Skip to Main Content
Publications

Ten Takeaways from IBM's 2026 Cost of a Data Breach Report

IBM has released its annual Cost of a Data Breach Report for 2026. The 21st edition of the report analyzed 602 data breaches experienced by organizations across 17 industries between March 2025 and February 2026. It provides one of the most comprehensive views available of the financial impact of data breaches on organizations around the globe.

This year's findings reinforce the way that AI-driven attack vectors are, unfortunately, reshaping the economics of a data breach. The proliferation of shadow AI, exponential increase in AI-based attacks, and persistent gaps in fundamental security controls have resulted in new record highs in the average costs of a data breach both globally and domestically. At the same time, organizations that have embraced AI and automation in their security operations continue to realize significant cost savings and faster response times.

Below are ten takeaways from the report along with recommended best practices for organizations seeking to manage the fluid cyber risk landscape.

1. The Average Cost of a Data Breach Reached New Highs in the U.S. and Globally: The global average cost of a data breach reached $4.99 million in 2026, a 12 percent increase over the prior year and the highest figure recorded in the report's history. In the U.S., breach costs remained more than double the global average at $11.5 million per incident, an 11 percent increase over last year. This upward trajectory continues a trend that accelerated following the pandemic and reflects the compound effect of regulatory complexity, litigation exposure, and increasingly sophisticated attacks targeting organizations based in the U.S.

2. AI-Driven Attacks Increased by 56 percent: Threat actors are weaponizing AI at an alarming pace. More than one in four organizations experienced an attack leveraging artificial intelligence, a 56 percent increase over last year. These AI-driven attacks have added an average of $1 million in costs per incident. According to IBM, most AI-driven attacks focused on critical infrastructure sectors – with financial services and energy organizations leading the way. Among AI attack vectors, deepfake impersonation drove the highest volume (45 percent of AI attacks), followed by AI-enabled malware (19 percent) and AI-generated phishing (19 percent).

3. Ransomware Attacks Rise with Shift to Targeting Brand Reputation: Thirty-nine percent of organizations reported that their systems were hit by ransomware attacks – marking the fourth consecutive year that incidents have increased. However, the threat actors are weaponizing ransomware in new ways. Although sensitive data and personally identifiable information (PII) remain critical targets, 41 percent of ransomware attacks reported that attackers targeted brand reputation, such as public shaming and media leaks. Therefore, while the threats of data theft and operational disruption remain, it's clear that threat actors are leveraging public forums to apply pressure and extort ransoms.

4. Breaches Involving AI Models Grew Substantially: AI-related breaches – meaning incidents involving the compromise of AI systems, training data, or infrastructure – represented 21 percent of all breaches, up from 13 percent just a year ago. Model inversion attacks, where threat actors extract sensitive data from a model, were the most expensive at $6.07 million. Other attacks that were among the costliest included data poisoning, prompt injections, and cloud misconfigurations affecting AI workloads. The substantial increase in attacks on AI models signifies that such tools are in the crosshairs of threat actors.

5. Organizations Still Lack AI Governance: Continuing a theme from last year, most organizations still lack proper AI governance and controls to protect against cyber threats. Of the organizations that experienced an AI-related incident, 92 percent lacked proper AI access controls and 68 percent lacked AI governance policies – which was actually up from 63 percent the prior year. Only 19 percent of organizations reported coordination between governance and security teams. These findings underscore the notion that AI adoption is outpacing oversight and that organizations deploying AI must treat AI security as a core element of their risk management framework – not an afterthought.

6. Shadow AI Incidents More than Double: Incidents involving shadow AI by employees more than doubled to 43 percent – compared to 20 percent in 2025. Such incidents also resulted in higher costs ($5.39 million versus $4.63 million). While data loss or compromise were present in nearly half of all of these incidents, more than one in five organizations also reported paying a regulatory fine.

7. Health Care Remains the Most Expensive Industry, but Financial Services is Gaining: For the 13th consecutive year, the health care industry had the highest average breach cost at $6.64 million. This number represents a 10.5 percent decrease from the prior year. Meanwhile, the average cost of a data breach in the financial sector was $6.29 million, compared to $5.56 million the previous year. Although threat actors continue to value the sensitive data in the health care industry, the increase in AI-related attacks has had a substantial impact on the financial sector, where costs continue to rise.

8. Average Breach Response Times Rose for the First Time in Five Years: After five consecutive years of improvement, the mean time to identify and contain a breach rose to 247 days – a 2.5 percent increase from the previous year. Breaches involving data stored across multiple locations took the longest to identify and contain (256 days). This regression illustrates the strong correlation between lifecycle duration and cost. Breaches with lifecycles exceeding 200 days cost an average of $5.65 million while those contained within 200 days cost $4.32 million on average. The overall uptick likely reflects the growing complexity of AI-driven and multi-vector attacks, which require more time to investigate and remediate. This finding reinforces the need for continued investment in detection engineering, incident response automation, and tabletop exercises.

9. A Majority of Organizations Failed to Encrypt Sensitive Data: A striking 53 percent of breached organizations reported that they did not encrypt sensitive data at rest and in transit at the time of the incident. An additional 10 percent were unsure whether their data was encrypted. This fundamental control gap persists despite years of regulatory guidance and industry best practices emphasizing encryption as a baseline safeguard. On-premises data was involved in 30 percent of breaches, up from 20 percent just two years ago, suggesting that legacy infrastructure remains a significant vulnerability. These findings serve as a stark reminder that organizations must prioritize data-centric security measures, including encryption, data classification, and access controls.

10. Organizations Remain Largely Unprepared for Quantum Threats: The report reveals significant preparedness gaps in two emerging areas. Only 26 percent of organizations have initiated a post-quantum cryptography project, and 61 percent lack controls to monitor and secure cryptographic objects. With quantum computing advancing rapidly, organizations that have not begun planning their cryptographic migration face increasing risk from adversaries stockpiling encrypted data.

Similarly, less than half (46 percent) of organizations secure non-human identities (NHIs) – such as service accounts, application programming interface (API) keys, and machine credentials – within AI workflows. Among those that do, 55 percent use machine identity lifecycle management, 39 percent employ secrets management, and only 36 percent deploy behavioral monitoring. As AI systems proliferate and interact with critical infrastructure through automated pipelines, unmanaged NHIs represent an expanding attack surface that demands immediate attention.

Recommendations and Best Practices for Your Organization

This year's report underscores several critical imperatives for organizations across all sectors. The following are some recommendations and best practices for your organization to address these risks:

  • Prioritize AI Governance Programs: With AI-driven attacks surging and AI-related breaches nearly doubling, organizations must invest in strong AI governance programs and security controls. This includes implementing proper access controls for AI systems, establishing frameworks and procedures, and addressing the persistent proliferation of shadow AI. The 2026 report illustrates that organizations are lagging even further behind on these issues. AI governance must be a core element of any organization's risk management framework moving forward.
     
  • Evolve Ransomware Preparedness: With threat actors now targeting brand reputation in ransomware attacks, your incident response plans need to evolve to address such extortion scenarios. Although the technical disruption of ransomware remains present, the legal and regulatory implications of public extortion attempts and leak sites must be considered proactively with pre-approved response strategies.
     
  • Close Fundamental Security Gaps: The finding that a majority of breached organizations lacked encryption is a true call to action. Organizations should ensure that sensitive data is encrypted at rest and in transit and conduct regular audits of such controls.
     
  • Prepare for the Post-Quantum Era Now: Begin assessing cryptographic dependencies now. Organizations should inventory their cryptographic assets, evaluate quantum-vulnerable algorithms, and develop migration roadmaps before quantum threats materialize.
     
  • Prioritize Tabletop Exercises: In light of the continued expansion of the attack surface and increase in AI-driven attacks, your organization must proactively prepare for these scenarios by conducting tabletop exercises on a routine basis. This is not just a technical issue; this is a management and enterprise-wide issue. Baker Donelson facilitates tabletop exercises for clients across the country and routinely consults with executive teams regarding these issues.

If you have questions about your data strategy or how to protect against unauthorized data access, please reach out to Alexander F. Koskey, CIPP/US, CIPP/E, PCIP or any member of our Data Privacy and Cybersecurity Team.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept