Blog
Insights from IBM's Cost of Data Breach Report 2025: Opportunities and Challenges (Part 1 of 4)
Adopting AI tools for your security procedures and personnel can possibly prevent and mitigate the cost of a security breach. Learn how AI is reshaping cybersecurity defense and attack strategies.
Do you think integrating AI into your security organization is a minefield? Think again.
Adopting AI tools for your security procedures and personnel can possibly prevent and mitigate the cost of a security breach.
In the Russo-Japanese war of 1905-1906, Russia was vastly favored to win. They had more capital ships in the Pacific, and a much stronger naval tradition and industrial base. However, Japan was able to turn the tables using the naval mine – a relatively new technology that had not been previously deployed on a wide scale. In a further twist, the mine was primarily seen as defensive, which should have benefitted Russia’s largely defensive objectives. Instead Japanese minelayers cleverly laid mines in front of the Russian port, boxing their ships in until Japanese ground artillery advanced into range and destroyed the Russian ships in harbor. This historical example illustrates the important truth that new technologies do not necessarily favor one side, but whichever side adapts to them properly.
Today, on a different battlefield, Artificial Intelligence has changed the playing field for cybersecurity. Like the early 20th century naval mine, it has been proven to be a useful tool for both defenders and attackers. IBM recently released a wealth of data in their Cost of Data Breach Report 2025 including how AI impacts both cybersecurity attack and defense. The stakes, as always, are high. The average cost of a data breach in the United States is the highest it has ever been, despite the world average dropping in 2025. At an average of 10.22 million USD per breach in the United States and 4.44 million USD worldwide, security is more valuable than ever. This is a number that includes the actual theft and ransom, as well as regulatory fines, detection efforts, etc. for one breach. We will be releasing several articles related to the report to analyze some of the security highlights and especially the AI-relevant elements.
AI Model Breaches: The New Frontier
To give some perspective on the significance of AI in security, consider that the IBM report identifies that 13 percent of organizations in the CDB analysis reported security breaches related to the AI model with an additional 8 percent that were unsure if the breach involved AI security. A full 97 percent of the organizations with breaches in their AI models lacked proper access controls. If this is a silver lining in this data it is that it seems as long as your access to an AI model is given basic safeguards infiltrators will go after softer targets than you.
The Shadow AI Threat
However, your AI model is not the only cause of AI-related breaches. So-called ‘shadow AI,’ defined in the CDB report as “the use of AI without employer approval or oversight” is even more dangerous than a poorly moderated AI model. 20 percent, almost double that of own-model breaches, of the organizations studied in the CDB report suffered a breach related to shadow AI. Further, using shadow AI added an average of 670 thousand USD to the cost of a breach. That’s 6.6 percent of a US breach and 15.1 percent of a world breach.
The Power of Extensive AI Implementation
It’s not all bad news, though. Extensive use of AI saved an average of 1.9 million USD per breach (18.6 percent of a US breach and 42.8 percent of a world breach). Barring spurious correlation or omitted variables, this statistic proves that Artificial Intelligence should not be feared, and likely should be implemented ubiquitously, saving companies much more than it costs them. While the power of AI does not obviate the dangers, it does demonstrate that the benefits can outweigh the costs so long as it is implemented with proper safeguards.
Fundamentals Remain Critical
Even though AI (at this level) is new and some aspects of its security are novel, much of the core fundamentals of cybersecurity remain the same. As always, there is no silver bullet when it comes to safeguards and the best defense is a holistic one. Fortifying security for identification and data are both important. Having proper access controls is one very easy way to avoid certain attacks. Human governance of your AI tools will make breaches less likely and quicker to respond to. Adopting AI tools for your security procedures and personnel can also prevent and mitigate the damage of security breaches.
Adapting to Change
Adapting to a changing world is difficult and uncomfortable for all involved. However, as the Russian tsar proved at the start of the 20th century, failure to adapt can be extremely costly. Over the next several weeks, we will be publishing a number of analyses of the Cost of Data Breach report to help you and your business continue to adapt. We will be examining own-model breaches, shadow AI, use of AI in security, and holistic defense. At Crimson Vista, we offer “novel technologies” as well as services that can improve your cyber safety and threat hunting capabilities. For instance, our SecurityHubSM service offers opportunities to train, guide, and even augment your cybersecurity team to better handle advanced cybersecurity issues, including ones related to Artificial Intelligence. If you have questions about the IBM report or need some expert support in securing your own AI systems, please reach out to us at: hello@crimsonvista.com.
Continue
Keep reading.
Psychology-Aware Security Design
Cybersecurity products need affordances that guide people toward the right actions under stress. Psychology-aware design is how defenders catch up with attackers who already use it.
AI: The New Face of Cybersecurity
OpenAI and Anthropic AI agents are escaping sandboxes and exploiting vulnerabilities at machine speed. Learn what the Hugging Face breach reveals about AI's growing role in offensive and defensive cybersecurity.
The Limitations of Hashing for Data Anonymization
Why using hashing alone is an incomplete anonymization process