
IBM said on July 29 local time that, according to an analysis of a survey conducted in collaboration with the Ponemon Institute, AI-driven attacks now account for 1/4 of all malicious data breaches, up 56% year over year. These incidents cause an average of $6 million in losses each, 20% higher than the average cost of data breaches overall.
62% of AI-driven cyberattacks target critical infrastructure, with financial services and energy organizations experiencing the highest concentration of attacks, increasing the possibility of cascading effects on the economy, supply chains, and essential services.
The data also shows:
Applying AI and automation technologies to security operations can save organizations nearly $2 million in breach costs on average, but 1/4 of organizations still do not do so;
Only 18% of surveyed organizations have deployed agents for vulnerability remediation and management, although more than half have already used agents for threat detection and containment;
More than 20% of organizations have experienced intrusion attacks targeting AI models or application systems, with weaknesses in surrounding systems and improper cloud platform configurations being the most common triggers.

Suja Viswesan, vice president of security software at IBM, said:
What is truly changing is the economics of cyberattacks. AI makes attacks faster and cheaper, while the cost of data breaches continues to rise. When there is too much time between an organization's discovery and remediation of vulnerabilities, this imbalance is directly reflected in breach costs.
The top priority now is to eliminate this time gap—to embed remediation capabilities into development processes, protect identities at runtime, and respond to attacks at a speed that matches the speed of the attacks.
