- Phishing, including voice and SMS phishing, was the most common initial attack vector in India
- 68% of Indian organizations surveyed still have limited or no use of AI and security automation
BENGALURU, INDIA | 03rd AUGUST 2026 | IBM today released its 2026 Cost of a Data Breach Report, which found that the average total organizational cost of a data breach in India reached an all-time high of INR 255 million (INR 25.5 crore) in 2026, a 15.9% increase over last year’s INR 220 million (INR 22 crore). The average breach in India also grew in scale, with 39,500 records compromised on average, up from 38,200 in 2025.
The report found that 26% of malicious breaches in India were AI-generated, highlighting how artificial intelligence is reshaping the cyber threat landscape by enabling attacks to become faster, more sophisticated and increasingly scalable. The findings show that while AI is transforming the nature of cyberattacks, it is also helping organizations strengthen cyber resilience. Organizations that extensively deployed AI and security automation experienced significantly lower breach costs and faster breach response, while nearly 73% of organizations also indicated plans to further strengthen investments in security tools and governance following a breach.
“India’s accelerating AI adoption is creating immense opportunities for innovation, but it is also enabling cyber threats to evolve rapidly. The findings underscore that organizations using AI and strong governance, were significantly better positioned to fend off cyberattacks,” said Gaurav Agarwal, Vice President, Technology, IBM India & South Asia. “Today, most organizations apply AI in limited ways, often focused on detection. To keep pace, AI with agentic capabilities must be embedded across the full security lifecycle—from detection and analysis to prioritization and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage,” he added.
Other key findings from the report for India are as follows:
The AI Gap: Adoption Lags, Costs and Delays Rise
- Automation Adoption Stalls: Only 32% of organizations reported extensive use of AI and security automation, while 36% reported limited and 32% reported no use at all.
- The Cost of Standing Still: Organizations with no AI and automation in security operations paid an average of INR 316 million (INR 31.6 crore) per breach, compared to INR 213 million (INR 21.3 crore) for organizations with extensive use, and INR 231 million (INR 23.1 crore) for those with limited deployment.
- Slower Response Without Automation: Breaches at organizations with no AI and security automation took an average of 236 days to identify and 75 days to contain, longer than those with extensive automation (175 days to identify and 81 days to contain).
- Shadow AI Remains a Significant Risk: Shadow AI added an average of INR 17.9 million (INR 1.79 crore) to the cost of a breach where present, making it one of the top three cost-increasing factors in India, alongside non-compliance with regulations and cloud migration.
The Financial Cost of a Breach
- Financial Services Face the Highest Costs: The financial services sector recorded the highest average breach cost in India at INR 409 million (INR 40.9 crore), followed by technology at INR 357 million (INR 35.7 crore) and communications at INR 345 million (INR 34.5 crore).
- Phishing Remains the Top Attack Vector: Phishing, including voice and SMS phishing, was the most common initial attack vector in India (19%), followed by drive-by compromise (16%) and supply chain compromise (15%).
- Offensive Security Pays Off: Offensive security testing, such as red teaming and penetration testing, was the largest cost-reducing factor in India, saving organizations an average of INR 24.7 million (INR 2.47 crore), followed by proactive threat hunting and AI governance technology.
Organizations Strengthen Cyber Resilience
- Investment Priorities: The top five areas where organizations are planning additional security investments are – incident response plans and testing (67%), threat detection and response technologies such as SIEM, SOAR and EDR (51%), identity and access management (49%), AI security and governance tools (39%), and employee awareness and training (36%).
Download the Cost of a Data Breach 2026 Global Report to learn more.
== ENDS ==

