Ponemon Institute is pleased to present the findings of the 2026 Cost of Insider Risks: Global study. Sponsored by DTEX, this is the seventh benchmark study conducted to understand the financial consequences of insider threats caused by careless or negligent employees or contractors, criminals or malicious insiders or credential thieves.
As revealed in this research, organizations face increasing costs to respond to insider security incidents. Since the 2018 study, the number of organizations represented in the research has more than doubled from 156 to 354 in 2025 and the average number of incidents discovered and analyzed in this research increased from 3,269 to 7,490 in 2025. The average time to contain the incident decreased significantly in 2025 to 67 days from 81 days in 2024. However, only 13 percent of incidents were contained in less than 30 days.
This cost study is unique in addressing the core systems and business process-related activities that drive a range of expenditures associated with a company’s response to insider negligence and criminal behaviors. In this research, we define an insider-related incident as one that results in the diminishment of a company’s core data, networks or enterprise systems. It also includes attacks perpetrated by external actors who steal the credentials of legitimate employees/users (i.e., imposter risk).
The first study was conducted in 2016 and focused exclusively on companies in North America. Since then, the research has been expanded to include organizations in EMEA and Asia-Pacific with a global headcount of less than 500 to more than 75,000. In this year’s study, we interviewed 8,750 IT and IT security practitioners in 354 organizations that experienced one or more material events caused by an insider.
The most prevalent insider security incident continues to be caused by careless or negligent employees.
According to the findings, 53 percent of incidents experienced by organizations represented in this research were due to employee negligence and the average annual cost to remediate these incidents was $10.3 million. Not as frequent are incidents involving criminal or malicious insiders (27 percent of incidents) and credential theft (20 percent of incidents). The average cost per malicious or criminal incidents is $4.7 million and the average cost for credential theft is $4.5 million.
As shown in this research, the cost of insider risk varies significantly based on the type of incident. The activities that drive costs are monitoring & surveillance, investigation, escalation, incident response, containment, ex-post analysis and remediation.
The following are the most salient findings from this research.
The negligent insider is the root cause of most incidents. The average number of negligent insider incidents is 13.8 in this year’s study and the average cost for each incident is $747,107. There are a variety of reasons employees can put their organizations at risk. These include not ensuring their devices are secured, not following the organization’s policies for safeguarding sensitive and confidential information and forgetting to patch and upgrade to the latest version.
Malicious insiders accounted for an average of 6.3 incidents and the average cost per incident of $742,125. In the context of this research, malicious insiders are employees or authorized individuals who use their data access for harmful, unethical or illegal activities. Because of their potentially wider access to an organization’s sensitive and confidential data, malicious insiders are harder to detect than incidents caused by external attackers or hackers.
Credential theft incidents average $842,462 per incident, an increase from $779,707 in 2024 and continues to be the costliest. The average number of credential theft incidents increased from 4.8 in 2024 to 5.3 in 2025. The intent of the credential thief is to steal users’ credentials that will grant them access to critical data and information. These attackers commonly use phishing.
Insider security incidents in 2025 cost more and their frequency is increasing. According to the 2024 research, 57 percent of companies experienced between 21 and more than 40 incidents per year. This year, 68 percent of organizations had between 21 and more than 40 incidents.
The research analyzed the impact security technologies and activities can have on reducing costs. Privileged access management (PAM) can save an average of $6.1 million and user behavior analytics (UBA) saves $5.1 million.
Technology and disruption or downtime are the most significant financial consequences when dealing with insider incidents. The research presents the average percentage of insider cost for careless or negligent employees, criminal insiders and credential theft according to the following seven consequences: Disruption cost (downtime), direct & indirect labor, technology, cash outlays, process/workflow changes, revenue losses and overhead.
The cost incurred by technologies (30 percent of the average cost of financial consequences) involves technologies used to respond to the insider incident includes the amortized value and the licensing for software and hardware that are deployed. Business disruption includes diminished employee/user productivity (19 percent of the average cost of financial consequences).
Companies spend the most on containment of the insider security incident. An average of $247,587 is spent to contain the consequences of an insider incident. The least amount of average cost is for escalation $39,728. The faster containment occurs, the lower the cost. If it takes more than 90 days, the average cost is $21.9 million. If it takes less than 30 days, the average cost is $14.2 million.
North American companies are spending more than the average annualized cost of $19.5 million on activities that deal with insider threats. Companies in North America experienced the highest average total cost at $24 million. European companies had the next highest cost at $18.6 million.
Health and pharma have the highest average activity costs. The average activity cost for health and pharma is $28.8 million. Technology and software are the next highest at $24.2 million.
Organizational size affects the cost. The cost of incidents varies according to organizational size. Large organizations with a headcount of more than 75,000 spent an average of $28.4 million over the past year to resolve insider-related incidents. To deal with the consequences of an insider incident, smaller-sized organizations with a headcount below 500 spent an average of $8.9 million.
Five signs that your organization is at risk
- Employees are not trained to fully understand and apply laws, mandates, or regulatory requirements related to their work and that affect the organization’s security.
- Employees are unaware of the steps they should take at all times to ensure that the devices they use—both company issued and BYOD—are secured at all times.
- Employees are sending highly confidential data to an unsecured location in the cloud, exposing the organization to risk.
- Employees break your organization’s security policies to simplify tasks.
- Employees expose your organization to risk if they do not keep devices and services patched and upgraded to the latest versions at all times.
To read the full findings of this report, visit DTEX’s website by clicking here.


