Every summer, IBM and the Ponemon Institute release the report that security teams quietly use to justify next year's budget. The 2026 edition, based on interviews tied to 602 breached organizations across 16 countries and 17 industries, lands with a headline number that will get board attention on its own. But the more useful story is underneath it: the economics of attack and defense have come apart, and AI is the reason.
Here's what's actually in the report, and what it should mean for leadership and security teams alike.
The global average cost of a data breach hit $4.99 million in 2026, a 12% jump from the year before and the highest figure the report has recorded in its 21 editions. That reverses a rare bit of good news from 2025, when average costs had actually dropped.
In the United States, the picture is starker: the average breach cost $11.5 million, more than double the global figure and up sharply from the prior year's record.
Where does the money actually go? Not mostly to ransom payments or regulatory fines, despite what boards often assume. Detection, escalation, and lost business—lost sales, customer churn, reputational damage—account for roughly 63% of the total cost, or about $3.18 million of the $4.99 million average. Both categories rose more than 11% year over year. Post-breach response costs (legal fees, fines, notification) grew fastest in percentage terms, but they're still a minority of the bill.
The lesson for leadership: the biggest expense of a breach isn't the incident itself, it's everything that happens while you're still figuring out what happened.
The report's breach lifecycle metric—mean time to identify and contain a breach—rose to 247 days (183 days to identify, 64 to contain), a few days longer than the year before. That number matters more than it might seem: organizations that contained a breach in less than 200 days averaged $4.32 million in costs, while those whose incidents dragged past 200 days averaged $5.65 million. Same kind of breach, same industries—the difference is almost entirely how fast the organization found and closed the gap.
This is the report's central theme, and it's worth taking seriously rather than treating as marketing framing.
Attackers are moving faster and cheaper
One in four malicious breaches studied were AI-enabled—a 56% increase over the prior year—and those breaches cost an average of $6 million, about $1 million above the overall average. The most common AI-driven techniques were deepfake impersonation (nearly half of AI-enabled attacks) and AI-generated malware. Critical infrastructure sectors bore the brunt: 62% of AI-driven attacks hit them, with financial services ($6.3 million average breach cost) and energy ($5.2 million) the most targeted.
Defenders using AI are seeing real payoff, but adoption is stalling
Organizations that used AI and automation extensively across their security operations cut breach costs by nearly $2 million and shortened detection and containment time meaningfully compared to those that didn't. Yet roughly a quarter of organizations still haven't adopted these tools in security operations at all—leaving a widening gap between AI-equipped and AI-unequipped defenders.
Frontier AI models are changing risk calculus before a breach even happens
In a follow-up study Ponemon ran after the main survey, 85% of organizations said awareness of highly-capable frontier AI models is pushing them to increase security spending—compared to just 64% who said the same after actually experiencing a breach. In other words, the threat of what frontier AI can do is now motivating faster action than the pain of a past incident. That's a meaningful shift in how security budgets get justified.
But deployment of AI defenses is uneven
More than half of organizations use AI agents for threat detection and containment, but only 18% apply them to vulnerability management—meaning known weaknesses often sit unpatched even as AI shortens the window attackers need to exploit them.
It's not just AI-powered attacks on traditional systems; AI systems themselves are now a breach category. More than 20% of organizations reported a breach targeting an AI model or application directly. The most common root causes weren't exotic model attacks but mundane infrastructure gaps: compromised APIs, applications, or plug-ins (27%), and cloud misconfigurations affecting AI workloads (27%). Attacking the AI model inversion specifically—extracting sensitive training data—carried an average breach cost around $6 million, underscoring how expensive it is to lose control of what a model has learned.
The takeaway for security teams: the AI attack surface isn't primarily "someone jailbroke our chatbot." It's the same identity, API, and cloud-configuration hygiene problems organizations have struggled with for years, now wrapped around a new, high-value asset.
Some findings will feel familiar to anyone who's read prior editions, and that consistency is itself a signal—these aren't solved problems.
Phishing remained the most common initial attack vector for the fourth consecutive year, alongside supply chain compromise, valid account abuse, and social-engineering tactics like help desk impersonation and MFA fatigue.
Healthcare stayed the most expensive industry to breach for the thirteenth year running, at $6.64 million on average, with financial services close behind.
Ransomware incidents rose (39% of breached organizations reported one, up from 34% the year before), and attackers are increasingly skipping pure operational disruption in favor of reputational pressure—threatening to expose brand-damaging data (41%), employee data (35%), or IP (31%) rather than just encrypting systems.
Encryption hygiene is still weak. Only 37% of breached organizations said they encrypt sensitive data both at rest and in transit, and just 34% have visibility into their own cryptographic assets—a gap that matters more, not less, as quantum-safe migration becomes a live conversation.
Supply chain compromise remains one of the costliest single factors in a breach, reflecting how much risk organizations inherit from vendors and partners they don't fully control.
A few things should land differently in the boardroom than they did a year ago.
Breach cost is now primarily a speed problem, not just a prevention problem. The 200-day cost cliff means that investment in detection and response capability pays for itself in a way that's now quantifiable. If your organization can't say with confidence how fast it detects and contains an incident, that's the first gap to close.
"We haven't been breached" is a weaker signal of security posture than it used to be. Frontier AI capability is now driving spending decisions ahead of incidents, not just after them. Treat that as permission to fund resilience work proactively rather than waiting for a scare.
AI governance is now a board-level exposure, not just an IT policy question. With more than a fifth of organizations reporting breaches targeting AI systems themselves, and root causes tracing back to ordinary API and cloud misconfiguration failures, "we have an AI policy" isn't the same as "we've secured our AI infrastructure." Ask which one you actually have.
The ROI case for security AI and automation is now backed by a specific number—nearly $2 million in average savings for organizations using it extensively. That's a concrete figure to put against the cost of the tooling and staffing needed to get there.
For the people actually doing the work, the report reinforces a few priorities.
Close the gap between detection and remediation. The report frames this explicitly: attackers can now move in hours or days, while organizations are still averaging months to identify, contain, and recover. Building remediation into development workflows and enforcing identity controls at runtime—rather than relying on periodic reviews—is the direction the data point.
Extend AI and automation beyond detection and into vulnerability management. Detection and containment are the most AI-automated parts of most security programs today; patching and exposure management lag far behind, even though that's where attackers are gaining the most speed advantage.
Treat AI infrastructure like any other production system, because attackers already are. Compromised APIs and cloud misconfigurations—not sophisticated model attacks—are the leading causes of AI-targeted breaches. Standard hygiene (access controls, configuration management, monitoring) applies here just as much as it does anywhere else.
Revisit encryption and cryptographic visibility now, not later. With only about a third of organizations able to say where their cryptographic assets even are, this is a foundational gap that predates AI concerns and will only get harder to close as post-quantum migration becomes necessary.
Expect social engineering to keep evolving with the attackers' tools. Deepfake impersonation and AI-enabled malware are now the leading edge of AI-driven attacks, and help desk impersonation and voice/SMS phishing carry some of the highest per-incident costs of any vector—meaning security awareness training built around "spot the suspicious email" is increasingly out of date.
The 2026 report's real message isn't "breaches are more expensive"—every edition says that. It's that the reasons they're expensive are shifting: less about the moment of compromise, more about the months an organization spends inside an incident before it's contained, and increasingly about whether AI is amplifying the attacker's side of that equation faster than it's strengthening the defender's.
Organizations that can point to fast detection, integrated remediation, and mature AI governance are, by the report's own numbers, paying millions less than the ones that can't. That gap is only going to widen.