Security Incident Costs Trending Downward
This year saw a 9% global decrease in the average cost of data breaches—$4.44 million compared to $4.88 million last year. This marks the first time since 2020 that such a positive trend has been observed. The primary reason for the decline: the implementation of Artificial Intelligence and automation systems within detection and response processes.
In contrast, the average cost of a data breach in the U.S. surged to a record high of $10.22 million. This increase is attributed to heavy regulatory fines, high response costs, and longer detection times. This highlights the gaps between countries regarding regulatory and technological maturity.
Shadow AI Threats – The Invisible Danger
20% of incidents involved the use of “Shadow AI”—AI services that were not officially recognized or authorized by the organization. Most organizations (63%) lack a structured corporate governance policy for AI, and many fail to conduct audits to detect unauthorized use. In 97% of AI-related incidents, adequate access controls were not defined.
Furthermore, phishing attacks and impersonation via Deepfakes have gained momentum, fueled in part by GenAI-based tools. The report indicates that the time required to write a phishing email has dropped from 16 hours to just 5 minutes thanks to the use of Generative AI—a reminder that hackers are equally adept at utilizing this technology.
Attack Vectors and Costs: Phishing and Supply Chain – The Most Common and Costly Threats
Phishing has become the most common initial infection vector (16%), with an average cost of $4.8 million. It is followed by supply chain breaches (15%), with a cost of $4.91 million. Supply chain incidents required the longest average time to identify and contain—267 days.
Incidents caused by malicious insiders—such as disgruntled employees or partners exploiting system access—resulted in the highest financial damages: an average of approximately $4.92 million per incident. The containment time for these threats was also among the longest (averaging 260 days). The reason: these threats often involve legitimate system access, making them harder to detect in time.
Recommendations from IPV Security Information Security Experts:
* Implement AI systems under a clear corporate governance policy, including regular audits to identify unauthorized usage.
* Apply strict access controls to AI systems, particularly in SaaS-based services and multi-vendor environments.
* Integrate automation into incident response processes to reduce detection time and lower costs.
* Consider prohibiting the use of Shadow AI and educate employees on its risks.
* Strengthen defenses against phishing and Deepfakes, especially for employees with extensive access privileges.
* Map supply chain attack vectors and apply monitoring measures to third-party systems.
Summary
The IBM 2025 report points to improved response times and a decrease in the average costs of security incidents, but it also highlights new and concerning challenges—particularly in the realm of AI. Organizations implementing AI must urgently adopt proper oversight measures, or they will pay the price.