Introduction to Industries

Please provide the information below to view the online Verizon Data Breach Investigations Report.

The information provided will be used in accordance with our terms set out in our Privacy Notice. Please confirm you have read and understood this Notice.

By submitting the form, you are agreeing to receive insights, reports and other information from Verizon and affiliated companies in accordance with our Privacy Policy. California residents can view our California Privacy Notice.

Verizon may wish to contact you in the future concerning its products and/or services. If you would like to receive these communications from Verizon, indicate by selecting from the dropdown menu below. Please note that you can unsubscribe or update your preferences at any time.

Indicates a required field. The content access link will be emailed to you.

View only

Thank You.

Thank you.

You will soon receive an email with a link to confirm your access, or follow the link below.

Download this document

Thank you.

You may now close this message and continue to your article.

  • If you are a long-time reader this introduction may be redundant, but for new readers it is worth perusing. This year we looked at 23,896 incidents, which boiled down to 5,212 confirmed data breaches. As always, we break these incidents and breaches into their respective industries to illustrate that all industries are not created equal. At least not when it comes to attack surfaces and threats. The type of attacks suffered by a particular industry will have a great deal to do with what infrastructure they rely upon, what data they handle, and how people (customers, employees, and everyone else) interact with them.

    A large organization whose business model focuses entirely on mobile devices where their customers use an app on their phone will have different risks than a small Mom and Pop shop with no internet presence, but who use a point-of-sale vendor that manages their systems for them. The infrastructure, and conversely the attack surface, largely drives the risk.

    Therefore, we caution our readers not to make inferences about the security posture (or lack thereof) of a particular sector based on how many breaches or incidents their industry reports. These numbers are heavily influenced by several factors, including data breach reporting laws and partner visibility. Because of this, some of the industries have very low numbers, and as with any small sample, we must caution readers that our confidence in any statistics derived from a small number must also be less. 

    When examining industries with a small sample, we will provide ranges where the actual value may reside. This allows us to maintain our confidence interval while giving you an idea of what the actual number might be, given a large enough sample. For example, instead of stating “In the Accommodation industry, 92% of attacks were financially motivated,” we might state that “financially motivated attacks ranged between 86% and 100%.” Check out our riveting Methodology section for far more information about the statistical confidence background used throughout this report.

    If you are reading this only for a glimpse of your industry, our recommendation is to verify what the top Patterns are on the summary table accompanying each industry and also spend some time with those Pattern sections. In addition, we provide a description of what Critical Security Controls (CSC) to prioritize in each industry section for ease of reading if you want to get straight to strategizing your security moves.

  • Incidents Total Small
    (1-1,000)
    Large
    (1,000+)
    Unknown Breaches Total Small
    (1-1,000)
    Large
    (1,000+)
    Unknown
    Total 23,896 2,065 636 21,195   5,212 715 255 4,242
    Accommodation (72) 156 2 1 153   69 1 1 67
    Administrative (56) 39 5 7 335   19 6 7 27
    Agriculture (11) 243 1 1 241   39 1 0 38
    Construction (23) 127 21 7 99   57 8 5 44
    Education (61) 1,241 112 48 1,081   282 57 15 210
    Entertainment (71) 215 12 5 198   96 6 3 87
    Finance (52) 2,527 103 50 2,374   690 56 32 602
    Healthcare (62) 849 36 14 799   571 14 10 547
    Information (51) 2,561 59 25 2,477   378 27 10 341
    Management (55) 8 1 2 5   2 0 0 2
    Manufacturing (31-33) 2,337 168 74 2,095   338 54 22 262
    Mining (21) 231 0 0 231   132 0 0 132
    Other Services (81) 180 16 1 163   101 8 1 92
    Professional (54) 3,566 1,095 144 2,327   681 263 52 366 
    Public (92) 2,792 110 88 2,594   537 74 25 438
    Real Estate (53) 118 31 5 82   76 19 2 55
    Retail (44-45) 629 157 68 404   241 54 35 152
    Wholesale Trade (42) 166 79 33 54   68 38 8 22
    Transportation (48-49) 305 26 38 241   137 17 23 97
    Utilities (22) 172 20 14 138   47 14 3 30
    Unknown 5,434 11 11  5,412   651 1 3 647
    Total 23,896 2,065 636 21,195   5,212 715 255 4,242

    Table 2. Number of security incidents and breaches by victim industry and organization size

Let's get started.