IBM Report Highlights Lax AI Security Controls Expose Enterprises to Record-Breaking Breach Costs
A new report from IBM and the Ponemon Institute reveals that most enterprises are not prioritizing AI security, despite the growing threat of AI-powered attacks. The report highlights that among organizations that experienced an AI-related breach, 92% had no proper AI access controls in place.
The global average cost of a data breach rose to $4.99 million, a 12% increase from last year. AI-driven attacks accounted for 56% of breaches and added around $1 million to the average breach cost.
Model inversion and prompt injection were found to be the most expensive types of AI incidents, costing $6.07 million and $5.89 million per breach, respectively. These attacks are essentially access failures disguised as AI-related issues.
The report emphasizes that securing non-human identities is crucial in preventing such breaches. Currently, fewer than half of organizations actively secure their machine identities, which often carry elevated privileges across applications and data stores.