Blog

Insights from IBM's Cost of Data Breach Report 2025: The Breach Lifecycle (Part 2 of 4)

The lifecycle of a data breach typically spans 200-300 days, with organizations often unaware of the breach for months. Learn how AI can dramatically reduce breach detection and recovery time.

The internals of a breach and IBM’s analysis of how AI impacts the entire breach lifecycle

This is the second article in a series based on IBM’s recently released “Cost of Data Breach Report 2025.” The first post provided an overview of IBM’s assessment including their observations about the increasing role of AI in both attacks used by intruders and the defenses used to stop them. In this analysis, we will dig deeper into the internals of a breach and IBM’s analysis of how AI impacts the entire breach lifecycle.

The Breach Lifecycle: A Race Against Time

The lifecycle of a data breach begins with an attacker identifying a vulnerability that can get them into your system and ends when your system has been fully recovered and secured. Unfortunately, for most organizations, this is a long process, typically between 200 and 300 days with typically a long time passing before the organization is even aware that there has been a breach.

The length of the breach lifecycle may seem irrelevant. With the average cost of a data breach in the US surpassing 10 million USD, breaches, whether “short” or “long” can significantly impact a company’s revenue. Therefore, it is, of course, best to deter them wholesale and have no breaches at all.

The Reality of Vulnerabilities

Unfortunately, while securing many vulnerabilities is possible, it is generally impossible to get them all, especially over time. In all likelihood, many vulnerabilities exist in your systems right now and are simply unknown. They are ticking time bombs waiting to go off. They might get identified by the defenders first and defused; but they might be discovered by the intruders first and used to slip through your defenses. In short, there is no way to prevent all possible breaches.

Every Day Counts

Thus, reducing the time of a breach lifecycle is crucial. Using a simplistic, but helpful, model of a uniform per-day cost, assume that each day in the breach lifecycle contributes equally to the overall cost of recovery. Within this model, if an average US data breach of 10.22 million USD were to last 250 days, cutting even one day off would save your company over 40,000 dollars.

AI’s Impact on Breach Recovery

The IBM report noted that the use of AI was significant in reducing the time to recovery. It states, “Security teams using AI and automation extensively shortened their breach times by 80 days and lowered their average breach costs by USD 1.9 million compared to organizations that didn’t use these solutions.” IBM also identified that AI tools were likely behind improved identification times, reducing the time intruders were not detected from 178 days on average in 2024 to 172 days on average in 2025.

The Bottom Line

The takeaway message is that once breached, every second is costing your organization money. The investment into AI-driven breach detection and breach recovery tools is crucial for reducing the cost and impact of breaches. And in today’s world, it is a matter of when, not if, a breach will occur.

Crimson Vista regularly works with organizations to identify and effectively incorporate advanced security tools, such as the AI tools referenced in the IBM report, into their security strategies and workflows. Whether you want to improve your security posture proactively or you need to improve your security after a breach, we can help you protect yourself and improve resiliency so that your goals, mission, and operations maintain continuity. You can contact us at: hello@crimsonvista.com.

Continue

Keep reading.