AI isn't just making security breaches more common. It's making them more expensive.
A report from IBM published last week found that the average cost of an AI-enabled malicious security breach for enterprises is roughly $6 million, around $1 million more than the global average for all security breaches. Around one in four security breaches in the last year were aided by AI, a 56% increase from the previous year.
"What's changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive," Suja Viswesan, VP of IBM Security Software, said in a statement.
A large majority of the attacks targeted critical infrastructure sectors, with energy and financial services seeing the highest concentration of AI-driven breaches. IBM noted that the density of attacks in these sectors presents the potential for cascading risks that interrupt supply chains and essential services.
According to IBM, these attacks were mostly facilitated by deepfake impersonation and AI-powered malware, and are becoming cheaper and easier for attackers to launch. However, AI may also present a solution:
- Companies that reported using AI in their security operations managed to cut the cost of breaches by an average of $2 million. Around 75% of the organizations surveyed have adopted AI into their security operations thus far, and three-fourths say that frontier AI is causing them to rethink agent deployment in security.
- Still, adoption within security is uneven. While more than 50% said they use AI for threat detection and containment, only 18% apply agents to vulnerability management, leaving potential attack windows open as AI makes it easier than ever to find and exploit vulnerabilities.
IBM's report is just the latest sign that frontier AI is causing a cybersecurity shake-up across industries, with OpenAI's breach of Hugging Face demonstrating the sheer power that these models possess, serving as a warning for what may come as bad actors get their hands on increasingly capable AI. Even some of the biggest companies in tech are strengthening their cybersecurity posture: Google now is patching Chrome twice a week, aided by rapid AI-assisted bug discovery.
Our Deeper View #
One of the most dangerous vulnerabilities that an enterprise can have is thinking that it's *not *vulnerable. Many organizations assume that a breach simply won't happen to them and don't invest in their security posture. But the speed and simplicity that AI has afforded attackers means that anyone can be a target, and any organization can suffer millions in losses as a result. Still, investing in AI-enabled cybersecurity doesn't have to be expensive. Both Microsoft and Cisco, for instance, are investing in efficient and affordable AI systems that are purpose-built to bolster enterprise defenses without breaking budgets. However, what's equally important to having the right tools for defense is having the right culture around security within your organization. Consistent education on AI risks and threats can go a long way in keeping an enterprise from falling victim to deepfakes or malware.