Initializing portfolio

000

Aravind.
All articles
Cybersecurity3 min read

The Number to Read in IBM's 2026 Breach Report Isn't the Cost

Breach costs rose 12% to $4.96 million globally. The findings underneath matter more: AI-enabled attacks up 56%, containment slowing for the first time in five years, and 92% of AI-breach victims with no AI access controls.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
The Number to Read in IBM's 2026 Breach Report Isn't the Cost

The number everyone quotes from IBM's Cost of a Data Breach Report is the average cost. This year: $4.96 million globally, up 12%. In the United States, $11.5 million, up 11% and nearly double the global figure.

That isn't the interesting number in the 2026 edition.

The report, produced with the Ponemon Institute, covers roughly 600 breached organisations between March 2025 and February 2026, with more than 3,500 security and C-suite leaders interviewed. What sits underneath the headline cost is more useful than the cost itself.

The five-year improvement just reversed

Mean time to identify and contain a breach rose to 247 days, up from 241.

Six days is small in absolute terms. The direction is not — it ends a five-year run of steady improvement. Detection and containment had been getting faster every year as tooling, automation and playbooks matured. Something arrested that. The obvious candidate is in the next finding.

More than a quarter of organisations faced AI-enabled attacks

Over 26% reported AI-enabled attacks, a 56% jump on the previous year. Not better-worded phishing. Attacks where the AI does the work.

Put that next to this week's Taiwan disclosure — a system of autonomous agents running a four-day government intrusion from reconnaissance to exfiltration — and the asymmetry is easy to state. Attack throughput went up. Defensive throughput didn't.

Of the organisations breached through something AI-related, 92% lacked proper AI access controls.

That's a governance failure, not a technology failure. AI got into production faster than identity, authorisation and audit were extended to cover it. The things your teams adopted this year — copilots, agents, model endpoints, retrieval pipelines sitting on internal data — hold credentials and have reach. Most of them have never appeared in an access review.

If you run AI programmes in a large organisation, take this one to your next steering committee. It's also the most fixable finding in the report.

What actually got breached

Customer personal data showed up in 52% of breaches, employee data in 35%, intellectual property in 32%. IP was the most expensive category to lose.

By cause: 55% malicious attacks, 23% human error, 22% IT failure. Nearly half of all breaches still come down to mistakes and broken systems rather than adversaries — worth remembering before the whole budget goes to threat intelligence.

The response, and the tension in it

85% of organisations plan to spend more on frontier AI threats. 75% of leaders say they'll deploy agents for alert triage, vulnerability management and penetration testing.

Both are defensible. Both also deserve a pause: the answer to agentic attackers is agentic defenders, deployed by a population of organisations where 92% haven't worked out access controls for the AI they already run. Adding more autonomous systems to an environment you can't yet govern is how next year's numbers get written.

Sequence it. Identity, authorisation and audit for AI systems first. Defensive agents after.

Source: Data breach costs climb as AI-powered attacks surge — FM Magazine

#AI Security#Agentic AI#Data Breach#Governance#IBM

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.