Sitemap

IBM — Cost of a Data Breach Report 2025 — The AI Oversight Gap

5 min readJul 31, 2025

--

Intro

With the 2025 report, IBM has begun chronicling and quantifying the risks associated with AI. According to this new report, organizations are skipping over security and governance for AI in favor of do-it-now AI adoption. Those ungoverned systems are more likely to be breached — and more costly when they are.

Global Cost Trends

The average breach cost: USD 4.44M (down 9% from 2024’s USD 4.88M) — the first decline in 5 years.

Healthcare has been the most expensive industry for 14th year, at USD 7.42M average per breach.

Breach Lifecycle & Identification

Each year, researchers analyze the average costs of the complete breach lifecycle — the total average number of days to identify and contain the breach — by breaking them into two categories: those that took less than 200 days and those that exceeded 200 days.

While the costs for both categories rose in the previous two years, they declined this year. It was likely due to the lower costs of AI-driven and automation-driven detection and response.

The Average time to identify and contain a breach: 241 days (a nine-year low).

While the share of breaches involving AI security incidents are small, IBM
researchers expect them to grow as AI vendors gain greater market share and penetration into enterprise systems. Shadow AI is of particular concern. As AI becomes integral to operations, AI security incidents have the potential to disrupt a range of business activities, including compromising sensitive data.

Regulatory & Business Impacts

Reporting a breach to regulators and other government agencies has become a common part of post-breach responses. This year’s report found a third of organizations paid a regulatory fine because of breaches. The study looked at the size of fines, which varied across countries and regions. Organizations in the United States paid the highest fines, which, in turn, drove up total United States breach costs.

  • 32% of breaches resulted in regulatory fines (48% of these >USD 100K).
  • 86% of organizations experienced operational disruption, and 45% passed some costs to customers.
  • Ransomware: 63% refused to pay ransoms (up from 59%), but costs remain high (USD 5.08M average).

Key Drivers & Risk Factors

For the second year in a row, malicious insider attacks resulted in the highest average breach costs among initial threat vectors: USD 4.92 million. Third-party vendor and supply chain compromise followed closely at USD 4.91 million.

  • Malicious insider attacks: Highest average cost at USD 4.92M.
  • Phishing: Most common initial attack vector (16%), averaging USD 4.8M. Phishing replaced stolen credentials this year as the most
    common initial vector (16%) attackers used to gain access to
    systems
  • Shadow AI: Added USD 670K on average to breach costs and led to more PII/IP data exposure.
  • AI-driven attacks: 1 in 6 breaches involved AI (e.g., AI-generated phishing, deepfakes).

The Cost of a Data Breach Report 2025 goes into significant detail about AI-related findings, covering both how attackers are leveraging AI and how organizations are using it:

Prevalence: 16% of all data breaches involved attackers using AI tools.

Tactics used:

  • AI-generated phishing: 37% of AI-driven attacks involved highly personalized phishing campaigns crafted with generative AI (gen AI) to make them harder to detect.
  • Deepfake impersonation: 35% involved audio/video deepfakes targeting executives, employees, or customers.
  • Impact: Gen AI reduced the time to create convincing phishing emails from 16 hours to only 5 minutes, dramatically scaling attacks.
  • These AI-powered attacks increased breach success rates and detection times, adding significant costs.

Shadow AI: 20% of organizations reported breaches involving “shadow AI” (unsanctioned AI tools). These breaches added USD 670K to average breach costs and led to greater exposure of PII and intellectual property.

AI-driven phishing & deepfakes: 16% of all breaches involved attackers using AI tools, with the majority using AI-generated phishing campaigns (37%) and deepfake attacks (35%) to impersonate executives or employees. These campaigns leveraged generative AI (gen AI) to cut email crafting time from 16 hours to just 5 minutes, enabling mass-scale attacks.

Manipulating humans with AI: The report highlights attackers using AI to produce realistic emails, voices, and videos mimicking trusted sources, making social engineering and malware delivery more successful.

AI & Automation Impact

Extensive use of AI in security cut breach costs by USD 1.9M and shortened breach lifecycles by 80 days. Organizations not using AI or automation faced average breach costs of USD 5.52M compared to USD 3.62M for those using them extensively.

AI in operations: 32% of organizations now use security AI and automation extensively, up slightly from 31% last year. These organizations cut breach costs by USD 1.9M on average and reduced breach lifecycles by 80 days compared to those not using AI.

AI Governance gap:

  • 97% of organizations that suffered AI-related breaches lacked proper AI access controls.
  • 63% lack formal AI governance policies, and among those that do, few conduct regular audits for unsanctioned AI.

AI in Security Defenses

Organizations using AI-powered threat detection, analytics, and automated response achieved lower breach costs (USD 3.62M) compared to those without these capabilities (USD 5.52M).

AI acts as a skills multiplier, helping security teams oversee more systems and respond faster to threats.

IAM Weaknesses Are a Common Breach Enabler

Many organizations still operate with lax access controls, over-permissioned accounts, and fragmented IAM tools.

These gaps increase attack surfaces and are actively exploited by attackers.

The report notes a shift in attacker behavior: “attackers are logging in rather than hacking in,” emphasizing the misuse of compromised credentials rather than direct exploits.

Fortify Human and Machine Identities

IAM must equally protect non-human identities (NHI) such as AI agents, applications, and service accounts. These entities increasingly hold high-value credentials and perform critical operations.

Organizations should maintain visibility into all NHI activity, distinguishing between accounts using managed (vaulted) vs. unmanaged credentials. Unmanaged credentials are a major blind spot.

Credentials must be brought under strict lifecycle management:

  • provisioning,
  • rotation,
  • auditing,
  • protection, and
  • decommissioning.

This applies to both human and non-human accounts. Continuous monitoring of credential usage helps detect anomalies and prevent misuse.

Organizations are encouraged to replace passwords and OTP-based MFA with modern, phishing-resistant authentication methods, such as passkeys or hardware-based solutions. These approaches significantly reduce the risk of credential interception or replay.

IAM was identified as one of the top cost-reducing security practices. Organizations with mature IAM programs reduced average breach costs by approximately USD 190K compared to those with poor IAM practices.

Need Help?

The functionality discussed in this post, and so much more, are available via the SOCFortress platform. Let SOCFortress help you and your team keep your infrastructure secure.

Website: https://www.socfortress.co/

Contact Us: https://www.socfortress.co/contact_form.html

--

--

SOCFortress
SOCFortress

Written by SOCFortress

SOCFortress is a SaaS company that unifies Observability, Security Monitoring, Threat Intelligence and Security Orchestration, Automation, and Response (SOAR).