Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What does a breach investigation cost?

Updated

A breach investigation (DFIR) is one bill, not the IBM total-breach average and not a GDPR or CRA fine. Cost drivers set the range; this page is not a quote. Not legal advice. Not financial advice.

Operational guidance, last verified 7 September 2026 against IBM's Cost of a Data Breach Report 2025 (Ponemon Institute research, sponsored and analyzed by IBM; 600 organizations, March 2024 through February 2025; industry survey, not a statute, not a quote for YOUR incident), Regulation (EU) 2016/679 (GDPR) Article 83 on EUR-Lex (administrative-fine MAXIMUM schedule, not a typical fine, not an investigation cost), and Regulation (EU) 2024/2847 (Cyber Resilience Act) Article 64 on EUR-Lex (a separate manufacturer-penalty MAXIMUM schedule). This page does not sell investigations, does not invoice a DFIR engagement, does not quote a ShipReady investigation fee, does not interpret YOUR cyber policy, does not rank DFIR firms, does not name any, does not invent hourly rates, and is not a substitute for counsel, your insurer, a retained DFIR firm, or a finance lead. The incident-response-retainer page on this site is the retainer explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. The questions-to-ask-an-incident-response-provider page on this site is the question bank, including cost-model questions. A dedicated incident-reporting-deadlines guide is not on this site yet. Not legal advice. Not financial advice. Not coverage advice. Not procurement advice.

This is a cost-driver explainer, not a quote and not YOUR invoice

Audience: a founder, CFO-adjacent leader, CISO, counsel, or incident commander who needs to budget a breach investigation without treating a headline as a quote. The incident-response-retainer page on this site is the commercial-structure explainer (retainer versus on-demand, typical terms as generic market design — not YOUR SOW). The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. The questions-to-ask-an-incident-response-provider page on this site is the question bank, including what draws hours. The when-you-need-dfir page on this site is the retain-or-not tree. The how-to-select-a-dfir-provider page on this site is the selection decision tree. The what-is-dfir page on this site is the DFIR explainer. The best-digital-forensics-firms page on this site is the inclusion-criteria checklist. The chain-of-custody page on this site is the handling record. The we've-been-breached page on this site is the first-moves hub. The first-15-minutes page on this site is the first-moves checklist. The preserve-evidence page on this site is the order-of-volatility checklist. It does not rank DFIR firms, does not name any, and is not a directory. It is not a rate card. The best-incident-response-firms page on this site is the inclusion-criteria checklist. The information-to-give-a-dfir-firm page on this site is the intake checklist. The comparing-major-incident-response-providers page on this site is the named-brand criteria table (not a ranking; inclusion is not endorsement). A dedicated incident-reporting-deadlines guide is not on this site yet.

Three different numbers get conflated under 'what does a breach cost': (a) the DFIR / investigation invoice for capture, analysis, and reporting; (b) the IBM Cost of a Data Breach total, which sums four activity-based categories over a two-year window; and (c) legal and regulatory penalties (for context, GDPR Article 83 and CRA Article 64 MAXIMUM schedules). Investigation is not total breach is not a fine. IBM's 2025 global average TOTAL is USD 4.44 million (down from USD 4.88 million in 2024) — industry data, not a statute, not YOUR cost, and not what a DFIR firm charges. This page does not invent hourly rates, does not invent a 'typical retainer', and does not present a single dollar figure as 'the cost'. If a public vendor rate card is cited anywhere, it would be labelled as one published disclosure, dated, not a market average; this page does not reprint a paywalled rate card. Last verified 7 September 2026. Not legal advice. Not financial advice. Not coverage advice. Not procurement advice.

  • A DFIR investigation invoice is what the retained firm bills for THIS work class — capture, analysis, reporting, meetings, and, if asked, testimony. It is not a ranking and not YOUR quote until the SOW names the draw.
  • IBM's Cost of a Data Breach Report 2025 is an industry survey of 600 organizations (March 2024–February 2025). The USD 4.44 million global average is a TOTAL across four categories. Do not present it as an investigation quote.
  • GDPR Article 83 and CRA Article 64 are MAXIMUM administrative-fine schedules. They are not typical fines, not YOUR fine, and not the investigation invoice. This page does not start a notification clock and does not apply a penalty.
  • Cost drivers below move the DFIR bill. Empty answers are unknowns, not a pass. This page does not invent hour numbers or dollar figures.
  • This page does not sell investigations, does not invoice an engagement, does not quote a ShipReady investigation fee, does not interpret YOUR policy, does not rank DFIR firms, does not name any, is not a rate card, is not legal advice, and is not financial advice.

Three different numbers people conflate

A DFIR invoice, an IBM total-breach average, and a statutory fine ceiling are not the same kind of number. Mixing them is how a founder budgets the wrong envelope. Last verified 7 September 2026. Not legal advice. Not financial advice.

Investigation cost vs total breach cost vs legal/regulatory penalties (not a quote, not YOUR invoice, not a ranking, not legal advice, not financial advice)
Number people quoteWhat it actually isWhat it is not
(a) DFIR / investigation costWhat a retained digital-forensics and incident-response firm bills for capture, analysis, reporting, and related work on THIS incident. The SOW names what draws hours (or on-demand fees) and what is out of scope. The questions-to-ask-an-incident-response-provider page on this site is that cost-model checklist.Not the IBM USD 4.44 million global average. Not a GDPR or CRA fine. Not a rate this page will invent. Not a ranking of firms. This page does not invent hourly rates.
(b) Total breach cost — IBM four categoriesIBM Cost of a Data Breach Report 2025 (industry survey, not a statute, not a quote for YOUR incident): activity-based costing across detection and escalation, notification, post-breach response, and lost business. Global average TOTAL: USD 4.44 million (down from USD 4.88 million in 2024, a 9 percent decrease). United States average TOTAL: USD 10.22 million. Sample: 600 organizations, March 2024 through February 2025; excludes very small and very large breaches (report: about 2,960–113,620 compromised records).Not a DFIR invoice. Detection and escalation (USD 1.47 million average, a nearly 10 percent drop) is the closest IBM bucket to investigation — it includes assessment and audits, crisis management, and communications to executive leadership and boards, and is still not what a DFIR firm charges. Lost business is a separate IBM bucket. Do not present USD 4.44 million as an investigation quote.
(c) Legal / regulatory penaltiesGDPR Article 83: administrative fines of up to EUR 10 million, or 2 percent of worldwide annual turnover, whichever is higher (Article 83(4)); and up to EUR 20 million, or 4 percent of worldwide annual turnover, whichever is higher (Article 83(5)). CRA Regulation (EU) 2024/2847 Article 64 is a separate manufacturer-penalty schedule: Article 64(2) sets administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2.5 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher, for non-compliance with Annex I essential cybersecurity requirements and the obligations in Articles 13 and 14. Lesser tiers sit in Article 64(3) and Article 64(4).A MAXIMUM schedule, not a typical fine, not YOUR fine, and not an investigation cost. Applicability is a counsel question. This page does not start a clock, does not decide that GDPR or CRA applies, and does not apply a penalty. A dedicated incident-reporting-deadlines guide is not on this site yet. Not legal advice.

Cost drivers — why the investigation bill moves

These drivers move a DFIR / investigation invoice. They are not a scoring model and not a price list. Combine them with counsel and finance; do not treat any one cell as 'the cost'. This page does not invent hourly rates. Last verified 7 September 2026. Not legal advice. Not financial advice. Not procurement advice.

Breach-investigation cost drivers (why the bill moves — not a rate card, not YOUR invoice, not a ranking, not legal advice, not financial advice)
DriverWhy it moves the billLimit — this is not a quote
ScopeHow many systems, accounts, and log sources are in play, and whether the work is host/disk, cloud identity and logs, mobile, or OT. Cloud API collection is not the same as a write-blocked disk image. OT is not a host-image lab by default.Scope is a class of work, not a named case study this page will invent. The how-to-select-a-dfir-provider page on this site is the scope tree. Empty answers are unknowns.
Data classCardholder data (PFI-class investigation), special-category personal data, trade secrets, or OT change who is qualified to do the work and how evidence is handled. A neighbouring accreditation class is not a pass.Data class is a factor. It is not, by itself, a dollar figure. PFI is a cardholder-data investigation class, not a general price mark. This page does not invent a premium.
Volatility / preservationLive memory, rotating logs, and cloud audit trails decay. Order-of-volatility capture (RFC 3227 teaching sequence) is time-sensitive. Reimaging before a forensic image exists destroys evidence and often expands later work. The preserve-evidence page on this site is that checklist.Preservation is a cost driver because delay expands scope. It is not a reason this page will invent a rush fee. Capture first; shop second.
JurisdictionWhere the work is done, where images and working papers live, who can testify, and whether a DPA is needed for personal data on the evidence. A regional CIR listing is a regional class, not a global licence.Jurisdiction is a selection criterion, not a price this page will invent. Counsel maps data residency. This page does not draft YOUR DPA.
Surge / hoursAfter-hours staffing, weekend start, and how fast the firm can put trained people on THIS class of work. A retainer reserves surge; on-demand uses whatever the firm can staff that day. The incident-response-retainer page on this site is that explainer.A marketing SLA is not a ranking and not a statute. This page does not invent hour numbers. Read what the SOW actually staffs.
Lab versus consultingForensic lab work (imaging, parsing, tool-backed examination) and consulting hours (scoping, briefings, report writing, meetings) often draw different lines on the same SOW. Mixing them into a blended 'investigation' line hides the draw.Ask what draws the bank. This page does not invent a lab rate or a consulting rate. A blended rate with no scope is a red flag on the questions-to-ask-an-incident-response-provider page on this site.
TravelOn-site collection versus remote collection. Travel, waiting, and after-hours on-site work are separate draws when the SOW names them.Remote versus on-site is a method and access question, not a quality ranking. This page does not invent a per-diem.
TestimonyExpert-witness preparation and time in a forum is often a different draw from investigation. Expert-witness standing is not a public roster. Court-admissibility is a legal question on YOUR facts.This page does not score witnesses and does not invent a testimony rate. Ask whether named examiners will testify if counsel asks. Not legal advice.
Dual-track counselCounsel-directed DFIR is common practice so working papers can sit under attorney-client privilege and work-product. You may pay counsel and DFIR on the same incident. That is practice, not a ruling that privilege will attach. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.Dual-track is a cost driver, not a statute. Signing a favourite-firm SOW and then asking counsel to wrap privilege around it is the reverse of common practice. Not legal advice.

Worked cost-driver example — a fictional scenario, ranges not a quote

This is a labeled fictional scenario so a founder and finance can see the three-number distinction without a fabricated price. It is not YOUR incident, not a benchmark, and not a reason to buy. Ranges below are sourced IBM survey figures and statutory MAXIMUM schedules — not a DFIR quote, not a typical fine, and not an ROI. This page does not invent hourly rates, hour counts, or a single dollar figure presented as 'the cost'. Last verified 7 September 2026. Not financial advice. Not legal advice. Not coverage advice.

Fictional cost-driver example (not YOUR incident, not a quote, not a price list, not legal advice, not financial advice)
EnvelopeWhat this fictional scenario runs intoRange / source — not a quote
The facts (fictional)Friday 22:00. An 80-person B2B SaaS. EU customers plus some US. Suspected access to a production database that holds customer PII. Theft unknown. Cloud identity and logs in play, not a single laptop. No IR retainer. Counsel has not yet directed a firm. A cyber form may have a panel clause — unverified.Fictional. Not YOUR estate. Empty answers (panel, theft, clocks) are unknowns, not a pass. Preserve first. The we've-been-breached page on this site is the first-moves hub. The preserve-evidence page on this site is the order-of-volatility checklist.
(a) DFIR / investigationDrivers that will move THIS bill: cloud identity and logs (not disk-only), EU data-residency for working papers, order-of-volatility capture while logs rotate, after-hours surge with no pre-signed retainer, counsel-directed dual-track still to be set, possible later testimony. Out of scope of a typical DFIR SOW: customer notification, credit monitoring, ransom, restoration, crisis communications — often separate vendors.Unknown until scoped. This page does not invent a dollar figure, an hourly rate, or a 'typical' investigation price. Ask the SOW what draws hours and what happens at zero of a retainer bank. The questions-to-ask-an-incident-response-provider page on this site is that checklist. The incident-response-retainer page on this site is retainer versus on-demand. Not financial advice.
(b) IBM total-breach contextIf this incident were in the IBM 2025 sample — it may not be; the report excludes very small and very large breaches (about 2,960–113,620 records) — the global average TOTAL is USD 4.44 million and the United States average TOTAL is USD 10.22 million. Detection and escalation, the closest IBM bucket to investigation, averaged USD 1.47 million and includes assessment, audits, crisis management, and board communications.IBM Cost of a Data Breach Report 2025 (industry survey, not a statute, not a quote for YOUR incident). USD 4.44 million is the sum of four categories, not a DFIR invoice. USD 1.47 million is still not what a DFIR firm charges. Do not budget this company's investigation as 4.44 million. Not financial advice.
(c) Legal / regulatory penaltiesIf GDPR applies, Article 83 is a MAXIMUM schedule (EUR 10 million or 2 percent; EUR 20 million or 4 percent — whichever is higher in the applicable tier). If CRA applies to a manufacturer of a product with digital elements, Article 64 is a separate MAXIMUM schedule (Article 64(2): up to EUR 15 000 000 or 2.5 percent of worldwide annual turnover, whichever is higher). Applicability is a counsel question. A dedicated incident-reporting-deadlines guide is not on this site yet.Ceilings, not typical fines, not this company's fine, and not the investigation invoice. This page does not start a clock and does not apply a penalty. Not legal advice.
What this example is notNot a claim that on-demand always costs more than a retainer. Not a claim that a retainer pays for itself. Not a ranking of firms. Not a product this site sells.Not YOUR ROI. Not a fabricated statistic. Not a quote you can send to finance as 'the cost'. Not legal advice. Not financial advice.

Retainer versus on-demand, and costs that are not the investigation invoice

A retainer reserves surge before an incident; on-demand is scoped after the incident is already running. Neither model is a ranking. Neither is a price this page will invent. Hidden costs below are real envelopes — they are labelled as not the DFIR investigation invoice. Last verified 7 September 2026. Not legal advice. Not financial advice. Not coverage advice.

Retainer vs on-demand, and hidden costs that are not the investigation invoice (not a quote, not a ranking, not legal advice, not financial advice)
ItemWhat it isWhat it is not
IR / DFIR retainerA pre-signed contract — typically prepaid hours plus a named response-time term — so a firm can start without a new procurement. The incident-response-retainer page on this site is the explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree.Not a legal duty. Not a ranking. Not YOUR SOW. Not a price this page will invent. Unused prepaid hours are a reservation cost, not a quality score. This page does not invent a 'typical retainer' dollar figure.
On-demand engagementWork scoped after intake, often at a different rate card the SOW names. Surge is whatever the firm can staff that day. Panel and notice clauses still apply if YOUR form has them.Not a failure. Not 'the cheap option' this page will price. Not a reason to skip panel, class, jurisdiction, or scope.
Business interruption / lost businessDowntime, customer churn, reputational damage. IBM's lost-business category sits inside the TOTAL breach cost, not on the DFIR invoice.NOT the investigation invoice. Do not add IBM lost-business into a DFIR budget line. Not financial advice.
NotificationTelling affected people, regulators, or customers when a duty applies. IBM's notification category is a TOTAL-breach bucket. Counsel maps which clocks apply. A dedicated incident-reporting-deadlines guide is not on this site yet.NOT the investigation invoice. A forensic report is not a GDPR Article 33 notice and not a CRA Article 14 filing. This page does not start a clock. Not legal advice.
Credit monitoring / identity protectionA common post-breach response spend in some jurisdictions and some IBM post-breach-response lines.NOT the investigation invoice. Often a separate vendor, sometimes a separate panel vendor on the same cyber form.
CounselPrivilege-and-engagement, clocks, DPA, and whether a duty exists. Dual-track (counsel retains DFIR) is common practice. The contact-breach-counsel page on this site is that checklist.NOT the DFIR invoice, even when the two bills travel together. Not a ruling that privilege will attach. Not legal advice.
Regulator / administrative finesGDPR Article 83 and CRA Article 64 MAXIMUM schedules, plus other regimes counsel maps. IBM's US-average TOTAL (USD 10.22 million) notes higher regulatory fines as one driver of the US figure — still industry data, not YOUR fine.NOT the investigation invoice. A MAXIMUM is not a typical fine. This page does not apply a penalty. Not legal advice.
Cyber insuranceMay cover DFIR costs subject to panel, prior consent, notice, retention, and limits. NAIC cyber-claims materials describe panel-vendor and prior-agreement designs. Verify YOUR policy. The contact-cyber-insurance page on this site is the notice-and-panel checklist.Not a quote. Not coverage advice. A panel is a contract role, not a quality ranking. This page does not interpret YOUR form.

Budgeting checklist (printable)

Print this page. Walk the list with the commander, counsel, and finance before you sign a SOW or treat a headline as a budget. Empty answers are unknowns, not a pass. Last verified 7 September 2026. Not legal advice. Not financial advice. Not coverage advice. Not procurement advice.

  • Separate three envelopes: (a) DFIR / investigation, (b) total-breach categories IBM uses (detection and escalation, notification, post-breach response, lost business), (c) legal and regulatory penalties. Do not collapse them into one number.
  • Do not budget the investigation as IBM's USD 4.44 million global average or USD 10.22 million United States average. Those are TOTAL-breach survey figures, not a DFIR quote. IBM Cost of a Data Breach Report 2025 is industry data, not a statute, not a quote for YOUR incident.
  • Do not budget the investigation as a GDPR Article 83 or CRA Article 64 MAXIMUM. Those are fine ceilings, not typical fines, and not the DFIR invoice.
  • Walk the cost-driver table: scope, data class, volatility/preservation, jurisdiction, surge/hours, lab versus consulting, travel, testimony, dual-track counsel. Empty cells are unknowns.
  • If you have a cyber policy, notice the carrier before you pick a non-panel firm. Panel is a contract role, not a ranking. Verify YOUR policy. The contact-cyber-insurance page on this site is that checklist. Not coverage advice.
  • Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Dual-track is a cost driver, not a statute.
  • Ask what draws hours (capture, analysis, reporting, meetings, testimony) and what happens at zero of a retainer bank (true-up, stop, on-demand rates the SOW names). The questions-to-ask-an-incident-response-provider page on this site is that bank. This page does not invent hour numbers.
  • Name out-of-scope items that are not the investigation invoice: ransom negotiation, restoration, customer notification, credit monitoring, crisis communications — often separate panel vendors.
  • Walk retainer versus on-demand with finance. The incident-response-retainer page on this site is the explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. This page does not invent a typical retainer price and does not invent ROI.
  • Preserve first. A firm you have not engaged cannot image a host you already rebuilt. The preserve-evidence page on this site is the order-of-volatility checklist. The we've-been-breached page on this site is the first-moves hub.
  • A dedicated incident-reporting-deadlines guide is not on this site yet. Counsel maps which clocks apply. This page does not start a clock.
  • This page is not a quote, not a rate card, not a ranking, not legal advice, and not financial advice.

Glossary — cost language you will hear

Short definitions so a founder, finance, and counsel can read the same invoice. They are not legal definitions and not YOUR quote. Last verified 7 September 2026. Not legal advice. Not financial advice.

Breach-investigation cost glossary (operational names — not legal definitions, not YOUR invoice, not a ranking)
TermMeaning on this page
DFIR / investigation costWhat a retained digital-forensics and incident-response firm bills for capture, analysis, reporting, and related work. Not the IBM total. Not a fine.
Total breach cost (IBM)IBM Cost of a Data Breach Report 2025 activity-based TOTAL across four categories. Industry survey, not a statute, not YOUR cost. Global average USD 4.44 million. United States average USD 10.22 million.
Detection and escalationIBM bucket closest to investigation: assessment and audits, crisis management, communications to executive leadership and boards. 2025 average USD 1.47 million. Still not a DFIR invoice.
Notification (IBM category)IBM TOTAL-breach bucket for contacting affected people and regulators. Not the DFIR invoice. Not a determination that a duty applies.
Post-breach responseIBM TOTAL-breach bucket that can include help desk, legal, and identity-protection spends. Not the DFIR invoice.
Lost businessIBM TOTAL-breach bucket for interruption, churn, and reputation. Not the DFIR invoice.
Administrative fine / penaltyA statutory MAXIMUM schedule (GDPR Article 83; CRA Article 64) or another regime counsel maps. Not a typical fine. Not the investigation invoice.
RetainerA pre-breach contract that reserves DFIR / IR surge. Not a price this page will invent. The incident-response-retainer page on this site is the explainer.
On-demandScoping and retaining a firm after the incident is already running. Not 'the cheap option' this page will price.
True-upA later invoice when you exceed the hour bank, often at a rate the SOW names. This page does not invent that rate.
Hidden costA real envelope that is not the DFIR investigation invoice: interruption, notification, credit monitoring, counsel, regulator. Label it separately.
Dual-track counselCounsel retains and directs DFIR so working papers can sit under privilege. Common practice, not a ruling. Two bills, not one.
Rate cardA vendor's published or quoted prices. One published disclosure, dated, is not a market average. This page does not invent hourly rates and does not reprint a paywalled rate card.

What you need to do now

Order is the failure mode. Treating IBM's USD 4.44 million as the investigation quote, or a GDPR ceiling as the DFIR budget, is how finance gets the wrong envelope. The sequence below is practice, not a statute. Last verified 7 September 2026. Not legal advice. Not financial advice. Not coverage advice. Not procurement advice.

  • If you are mid-incident, preserve first. Do not reimage or rotate logs before capture. Do not shop a quote on the incident clock. The we've-been-breached page on this site is the first-moves hub. The first-15-minutes page on this site is the first-moves checklist. The preserve-evidence page on this site is the order-of-volatility checklist.
  • Separate the three numbers: DFIR / investigation, IBM-style total-breach categories, penalties. Print the budgeting checklist above.
  • Walk the retain-or-not tree with the commander and counsel. The when-you-need-dfir page on this site is that tree. If you do not need a firm, stop.
  • If you have a cyber policy, notice the carrier before you pick a non-panel firm. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
  • Counsel-directed engagement is common practice. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
  • Select on stated criteria, not a blog list. The how-to-select-a-dfir-provider page on this site is that tree. The best-digital-forensics-firms page on this site is the roster checklist. This page does not rank firms and does not name any.
  • Ask the cost-model questions: what draws hours, lab versus consulting, travel, testimony, out of scope. The questions-to-ask-an-incident-response-provider page on this site is that bank. This page does not invent dollar figures.
  • Walk retainer versus on-demand. The incident-response-retainer page on this site is the explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. This page does not invent ROI.
  • A dedicated incident-reporting-deadlines guide is not on this site yet. The information-to-give-a-dfir-firm page on this site is the intake checklist. The comparing-major-incident-response-providers page on this site is the named-brand criteria table (not a ranking; inclusion is not endorsement). The best-incident-response-firms page on this site is the inclusion-criteria checklist.

Where this shows up in ShipReady Metrics

The signed-in app does not sell a DFIR retainer, does not invoice an investigation, does not quote a ShipReady investigation fee, does not interpret YOUR cyber policy, and does not start a notification clock. It does not rank forensic vendors, does not retain a DFIR firm, and does not produce a cost estimate. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it is not a cost estimate, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. Compliance surfaces also hold evidence artifacts (control-mapped collection and review for SOC 2 / ISO 27001-style programs — not a forensic exam and not a cost estimate). The cyber risk register lives under Security. The obligation map (frameworks you have marked in-scope) is under Compliance. Evidence and inventory the product already holds can be in-scope context a DFIR firm requests during scoping — scope-reducing in principle, not a dollar-savings claim, and not a claim that this product reduces IBM's USD 4.44 million average. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

IBM Cost of a Data Breach Report 2025 (Ponemon Institute research, sponsored, analyzed, and published by IBM): 600 organizations impacted by data breaches between March 2024 and February 2025, across 17 industries and 16 countries and regions; breaches ranged from 2,960 to 113,620 compromised records (very small and very large breaches excluded). Global average TOTAL USD 4.44 million (down from USD 4.88 million in 2024). United States average TOTAL USD 10.22 million. Detection and escalation USD 1.47 million average (a nearly 10 percent drop); that bucket includes assessment and audits, crisis management, and communications to executive leadership and boards. Four IBM categories: detection and escalation, notification, post-breach response, lost business. Industry survey, not a statute, not a quote for YOUR incident. Regulation (EU) 2016/679 (GDPR) Article 83 on EUR-Lex: administrative-fine MAXIMUM schedule — up to EUR 10 million or 2 percent of worldwide annual turnover, whichever is higher (Article 83(4)); up to EUR 20 million or 4 percent, whichever is higher (Article 83(5)). Regulation (EU) 2024/2847 (Cyber Resilience Act) Article 64 on EUR-Lex: separate manufacturer-penalty MAXIMUM schedule — Article 64(2) up to EUR 15 000 000 or 2.5 percent of worldwide annual turnover, whichever is higher, for Annex I and Articles 13 and 14; lesser tiers in Article 64(3) and Article 64(4). NIST SP 800-61 Revision 3 (April 2025) is guidance, not a statute; it does not price an investigation. NIST SP 800-86 remains the current final forensic-method guide this cluster cites — guidance, not a statute. NAIC cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. This page does not reprint a paywalled vendor rate card.

Frequently asked questions

What does a breach investigation cost?

It depends on cost drivers — scope, data class, volatility, jurisdiction, surge, lab versus consulting, travel, testimony, and dual-track counsel — and on the SOW that names what draws hours. It is not IBM's USD 4.44 million global average TOTAL, and it is not a GDPR or CRA fine. This page is a cost-driver explainer, not a quote. Not legal advice. Not financial advice.

Is the IBM USD 4.44 million figure what a DFIR firm charges?

No. IBM Cost of a Data Breach Report 2025 is an industry survey (600 organizations, March 2024–February 2025), not a statute and not a quote for YOUR incident. USD 4.44 million is the global average TOTAL across four categories. Detection and escalation (USD 1.47 million average) is the closest IBM bucket to investigation and is still not a DFIR invoice. Not financial advice.

Is a GDPR or CRA fine part of the investigation invoice?

No. GDPR Article 83 and CRA Article 64 are MAXIMUM administrative-fine schedules, not typical fines, not YOUR fine, and not the DFIR bill. Applicability is a counsel question. This page does not start a clock and does not apply a penalty. Investigation is not total breach is not a fine. Not legal advice. Not financial advice.

Does a retainer make the investigation cheaper?

A retainer reserves surge and a named start; on-demand is scoped after the incident is already running. Unused prepaid hours are a reservation cost, not a quality score. This page does not invent a typical retainer price and does not invent ROI. The incident-response-retainer page on this site is the explainer. The should-you-have-an-ir-retainer page on this site is the buy-or-wait tree. Not financial advice.

Does ShipReady Metrics sell investigations or quote a fee?

No. The product does not sell a DFIR retainer, does not invoice an investigation, does not quote a ShipReady investigation fee, does not interpret YOUR cyber policy, and does not start a notification clock. Signed-in app → Compliance → CRA reporting tracks a CRA Article 14 ladder from recorded awareness for CRA-in-scope findings; that is not a forensic exam and not a cost estimate. Not legal advice. Not financial advice.

Is this a ranking?

No. It is a cost-driver explainer: three numbers people conflate, a driver table, a fictional range example, retainer versus on-demand, and a budgeting checklist. This page does not rank DFIR firms, does not name any, and does not reprint a rate card. Not legal advice. Not financial advice.

Is this legal advice?

No. It is operational guidance distilled from IBM's Cost of a Data Breach Report 2025 (industry survey, not a statute), GDPR Article 83, and CRA Article 64 MAXIMUM schedules. Whether a duty applies, whether privilege attaches, whether a panel clause is satisfied, and which firm to retain are questions for counsel and YOUR policy. This page does not start a clock. Not financial advice.

Is this financial advice?

No. It is a cost-driver explainer with sourced ranges and caveats, not a quote, not a budget for YOUR incident, and not an ROI. IBM figures are industry survey averages, not YOUR cost. Statutory fine figures are MAXIMUM schedules, not typical fines. This page does not invent hourly rates. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.