Core Insights - The average cost of a data breach in the U.S. has risen to $10.22 million, while the global average has decreased to $4.44 million [1][7] - There is a significant gap between AI adoption and its security governance, with only 49% of breached organizations planning to invest in security post-breach [1][13] Breaches and AI Security - 13% of organizations reported breaches involving AI models or applications, with 97% of those lacking AI access controls [6] - 60% of AI-related security incidents resulted in compromised data, and 31% led to operational disruptions [6] - Organizations extensively using AI in security operations saved an average of $1.9 million in breach costs and reduced the breach lifecycle by 80 days [3][4] Financial Impact of Breaches - The global average cost of a data breach fell to $4.44 million, marking the first decline in five years, while U.S. breaches reached a record high [7] - Healthcare breaches remain the most expensive, averaging $7.42 million, despite a $2.35 million reduction compared to 2024 [7] - Organizations that detected breaches internally saved an average of $900,000 in breach costs compared to those disclosed by attackers [7] Operational Disruption - Nearly all organizations studied experienced operational disruption following a data breach, with most taking over 100 days to recover [8] - Almost half of the organizations reported plans to raise prices due to breaches, with one-third indicating increases of 15% or more [9] AI Governance and Shadow AI - 63% of breached organizations lack an AI governance policy, and only 34% of those with policies conduct regular audits [7] - One in five organizations reported breaches due to shadow AI, with those using high levels of shadow AI facing $670,000 higher breach costs [7] Ransom Payment Trends - There is a growing trend of organizations refusing to pay ransom demands, with 63% opting not to pay compared to 59% the previous year [13]
IBM Report: 13% Of Organizations Reported Breaches Of AI Models Or Applications, 97% Of Which Reported Lacking Proper AI Access Controls