Full Story on:
Learn how to optimize your SIEM solution with key strategies and practices.
cybersecurityventures.com
The quoted passage is consistent with what Cybersecurity Ventures published in its “Official Cybercrime Report 2025” post dated May 28, 2025 (including the $10.5T for 2025, $12.2T by 2031, and the “2.5% annually” plateau claim). ([cybersecurityventures.com](https://cybersecurityventures.com/official-cybercrime-report-2025/))
How to read these “$10.5T / $12.2T” numbers
Cybersecurity Ventures is using a very broad definition of “cybercrime costs” (not just ransoms paid). They explicitly include items like business disruption, lost productivity, forensic work, restoration, reputational harm, legal costs, and potential regulatory fines. ([cybersecurityventures.com](https://cybersecurityventures.com/official-cybercrime-report-2025/)) That breadth is important, because it means the headline figure is best treated as a macro-level
economic impact estimate rather than something directly comparable to a company’s “revenue” number.
Why the comparison to GDP can be misleading
The “if cybercrime were a country…” framing is a rhetorical device to convey scale. GDP is a measure of value added in an economy, while “cybercrime cost” is a modeled sum of losses and downstream impacts (and may involve overlaps/double counting depending on methodology). So it’s an attention-getter, but it shouldn’t be taken as a literal apples-to-apples economic ranking. ([cybersecurityventures.com](https://cybersecurityventures.com/official-cybercrime-report-2025/))
A useful reality check: measured loss reports vs global projections
To contrast with projections, some sources publish “reported loss” figures grounded in complaints/cases. For example, Reuters reported the FBI said cybercrime costs rose to at least $16B in 2024 (IC3 data), while also noting underreporting (especially around ransomware). ([reuters.com](https://www.reuters.com/world/us/fbi-says-cybercrime-costs-rose-least-16-billion-2024-2025-04-23/?utm_source=openai)) This highlights the gap between (1) what gets reported/measured directly and (2) global “total cost” models that try to include indirect impacts.
Practical takeaway (what matters for defenders)
Regardless of whether the true global number is $X trillion, the dominant “money movers” remain very familiar (scams, credential theft/account takeover, BEC-style payment diversion, ransomware disruption). If you’re using this stat in a security discussion, it’s most productive to pair it with concrete controls, e.g.:
- MFA everywhere (and phishing-resistant MFA for admin/high-risk roles where possible)
- Strong email security + payment-change verification (anti-BEC)
- Patch/vuln management basics (especially edge devices/VPNs)
- Offline/immutable backups + restore testing (anti-ransomware impact reduction)
- User training focused on today’s scam patterns (not generic “don’t click links”)
Net: treat the CV “$10.5T” figure as a big-picture estimate meant to communicate scale, and anchor any decision-making to measurable risk in your environment (incident rates, top loss scenarios, and control gaps).