What Is Operational Resilience?
Learn how to build operational resilience against cyber threats, outages, and disruption, with best practices aligned to FCA, PRA, and DORA.
Secure data optimisation & proactive backup
Proactive Licensing, Compliance & Asset Management
Agile, Modular, & Secure Cyber Security & Managed Siem
Manage & Transform Multi-Cloud, Hybrid & On-Premise
Artificial intelligence has changed the maths of cybersecurity. For the first time, attackers are routinely operating at machine speed, using AI to find vulnerabilities, craft convincing phishing lures and scale attacks in a fraction of the time it once took. Defenders are having to catch up fast, and this year's numbers show just how expensive it is when they don't.
In this blog, we break down the headline findings from the IBM Cost of a Data Breach Report 2026, with a focus on what's driving the record cost increase, where AI is creating new exposure, and what organisations can do about it.
Attackers are no longer just using AI to write better phishing emails, although that remains the single most common tactic. This year's report found that AI deepfake impersonation and AI-enabled malware are driving the highest volume of AI-driven attacks, and that these attacks are increasingly concentrated on critical infrastructure. Financial services and energy alone accounted for 62% of all AI-driven breaches studied, a worrying sign given how much these sectors underpin everyday life.
Attackers are also targeting AI itself. Breaches involving model inversion and prompt injection were among the costliest incident types in the whole report, averaging $6.07 million and $5.89 million respectively. As organisations plug AI models and agents deeper into daily workflows, those models are becoming an attack surface in their own right, not just a productivity tool sitting on the sidelines.
For organisations still assessing where their exposure sits today, an independent exposure management assessment is a practical starting point, giving visibility into how an organisation actually appears to attackers before AI-driven reconnaissance finds the gaps first.
The most striking figure in this year's report is the 92% of AI-related breaches that involved organisations with no proper AI access controls in place. That's not a sophisticated attack finding a zero-day. In most cases, it's a basic enforcement gap that never needed attacker sophistication to exploit.
Shadow AI, meaning employees using AI tools that haven't been sanctioned or secured, is compounding the problem. Security incidents involving shadow AI more than doubled this year, and where they occurred, they led to data loss, disrupted operations and, in around one in five cases, a regulatory fine. At the same time, fewer than half of organisations report securing the non-human identities, such as service accounts and API keys, that AI agents rely on to function. As AI agents proliferate across the business, from customer service to security operations, those unmanaged identities represent a fast-growing blind spot.
This is where a managed approach to identity and credential protection matters. Our secrets and service management service exists precisely to close this gap, bringing the same governance and lifecycle control to machine identities that most organisations already apply to human ones.
The report's clearest message is that speed decides outcomes. Organisations using AI and automation extensively across their security lifecycle cut their identification and containment time to 215 days, 65 days faster than organisations not using these tools at all, and saved close to $2 million per breach as a result. Yet only 36% of breached organisations said they were using these tools extensively, and even fewer had extended that use into prevention rather than just detection and response.
The same pattern shows up in agentic AI adoption within the security operations centre (SOC). Half of breached organisations have deployed AI agents in their SOC, but the majority are focused on threat hunting and response. Only 18% are using agents for vulnerability scanning and management, precisely the area where frontier AI models are giving attackers their biggest advantage. Closing that gap is one of the most direct ways organisations can start levelling the playing field.
Services like Managed SIEM and MDR & MXDR are designed to bring that machine-speed detection and response to organisations that don't have the resource to build it in-house, turning the report's findings into a practical advantage rather than a source of anxiety.
Taken together, this year's findings paint a clear picture. AI is reshaping breach economics in favour of attackers, but only for organisations that haven't matched their AI adoption with equivalent governance and machine-speed defences. The gap between the two groups is now measured in millions of pounds and months of exposure.
The full IBM Cost of a Data Breach Report 2026 goes into far greater depth, covering industry-specific breach costs, the true cost of ransomware's evolving tactics, and detailed recommendations for closing the gap between AI adoption and AI governance. Whether you're responsible for cyber strategy in financial services, the public sector, healthcare or manufacturing, it's essential reading for anyone shaping next year's security investment.
Report
Download the IBM Cost of a Data Breach Report 2026 for full analysis of AI-driven attack trends, the true cost of ungoverned AI, and practical recommendations for closing the gap between adoption and oversight.
Download Report
Learn how to build operational resilience against cyber threats, outages, and disruption, with best practices aligned to FCA, PRA, and DORA.
Vibe coding leads to reliance on familiar patterns, quick fixes, and unchecked dependencies. Learn how these hidden risks expose organisations to cybe...
Key Takeaways AI in cyber security helps organisations detect, prevent and respond to evolving threats faster than traditional security tools. AI-powe...