Security budgets get approved with numbers, not adjectives. This page collects the penetration testing and breach statistics that actually move decisions, drawn from the primary industry reports (IBM, Verizon, Cybersecurity Ventures, the CVE program, and the major market analysts), with a source for every figure so you can cite them in a board deck, a budget request, or your own writing. We update it as the annual reports land.
How to cite: link to this page or to the primary source listed beside each figure. Every number below is attributed.
1. What a breach costs
- $4.44 million: the global average cost of a data breach in 2025, down 9% from $4.88 million the year before, the first decline in five years, driven largely by faster containment. (IBM Cost of a Data Breach Report 2025)
- $10.22 million: the average cost of a breach for US organizations in 2025, an all-time high and up 9% year over year, even as the global figure fell. (IBM 2025)
- 241 days: the mean time to identify and contain a breach in 2025, the lowest in nine years. Shorter detection is the main reason global costs dropped. (IBM 2025, via CyberScoop)
What this means for testing: the US number is the one that matters for a New York company, and it is going the wrong direction. Against a $10.22 million average, a fixed-price penetration test is a rounding error. See how much a penetration test costs for the real market range.
2. How attackers actually get in
From Verizon’s 2025 Data Breach Investigations Report, which analyzed more than 22,000 security incidents including 12,195 confirmed breaches:
- 22% of breaches began with stolen credentials, the single most common initial access vector. (Verizon DBIR 2025)
- 20% of breaches began with exploitation of a vulnerability, and vulnerability exploitation as an initial access vector grew 34% year over year, with a heavy focus on zero-days in perimeter devices and VPNs. (Verizon DBIR 2025)
- 30% of breaches involved a third party, double the previous year’s share. (Verizon DBIR 2025)
What this means for testing: the top two initial access vectors, credentials and exploitable vulnerabilities, are precisely what an external network test and a phishing and social engineering assessment measure. The third-party figure is why enterprise customers now send security questionnaires to every vendor, and why a current penetration test report has become a sales document as much as a security one.
3. Ransomware
- 44% of breaches in the 2025 DBIR involved ransomware, up 37% from the prior year. (Verizon DBIR 2025)
- $57 billion: projected global ransomware damage costs in 2025, which works out to roughly $156 million per day. (Cybersecurity Ventures)
- $275 billion: projected annual ransomware damage by 2031, with an attack every two seconds. (Cybersecurity Ventures)
What this means for testing: ransomware operators get in through the same doors as everyone else (credentials, exposed services, unpatched perimeter devices) and then spread laterally. The spread is what an internal network penetration test measures, and flat networks with weak Active Directory hygiene are where a single compromised laptop becomes a company-wide event. Our guide to how ransomware attacks work traces the full chain.
4. The vulnerability firehose
- 48,185 CVEs were published in 2025, a 20.6% increase over 2024 and the highest annual total on record, roughly 131 new vulnerability disclosures every day. (Jerry Gamblin, 2025 CVE Data Review; The Stack)
- Counting methods vary by source; an alternative tally puts 2025 at 46,407 CVEs, up 16% from 40,009 in 2024, or about 127 per day. Either way, 2025 set a record. (Socket; DeepStrike)
What this means for testing: at more than a hundred new disclosures a day, an annual point-in-time test describes a system that no longer exists by the time the report is filed. This is the arithmetic behind continuous penetration testing and validated vulnerability scanning between manual tests, the model our penetration testing as a service program is built on. The vulnerability count is also why “we patch monthly” is not a security posture; the DBIR’s 20% exploitation figure is what happens in the gap.
5. The size of cybercrime
- $10.5 trillion: the projected annual global cost of cybercrime in 2025, which if measured as a country would be the world’s third-largest economy after the US and China. (Cybersecurity Ventures)
- $12.2 trillion: the projected annual cost by 2031. (Cybersecurity Ventures, Official Cybercrime Report 2025)
- 15% per year: the expected growth rate of global cybercrime costs, from $3 trillion in 2015. (Cybersecurity Ventures)
6. The penetration testing market
The analyst firms disagree on the exact size, which is itself worth knowing before you quote one number as fact. The range for 2025:
- $1.98 billion (2025), growing at 14.2% CAGR to 2031. (MarketsandMarkets)
- $2.36 billion (2025) and $2.72 billion (2026), growing at 15.29% CAGR from 2026 to 2031; North America held a 35.1% share in 2025. (Mordor Intelligence)
- $2.74 billion (2025) and $3.09 billion (2026), growing at 11.6% CAGR through 2034. (Fortune Business Insights)
- $3.36 billion (2025), growing at 20% CAGR from 2026 to 2033. (Data Bridge Market Research)
The consistent story across all four: a $2 to 3 billion market growing 12 to 20% a year, with North America the largest region. The growth is compliance-driven (SOC 2, PCI DSS, HIPAA, NYDFS 500, and CMMC all expect testing) and customer-driven (the third-party breach share above).
7. What the numbers add up to
Put the primary sources side by side and a clear picture emerges:
- Breaches are expensive and, in the US, getting more so ($10.22 million average).
- Attackers arrive through credentials and exploitable vulnerabilities (22% and 20% of breaches), the two things penetration testing directly measures.
- Ransomware is in nearly half of breaches (44%), and it spreads through internal networks that were never tested from the inside.
- New vulnerabilities appear faster than annual testing can track (131 a day), which argues for continuous coverage.
- Your customers’ breaches are increasingly your problem (30% third-party involvement), which is why they now demand your test report.
The practical conclusion is not “test more.” It is: test the external perimeter and credentials at least annually, test the internal network before ransomware does, and if you ship software weekly, move to a cadence that matches. Every one of those engagements has a fixed price at Invadel, and every one includes a free retest.
Frequently asked questions
How often is this page updated? When the primary annual reports publish: IBM’s Cost of a Data Breach (typically mid-year), Verizon’s DBIR (typically spring), and the CVE program’s year-end totals. Check the source links for the newest edition.
Why do the market-size figures differ so much? Each analyst defines the market differently (some include automated scanning platforms, some only services) and uses different survey bases. Quote a range, or name the firm whose definition matches your use.
Which single statistic should I use in a budget request? For a US company, the $10.22 million average breach cost from IBM 2025, alongside the DBIR’s 20% of breaches starting from an exploitable vulnerability. Together they say: the thing a penetration test finds is one of the top two ways breaches start, and a breach costs eight figures.
Can I reuse these statistics? Yes. Cite the primary source listed with each figure, and feel free to link this page as the compilation.
Sources
- IBM Cost of a Data Breach Report 2025
- CyberScoop coverage of IBM 2025
- Verizon 2025 Data Breach Investigations Report
- Cybersecurity Ventures: cybercrime $10.5 trillion by 2025
- Cybersecurity Ventures: Official Cybercrime Report 2025
- Cybersecurity Ventures: ransomware $57B in 2025
- Cybersecurity Ventures: ransomware $275B by 2031
- Jerry Gamblin: 2025 CVE Data Review
- The Stack: 2025 CVE analysis
- Socket: CVE volume in 2025
- DeepStrike: vulnerability statistics 2025
- MarketsandMarkets penetration testing market
- Mordor Intelligence penetration testing market
- Fortune Business Insights penetration testing market
- Data Bridge penetration testing market
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →