Public sources · August 2026
The Threat Landscape
Cybersecurity reports measure different things, but they point to the same practical issue: organizations need to know whether their own systems, processes, and response plans are ready when something happens.
The figures below are for planning context. They do not describe your organization’s readiness.
Global
~22,000 incidents · ~12,000 confirmed breaches
Verizon’s 2025 Data Breach Investigations Report analyzed approximately 22,052 security incidents and 12,195 confirmed breaches across 139 countries.
Source:
Verizon DBIR 2025
United States
~1.01 million complaints · ~$20.9 billion in reported losses
The FBI Internet Crime Complaint Center received approximately 1,008,597 complaints in 2025, with reported losses of roughly $20.9 billion.
The Identity Theft Resource Center also tracked 3,322 U.S. data compromises during 2025.
Sources:
FBI IC3 2025 Annual Report
·
ITRC 2025 Data Breach Report
Ohio
~27,600 reported complaints
FBI IC3 state data associates Ohio with approximately 27,626 internet-crime complaints in 2025.
Ohio public organizations also have specific cybersecurity governance and incident-reporting requirements that should be addressed as part of readiness planning.
Sources:
FBI IC3 2025
·
ORC § 9.64
What this means for your organization: These reports provide context, but they do not tell you whether your organization is ready. That requires looking at your own systems, responsibilities, documentation, vendors, and supporting records.
~7 days
OCIC notification timing associated with ORC § 9.64
~30 days
Auditor of State notification timing
Federal or sector-specific reporting may also apply. Exact obligations depend on the organization and the incident and should be confirmed against current official guidance.
Good places to start
Confirm MFA is in place for email, remote access, and privileged accounts.
Test restoration of critical backups.
Know who is responsible for incident decisions and notifications.
Keep current security information for key vendors and service providers.
Make sure written cybersecurity policies reflect what actually happens in practice.
Keep the records needed to show that important controls and processes are operating.
Threat figures are rounded from public reports and provided for general context. Re-check primary sources before citing them externally.