Cyentia Institute argued that widely cited single-number metrics like an “average cost per record” (e.g., figures popularized in annual breach-cost studies) are frequently misleading because breach losses and record counts are highly skewed. Using incident data spanning roughly the last 15 years, Cyentia illustrated that applying a single per-record average can produce large estimation errors for many events—especially those outside the narrow scope where such averages are even intended to apply—undermining its usefulness for budgeting, risk quantification, and executive decision-making.
Separately, ProcessUnity’s State of Third-Party Risk Assessments 2026 survey (conducted by Ponemon Institute) reported that 90% of organizations experienced at least one third-party breach in the prior year, with respondents indicating an average of 12 third-party breaches per year. The report also described operational gaps that can contribute to this exposure, including long assessment cycles (often 4+ months), limited vendor coverage (organizations assessing about 36% of vendors on average), and heavy reliance on manual methods (e.g., spreadsheets), despite over half of respondents expressing confidence in their third-party risk management programs.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Cyentia published updated analysis of roughly 15 years of breach data, concluding that single average cost-per-record estimates frequently produce large errors and recommending medians, quantiles, or full loss distributions instead.
ProcessUnity's State of Third-Party Risk Assessments 2026 report found organizations experienced an average of 12 third-party breaches per year, while assessments were often slow, incomplete, and heavily manual.
The 2025 Ponemon Cost of a Data Breach Study reported an average cost-per-record figure, which Cyentia later said was only applicable to a limited subset of incidents and inaccurate outside that scope.
Cyentia's IRIS 2022 report again challenged the practice of applying a single average cost-per-record figure to estimate breach losses, reinforcing that the metric performs poorly across varied incidents.
Cyentia's IRIS 2020 report argued that using a single average cost per record to estimate cyber incident losses is misleading because breach costs and record counts are highly skewed across incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.