Weak Access Controls Leave 92% of Companies Vulnerable to AI-Related Breaches
The latest report from IBM has shed light on the vulnerabilities of AI-related security breaches. According to the study, nine out of ten companies hit by such incidents had weak access controls in place, making it easy for attackers to exploit these weaknesses.
The research, conducted by the Ponemon Institute and spanning 602 companies, found that 92% of breached organizations had inadequate access controls. This is not a matter of sophisticated attacks, but rather basic oversights that require no advanced tooling to take advantage of.
The study also revealed that in many cases, the entry point for attackers was not the AI model itself, but rather compromised APIs, connected applications, or cloud services left misconfigured. Furthermore, running an open-source versus proprietary model made almost no difference in terms of security.
The average cost of an AI-related breach stood at $5.33 million, compared to $4.70 million for breaches without an AI component. This gap grows even wider when attackers use AI themselves, with breaches averaging $6.04 million compared to $5.03 million.