{"id":9055,"date":"2026-08-07T08:25:00","date_gmt":"2026-08-07T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9055"},"modified":"2026-08-07T08:25:00","modified_gmt":"2026-08-07T08:25:00","slug":"what-does-a-data-breach-cost-ai-is-a-sizable-factor","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9055","title":{"rendered":"What does a data breach cost? AI is a sizable factor"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">The financial impact of a data breach is substantial for any modern business, regardless of industry or size. <a href=\"https:\/\/www.ibm.com\/reports\/data-breach\">IBM\u2019s latest Cost of a Data Breach report<\/a> discovered that, from March 2025 to February 2026, the average cost of a <a href=\"https:\/\/www.csoonline.com\/article\/574289\/twitters-mushrooming-data-breach-crisis-could-prove-costly.html\">data breach<\/a> rose to $6 million, up 35% from $4.44 million a year earlier.<\/p>\n<p class=\"wp-block-paragraph\">The 2026 report, conducted by Ponemon Institute and sponsored by IBM, is based on an analysis of data breaches experienced by 600 organizations globally.<\/p>\n<p class=\"wp-block-paragraph\">According to the report, one in four malicious breaches were AI-enabled. Deepfake impersonation and AI-enabled malware made up the majority of these AI-assisted attacks.<\/p>\n<p class=\"wp-block-paragraph\">The study found that AI and automation in security operations cut breach costs by an average of almost $2 million dollars. Despite that impact, one in four organizations have yet to adopt these tools in their security operations, the survey found.<\/p>\n<p class=\"wp-block-paragraph\">In a follow-up study, more than half the organizations reported using agents for threat detection and containment but only 18% apply agents to vulnerability management. Three in four of the enterprises polled say that frontier AI threats are prompting them to rethink how agents are deployed across their security operations.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,\u201d says <strong>Suja Viswesan, VP of IBM Security Software<\/strong>.<\/p>\n<h2 class=\"wp-block-heading\">AI models under attack<\/h2>\n<p class=\"wp-block-paragraph\">One in five organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).<\/p>\n<p class=\"wp-block-paragraph\">The vast majority of organizations suffering AI-related breaches lacked proper access controls, yet only 40% deployed access controls on their AI models and data.<\/p>\n<p class=\"wp-block-paragraph\">Improving access controls on AI models is the most obvious security gap to close, according to Kayne McGladrey, a senior member of IEEE, CISSP-certified cybersecurity advisor, and former CISO of compliance automation vendor Hyperproof.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTreat your models and their APIs like crown jewels,\u201d says McGladrey. \u201cIf you wouldn\u2019t expose your database to the public internet without identity and access controls, why would you do that for your AI model?\u201d<\/p>\n<p class=\"wp-block-paragraph\">Udaya Bhaskar Vemuri, senior application security analyst and DevSecOps professional, adds that organizations should also be \u201creviewing integrations and plug-ins, monitoring unusual activity, protecting sensitive data, and making sure every AI system has a clearly defined owner who is responsible for its security and oversight.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Prompt criticality<\/h2>\n<p class=\"wp-block-paragraph\">Beyond deepfakes and AI malware, <a href=\"https:\/\/www.csoonline.com\/article\/3850783\/11-ways-cybercriminals-are-making-phishing-more-potent-than-ever.html\">AI-driven phishing<\/a> and <a href=\"https:\/\/www.csoonline.com\/article\/4110008\/top-cyber-threats-to-your-ai-systems-and-infrastructure.html\">direct attacks on AI models<\/a>, such as prompt injection, are emerging as costly enterprise blind spots.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe threat isn\u2019t just external; unapproved employee use of AI applications introduces unmanaged vulnerabilities into corporate environments,\u201d says Dray Agha, senior manager of security operations at managed detection and response firm Huntress.<\/p>\n<p class=\"wp-block-paragraph\">CISOs must shift to proactive governance by embedding security into development workflows, managing exposures aggressively, and applying strict access controls to AI workloads, Agha advises.<\/p>\n<p class=\"wp-block-paragraph\">Peter Garraghan, CSO and founder at AI security testing firm Mindgard, adds that blindly trusting in the effectiveness of AI security guardrails is fraught with risk.<\/p>\n<p class=\"wp-block-paragraph\">\u201cResearch has demonstrated that existing guardrails currently have various blind spots, and that a defense in depth approach is required,\u201d says Garraghan. \u201cAttackers are constantly adapting, so organizations need to continuously test AI models and applications against realistic adversarial attacks to identify where protections fail.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Garraghan adds: \u201cBy validating guardrails before and throughout deployment, CISOs can ensure AI systems are resilient enough to protect sensitive data, and user privacy as threats evolve.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Attackers are compromising APIs, plug-ins, and cloud misconfigurations around models rather than defeating them, according to Ariel Parnes, co-founder and COO of cloud security vendor Mitiga.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThese attacks land in the telemetry of the cloud and identity environments, not in the model itself, so the defense is behavioral detection across everything the AI touches,\u201d Parnes advises.<\/p>\n<h2 class=\"wp-block-heading\">Upping the ante<\/h2>\n<p class=\"wp-block-paragraph\">The abuse of AI tools by attackers doesn\u2019t just mean enterprises are subject to more sophisticated attacks. It also means that these attacks unfold more quickly.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOrganizations need to respond with the same level of automation, but with strong guardrails,\u201d says John-Paul Cunningham, CISO at identity security vendor Silverfort. \u201cAI can improve the speed of cyber defense, but only if organizations build governance and accountability into those systems from the start.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Regional costs<\/h2>\n<p class=\"wp-block-paragraph\">Average breach costs in the US reached a record $11.5 million, an 11% increase over last year and nearly double the global average.<\/p>\n<p class=\"wp-block-paragraph\">This rise was driven in part by steeper regulatory penalties and higher business costs, according to the IBM-sponsored study.<\/p>\n<p class=\"wp-block-paragraph\">The Middle East, which considered Saudi Arabia and the United Arab Emirates for the report, was No. 2 of the 16 countries and regions surveyed, at $8 million.<\/p>\n<p class=\"wp-block-paragraph\">Canada ($5.2 million) and the UK ($4.17 million) remain in the top 10 hardest hit, with ASEAN or Association of Southeast Asian Nations ($4.12 million), <a href=\"https:\/\/www.csoonline.com\/article\/1309403\/australian-government-back-on-top-5-sectors-with-most-reported-data-breaches.html\">Australia<\/a> ($2.96 million), and India ($2.79 million) among the top 15.<\/p>\n<p class=\"wp-block-paragraph\">Phishing topped initial attack vectors and led to the costliest breaches. Social engineering, such as impersonating help desk staff, was used in 13% of attacks while voice and SMS phishing featured in 17% of attacks.<\/p>\n<h2 class=\"wp-block-heading\">Breaches by industry<\/h2>\n<p class=\"wp-block-paragraph\">Healthcare remains the industry hit with the highest average costs per breach at $6.64 million despite a drop from $7.42 million last year.<\/p>\n<p class=\"wp-block-paragraph\">Attackers continue to value and target the industry\u2019s patient personal identification information (PII), which can be used for identity theft, insurance fraud, and other financial crimes.<\/p>\n<p class=\"wp-block-paragraph\">The mean time organizations took to identify and contain a breach rose to 247 days, a slight 2.5% year-on-year increase that reversed a five-year decline. \u201cNew threats from AI-driven attacks are challenging even the quickest response times,\u201d the IBM-sponsored study notes.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Average breach cost by industry<\/strong><\/p>\n<div class=\"overflow-table-wrapper\"><strong>Industry<\/strong><strong>2026<\/strong><strong>2025<\/strong><strong>Change<\/strong>Healthcare$6.64M$7.42M-11%Financial$6.29M$5.56M+13%Industrial$5.50M$5.00M+10%Technology$5.50M$4.79M+15%Entertainment$5.38M$4.43M+21%Pharmaceuticals$5.25M$4.61M+13%Energy$5.24M$4.83M+8%Professional services$5.08M$4.56M+11%Communications$4.71M$3.75M+26%Transportation$4.50M$3.98M+13% <\/div>\n<h2 class=\"wp-block-heading\">Breach cost variables<\/h2>\n<p class=\"wp-block-paragraph\">While industry averages provide benchmarks, calculating the true, final cost of a specific data breach is notoriously difficult and relies heavily on forecasting.<\/p>\n<p class=\"wp-block-paragraph\">\u201cImmediate technical costs are quantifiable, but devastating long-term impacts like reputational damage, lost business, and regulatory fines are intangibles, making total breach cost figures informed estimates rather than exact science,\u201d says Huntress\u2019 Agha.<\/p>\n<p class=\"wp-block-paragraph\">Several experts quizzed by CSO named the cybersecurity skills gap, supply chain vulnerabilities, and the escalating threat landscape as the three main factors in making breaches more expensive and harder to manage.<\/p>\n<p class=\"wp-block-paragraph\">AJ Thompson, chief commercial officer at IT consultancy Northdoor, who sits on IBM\u2019s Worldwide Security Advisory Council advising on data access and security, says the \u201cbigger cost driver is still \u2018how fast you spot a breach\u2019 rather than the sophistication of an attack.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cA shortage of experienced security staff and patchy visibility into supply chain and third-party risk both stretch out that detection window, and every extra week unnoticed adds to the bill,\u201d Thompson adds.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Reputational damage remains a key cost of being breached<\/h2>\n<p class=\"wp-block-paragraph\">In many ways immeasurable, <a href=\"https:\/\/www.csoonline.com\/article\/571857\/the-emotional-stages-of-a-data-breach-how-to-deal-with-panic-anger-and-guilt.html\">reputational damage<\/a> remains among the most significant costs in the wake of a breach. \u201cUltimately, customer trust is very easy to break, and very difficult to build,\u201d <a href=\"https:\/\/www.forrester.com\/analyst-bio\/allie-mellen\/BIO16084\">Allie Mellen<\/a>, senior analyst at Forrester, tells CSO.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/businessvalue\/\">Bob Dutile<\/a>, chief commercial officer at UST, agrees: \u201cThe cost of a data breach is typically realized in relative competitive change in the marketplace. Companies find that their brand does not command the same price premium, customer conversion costs are higher, and market share is lost. For a public company, the near-term assessment of the cost impact is reflected in stock price movement.\u201d<\/p>\n<p class=\"wp-block-paragraph\">According to Dutile, research shows that between $8 million and $10 million is a good planning number in the US for a midsize business facing a modest breach of under 250,000 records. About a third of that cost will be loss of business due to reputation damage.<\/p>\n<p class=\"wp-block-paragraph\">How a company responds to and communicates a breach can have a large bearing on that reputational impact, Forrester\u2019s Mellen notes. \u201cUnderstanding how to maintain trust with your consumers and customers is really critical here,\u201d she adds. \u201cThere are ways to do this, especially around building transparency and using empathy, which can make a huge difference in how your customers perceive you after a breach. If you try to sweep it under the rug or hide it, then that will truly affect their trust in you far more than the breach alone.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Severe business downtime can cost millions<\/h2>\n<p class=\"wp-block-paragraph\">Business downtime can also be significantly costly for a breached organization, depending on the level and extent of the downtime and how technology-dependent the firm is.<\/p>\n<p class=\"wp-block-paragraph\">Nearly all the organizations studied suffered operational disruption, taking an average of 100 days to recover from a security incident.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/heretoserve.org\/team\/jason-hicks\/\">Jason Hicks<\/a>, field CISO at Coalfire, tells CSO: \u201cOften a breach is not going to take a company completely offline, but it can happen. The more critical systems that are taken down, the more significant the cost.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Manufacturing tends to have the best metrics around this, as it\u2019s relatively simple to measure the cost per minute if an assembly line is down, Hicks says. \u201cThis can translate into millions of dollars a day for a large manufacturing company. This can be more nebulous for other industry verticals, but there are models to get a reasonable feel that can be applied to each vertical.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Regulation and litigation add to data breach costs<\/h2>\n<p class=\"wp-block-paragraph\">Increasingly strict <a href=\"https:\/\/www.csoonline.com\/article\/573561\/instagram-faces-402-million-fine-for-alleged-mishandling-of-childrens-data.html\">data protection and privacy laws<\/a> along with litigation are seeing a growing number of companies issued large fines, paying hefty settlements, and stumping up for legal fees following data breaches and non-compliance.<\/p>\n<p class=\"wp-block-paragraph\">\u201cRegulated industries suffer not only the immediate cost of responding to, containing, and remediating vulnerabilities but also the long-term effects of additional penalties from their regulatory bodies and legal settlements,\u201d Nick says. Highly regulated industries, such as healthcare and financial services, typically run one and two in order of cost per breach because they will pay more non-compliance fines than others, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cInvestigation and adjudication often take years for the victim organization to reach a monetary settlement with affected parties.\u201d <a href=\"https:\/\/www.csoonline.com\/article\/574681\/paypal-sued-for-negligence-in-data-breach-that-affected-35000-users.html\">Legal costs<\/a> are one of the largest expenditures organizations face in data breaches, Nick states. \u201cOrganizations rarely have the legal and privacy expertise in-house. To ensure compliance, they must hire outside counsel to lead their reporting.\u201d<\/p>\n<h2 class=\"wp-block-heading\">The role of cyber insurance<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.csoonline.com\/article\/571703\/cyber-insurance-explained.html\">Cyber insurance<\/a> is one way that companies mitigate the cost risks of breaches. Sharp increases in cyber insurance premiums <a href=\"https:\/\/www.csoonline.com\/article\/3537205\/cyber-insurance-price-hikes-stabilize-as-insurers-expect-more-from-cisos.html\">have been stabilizing of late<\/a>, but even organizations covered by insurance can expect to dole out extra cash to make good after a breach. One definite cost hit will be a hike in their premiums, Guidehouse\u2019s Nick says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSome organizations have reported post-breach increases in premiums of approximately 200%,\u201d he adds.<\/p>\n<p class=\"wp-block-paragraph\">Insurers are also implementing more coverage limitations, meaning that even with a policy in place, businesses could find themselves financially responsible for certain breach-related costs.<\/p>\n<p class=\"wp-block-paragraph\">In fact, Forrester\u2019s Mellen says any notion that policies will allow organizations to fully recover financially from a cyberattack is folly. \u201cIn reality, it\u2019s not going to cover all of the costs associated with any type of cyberattack, and we see some insurance firms not even covering ransomware at this point as part of their payouts,\u201d she adds.<\/p>\n<p class=\"wp-block-paragraph\">Another factor to consider is that cyber insurance providers typically have a list of approved service providers such as lawyers and forensics firms, Hicks says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf your preferred provider is not on their list, you may have to work with them to get them included, or potentially have to change providers. This can be costly, as firms are often leveraging their existing service providers to secure the maximum discounts based on the volume of work done with the partners,\u201d Hicks says.<\/p>\n<h2 class=\"wp-block-heading\">Ransomware extortion on the rise<\/h2>\n<p class=\"wp-block-paragraph\">Reported ransomware incidents rose in the last 12 months compared to the year prior (39% vs. 34%) as attackers have abused AI technologies to automate and scale their attacks.<\/p>\n<p class=\"wp-block-paragraph\">While disrupting operations through encrypting<strong> <\/strong>remains a key tactic (23%), attackers are shifting to higher-impact pressure methods, such as threatening to leak stolen data (a common feature of so-called double extortion attacks).<\/p>\n<h2 class=\"wp-block-heading\">Insufficient security staffing leads to higher breach costs<\/h2>\n<p class=\"wp-block-paragraph\">According to IBM\u2019s latest report, the security skills shortage is one of the biggest data breach cost amplifiers, with the average additional cost of data breach due to cyber skills shortage pegged at $180,000.<\/p>\n<p class=\"wp-block-paragraph\">If insufficient security staff equates to greater data breach costs, organizations should heed Mellen\u2019s warning about the impact a poorly handled data breach can have on employees.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf they don\u2019t feel like the organization is able to protect them or customers in the event of a breach, or that they blame their employees for a breach, then they\u2019re likely going to start looking for jobs elsewhere because it creates a bit of a hostile environment for them,\u201d she says. \u201cIt is very important for organizations to recognize that they need to accept responsibility and protect both their employees and their customers.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Taking a DevSecOps approach to software development was the No. 1 factor that reduced breach costs, according to the report, ahead of use of identity and access management. Running key lifecycle management tools rounded out the top three factors.<\/p>\n<p class=\"wp-block-paragraph\">Security incidents involving <a href=\"https:\/\/www.csoonline.com\/article\/3964282\/cisos-no-closer-to-containing-shadow-ais-skyrocketing-data-risks.html\">shadow or unsanctioned use of AI tools<\/a> more than doubled to 43% this year compared to 20% in 2025. Shadow AI is starting to rival supply chain breaches and security system complexity as a leading factor in exacerbating breach costs, according to the report.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Preparedness is key to managing data breach costs<\/h2>\n<p class=\"wp-block-paragraph\">No matter the specific costs involved, experts agree that preparedness is key to mitigating the financial repercussions of a breach.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFaster incident response continues to be a clear driver for lowering the cost of a breach,\u201d UST\u2019s Dutile says. \u201cThe worst losses are those that go undetected for an extended time or have a slow or ineffective response.\u201d<\/p>\n<p class=\"wp-block-paragraph\">To that end, more than half of organizations surveyed say they plan to invest in AI security and governance tools post-breach, an 88% increase from last year and a reaction to concerns over frontier AI model threats.<\/p>\n<p class=\"wp-block-paragraph\">Modern cybersecurity requires a post-breach mindset which understands that, eventually, a successful data breach is going to occur, Forrester\u2019s Mellen adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOperating under those conditions, you need to figure out how you\u2019re going to handle that and build your resiliency to respond better and faster. This isn\u2019t just about the security function either, and it needs to be spread across an organization, considering what marketing is going to do, what sales is going to do, etc. \u2014 how, as a business, you can demonstrate you value your customers and that you want to make it right as quickly and effectively as possible,\u201d she says.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The financial impact of a data breach is substantial for any modern business, regardless of industry or size. IBM\u2019s latest Cost of a Data Breach report discovered that, from March 2025 to February 2026, the average cost of a data breach rose to $6 million, up 35% from $4.44 million a year earlier. The 2026 [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9056,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9055","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9055"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9055"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9055\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9056"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9055"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9055"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9055"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}