Indian firms face record ₹25.5 crore data breach costs

Cyber threats driven by artificial intelligence have grown faster than defensive measures, according to a recent study.
Companies using AI and security automation extensively reduced costs by over ₹10 crore per incident. Those without such systems paid an average of ₹31.6 crore, while organizations with extensive deployment incurred average costs of ₹21.3 crore. The difference shows how uneven adoption of AI-based defenses increases financial risks across industries.
Gaurav Agarwal, Vice President of Technology at IBM India & South Asia, stated that India’s quick AI adoption creates opportunities while speeding up cyber threats. He noted that organizations with AI and strong governance handled attacks far better.
Most companies still use AI in limited ways, mainly for detection rather than full security coverage. Agarwal said embedding AI with decision-making abilities across detection, analysis, and response should be a key goal. That approach helps businesses build resilience and stay ahead.
Only 32% of surveyed Indian organizations reported extensive use of AI and security automation. Another 36% had limited deployment, while 32% used none. The gap has real effects: breaches at companies without automation took 236 days to detect and 75 days to contain. Extensive automation cut detection time to 175 days, though containment took 81 days on average.
Related: Stocks to watch today include Maruti Suzuki
Unapproved AI tools, known as “shadow AI,” also play a role. These added ₹1.79 crore to breach costs where they appeared, ranking among the top cost drivers alongside regulatory failures and cloud migration issues.
The financial impact varied by sector. Critical infrastructure faced the highest losses, with financial services firms reporting average breach costs of ₹40.9 crore. Technology companies followed at ₹35.7 crore, while communications firms saw costs of ₹34.5 crore.
Phishing remained the most common attack method, responsible for 19% of breaches. Drive-by compromises accounted for 16%, and supply chain attacks made up 15%.
Proactive steps helped reduce costs. Offensive security testing, such as red teaming, saved organizations an average of ₹2.47 crore. Threat hunting and AI governance tools also lowered expenses, though their use remains inconsistent.
Many companies plan to boost security spending after a breach. Nearly 73% of Indian organizations intend to increase investments. Their top priorities include incident response planning, threat detection technologies, and identity management. Employee training and AI governance tools also ranked, though less frequently.
Related: Russia’s oil exports hit massive bottleneck
The study, conducted by the Ponemon Institute and sponsored by IBM, surveyed 602 global organizations between March 2025 and February 2026. A later review in May 2026 found that 78% of respondents knew about advanced AI models like Mythos. This suggests the competition between attackers and defenders continues to escalate.
The figures reveal only part of the story. The full impact includes supply chain disruptions, lost customer trust, and increased regulatory scrutiny. For now, the lesson is straightforward: companies that integrate AI into their security strategy, rather than treating it as an add-on, will handle threats more effectively.
Many organizations still hesitate to adopt these tools despite clear benefits.
The delay may stem from inertia rather than technology. Systems that once seemed adequate now fall short, yet some companies resist major changes.
