
India's average data breach cost has reached an all-time high of ₹25.5 crore in 2026, representing a 16% increase from ₹22 crore in 2025, according to IBM's 2026 Cost of a Data Breach Report. The average breach scale has also grown significantly, with 39,500 records compromised on average, up from 38,200 in 2025. As reported by Business Standard, this surge reflects how AI-enabled attacks are transforming the cyberthreat landscape by enabling faster, more sophisticated and increasingly scalable operations. The findings show that while AI is reshaping cyberattacks, it is also helping organisations strengthen cyber resilience through proper implementation.
AI-generated attacks have become a dominant force in India's cybersecurity landscape, accounting for 26% of all malicious breaches according to IBM's latest findings. These AI-driven breaches cost organisations an average of ₹21.3 crore, significantly lower than the ₹31.6 crore paid by organisations with no AI and security automation. The report reveals that one in four malicious breaches now involve AI, with deepfake impersonation, AI-generated malware and AI-assisted phishing becoming increasingly common. As reported by Business Standard, cybercriminals are automating parts of the attack process and operating at greater speed and scale through AI-enabled tools.
The financial services sector recorded the highest average breach cost in India at ₹40.9 crore, followed by technology at ₹35.7 crore and communications at ₹34.5 crore, according to IBM's findings. India's breach costs remain lower than regions such as the US and West Asia, but the upward trend reflects growing financial impact as enterprises expand AI and digital technology use. The reports highlight how AI adoption is advancing at a similar pace to innovation, creating a paradox where businesses struggle to implement adequate governance controls. Phishing, including voice and SMS phishing, emerged as the most common initial attack vector at 19%, followed by drive-by compromise at 16% and supply chain compromise at 15%.
Despite widespread AI deployment, governance controls are lagging significantly behind adoption rates, with only 40% of organisations able to quickly terminate an AI agent that behaves unexpectedly. An EY survey published in March found that 85% of technology leaders prioritised speed to market over exhaustive AI vetting, while 52% of department-level AI initiatives operated without formal approval. As reported by Business Standard, the average organisation experienced 223 data-policy violations involving generative AI applications each month, with source code accounting for 42% and regulated data for 32% of such incidents. However, IBM found that organisations making extensive use of AI and automation in security operations reduced breach costs by an average of ₹1.93 crore and shortened breach identification and containment by 65 days.
Organisations with extensive AI and security automation deployment demonstrated significantly better breach response capabilities. According to IBM's report, these organisations experienced 175 days to identify and 81 days to contain breaches, compared to 236 days to identify and 75 days to contain for organisations with no AI and security automation. The report found that nearly 73% of organisations indicated plans to further strengthen investments in security tools and governance following a breach. As reported by Business Standard, Kiteworks similarly found that organisations are placing greater emphasis on AI governance, data visibility and technically enforceable controls. IBM's Gaurav Agarwal emphasised that AI with agentic capabilities must be embedded across the full security lifecycle to build resilience and competitive advantage.