BakerHostetler's 12th annual Data Security Incident Report highlights cyber challenges in 2025

BakerHostetler’s 2025 report examines cybersecurity threats, regulatory developments, and incident response trends, offering an overview for organisations assessing risk and preparedness.

  • Friday, 10th April 2026 Posted 3 weeks ago in by Sophie Milburn
BakerHostetler has released its 12th annual Data Security Incident Response (DSIR) Report, which examines the cybersecurity breach landscape in 2025. Produced by the law firm’s Digital Assets and Data Management Practice Group, the report analyses more than 1,250 data security incidents.

The 2026 DSIR Report reviews key metrics, including timelines for network intrusion response and ransomware trends. It reports that average ransomware demands have risen to $4.2 million, alongside increasing settlement amounts, highlighting financial impacts on affected organisations.

The report also notes an increase in class actions, which now appear in 14% of security breaches, up from 9% the previous year. Large enterprises are identified as facing litigation risk even in cases involving minimal notification.

Phishing remains the most common cause of incidents, followed by unpatched vulnerabilities. Regulatory challenges are reported across multiple sectors, with health care most affected, followed by finance and insurance.

Improvements in forensic investigation processes are associated with reduced notification times, although costs have increased, particularly for larger investigations.

Vendor-related vulnerabilities are reported in around a quarter of incidents, indicating ongoing risks associated with third-party relationships. Artificial intelligence is also identified as an emerging factor, associated with faster attack execution and increased legislative activity across U.S. states.

The report presents these findings as part of an overview of current cybersecurity risks and incident response trends.

AI trust fails to keep pace with rate of adoption

Posted 1 day ago by Phil Alsop
Two thirds of organisations (64 per cent) are actively using artificial intelligence across the UK, a 12 per cent increase from last year according...

AI adoption is accelerating identity sprawl

Posted 1 day ago by Phil Alsop
Keeper Security has released its latest global insight report, “Identity Security at Machine Speed.”

Surge in AI-enabled cybercrime

Posted 2 days ago by Phil Alsop
Fortinet leverages threat intelligence to disrupt global cybercrime, transforming awareness into actionable insights.
Study finds most organizations recognize the need for connected data, content, and workflows, but few have built the operational foundation required...
A third (35%) of European organisations cannot say whether they have been hit by an AI-powered cyberattack, according to the latest AI Pulse Poll...
Nearly half of European organisations spend up to €5 million a year on cloud – yet a quarter of capacity sits idle.

AI-Driven attacks reshape the MSP threat landscape

Posted 6 days ago by Phil Alsop
New research shows session hijacking surging 23%, ransomware up 190%, and non-human identities outnumbering users 25:1 as AI accelerates attacks...
Lenovo research highlights a growing AI execution gap as organizations struggle to control and operate AI across their environments.