Business · Risk Management
What a Security Incident Actually Costs a Company in 2026
IBM's 2026 report puts the average breach at $4.99M. Pentests run $4K-$30K, IR retainers $25K-$150K a year. Patching early is the cheapest line item.
Shashikant Gupta
6 min read
Sponsored
A pentest costs $4,000 to $30,000. A year of incident response retainer coverage costs $25,000 to $150,000. A breach that gets past both costs $4.99 million on average, according to IBM’s 2026 Cost of a Data Breach Report. Put those three numbers next to each other and the budgeting question mostly answers itself: the proactive work is cheap compared to the thing it’s meant to prevent, and the gap between them is the actual argument for spending money before something goes wrong instead of after.
That gap isn’t abstract right now. On September 2, 2026, CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog in a single batch, including bugs in LiteLLM, Kestra OSS, and Sangoma Switchvox. A KEV listing means confirmed active exploitation, not a theoretical risk score. Every company running any of those products now has a live version of the cost decision this post is about: patch this week, or find out later what the reactive number actually looks like.
The proactive side: patching and pentesting
Patching a known-exploited vulnerability costs almost nothing compared to a breach, yet the 2026 Verizon DBIR found only 26% of vulnerabilities on CISA’s KEV catalog got fully remediated in 2025, down from 38% the prior year. Median time to patch one rose to 43 days, up from 32. The gap isn’t budget. It’s volume outrunning triage capacity.
That’s the real story hiding in those numbers. DBIR attributes the slide to a sharp rise in the sheer count of vulnerabilities landing on security teams’ plates every month, faster than anyone can realistically prioritize them. A patch that costs a few engineering hours when applied on release day costs a great deal more once it’s sitting unpatched in production for six weeks and shows up on a KEV list.
The other proactive line item is testing your own exposure before someone else finds it for you. Real 2026 numbers, not estimates:
- External network pentest: $4,000-$12,000, per Synack’s 2026 pricing guide. A small environment (roughly 50 IPs) sits at the low end.
- Web application pentest: $5,000-$30,000, same source. Complexity drives the range: a static marketing site is cheap to test, a multi-tenant SaaS product with SSO and payment flows is not.
- Entry-level automated pentest: $3,500, Cobalt’s published price for its Autonomous Pentest product as a limited-time offer through the end of 2026. It’s narrower in scope than a full manual engagement, but it’s a real, resolvable number from a named vendor, not a guess.
None of those figures come close to the reactive numbers below. A company that runs an annual pentest and actually acts on the findings is spending less in a year than a single day of incident response typically costs once a breach is confirmed.

The reactive side: incident response and breach cost
This is where the money actually goes. IBM’s 2026 Cost of a Data Breach Report, based on a Ponemon Institute survey of 602 organizations that experienced a breach between March 2025 and February 2026, put the global average cost at $4.99 million. Breaches involving AI-enabled attacks (deepfake impersonation, AI-assisted malware) averaged $6 million, about $1 million above the overall figure. On the other side of that same coin, companies that had already deployed AI and automation in their security operations cut their average breach cost by close to $2 million. Security spend on the right tooling shows up directly in the recovery number, not just in fewer incidents.
Incident response retainers exist specifically to control what happens in the hours after a breach is discovered, because those hours are expensive in a way that’s easy to underestimate until you’re in them. LevelBlue’s published Resilience Retainer tiers run:
| Tier | Annual retainer | Response SLA |
|---|---|---|
| Essentials | $25,000-$74,999 | 4 hours |
| Advanced | $75,000-$149,999 | 2 hours |
| Premium | $150,000+ | 1 hour |
Once a retainer is signed, incident work bills at a discounted rate. Arctic Wolf’s published Incident360 rates run $295-$325/hour for retained clients. Without a retainer, emergency incident response runs $800-$1,500/hour, and you’re also waiting 24-72 hours for a firm with no prior relationship to your environment to mobilize a team. The retainer fee is credited against hours used in most structures, so a single incident during the coverage year effectively pays for the retainer on its own.
Where the numbers actually stack up
| Line item | Typical 2026 cost | Source |
|---|---|---|
| External network pentest | $4,000-$12,000 | Synack |
| Web app pentest | $5,000-$30,000 | Synack |
| Annual IR retainer | $25,000-$150,000+ | LevelBlue |
| Retained IR hourly rate | $295-$325/hr | Arctic Wolf |
| Emergency IR, no retainer | $800-$1,500/hr | Industry-standard emergency pricing |
| Average data breach | $4.99M | IBM / Ponemon Institute |
| AI-enabled breach | $6.0M | IBM / Ponemon Institute |
Read that table by order of magnitude, not line by line. The proactive column tops out around $150,000 a year for the top retainer tier. The reactive column starts at roughly 30 times that. A company that skips the pentest to save $10,000 and skips the retainer to save $50,000 hasn’t saved $60,000; it’s deferred a much larger bill and added interest in the form of a 24-72 hour response gap.
Building vs. buying this capability
The team question underneath the budget question is who actually does this work. Full-time security hires are expensive and hard to find for the specialist skills involved: network pentesting, application security, cloud forensics, and incident command are close to four different jobs. Most mid-size companies can’t keep one person busy full time in each of those lanes, which is exactly why the retainer and per-engagement model exists in this market. An agency retainer for security work behaves the same way a development agency retainer does for engineering capacity, covered in more detail on our services page — you’re paying for access to a bench when you need it, not carrying the headcount when you don’t. The math tips toward in-house only once your attack surface is large enough, or your compliance obligations frequent enough, to keep a dedicated team occupied year-round.
The takeaway
Run the comparison in your own budget the way the table above lays it out: proactive work tops out in the low six figures a year, reactive cost starts north of $4 million once a breach clears containment. The seven vulnerabilities CISA added to its KEV catalog on September 2 aren’t a special case; they’re this month’s version of a pattern that repeats every few weeks. The companies that treat a KEV listing as a same-week patch trigger, and that already have a pentest cadence and an IR retainer in place before they need one, are the ones whose 2026 security line item stays in the thousands instead of the millions.
Frequently asked questions
- How much does a penetration test cost in 2026?
- An external network pentest runs $4,000 to $12,000 and a web application pentest runs $5,000 to $30,000, according to Synack's 2026 pricing guide. Cobalt's autonomous pentest product starts at $3,500 as a limited-time entry price. Full enterprise-scope engagements with multiple applications and cloud environments in scope can run into six figures, but a single-target test for a small company sits well under $15,000.
- What does an incident response retainer cost?
- LevelBlue's published Resilience Retainer tiers start at $25,000-$74,999 a year for a 4-hour response SLA, rise to $75,000-$149,999 for a 2-hour SLA, and $150,000+ for a 1-hour SLA. Once a retainer is in place, incident work bills at a discounted hourly rate, around $295-$325/hour on Arctic Wolf's published Incident360 rates, versus $800-$1,500/hour for emergency response with no retainer in place.
- Is patching cheaper than dealing with a breach?
- By a wide margin. A pentest or a patch cycle costs thousands of dollars. A breach that a known, exploited vulnerability made possible costs millions: IBM's 2026 report puts the global average at $4.99 million. The 2026 Verizon DBIR also found that vulnerability exploitation overtook stolen credentials as the top initial access vector for the first time in the report's 19-year history, which makes patch cadence a direct line to breach exposure, not a background maintenance task.
- What is CISA's Known Exploited Vulnerabilities catalog and why does it matter for budgeting?
- The KEV catalog is CISA's running list of vulnerabilities with confirmed active exploitation, and federal agencies are required to patch KEV entries on a deadline. For everyone else, a KEV listing is a signal that the cost math has already tipped: the vulnerability isn't theoretical anymore, someone is actively using it. On September 2, 2026, CISA added seven vulnerabilities to the catalog in a single batch, including bugs in LiteLLM, Kestra OSS, and Sangoma Switchvox, which is the kind of event that should trigger an unscheduled patch cycle rather than waiting for the next maintenance window.
- Should a company hire an in-house security engineer or use an agency retainer for this work?
- It depends on how often the work recurs. A company running quarterly pentests and holding a standing IR retainer is buying access to a bench of specialists on demand, which usually costs less than a full-time hire once salary, benefits, and the fact that one person can't cover every specialty (network, web app, cloud, forensics) are counted. A company with a large enough attack surface to keep someone busy full time is a different calculation. Most mid-size companies land on a hybrid: a lean in-house security lead who manages vendor relationships, and outside retainers for the specialist work.
Sources
- IBM: One in Four Malicious Breaches Are AI-Enabled, Costing Companies $6 Million on Average (2026 Cost of a Data Breach Report)
- Verizon 2026 Data Breach Investigations Report findings (Help Net Security summary)
- CISA: Adds Seven Known Exploited Vulnerabilities to Catalog (September 2, 2026)
- Synack: How Much Does a Pentest Cost? (2026 Pricing Guide)
- Cobalt: Pentest Pricing & Penetration Testing Costs
- LevelBlue: Resilience Retainer, Enhanced Incident Response Retainer (published pricing tiers)
- Arctic Wolf: Incident360 Retainer (published hourly IR rates)
Sponsored
Sponsored
Discussion
Join the conversation.
Comments are powered by GitHub Discussions. Sign in with your GitHub account to leave a comment.
Sponsored