The report, released on
This is the first time IBM's annual report—based on analysis of nearly 6,500 breaches over 20 years—has tracked AI-related security practices. While AI-related breaches are still relatively few, the findings suggest that unregulated AI systems are becoming an attractive target for cybercriminals.
“India’s accelerating AI
IBM’s study found that nearly 60% of Indian organisations that experienced a breach either had no AI governance policies in place or were still developing them. Only 37% had implemented AI access controls. Alarmingly, among
One of the most striking findings was the financial toll of shadow AI—the use of unregulated AI tools outside the purview of an organisation’s IT or security teams. Shadow AI was among the top three cost amplifiers, adding an average of ₹1.79 crore to breach costs in India.
Phishing remained the top initial attack vector in India (18%), followed closely by third-party vendor and supply chain compromise (17%) and vulnerability
Despite clear evidence that AI-driven security automation can dramatically reduce breach costs—nearly halving them—73% of surveyed Indian organisations reported limited or no use of such tools.
The research sector saw the highest average breach cost at ₹28.9 crore, followed by transportation (₹28.8 crore) and industrials (₹26.4 crore), the latter having topped the list in 2024.
On a positive note, breach lifecycle times in India hit a record low, dropping to 263 days—a 15-day improvement over
Also Read: US federal judiciary’s electronic case system breached in major cyberattack: Report