
According to IBM's Cost of a Data Breach Report 2026, the cost of a data breach in India has reached a record ₹25.5 crore in 2026, representing an alarming 15.9% increase from ₹22 crore in 2025. The report reveals a fundamental shift in enterprise cybersecurity, with artificial intelligence accelerating cyberattacks while many Indian organisations still rely on slower, largely manual security operations. Among Indian organisations surveyed, those without AI and security automation took an average of 236 days to identify a breach, compared with 175 days for organisations that had extensively deployed AI across their security operations. As per IBM, cybercriminals are not abandoning traditional attack methods in favour of entirely new AI-powered techniques. Instead, AI is making existing attacks faster, cheaper and more convincing. Among the malicious breaches analysed in India, 26% involved AI-generated attacks. The latest CrowdStrike 2026 Threat Hunting Report confirms this trend, with AI now embedded across modern adversary operations, changing how attacks are planned, executed, and scaled while expanding the attack surface organisations must defend. "AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend," said CrowdStrike's Adam Meyers, head of counter adversary operations. "The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary."
As reported by CrowdStrike, threat actors are now using AI to generate payloads and shell commands, exploit AI infrastructure, and abuse enterprise LLMs - including one campaign that sent nearly 200,000 AI model requests in two minutes. The AI ecosystem has become the next supply chain battleground, with DPRK-nexus STARDUST CHOLLIMA injecting malicious npm packages into 131 trusted Mastra AI frameworks. During the first half of 2026, 87% of identified software registry threats involved malicious npm packages. CrowdStrike OverWatch observed that AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads, demonstrating how AI is accelerating the volume and velocity of activity security teams must investigate. The report also reveals that 88% of CrowdStrike-observed exploitation of vulnerabilities with proof-of-concept occurred within 48 hours of release, with China-nexus actors VAULT PANDA and GENESIS PANDA launching deliberate attacks within 24 hours of disclosure. Phishing remained the prevalent initial attack vector, representing 19% of recorded incidents, with voice phishing and SMS phishing emerging as rising threats accompanied by drive-by compromises and supply chain assaults. Monthly device code phishing attempts increased 15x in the first half of 2026, reflecting growing abuse of trusted authentication workflows.
According to McKinsey's latest report, AI is reshaping the role of managers as organisations begin deploying AI agents alongside human employees. Leaders are now considering how to manage agent capacity together with human capacity, a shift the report described as a fundamental transformation in the way management functions. The report indicates that AI is leading to smaller, more productive teams and could eventually result in organisations having fewer management layers over time. McKinsey found that companies creating the greatest value from AI are not attempting enterprise-wide transformation all at once. Instead, they are prioritising a few high-impact business areas and combining AI deployment with workforce reinvention and workflow redesign. The report emphasizes that organisations are increasingly investing in dedicated teams, tools and methodologies to help business leaders better understand tasks, skills and workforce implications as AI adoption accelerates. This strategic approach allows enterprises to optimize their AI investments while managing the transition to new management paradigms effectively. As AI progresses from executing tasks to making recommendations and collaborating across applications and business environments, organisations must focus not only on adopting the technology but also on preparing people to use it effectively. Successful AI adoption requires a balanced approach that considers AI governance, risk management, model oversight and business outcomes together.
The report identifies Shadow AI - the unauthorized utilization of AI applications by employees - as one of the three primary amplifiers of costs associated with data breaches in India. Where Shadow AI comes into play, breach costs surged by an average of ₹1.79 crore, positioning it alongside issues of regulatory non-compliance and cloud migration complexities as the largest contributors to escalating breach costs. This report underscores the governance challenges organisations face amidst an environment where employees are increasingly experimenting with public AI tools. The swift adoption of generative AI has also spawned new security vulnerabilities, with the report suggesting that AI is increasingly becoming an economic necessity rather than a mere cybersecurity tool. As per IBM's Gaurav Agarwal, Vice President of Technology for IBM India & South Asia, "The rapid proliferation of AI in India offers substantial opportunities for innovation; however, it concurrently accelerates the evolution of cyber threats. It is imperative for businesses to embed AI with agentic capabilities throughout the entire security lifecycle—from detection and analysis to prioritization and remediation."
According to the report, the financial sector remains the most expensive industry in India when it comes to recovering from a cyberattack. Financial services recorded the highest average breach cost at ₹40.9 crore, followed by the technology sector at ₹35.7 crore and communications at ₹34.5 crore. These sectors store large volumes of sensitive financial, customer and enterprise data, making them attractive targets for cybercriminals. The average number of compromised records surged to 39,500, illuminating the escalating financial and operational ramifications of cybersecurity incidents for Indian enterprises. The latest CrowdStrike data shows that cloud-conscious eCrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft, with monthly device code phishing attempts increasing 15x in the first half of 2026.
The report identifies new sources of risk emerging alongside AI adoption. Shadow AI, where employees use AI tools outside approved enterprise policies, increased the average breach cost by ₹1.79 crore among organisations where it was present. Globally, IBM found that 92% of organisations experiencing AI-related breaches lacked adequate AI access controls. However, proactive security initiatives delivered tangible financial advantages, with red teaming and penetration testing emerging as the most effective cost-saving measures, resulting in a reduction of breach costs by an average of ₹2.47 crore. The findings illustrate that Indian enterprises are responding by amplifying their investments in cyber resilience, with approximately 73% of organisations surveyed expressing intentions to increase cybersecurity expenditures following a breach. Prioritized areas for investment include incident response planning, threat detection and response platforms such as SIEM, SOAR, and EDR, identity and access management, AI security governance tools, and employee awareness initiatives. The report emphatically suggests that as AI becomes integral to both enterprise operations and the realm of cybercrime, reliance on conventional security models is no longer viable. As organisations accelerate AI adoption, security must become an organisational culture rather than being limited to periodic awareness programmes. Strengthening digital infrastructure, conducting regular security audits and adopting security-by-design principles are essential for reducing cyber risks.