Anatomy of a Record-Breaking Cost
The staggering Rs 25.5 crore figure represents the average cost Indian organisations faced per data breach in 2026, a significant 15.9% jump from the previous year. This data comes from the latest 'Cost of a Data Breach Report' by IBM, an annual study
that analyses real-world security incidents. This cost is not a single penalty but a combination of expenses. It includes the vast sums spent on detecting and escalating the issue, notifying affected customers and regulators, the cost of lost business due to operational disruption and reputational damage, and the expenses incurred after the breach for remediation and recovery. Each incident also grew in scale, compromising an average of 39,500 records. The financial services sector was hit hardest, with average breach costs soaring to Rs 40.9 crore, followed by the technology sector at Rs 35.7 crore.
The High Price of a Slow Response
The core lesson from the report is that time is, quite literally, money. The longer a threat actor remains undetected within a network, the more damage they can inflict and the higher the eventual cost. According to the findings, Indian organisations that lacked security AI and automation took an average of 236 days just to identify that a breach had occurred. This extended dwell time allows attackers to move laterally, escalate privileges, and exfiltrate more data. In sharp contrast, companies that had extensively deployed AI-powered security tools were able to identify breaches much faster, averaging 175 days. This 61-day difference is crucial. The financial gap is even more stark: organisations without automation faced an average cost of Rs 31.6 crore per breach, while those with extensive automation saw that figure drop to Rs 21.3 crore—a saving of over Rs 10 crore per incident.
AI: A Double-Edged Sword
Artificial intelligence is a central character in this evolving cybersecurity drama, playing the role of both villain and hero. The report highlights that 26% of malicious breaches in India were AI-generated, with cybercriminals using the technology to create more sophisticated phishing attacks and scalable malware campaigns. However, the same technology offers a powerful defence. Despite the clear benefits of faster detection and lower costs, an alarming 68% of Indian organisations surveyed have limited or no deployment of AI and security automation. This gap between the capabilities of attackers and the readiness of defenders is a significant driver of rising breach costs. Furthermore, the rise of 'Shadow AI'—the use of unsanctioned AI tools by employees—has emerged as a major risk, adding an average of Rs 1.79 crore to the cost of a breach where it was present.
Beyond the Financial Fallout
While the Rs 25.5 crore figure is a powerful benchmark, the true cost of a data breach extends far beyond the balance sheet. The erosion of customer trust is one of the most significant and long-lasting consequences. When personal data is compromised, customers lose confidence in a company's ability to protect them, leading to churn and long-term revenue loss. Reputational damage can tarnish a brand for years, affecting its ability to attract new customers, partners, and even employees. In India's regulatory landscape, which includes the Digital Personal Data Protection (DPDP) Act, non-compliance adds another layer of financial risk and legal scrutiny. The IBM report identified regulatory non-compliance as one of the top three factors that amplify breach costs, reinforcing the importance of a robust governance framework.














