Data breaches are becoming more costly for Canadian companies, a new report suggests. Canadian organizations paid an average of $7.11 million per data breach in 2026, up from $6.98 million in 2025, according to research tech giant IBM released Wednesday. The average breach exposed 28,500 records, up eight per cent from last year, and took 205 days to detect and contain, a six per cent increase from 2025.
It’s getting more expensive to tackle the breaches because addressing them takes a multi-faceted approach, said Chris Sicard, security leader at IBM Canada. “What drives costs higher isn’t just the attack itself,” he said in an email. “It’s everything that follows: business interruption, recovery efforts, customer communications, legal and regulatory obligations, and the impact on day-to-day operations.” IBM classifies data breaches as events where personally identifiable, financial, medical, confidential or proprietary information is put at risk.
Up to 115,380 records were compromised in some of the breaches it studied. Sicard pointed out it’s not just companies that pay the price when their systems and data are compromised. Because of the damage that can be inflicted with stolen information and the way services are often disrupted or downed during breaches, customers are inconvenienced as well.
In some cases, companies even pass along recovery costs to clients. Canadian telecommunications company Rogers and its subsidiary Fido, as well as Telus Digital, Loblaw Cos. Ltd., Canada Computers and Ardene have all reported breaches this year.
However, it was energy companies that IBM found to have the highest average breach costs in Canada at $9.21 million per incident, followed by technology firms at $9.02 million and industrial organizations at $8.89 million. Sicard suspects their costs were larger because they tend to have bigger networks of customers, suppliers and business partners — making them a more lucrative target for attackers. “These organizations also tend to have complex environments, large amounts of sensitive data and very little tolerance for downtime,” he explained.
Organizations using artificial intelligence extensively in their security operations reported average breach costs of $5.5 million, compared with $8.91 million among companies not using AI. Companies often use AI to find and patch vulnerabilities in their system.
Summary from source