The Escalating Cost and Velocity of Breaches

Data breaches are becoming more expensive and harder to contain. The average cost of a breach has reached $5 million worldwide—a 12% increase from the previous year—with U.S.-based incidents averaging $11.5 million. The total lifecycle of a breach (identification plus containment) now averages 247 days, an increase of six days over the prior year. Phishing remains the most frequent and costly attack vector, followed by social engineering and supply chain vulnerabilities.

AI as a Double-Edged Sword

AI is fundamentally changing the threat landscape. AI-driven attacks are responsible for a 56% increase in incidents, with one in four breaches now involving some form of AI. Attackers are leveraging AI to generate convincing deepfakes for social engineering and to create malicious code, which adds an average of $1 million in costs per breach. A critical failure point is that 92% of organizations lack proper access controls for their AI systems, leaving APIs, apps, and plugins exposed.

Defensive Strategies and AI Force Multipliers

Organizations that deploy AI and automation for threat detection and response see significant benefits, including a $2 million reduction in breach costs and a 65-day reduction in response time. To stay ahead, organizations must shift from human-speed to machine-speed defense by:

  • Leveraging Frontier Models: Using AI to proactively discover vulnerabilities before attackers can exploit them.
  • Managing Non-Human Identities: Implementing automated, frictionless identity management for the massive influx of AI agents, which can outnumber human identities by 50 to 1.
  • Prioritizing AI Sovereignty: Maintaining strict visibility and control over where data resides and how it is accessed by AI models.
  • Improving Crypto-Agility: Only 37% of breached data was encrypted. Organizations must prioritize encryption and adopt post-quantum cryptographic algorithms now to protect against future "Q-day" threats where quantum computing could break current standards.