Annex A
Headline figures
$4.88M
Avg breach cost (phishing initial vector)
[IBM 2025]
$2.77B
US BEC losses, 2024
[FBI IC3 2024]
21,442
BEC complaints filed, 2024
[FBI IC3 2024]
254 days
Mean detection + containment
[IBM 2025]
84%
Organisations hit by successful phishing in 2024
[Proofpoint 2025]
82.6%
Detected phishing using AI
[Hoxhunt 2026]
3.4B/day
Phishing emails sent globally (estimate)
[APWG aggregate]
$25B
Annualised global phishing losses
[Industry projection]
16%
Share of breaches with phishing as listed initial vector
[IBM 2025]
$3.31M
Avg breach cost, organisations under 500 employees
[IBM 2025]
60%
SMBs that close within 6 months of major incident
[NCSA]
<5%
Click rate after 12 months of monthly simulation
[SANS]