How to Reduce Data Breach Costs With AI Security

TL;DR
Extensive use of AI in security reduced breach identification and containment time by 80 days and lowered costs by about $1.9 million. Organizations should combine AI-assisted security with stronger identity and access management, secrets management, employee defenses against phishing and deepfakes, third-party risk controls, and formal AI governance that addresses unauthorized shadow AI.
Transcript
How many times have you heard this? We really can't afford to spend that much on security. Maybe instead, we should be asking ourselves if we can afford not to. After all, it's not just about dollars. It's downtime. Reputation. Lost trust. And the fact is that many of these breaches are preventable. But let's face the decision regarding security in... Read More
Key Insights
- The worldwide average cost of a data breach is $4.44 million, a 9% decline from the prior figure discussed in the report. The calculation excludes exceptionally large mega breaches because those incidents would distort the average and make it less representative of typical organizational experiences.
- The combined time required to identify and contain a breach is 241 days, compared with about 257 days four or five years earlier. Most of that period is spent identifying the intrusion, leaving attackers inside affected environments for the better part of a year.
- The average United States data breach costs $10.22 million, following a 9% increase. That figure is almost twice the worldwide average, with higher regulatory fees and growing detection expenses identified as factors contributing to the increase.
- AI-related breaches affected 13% of surveyed organizations, and 60% of that group experienced data compromise while 31% experienced operational disruption. These findings show that AI implementations can introduce attack vectors with consequences for both sensitive information and business operations.
- Shadow AI is unauthorized artificial intelligence operating within an organization without approval or prior awareness. Twenty percent of organizations discovered these implementations in their environments, indicating that unmanaged AI can appear and remain unnoticed until it creates a problem.
- Insider threats produced the costliest attacks because insiders already understand the environment and can move directly toward valuable systems or information. Third-party risk was nearly tied in cost, including situations involving external access and third-party software.
- Phishing caused 16% of breaches and remained the most frequent attack vector discussed. AI can automate persuasive phishing content quickly, with a chatbot producing in five minutes a result that performed nearly as well as work created by a skilled cybersecurity professional over 16 hours.
- Extensive AI use in security reduced mean time to identify and contain breaches by 80 days and lowered associated costs by about $1.9 million. However, 63% of organizations had no AI governance policy or were still developing one, leaving many without defined objectives.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is the average cost of a data breach in 2025?
The worldwide average cost of a data breach reported by IBM for 2025 is $4.44 million, representing a 9% decline. The report excludes exceptionally large mega breaches because their extreme costs would skew the average. In the United States, the average is substantially higher at $10.22 million after a 9% increase, partly associated with rising regulatory fees and detection costs.
Q: How long does it take to identify and contain a data breach?
The combined mean time to identify and contain a data breach is 241 days in the 2025 report. Four or five years earlier, the combined figure was about 257 days. Most of the delay occurs during identification, before the organization recognizes the intrusion. Although the improvement is positive, 241 days still leaves attackers uncontrolled inside an environment for much of a year.
Q: Why are data breaches more expensive in the United States?
The average United States breach cost reached $10.22 million, nearly twice the worldwide average of $4.44 million, after rising 9%. The transcript identifies increased regulatory fees and higher detection expenses as contributing factors. Detection expenses include the tooling and related work needed to find incidents. The United States historically had higher breach costs than the rest of the world, and the gap continued to grow.
Q: What is shadow AI, and why is it a security risk?
Shadow AI is an unauthorized AI implementation operating inside an organization without approval, and sometimes without anyone knowing it exists until a problem occurs. The report found that 20% of organizations had shadow AI in their environments. Its presence creates a governance and visibility challenge because security teams cannot properly oversee, protect, or define acceptable outcomes for AI systems they have not identified or authorized.
Q: How are attackers using AI in data breaches?
Attackers are using AI to support phishing and deepfake attacks. Among organizations that experienced breaches resulting from attackers’ AI, roughly 37% involved phishing and 35% involved deepfakes. AI-generated phishing can avoid obvious spelling and grammar mistakes while quickly creating convincing scenarios. Deepfakes imitate a person’s voice, likeness, or image to persuade someone to perform an action they should not take.
Q: How can organizations use AI to reduce breach costs?
Organizations with extensive AI use in security reduced the combined time required to identify and contain breaches by 80 days. Their breach costs also fell by about $1.9 million. The report therefore presents AI as both an attack tool and a defensive capability. Its security value comes from helping organizations identify incidents, respond faster, contain damage sooner, and reduce the financial consequences associated with prolonged intrusions.
Q: Which data breach vectors are the most costly and frequent?
Insider threats were the costliest attack vector because insiders already understand the environment and can reach important systems or information without searching blindly. Third-party risk was almost tied for the highest cost, including external access and third-party software exposures. Phishing was the most frequent vector, causing 16% of breaches and continuing its prominent position among breach causes over multiple years.
Q: How should organizations improve identity and secrets security?
Organizations should strengthen identity and access management because attackers often find it easier to log in than to hack into systems. Protection should cover human users and non-human identities, including system accounts with high privileges. Secrets management is needed to control passwords, API keys, and cryptographic keys at scale, particularly when system-level credentials are powerful, infrequently changed, or used by applications to access databases.
Summary & Key Takeaways
-
IBM’s 2025 report draws on 600 organizations that experienced breaches and interviews with approximately 3,500 leaders who had direct knowledge of those incidents. The worldwide average breach cost fell 9% to $4.44 million, while the combined time needed to identify and contain a breach improved from about 257 to 241 days.
-
The United States moved in the opposite direction, with its average breach cost rising 9% to $10.22 million. Increased regulatory fees and detection expenses contributed to the higher total. Insider threats and third-party risks produced the costliest incidents, while phishing remained the most frequent initial vector, accounting for 16% of breaches.
-
AI creates risks and defensive opportunities. AI-related breaches affected 13% of organizations, while 20% discovered unauthorized shadow AI. Attackers used AI for convincing phishing and deepfakes, but organizations using AI extensively for security reduced identification and containment by 80 days and lowered breach costs by approximately $1.9 million.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from IBM Technology 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator