Report by BakerHostetler

2026 Data Security Incident Response Report

12 FINDINGSPublished Mar 26, 2026
View Original Report →

Key Findings

Completing forensic investigations faster reduced time to notification by three days.

Incident ResponseForensics Investigations

Class-action lawsuits were filed in 14% of data security incidents, up from 9% the previous year.

Data Security IncidentClass-action LawsuitLitigation

For network intrusions, unpatched vulnerabilities were the root cause 21% of the time.

VulnerabilitiesNetwork IntrusionNetwork SecurityUnpatched Vulnerabilities

Health care was the most affected sector by data security incidents, accounting for 27% of incidents; finance and insurance accounted for 18%; business and professional services accounted for 15%.

HealthcareFinanceProfessional Services

For network intrusions, the root cause was not found 34% of the time.

Network SecurityNetwork Intrusion Root Cause

The cost of the largest investigations increased by more than 10% in 2025 compared with the previous year.

Data Breach CostForensics Investigations

Ransomware negotiation discounts of 50%–75% often take 20–60 days of negotiations.

RansomwareIncident ResponseRansomware NegotiationRansomware Cost

Vendors were the cause of 25% of data security incidents analyzed.

Third Party RiskVendor Management

The average initial ransomware demand increased 70% to $4.2 million compared to the previous year.

RansomwareRansom DemandRansomware Cost

In 2025, lawsuits were filed in 68 of 482 disclosed data security incidents, up from 51 of 518 in 2024.

LitigationData Security IncidentLawsuit

Phishing was the leading cause of data security incidents, accounting for 30%.

PhishingData Security Incident Cause

The average ransomware payment increased 36% to $682,702 compared to the previous year.

RansomwareRansom PaymentRansomware Cost