What does a data breach cost? AI is a sizable factor

Tags:

The financial impact of a data breach is substantial for any modern business, regardless of industry or size. IBM’s latest Cost of a Data Breach report discovered that, from March 2025 to February 2026, the average cost of a data breach rose to $6 million, up 35% from $4.44 million a year earlier.

The 2026 report, conducted by Ponemon Institute and sponsored by IBM, is based on an analysis of data breaches experienced by 600 organizations globally.

According to the report, one in four malicious breaches were AI-enabled. Deepfake impersonation and AI-enabled malware made up the majority of these AI-assisted attacks.

The study found that AI and automation in security operations cut breach costs by an average of almost $2 million dollars. Despite that impact, one in four organizations have yet to adopt these tools in their security operations, the survey found.

In a follow-up study, more than half the organizations reported using agents for threat detection and containment but only 18% apply agents to vulnerability management. Three in four of the enterprises polled say that frontier AI threats are prompting them to rethink how agents are deployed across their security operations.

“AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” says Suja Viswesan, VP of IBM Security Software.

AI models under attack

One in five organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).

The vast majority of organizations suffering AI-related breaches lacked proper access controls, yet only 40% deployed access controls on their AI models and data.

Improving access controls on AI models is the most obvious security gap to close, according to Kayne McGladrey, a senior member of IEEE, CISSP-certified cybersecurity advisor, and former CISO of compliance automation vendor Hyperproof.

“Treat your models and their APIs like crown jewels,” says McGladrey. “If you wouldn’t expose your database to the public internet without identity and access controls, why would you do that for your AI model?”

Udaya Bhaskar Vemuri, senior application security analyst and DevSecOps professional, adds that organizations should also be “reviewing integrations and plug-ins, monitoring unusual activity, protecting sensitive data, and making sure every AI system has a clearly defined owner who is responsible for its security and oversight.”

Prompt criticality

Beyond deepfakes and AI malware, AI-driven phishing and direct attacks on AI models, such as prompt injection, are emerging as costly enterprise blind spots.

“The threat isn’t just external; unapproved employee use of AI applications introduces unmanaged vulnerabilities into corporate environments,” says Dray Agha, senior manager of security operations at managed detection and response firm Huntress.

CISOs must shift to proactive governance by embedding security into development workflows, managing exposures aggressively, and applying strict access controls to AI workloads, Agha advises.

Peter Garraghan, CSO and founder at AI security testing firm Mindgard, adds that blindly trusting in the effectiveness of AI security guardrails is fraught with risk.

“Research has demonstrated that existing guardrails currently have various blind spots, and that a defense in depth approach is required,” says Garraghan. “Attackers are constantly adapting, so organizations need to continuously test AI models and applications against realistic adversarial attacks to identify where protections fail.”

Garraghan adds: “By validating guardrails before and throughout deployment, CISOs can ensure AI systems are resilient enough to protect sensitive data, and user privacy as threats evolve.”

Attackers are compromising APIs, plug-ins, and cloud misconfigurations around models rather than defeating them, according to Ariel Parnes, co-founder and COO of cloud security vendor Mitiga.

“These attacks land in the telemetry of the cloud and identity environments, not in the model itself, so the defense is behavioral detection across everything the AI touches,” Parnes advises.

Upping the ante

The abuse of AI tools by attackers doesn’t just mean enterprises are subject to more sophisticated attacks. It also means that these attacks unfold more quickly.

“Organizations need to respond with the same level of automation, but with strong guardrails,” says John-Paul Cunningham, CISO at identity security vendor Silverfort. “AI can improve the speed of cyber defense, but only if organizations build governance and accountability into those systems from the start.”

Regional costs

Average breach costs in the US reached a record $11.5 million, an 11% increase over last year and nearly double the global average.

This rise was driven in part by steeper regulatory penalties and higher business costs, according to the IBM-sponsored study.

The Middle East, which considered Saudi Arabia and the United Arab Emirates for the report, was No. 2 of the 16 countries and regions surveyed, at $8 million.

Canada ($5.2 million) and the UK ($4.17 million) remain in the top 10 hardest hit, with ASEAN or Association of Southeast Asian Nations ($4.12 million), Australia ($2.96 million), and India ($2.79 million) among the top 15.

Phishing topped initial attack vectors and led to the costliest breaches. Social engineering, such as impersonating help desk staff, was used in 13% of attacks while voice and SMS phishing featured in 17% of attacks.

Breaches by industry

Healthcare remains the industry hit with the highest average costs per breach at $6.64 million despite a drop from $7.42 million last year.

Attackers continue to value and target the industry’s patient personal identification information (PII), which can be used for identity theft, insurance fraud, and other financial crimes.

The mean time organizations took to identify and contain a breach rose to 247 days, a slight 2.5% year-on-year increase that reversed a five-year decline. “New threats from AI-driven attacks are challenging even the quickest response times,” the IBM-sponsored study notes.

Average breach cost by industry

Industry20262025ChangeHealthcare$6.64M$7.42M-11%Financial$6.29M$5.56M+13%Industrial$5.50M$5.00M+10%Technology$5.50M$4.79M+15%Entertainment$5.38M$4.43M+21%Pharmaceuticals$5.25M$4.61M+13%Energy$5.24M$4.83M+8%Professional services$5.08M$4.56M+11%Communications$4.71M$3.75M+26%Transportation$4.50M$3.98M+13%

Breach cost variables

While industry averages provide benchmarks, calculating the true, final cost of a specific data breach is notoriously difficult and relies heavily on forecasting.

“Immediate technical costs are quantifiable, but devastating long-term impacts like reputational damage, lost business, and regulatory fines are intangibles, making total breach cost figures informed estimates rather than exact science,” says Huntress’ Agha.

Several experts quizzed by CSO named the cybersecurity skills gap, supply chain vulnerabilities, and the escalating threat landscape as the three main factors in making breaches more expensive and harder to manage.

AJ Thompson, chief commercial officer at IT consultancy Northdoor, who sits on IBM’s Worldwide Security Advisory Council advising on data access and security, says the “bigger cost driver is still ‘how fast you spot a breach’ rather than the sophistication of an attack.”

“A shortage of experienced security staff and patchy visibility into supply chain and third-party risk both stretch out that detection window, and every extra week unnoticed adds to the bill,” Thompson adds.

Reputational damage remains a key cost of being breached

In many ways immeasurable, reputational damage remains among the most significant costs in the wake of a breach. “Ultimately, customer trust is very easy to break, and very difficult to build,” Allie Mellen, senior analyst at Forrester, tells CSO.

Bob Dutile, chief commercial officer at UST, agrees: “The cost of a data breach is typically realized in relative competitive change in the marketplace. Companies find that their brand does not command the same price premium, customer conversion costs are higher, and market share is lost. For a public company, the near-term assessment of the cost impact is reflected in stock price movement.”

According to Dutile, research shows that between $8 million and $10 million is a good planning number in the US for a midsize business facing a modest breach of under 250,000 records. About a third of that cost will be loss of business due to reputation damage.

How a company responds to and communicates a breach can have a large bearing on that reputational impact, Forrester’s Mellen notes. “Understanding how to maintain trust with your consumers and customers is really critical here,” she adds. “There are ways to do this, especially around building transparency and using empathy, which can make a huge difference in how your customers perceive you after a breach. If you try to sweep it under the rug or hide it, then that will truly affect their trust in you far more than the breach alone.”

Severe business downtime can cost millions

Business downtime can also be significantly costly for a breached organization, depending on the level and extent of the downtime and how technology-dependent the firm is.

Nearly all the organizations studied suffered operational disruption, taking an average of 100 days to recover from a security incident.

Jason Hicks, field CISO at Coalfire, tells CSO: “Often a breach is not going to take a company completely offline, but it can happen. The more critical systems that are taken down, the more significant the cost.”

Manufacturing tends to have the best metrics around this, as it’s relatively simple to measure the cost per minute if an assembly line is down, Hicks says. “This can translate into millions of dollars a day for a large manufacturing company. This can be more nebulous for other industry verticals, but there are models to get a reasonable feel that can be applied to each vertical.”

Regulation and litigation add to data breach costs

Increasingly strict data protection and privacy laws along with litigation are seeing a growing number of companies issued large fines, paying hefty settlements, and stumping up for legal fees following data breaches and non-compliance.

“Regulated industries suffer not only the immediate cost of responding to, containing, and remediating vulnerabilities but also the long-term effects of additional penalties from their regulatory bodies and legal settlements,” Nick says. Highly regulated industries, such as healthcare and financial services, typically run one and two in order of cost per breach because they will pay more non-compliance fines than others, he adds.

“Investigation and adjudication often take years for the victim organization to reach a monetary settlement with affected parties.” Legal costs are one of the largest expenditures organizations face in data breaches, Nick states. “Organizations rarely have the legal and privacy expertise in-house. To ensure compliance, they must hire outside counsel to lead their reporting.”

The role of cyber insurance

Cyber insurance is one way that companies mitigate the cost risks of breaches. Sharp increases in cyber insurance premiums have been stabilizing of late, but even organizations covered by insurance can expect to dole out extra cash to make good after a breach. One definite cost hit will be a hike in their premiums, Guidehouse’s Nick says.

“Some organizations have reported post-breach increases in premiums of approximately 200%,” he adds.

Insurers are also implementing more coverage limitations, meaning that even with a policy in place, businesses could find themselves financially responsible for certain breach-related costs.

In fact, Forrester’s Mellen says any notion that policies will allow organizations to fully recover financially from a cyberattack is folly. “In reality, it’s not going to cover all of the costs associated with any type of cyberattack, and we see some insurance firms not even covering ransomware at this point as part of their payouts,” she adds.

Another factor to consider is that cyber insurance providers typically have a list of approved service providers such as lawyers and forensics firms, Hicks says.

“If your preferred provider is not on their list, you may have to work with them to get them included, or potentially have to change providers. This can be costly, as firms are often leveraging their existing service providers to secure the maximum discounts based on the volume of work done with the partners,” Hicks says.

Ransomware extortion on the rise

Reported ransomware incidents rose in the last 12 months compared to the year prior (39% vs. 34%) as attackers have abused AI technologies to automate and scale their attacks.

While disrupting operations through encrypting remains a key tactic (23%), attackers are shifting to higher-impact pressure methods, such as threatening to leak stolen data (a common feature of so-called double extortion attacks).

Insufficient security staffing leads to higher breach costs

According to IBM’s latest report, the security skills shortage is one of the biggest data breach cost amplifiers, with the average additional cost of data breach due to cyber skills shortage pegged at $180,000.

If insufficient security staff equates to greater data breach costs, organizations should heed Mellen’s warning about the impact a poorly handled data breach can have on employees.

“If they don’t feel like the organization is able to protect them or customers in the event of a breach, or that they blame their employees for a breach, then they’re likely going to start looking for jobs elsewhere because it creates a bit of a hostile environment for them,” she says. “It is very important for organizations to recognize that they need to accept responsibility and protect both their employees and their customers.”

Taking a DevSecOps approach to software development was the No. 1 factor that reduced breach costs, according to the report, ahead of use of identity and access management. Running key lifecycle management tools rounded out the top three factors.

Security incidents involving shadow or unsanctioned use of AI tools more than doubled to 43% this year compared to 20% in 2025. Shadow AI is starting to rival supply chain breaches and security system complexity as a leading factor in exacerbating breach costs, according to the report.

Preparedness is key to managing data breach costs

No matter the specific costs involved, experts agree that preparedness is key to mitigating the financial repercussions of a breach.

“Faster incident response continues to be a clear driver for lowering the cost of a breach,” UST’s Dutile says. “The worst losses are those that go undetected for an extended time or have a slow or ineffective response.”

To that end, more than half of organizations surveyed say they plan to invest in AI security and governance tools post-breach, an 88% increase from last year and a reaction to concerns over frontier AI model threats.

Modern cybersecurity requires a post-breach mindset which understands that, eventually, a successful data breach is going to occur, Forrester’s Mellen adds.

“Operating under those conditions, you need to figure out how you’re going to handle that and build your resiliency to respond better and faster. This isn’t just about the security function either, and it needs to be spread across an organization, considering what marketing is going to do, what sales is going to do, etc. — how, as a business, you can demonstrate you value your customers and that you want to make it right as quickly and effectively as possible,” she says.

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *