The security boundary of organizations has shifted from the internal network to the publicly visible layer and the vendors behind it. The cookie banner is the most visible layer of all: one click that says “we respect your choice.” When that banner has no reject button, pre-ticks its options, or fires trackers before consent, it often signals the same thing that is happening behind the screen: data is not mapped, vendors are not supervised, and basic controls are not carried out.
We synthesize the two latest global datasets, Verizon DBIR 2026 (22,000+ confirmed breaches across 145 countries) and IBM/Ponemon 2026 (602 organizations), then test them against Indonesia using data from Komdigi, BSSN, and the PDNS 2 case. The results: vulnerability exploitation is now the number one entry point (31%), third-party involvement rose from 30% to 48% in a single year, and Indonesia’s oversight cannot yet impose administrative sanctions because the PDP Agency has not been established.
Summary
Failures in data protection are structural, not isolated incidents. Five failure vectors recur: unpatched vulnerabilities, weak identity and MFA controls, third-party exposure, weak backup and detection, and governance that exists only on paper (including cookie banners). They persist because operational speed and cost are often prioritized over continuous verification of controls.
For organizations, this means three things:
- Third-party risk is now the majority case. In 2026, third parties were involved in 48% of breaches, up from 30% in 2025 (a 60% jump).
- Long-tail cost impact. Supply chain incidents take an average of 258 days to resolve, and breaches lasting more than 200 days cost US$5.65 million, versus US$4.32 million for faster ones.
- Paper compliance is not enough. In Indonesia, Komdigi found potential PDP violations on 41% of monitored websites, while administrative sanctions cannot yet be imposed because the supervisory agency does not exist.
Five Failure Vectors, One Root Cause
| Failure Vector | Operational Manifestation | Point of Failure | Primary Impact |
|---|---|---|---|
| Unpatched Vulnerabilities | Already-exploited flaws left open | Only 26% of KEVs fully remediated; median patch time 43 days | 31% of breaches start here |
| Identity & MFA Gaps | Weak credentials, stale accounts active, uneven MFA | Only 23% of third parties fully fixed MFA; permission findings take about 8 months | Initial access and lateral movement |
| Third-Party Exposure | Vendors hold data with weaker controls | Vendor controls not continuously verified | 48% of breaches involve a third party |
| Weak Backup & Detection | Backups missing or untested | PDNS 2: 44 of 282 agencies had backups; about 2% of data backed up | Permanent data loss; 247-day detection |
| Governance Theater | Cookie banners and privacy policies are a formality | No first-layer reject button on 44.4% of banners (Denmark); PDP Agency not yet established | Invalid consent, toothless oversight |
The root cause is the gap between compliance claims and operational reality. Organizations declare themselves compliant, while patching, MFA, backups, and the choices shown on the user’s screen are not technically verified.
What Each Failure Actually Looks Like
1. Unpatched Vulnerabilities
For the first time in the report’s 19 years, vulnerability exploitation overtook stolen credentials as the initial entry point: 31% versus 13%. As an illustration, a VPN flaw already being exploited by attackers stays open for more than 6 weeks at the median organization.
2. Identity, Credentials, and the Human Element
The human element is present in 62% of breaches. Phishing by phone and SMS is about 40% more successful than email. For half of ransomware victims whose credentials had previously leaked, that leak occurred within 95 days before the attack.
3. Third-Party Dependence
A single vendor without MFA is enough to open your customers’ data. In cost terms, a compromised business partner or supply chain adds US$227,250 to the average breach, the largest cost amplifier among the 30 factors IBM analyzed.
4. Backup and Detection Collapse
PDNS 2 shows what this looks like: the data of 282 agencies was locked, and the BSSN regulation requiring backups was not carried out.
5. Consent and Governance Theater
An audit of the 99 highest-traffic sites in Denmark (October 2025) found an accept button on the first layer of 92.2% of banners, but a reject button on only 55.6%. Of the 28 settings menus that could be opened, 71.4% contained pre-ticked options. Cookie banners do not cause breaches. They are simply visible from the outside, which makes them a quick test of governance (our interpretation, not a study finding).
The Numbers: Cost, Speed, and Exposure
Breach Cost and Lifespan Trends (2025 to 2026)
| Metric | 2025 | 2026 | YoY Change |
|---|---|---|---|
| Global Average Breach Cost | US$4.44 million | US$4.99 million | +12% |
| Third-Party Involvement (Verizon) | 30% | 48% | +60% |
| Ransomware Presence (Verizon) | 44% | 48% | +4 points |
| Known-Exploited Vulns Fully Remediated | 38% | 26% | -12 points |
| Median Time to Fully Patch | 32 days | 43 days | +11 days |
| Mean Time to Identify & Contain | 241 days | 247 days | +2.5% |
| Shadow AI Incidents (IBM) | 20% | 43% | +23 points |
| Supply Chain Incident Lifecycle | N/A | 258 days | above the global average |
Table 1. Elements present in breaches, Verizon DBIR 2026
| Element | % |
|---|---|
| Human element | 62% |
| Ransomware | 48% |
| Third party | 48% |
| Credentials present | 39% |
| Vulnerability exploitation (initial access) | 31% |
| Credentials (initial access) | 13% |
A single breach can contain several elements, so the total exceeds 100%.
Duration is the main cost driver:
- Breaches lasting more than 200 days: US$5.65 million on average, versus US$4.32 million for faster ones.
- IBM estimates a cost of about US$1,100 per hour while an incident is ongoing.
- Supply chain incidents last longest because investigating third-party environments is complex.
Cost by Initial Attack Vector (2026)
| Initial Attack Vector | Average Cost |
|---|---|
| Voice/SMS phishing (vishing, smishing) | US$5.29 million |
| Social engineering (help desk, MFA fatigue) | US$5.23 million |
| External remote services | US$5.11 million |
| Valid account abuse | US$5.07 million |
| Drive-by compromise | US$4.99 million |
| Supply chain compromise | US$4.96 million |
| Exploitation of public-facing applications | US$4.68 million |
In the United States, the average breach cost reached US$11.5 million, up 11%. One in four malicious breaches now involves AI and adds roughly US$1 million in cost.
Indonesia in Numbers
| Indicator | Figure | Source |
|---|---|---|
| Cyberattacks recorded in 2025 | 5.5 billion (+714% vs the 2020 to 2024 average) | BSSN via Proxsis |
| Data exposures in 2024 | 56 million+, 461 stakeholders | BSSN via Melek Media |
| Leaked accounts, 2020 to April 2026 | 119.5 million; Q1 2026 down 43% from Q4 2025 | Surfshark via Medium (secondary) |
| Websites with potential PDP violations | 115 of 280 (41%) | Komdigi via CNN Indonesia |
| Apps with potential PDP violations | 24 of 70 (34%) | Komdigi |
| Complaints and consultations to the PDP Service | 342 complaints (41% PDP-related); 483 consultations (89% PDP-related) | Komdigi |
| Alleged PDP violations during monitoring | 56 cases; peaks in June (20) and July 2025 (15) | Komdigi |
Table 2. Indonesia: compliance and readiness
| Indicator | % |
|---|---|
| Websites: potential PDP violations | 41% |
| Apps: potential PDP violations | 34% |
| PDNS 2 agencies with backups | 16% |
Table 3. Banner audit, 99 sites in Denmark
| Indicator | % |
|---|---|
| Accept button on layer 1 | 92% |
| Reject button on layer 1 | 56% |
| Accept larger than alternative | 63% |
| Pre-ticked options present | 71% |
| At least 1 violation | 63% |
Denominators: 90 banners detected; 80 measurable button pairs; 28 settings menus opened. This is an interface proxy, not a legal ruling.
What Reduces the Damage
| Safeguard / Mitigator | Measured Effect | Mechanism |
|---|---|---|
| Security AI & Automation (extensive) | -US$1.93 million; breach lifecycle 65 days shorter (IBM) | Faster detection and automated isolation |
| DevSecOps | -US$253,805 (IBM, via Cycode) | Vulnerability scanning in the CI/CD pipeline |
| Prioritized KEV patching | Closes the number one entry point (31% of breaches) | Focus on flaws actually being exploited |
| MFA on vendor accounts | Only 23% of third parties fully fixed MFA | Stops credential abuse |
| Tested offline backups | PDNS 2: 44 of 282 agencies had backups | Recovery without paying a ransom |
69% of ransomware victims in the Verizon dataset chose not to pay, which makes tested backups a real option.
Enforcement: What Regulators Have Done
Legal Framework
Enforcement in Indonesia centers on the Personal Data Protection Law (UU PDP), fully in force since 17 October 2024, with two tracks:
- Administrative sanctions (Article 57): warnings, suspension of processing, deletion of data, and fines of up to 2% of annual revenue. Only the PDP agency has the authority to impose them.
- Criminal sanctions (Articles 67 to 73): 4 to 6 years in prison and fines of Rp4 to 6 billion for individuals; for corporations up to 10 times the base fine (Article 70), as summarized by Proxsis. This track does not wait for the PDP Agency.
Consent must be valid, explicit, and specific. Breach notification is mandatory within 3×24 hours.
Institutional status: according to CNBC Indonesia (16 September 2026), Government Regulation 33/2026 was only issued in August 2026 and the PDP Agency has not been established. Komdigi carries out oversight in the interim.
In Europe, Denmark’s authority has made cookie consent a 2026 enforcement priority, focusing on whether users have a real opportunity to refuse.
Case Studies
| Parameter | PDNS 2 (Indonesia, 2024) | Denmark banner audit (2025 to 2026) |
|---|---|---|
| Findings | Brain Cipher ransomware locked the data of 282 agencies; US$8 million ransom; about 2% of data backed up | 63.3% of banners had at least one interface violation |
| Parties involved | Kominfo, Telkom, BSSN | DTU researchers; Datatilsynet (2026 priority) |
| Impact | Recovery prioritized for the 44 agencies with backups; others rebuilt in a new environment | Consent not fully free and informed |
| Remediation | Government drafting a mandatory backup rule | Equalizing reject buttons, removing pre-ticked options |
| Note | Not the result of a court ruling | Interface proxy, not a legal ruling |
PDNS 2 details: PDNS 2 in Surabaya was paralyzed from 20 June 2024. BSSN said the root of the problem was a shortfall in governance, and forensics pointed to the use of a password by a specific user as one of the causes. Only 44 of 282 agencies had backups, and only about 2% of the data was stored in Batam. The then Minister of Communication cited budget as one reason many agencies had no backups.
Why Standard Audits Miss It
Conventional audits and monitoring rely on static artifacts: whether a banner exists, a privacy policy, or a certificate. There are five blind spots:
| Blind Spot | Failure Mechanism |
|---|---|
| Interface vs. Behavior | Banner studies measure appearance (buttons, pre-ticked boxes), not whether trackers actually stop after rejection. The authors themselves name this as a limit. |
| Point-in-time Snapshot | The audit result is a snapshot of October 2025. A/B tests, CMP updates, and redesigns change what users see. |
| Opaque Criteria | Komdigi’s finding (41% of websites) is reported as “potential violations” without detailing the type of violation or the sampling criteria, so it cannot be replicated. |
| Vendor Layer | Banners are often supplied by CMP vendors. In the 31-country study, CMP identity explained 17.8% of the variance in compliance scores, so one vendor can spread a single flaw across many sites. |
| Unverified Claims | Dark web breach claims are often untestable. The February 2026 claim of 240 million citizen records had no verifiable sample and may be recycled data. |
One misreading to avoid: a consultant linked that 41% figure to “blanket consent.” Komdigi’s statement does not specify the type of violation, so we do not use that claim.
Our Take
The prevailing assumption that an installed privacy policy and a banner that appears signal compliance is wrong. Banners were detected on 90 of the 99 audited Danish sites, but only 33 of those 90 banners (36.7%) had no observable interface violation. The existence of a control is not the same as the control working.
The same pattern appears in breaches. PDNS 2 had a backup obligation on paper, but only 44 of 282 agencies carried it out. Globally, only 26% of already-exploited flaws were fully patched even though the KEV list is available to everyone. The problem is not a lack of rules but the gap between rules and execution, compounded by an enforcer that is not yet complete.
As more vendors, CMPs, and AI tools connect, that gap tends to widen. The answer is not longer questionnaires but regularly measuring real behavior: patch by exploitation, mandate MFA, test backups, supervise vendors through technical evidence, and audit banners with a replicable protocol.
What You Should Do
Five priorities for organizations that handle personal data:
- Patch by exploitation. Prioritize KEVs and internet-facing assets, with a target well below the 43-day median. Monitor the perimeter continuously, including vendors’ perimeters.
- Mandate MFA and clean up identity. Apply it to all accounts, especially vendor and service accounts. Remove accounts of departed employees and rotate credentials regularly.
- Build tested backups and drill incident response. Keep offline copies, test recovery, and prepare the 3×24-hour notification. Every day of delayed detection adds cost.
- Fix consent banners and map your data. An equal reject button on the first layer, no pre-ticked options, non-essential cookies blocked before consent, and withdrawal of consent as easy as giving it. Use the following audit protocol before naming any site:
- Sample: the 100 highest-traffic sites in Indonesia, fresh Chrome profile, id-ID language.
- Test 1: is there an equal reject button on the first layer?
- Test 2: are there pre-ticked boxes in the settings menu?
- Test 3: is the accept button larger or more prominent?
- Test 4: are non-essential cookies already set before any click?
- Test 5: after rejecting, do trackers still run?
- Quality control: two independent reviewers, figures reported with numerator and denominator, full screenshots.
- Write vendor terms into contracts. Require penetration test evidence, technical audit rights, incident reporting within 24 to 72 hours, and data deletion after the contract ends. Prohibit vendors from using your data to train AI models without written permission.
For regulators: establish the PDP Agency and publish supervision criteria, so that figures such as 41% can be read and acted upon.
Methodology & Sources
This analysis synthesizes 2026 data where available, and falls back to the 2020 to 2026 range where it is not. Figures are not pooled across sources because their populations and definitions differ.
| Source | Sample | Used For |
|---|---|---|
| Verizon DBIR 2026 (May 2026) | 22,000+ breaches, 145 countries, Nov 2024 to Oct 2025 | Entry points, causes |
| IBM Cost of a Data Breach 2026 (July 2026) | 602 organizations, Mar 2025 to Feb 2026 | Cost, duration |
| Komdigi, BSSN, Kompas, CNN Indonesia, CNBC Indonesia | 350 platforms; PDNS 2 data | Indonesia |
| Ntemkas et al., Future Internet 18(9):487 (Sep 2026) | 99 high-traffic sites in Denmark | Banner behavior |
| Cookie Information | Danish sites (vendor report) | Supplementary indication |
