Blog | comforte

What IBM’s Latest Breach Report Says About Data Security in an AI-Centric World

Written by Erfan Shadabi | Aug 27, 2026

IBM has been charting the data breach landscape now for over two decades. But you’d be hard pressed to find any point over the past 21 years as volatile as today. AI is rewriting the rules of the game for network defenders and their adversaries,  simultaneously arming attackers and creating a dangerous new corporate attack surface that must be protected.

The latest Cost of a Data Breach report provides some interesting insights into the scale of the threat, and how technologies like encryption can help organizations mitigate fast-evolving risks.

AI is Driving Attacks

The headline finding is a troubling one for security teams: the average cost of a data breach has now risen to a record $4.99m. That’s a 12% increase on the 2025 figure and mainly driven by detection, escalation and lost business costs. Worse, AI-driven attacks have added $1m to the average cost of a breach. According to IBM: “attacks are getting faster and cheaper to launch while breaches are becoming more expensive to find and fix.” AI-driven attacks increased 56% year-on-year (YoY).

This shouldn’t be a revelation for cybersecurity leaders. Research reports are emerging on a daily or weekly basis detailing the power of frontier AI to find and exploit new vulnerabilities, compose perfect social engineering campaigns, assist with victim reconnaissance, and even generate novel malware. It’s why authorities from the European Central Bank and the UK’s financial authorities to the Five Eyes intelligence alliance are urging companies to shore up their defenses and improve resilience.

Expanding the Attack Surface

At the same time, AI is being adopted with gusto by countless organizations. Although measurable gains in productivity and efficiency have not yet materialized, another trend has: AI infrastructure is becoming a security risk in its own right.

IBM’s data backs this view: it claims the share of breaches involving AI systems/models increased 61% over the past year. Breaches involving model inversion (where attackers use a model’s output to reconstruct training data) were 18% higher than the global average ($6.1m). Financial loss and operational disruption were the top impacts of these attacks.

Shadow AI increases the likelihood of such incidents, as well as accidental data leaks. Organizations can’t protect or govern what they can’t see. Yet AI blind spots appear to be proliferating. Shadow AI incidents more than doubled to 43%, and led to higher average breach costs this year ($5.39m) than last year ($4.63m), IBM says.

For HPE Nonstop customers in particular, there are additional concerns from the report. Financial services was the most targeted sector last year, with average breach costs of $6.3m the second highest behind healthcare ($6.6m).

From Encryption to Key Management

Although some attacks on AI are designed to manipulate models in order to do the bidding of the attacker, data is very often the prize that they are seeking: both to steal and extort. That’s why it’s critical for organizations to invest in tools that can automatically discover and protect it at source. Ideally, this should happen before the data even reaches any AI systems.

Yet many organizations are still failing to do so. Among breached organizations, over half (53%) didn’t encrypt sensitive data at rest and in motion, according to IBM. Another 10% say they weren’t sure if the data was encrypted, which suggests it was not.

It’s also important what type of encryption organizations use. Only a quarter (26%) of those polled by IBM report having a post-quantum cryptography (PQC) project in place. Most (69%) don’t, which exposes them to harvest-now-decrypt-later (HNDL) attacks. Additionally, most (61%) organizations admit they “lack controls to monitor and secure cryptography and cryptographic objects, such as keys, certificates and algorithms.” IBM attributes this to outdated cryptography and a growing attack surface.

Key and certificate lifecycle management is an often overlooked but critically important part of any security strategy. Too many organizations still store keys and certificates in plaintext on disk —which is a massive security, operational and financial risk. Certificates are often managed and rotated manually, adding admin overhead, human error, and potential downtime to the mix. And secrets are scattered across the enterprise, posing problems for auditors and creating breach and leak risks.

IBM highlights the potential financial impact: mismanaged secrets and keys could add $198,933 to average breach costs, it claims.

Why comforte TAMUNIO?

This is part of the reason why comforte TAMUNIO exists. It uses AI to continuously discover, classify and then protect data, via tokenization and format-preserving encryption (FPE). This eliminates blind spots and ensures data can be used by organizations for analytics without compromising on security or compliance.

Additionally, it mitigates AI-related risk through three layers of defense:

  • Protecting data before it reaches any AI system
  • Detecting and deidentifying sensitive data on the fly
  • Confidential compute to protect sensitive AI training data

TAMUNIO also offers HPE Nonstop customers:

  • A drop-in, post-quantum ready SSH/SSL upgrade
  • Centralized, HSM-backed key & secrets storage
  • An automated certificate lifecycle
  • A single console for all secrets management

With this in hand, organizations can look forward to significant benefits, not just in reducing cyber risk but also potential costs. According to IBM, use of key lifecycle management tools could reduce breach costs by $214,923. Encryption might further trim costs by $213,478, while savings from certificate lifecycle management come in at $205,265.

Security is about more than the bottom line. But independent calculations like these can be a useful tool for CISOs the next time they ask the board for more money.