Key Takeaways
- 2.5x lower costs for organizations that used encryption for data at rest (IBM Cost of a Data Breach 2023).
- 23% of breaches involve “weaknesses in system configuration” (Verizon DBIR 2024).
- 41% of breaches involve the use of valid accounts (Mandiant/Google Cloud Threat Intelligence 2024/2023).
- USD 3.2 million average annual cost of downtime for enterprises (BCDR/uptime benchmark figures in Gartner/industry surveys consolidated in 2023–2024).
- 2.4x more common data loss due to accidental deletion than due to cyberattacks (Backblaze data loss findings, 2023/2024).
- 9.1% of organizations have lost data due to storage failures in the past year (IDC/industry survey findings in 2023–2024 on storage reliability).
- 2.9 million phishing attacks were detected in the first half of 2024 by APWG (Anti-Phishing Working Group) reporting.
- 5,487 vulnerabilities were listed as actively exploited in the CISA KEV Catalog as of 2024 (count as published on the KEV page).
- 58% of organizations reported using immutable backups (2024 Druva survey).
- NIST SP 800-53 Rev. 5 includes 44 controls related to 'Recovery' capabilities across 'Contingency Planning' and 'System and Communications Protection' (controls cataloged in the publication).
- The EU GDPR mandates informing affected individuals 'without undue delay' when the breach is likely to result in high risk (GDPR Article 34).
- NIST SP 800-61 Rev. 2 recommends using a severity model to prioritize incident response decisions (incident handling guidance, with explicit severity levels in the publication).
- U.S. HIPAA breach notification rules require notification to HHS within 60 days of discovery of breaches affecting 500 or more individuals (HIPAA Breach Notification Rule).
- 68% of organizations reported that they do not have a reliable way to recover data quickly, which increases the likelihood of prolonged data unavailability after loss events
- Ransomware victims reported average downtime of 22 days in 2023, which drives prolonged data unavailability and downstream data-loss risk
Encryption, strong recovery, and immutable backups help curb costly downtime and reduce preventable data loss.
Related reading
01 · Category
Controls Effectiveness1 stats
Controls Effectiveness Interpretation
02 · Category
Attack Vectors2 stats
Attack Vectors Interpretation
03 · Category
Impact Outcomes1 stats
Impact Outcomes Interpretation
04 · Category
Risk Prevalence2 stats
Risk Prevalence Interpretation
05 · Category
Threat Landscape1 stats
Threat Landscape Interpretation
06 · Category
Root Causes1 stats
Root Causes Interpretation
07 · Category
Mitigation Practices2 stats
Mitigation Practices Interpretation
More related reading
08 · Category
Compliance & Reporting3 stats
Compliance & Reporting Interpretation
09 · Category
Recovery Metrics2 stats
Recovery Metrics Interpretation
10 · Category
Operational Risk1 stats
Operational Risk Interpretation
11 · Category
Industry Trends1 stats
Industry Trends Interpretation
12 · Category
Market Size2 stats
Market Size Interpretation
13 · Category
Cost Analysis1 stats
Cost Analysis Interpretation
Where Data Loss Comes From
Accidental issues are more common than cyberattacks, while many orgs still lack reliable recovery options.
Cite This Report
This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.
Helena Kowalczyk. (2026, February 13). Data Loss Statistics. Gitnux. https://gitnux.org/data-loss-statistics
Helena Kowalczyk. "Data Loss Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/data-loss-statistics.
Helena Kowalczyk. 2026. "Data Loss Statistics." Gitnux. https://gitnux.org/data-loss-statistics.
Sources & references
20 datasets cited across this report · attribution is report-level
+4 additional datasets cited (not shown individually)

