This page was machine-translated and may differ from the original. View original
Up 56% year-over-year, companies adopting security AI save $2 million in damage costs
On the 30th, IBM released the '2026 Cost of a Data Breach Report,' conducted jointly with the Ponemon Institute.
An analysis of actual breaches at 602 organizations worldwide from March 2025 to February 2026 found that 25% of malicious breaches were attacks utilizing AI.
This is a 56% increase compared to the previous year.
The average cost of damage from AI-based breaches was $6 million, exceeding the overall average of $4.99 million by about $1 million.
AI-based attacks mainly took the form of impersonation using deepfakes and AI-generated malware.
IBM analyzed that the economic structure of cyber risk is fundamentally changing, as the cost of an attack has dropped to the thousands of dollars level, while the cost of damage recovery amounts to millions of dollars.
halfCompanies that actively adopted AI and automation into their security operations were found to have saved an average of $2 million in incident costs.
One in four companies was still not applying these technologies to security.
“AI makes attacks faster and cheaper, while the cost of responding to breaches continues to rise,” said Suja Viswesan, Vice President of IBM Security Software. “The longer it takes from the discovery of a threat to its actual resolution, the higher the cost of damages becomes.”
62% of AI-based attacks targeted critical infrastructure.
The average cost of a breach in the financial services industry was $6.3 million, while in the energy industry it was $5.2 million.
IBM analyzed that targeted attacks on specific industries could have a cascading impact across the supply chain and essential services.
A follow-up survey conducted by the Ponemon Institute on 456 organizations included in this report found that 85% of companies aware of advanced next-generation AI attack capabilities plan to expand their security investments.
This figure significantly exceeds the 64% of companies that expressed an intention to expand security investment after experiencing an actual security breach.
However, while more than half of companies utilize AI agents for threat detection and response, only 18% apply them to vulnerability management, revealing a gap in response.
Key additional findings include: more than 20% of companies have experienced AI model or application infringement incidents; only 37% of companies encrypt all stored and transmitted data; the proportion of ransomware incidents increased from 34% in the previous year to 39%; and the main means of ransomware pressure were identified as corporate reputation (41%), employee data (35%), and intellectual property rights (31%).
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













