IBM's Cost of Data Breach Report shows that global costs have decreased, but in the United States they have increased. Above all, it highlights a new emerging trend: the impact of Artificial Intelligence on both attacks and defenses.
See also: IBM i vulnerability allows privilege escalation

The average global cost of a data breach fell to $4.44 million (the first decrease in five years), while the average cost in the U.S. rose to a record $10.22 million , according to IBM. The average breach life cycle decreased to 241 days – a record low and 17 days fewer than the previous year.
The higher cost of a breach in the US is not so much related to regional security levels or the impact of AI. “Although the US has adopted AI-based defense technologies at a slightly higher rate, US organizations continue to face the highest cost of a data breach each year,” explains Kevin Albano, partner at IBM X-Force Intel.
The most striking element of this year’s report (PDF) is that, for better or worse, AI is here – and criminals seem to be taking it more seriously than defenders. AI is a new and high-value target, and while breaches involving it are still a relatively small percentage of the total number of breaches, they are sure to grow as its use increases.
See also: SIEM vulnerabilities in IBM QRadar allow execution of arbitrary commands
AI is used both as a target and as a means of attack and a defense tool. It is a high-value target. It amplifies the scale and complexity of attacks, but can also be used for faster detection of them. It is characteristic that companies that use AI in their defense reduce the cost of a breach. Equally concerning, however, is that many companies exhibit weaknesses in protecting their own AI models.

13% of breaches involved AI models or applications, and 97% of them had no access control mechanisms at all. 60% led to data leakage and 31% to operational disruption. Security and governance appear to be given second priority when implementing AI.
The lack of access control is particularly concerning, given that preventing unauthorized access is the foundation of any form of security. This failure is largely due to the pressure to quickly implement AI, due to its potential to automate functions and reduce costs. “The complexity and novelty of AI make it difficult for organizations to implement effective access controls, as security best practices for AI systems are still in the formative stages,” Albano explains.
See also: IBM: $150 billion investment in the United States
Most breaches target customers' personal data, accounting for 53% of stolen or compromised data. This year, electronic phishing replaced stolen credentials as the most common initial attack vector – likely due to the increasing use of artificial intelligence.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
