely is it to become a breach, and how many doors did we leave open? Axis Intelligence Research built the Industry Breach Exposure Index (IBEX™) to answer it with public, primary-sourced sector data.
How IBEX™ is calculated
IBEX = 0.30 × Conversion + 0.25 × Exploitation + 0.25 × Third-party + 0.20 × Human element
- Conversion (30%) — confirmed breaches ÷ incidents × 100 (Axis-calculated from DBIR counts). Weighted highest because it measures what happens after the attacker arrives.
- Exploitation (25%) — share of breaches opened by exploited vulnerabilities.
- Third-party (25%) — share of breaches involving a third party.
- Human element (20%) — share of breaches involving non-malicious human action.
All inputs are percentages on a 0–100 scale, so no further normalization is applied. All inputs come from the Verizon 2026 DBIR industry snapshots.
IBEX™ scores by industry (baseline reading, as of the DBIR 2026 dataset)
| Rank | Industry | Conversion | Exploitation | Third-party | Human | IBEX™ |
|---|---|---|---|---|---|---|
| 1 | Retail | 80.84 | 42 | 68 | 58 | 63.35 |
| 2 | Educational Services | 96.16 | 34 | 40 | 68 | 60.95 |
| 3 | Manufacturing | 74.80 | 38 | 61 | 56 | 58.39 |
| — | All industries | 82* | 31 | 48 | 62 | 56.75 |
| 4 | Healthcare | 96.38 | 20 | 32 | 54 | 52.71 |
| 5 | Public Administration | 66.32 | 40 | 36 | 69 | 52.70 |
*All-industry conversion uses DBIR’s reported 82% confirmed-disclosure share of incidents. Worked example (retail): 0.30 × 80.84 + 0.25 × 42 + 0.25 × 68 + 0.20 × 58 = 24.25 + 10.50 + 17.00 + 11.60 = 63.35.
Marcus Chen’s read: Two things surprised us. Retail leads because it fails on the two dimensions a retailer can’t fix alone: supplier sprawl (68%) and internet-facing assets that get exploited (42%). And healthcare, the most expensive sector, scores below average on exposure — its breaches are costly because of what’s stolen and how long containment takes, not because it’s the easiest to get into. Healthcare and public administration are effectively tied at the bottom; a 0.01-point gap sits well inside DBIR’s own confidence intervals, so treat them as equal.
What IBEX™ does not merge — on purpose
We did not fold IBM’s cost figures into IBEX™. IBM measures ~600 breached organizations through interviews; Verizon codes tens of thousands of incidents from contributors. Blending a survey-based dollar figure with a case-coded percentage would produce a number with no meaning. We publish them side by side instead.
How Many Ransomware Attacks Hit Each Industry?
Ransomware appeared in 48% of all breaches in the 2026 DBIR — and in 61% of manufacturing breaches. Yet payment behavior is changing: 69% of ransomware victims didn’t pay, and the median payment fell to $139,875.
In the U.S., the FBI’s IC3 received 3,611 ransomware complaints in 2025, with $32,320,105 in reported losses (a figure that excludes downtime and recovery costs). IC3 identified 63 new variants. Healthcare led all critical infrastructure sectors with 460 ransomware complaints. Outside critical infrastructure, legal services (18%), contracting services (17%) and engineering/architecture firms (10%) filed the most ransomware complaints.
IBM’s 2026 study found 39% of breached organizations reported a ransomware incident.
Marcus Chen’s read: Law firms at the top of the non-critical list isn’t random. Small headcount, client trust accounts, and deadlines that make downtime unaffordable — the same leverage math that makes hospitals targets, at a tenth of the security budget.
Who Attacks Each Industry — Criminals, Spies or Insiders?
| Industry | Financial motive | Espionage motive | Internal actors | Source |
|---|---|---|---|---|
| Healthcare | 99% | 2% | 19% | Verizon DBIR 2026 |
| Manufacturing | 87% | 15% | 5% | Verizon DBIR 2026 |
| Retail | 85% | 19% | 1% | Verizon DBIR 2026 |
| Educational Services | 78% | 21% | 22% | Verizon DBIR 2026 |
| Public Administration | 69% | 33% | 44% | Verizon DBIR 2026 |
Motives can overlap within a breach, so rows may exceed 100%. Retail’s espionage share rose to 19%, and internal data (plans, strategy) was taken in 84% of retail breaches, up from 65%. In public administration, misdelivery accounts for 88% of errors, and personal data was compromised in 50% of breaches.
Methodology
Collection. Axis Intelligence Research fetched and read every source during production on September 26, 2026: the Verizon 2026 DBIR full report and its Manufacturing, Healthcare, Public Sector and Retail snapshots; the IBM newsroom release for the 2026 Cost of a Data Breach Report; the FBI IC3 2025 Annual Report; ENISA’s 2026 Threat Landscape page. The healthcare cost figure ($6.64M), its prior-year value and the 247-day lifecycle come from Becker’s Hospital Review coverage of the IBM report because IBM’s full report is gated; these rows are flagged is_primary = no.
Axis-calculated figures. Conversion rate = breaches ÷ incidents × 100. Cost premium = (sector average ÷ 4.99 − 1) × 100. IC3 ratio = 460 ÷ 182. IBEX™ as defined above. All arithmetic was run twice (floating point and exact rational).
Scope. Verizon’s financial and insurance sector snapshot could not be retrieved, so financial services is absent from IBEX™ rather than estimated. DBIR data is a sample of contributed cases, not a census; small differences between sectors can fall within its confidence intervals. IBM figures are survey-based. IC3 counts are U.S. complaints only; ENISA counts EU incidents.
About This Dataset
cybersecurity-statistics-by-industry.csv — 110 rows, long format, one observation per row, with source_org, source_document, source_url, retrieved_date, is_primary, axis_calculated and method_note on every row. Licensed CC BY 4.0. Also published on Hugging Face, Kaggle and GitHub.
How to Cite
APA: Axis Intelligence Research, & Chen, M. (2026, September 26). Cybersecurity statistics by industry 2026. Axis Intelligence Research. https://axis-intelligence.com/cybersecurity-statistics-by-industry/
MLA: Axis Intelligence Research, and Marcus Chen. “Cybersecurity Statistics by Industry 2026.” Axis Intelligence Research, 26 Sept. 2026, axis-intelligence.com/cybersecurity-statistics-by-industry/.
Chicago: Axis Intelligence Research and Marcus Chen. “Cybersecurity Statistics by Industry 2026.” Axis Intelligence Research, September 26, 2026. https://axis-intelligence.com/cybersecurity-statistics-by-industry/.
Related Research
- Cybersecurity statistics 2026: breaches, costs and ransomware
- Critical infrastructure cyberattack statistics
- Government cyberattack statistics and disclosure gaps
- Cybercrime losses reported to the FBI
- AI-driven cyberattack statistics
- Cybersecurity jobs and workforce gap data
FAQ
Why does healthcare have the most expensive breaches but not the highest exposure score?
Because cost and exposure measure different things. IBM’s $6.64M healthcare average reflects regulated patient data and long containment. IBEX™ measures how often incidents convert to breaches and how many entry doors are open — and healthcare’s 20% exploitation and 32% third-party shares sit well below retail’s.
What percentage of retail breaches involve a third party?
68%, per Verizon’s 2026 DBIR — the highest of any profiled sector and 20 points above the 48% all-industry figure.
Is manufacturing the top ransomware target?
Among DBIR sectors, ransomware appeared in 61% of manufacturing breaches, above the 48% all-industry share. In FBI IC3’s U.S. data, healthcare filed the most ransomware complaints of any critical infrastructure sector (460 in 2025).
Why do universities almost always get breached once attacked?
96.16% of education incidents in the 2026 DBIR became confirmed breaches (1,252 of 1,302). Web applications were the malware vector in 71% of education malware cases, and the late-2025 Oracle E-Business Suite campaign hit the sector heavily.
Why are government agencies’ insider numbers so high?
Internal actors appear in 44% of public administration breaches, driven mostly by misdelivery (88% of errors). Verizon notes government bodies report more incident types in more detail, which inflates internal-error counts relative to private sectors.
Which EU sector sees the most cyber incidents?
Public administration, at 32% of incidents in ENISA’s 2026 Threat Landscape, but 82% of those were hacktivist DDoS events rather than data breaches.
Can IBEX™ be recomputed independently?
Yes. Every input is a row in the CSV with its Verizon URL; the weights are published above. Anyone can reproduce each score to two decimals.
Where does financial services rank on IBEX™?
It isn’t scored in this baseline reading because Verizon’s financial-sector snapshot was not retrievable. IBM’s data puts its average breach at $6.3M, second only to healthcare.
