Data breach costs climb as AI-powered attacks surge

More than one in four data breaches are AI-enabled, according to an annual IBM report. The shifting threat landscape has prompted C-suite leaders to rethink the use of AI agents in security.

Cyberattacks are getting cheaper; breaches are getting costlier. That’s one key point of an annual report that underscores how artificial intelligence (AI) is radically changing the cyber-threat landscape.

More than one in four organisations experiencing a malicious attack reported that it was AI‑driven, a 56% increase over last year. The average cost of a data breach climbed 12% globally over last year, reaching nearly $5 million, according to IBM’s Cost of a Data Breach Report 2026.

The longstanding report, conducted jointly with the Ponemon Institute, used data from about 600 organisations affected by data breaches from March 2025 through February 2026. The Ponemon Institute interviewed more than 3,500 security and C-suite business leaders.

The US had the highest average costs among the markets studied. The average cost of a breach in the US reached a record $11.5 million, an 11% increase over last year and nearly double the global average. The report found that higher business costs and higher regulatory fines contributed to the disparity.

Most breaches (52%) targeted customer personally identifiable information (PII), followed by employee PII (35%). Intellectual property — the costliest type of breach — was stolen or compromised in nearly a third of data breaches (32%).

Detection, escalation, and lost business accounted for most breach-related costs, the report said. Those costs include everything from crisis management to disrupted operations and customer churn.

Weak access controls allow adversaries to gain unauthorised access to sensitive data. Among organisations experiencing an AI-related breach, the vast majority (92%) lacked proper AI access controls, the report said.

Malicious attacks accounted for 55% of breaches (up from 51% last year), followed by human error (23%) and IT failure (22%).

Incident response time increased

Ending a five-year trend of improvement, breach response time rose by 2.5% year over year. The mean time that organisations took to identify and contain a breach increased from 241 days in last year’s report to 247 days this year.

Security teams using AI and automation have generally become faster at finding and stopping attacks, the report said. Simultaneously, cybercriminals are using those tools to launch more sophisticated attacks, causing teams to rethink their defences.

In response, 85% of organisations plan to increase spending in response to frontier AI model threats, the report said. Three quarters of leaders said they will deploy agents at higher rates in alert triage, vulnerability management, and scans and penetration testing.

4 ways to prevent a data breach

The report recommends four approaches organisations can take to prevent and reduce the costs of a data breach:

Apply agentic AI to vulnerability management. Using AI to analyse exposures, enforce policies, and coordinate detection and containment with minimal human intervention can reduce exposure windows and contain “high velocity” attacks faster.

Transform identity systems. Identity systems can then help ensure AI agents operate safely by implementing just-in-time access, time-bound approvals, and continuous risk-based runtime controls from devices, users, and workloads.

Maintain control over where AI systems run. “Monitoring how data enters, transforms within, and exits AI systems can help organisations proactively identify sensitive data exposure risks, strengthen AI governance and compliance, and securely scale AI adoption,” the report said.

Establish post-quantum agility. Threats to sensitive data require modernised cybersecurity practices that improve encryption and cryptography management.

— To comment on this article or to suggest an idea for another article, contact Steph Brown at Stephanie.Brown@aicpa-cima.com.

Up Next

UK hiring measure hits neutral level for first time since 2022

By Steph Brown
August 11, 2026
July marks the first month without a drop in permanent hiring since September 2022, but companies remain more reliant on temporary workers.
Advertisement

LATEST STORIES

Data breach costs climb as AI-powered attacks surge

Steps to strengthen your company’s corporate culture

UK hiring measure hits neutral level for first time since 2022

Ways managers can use company values to frame performance metrics

Employees increasingly consult AI, not coworkers

Advertisement
Read the latest FM digital edition, exclusively for CIMA members and AICPA members who hold the CGMA designation.
Advertisement

Related Articles