IBM put the global average at $4.99 million, up 12% in a year across 602 breached organisations. More than a quarter of malicious attacks were AI-driven, and those cost roughly a million dollars more each.
Key Takeaways
The headline from IBM's 2026 Cost of a Data Breach Report is a record: $4.99 million on average globally, up 12% in a single year across 602 organisations breached between March 2025 and February 2026. A 12% rise is notable in a series that usually moves in single digits, and IBM attributes it largely to higher costs for detection, escalation and business disruption.
The more consequential finding is the one IBM broke out for the first time. More than a quarter of malicious attacks were AI-driven, a 56% increase on the previous year, and those attacks added an average of $1 million to the cost of a breach. That is not a claim that AI makes attackers cleverer in the abstract. It is a measured cost differential attached to a specific and rapidly growing category of incident.
The mechanism is speed. Breach cost correlates strongly with dwell time, because everything expensive, lateral movement, data staging, exfiltration, follows from how long an intruder operates undetected. Compressing the attacker's workflow compresses the defender's window, and a defender who arrives after the data has moved is running a recovery rather than a containment.
“AI has dramatically lowered the barrier for cybercriminals. Attackers can now execute attacks in minutes rather than days.”
Mark Hughes, Global Managing Partner for Cybersecurity Services, IBM
That framing also explains the sector spread. Healthcare stayed most expensive at $6.6 million, ahead of financial services at $6.3 million, industrial and technology at $5.5 million each, and entertainment at $5.4 million. The ordering has been stable for years and tracks two things: how tightly regulated the disclosure is, and how badly the organisation functions while its systems are down.
It is worth naming which components moved, because they point at different remedies. IBM attributes the rise largely to detection and escalation costs and to business disruption. Detection and escalation is internal labour and external forensics, and it scales with how long and how confusing the investigation is. Business disruption is revenue and productivity lost while systems are unavailable, and it scales with how much of the business stops. Neither responds to prevention spending; both respond to speed and to recoverability.
85% of organisations say they plan to increase security spending in response to frontier AI threats. Read alongside the rest of this year's research, that is where the risk of a bad decision sits. This publication reported last week on Splunk's finding that 46% of security teams already spend more time maintaining tools than defending, and that 78% describe their tooling as dispersed and disconnected. An increase in spend that arrives as additional products makes the measured problem worse.
If the cost driver is attacker speed, the spend that pays for itself is whatever shortens detection and response: correlation across the estate, automated containment, tested recovery. None of those is a new category of product, and all of them are harder to buy than another sensor, which is precisely why 85% intending to spend more is not the same as 85% reducing cost.
There is a sequencing implication for anyone planning next year's budget. If AI-driven attacks are up 56% and carry a $1 million premium, the marginal value of an hour saved in detection is now higher than it was, which changes the return on automation relative to the return on additional coverage. That is a genuine reallocation argument rather than a call for more money, and it is available to teams whose budgets are flat.
A single global average across 602 organisations flattens an enormous distribution, and $4.99 million is not a forecast for any individual company. Its usefulness is comparative: the year-over-year direction, the sector ranking, and the AI premium are all robust in a way the absolute figure is not. Boards that adopt $4.99 million as their expected loss are substituting a benchmark for a risk assessment.
The better use of the report is to check whether your own controls address what it says drives cost. Detection and escalation costs rose. Business disruption costs rose. Those are consequences of time, not of insufficient tooling, and they are measurable internally without waiting for next year's survey.
The report is often read as a warning about how expensive breaches have become. It reads better as a statement about tempo: the bill went up because attackers got faster, and nothing on a purchase order makes a defender faster by itself.
Guide
Detection and escalation costs are what rose, and both are decided in the first hour by whether a runbook exists in writing.
Download
Report
Sector detail behind the $6.3 million financial services figure, including the access routes that recur in the most expensive cases.
Download
Whitepaper
Business disruption cost tracks how much of the estate stops working, which makes cloud architecture a breach-cost variable rather than an infrastructure one.
Download
Analysis of 800 breach events reveals the regulatory fine represents less than 30% of total breach cost.
Regular AI use on corporate devices rose from 15% to 45% of employees, with 67% using non-corporate accounts.