Blog

Insights from IBM's Cost of Data Breach Report 2025: AI - The Inescapable Aspect of Security (Part 4 of 4)

AI is an inescapable aspect of modern security. Organizations with extensive AI use saved nearly $2 million per breach. Learn how to integrate AI effectively into your security strategy.

AI - The Inescapable Aspect of Security

At time of this writing, Artificial Intelligence is an inescapable aspect of the current security environment. This relatively new, but massively expanding technology is already being used by bad actors to increase the quality and quantity of malicious content. Security is also being updated to use Artificial Intelligence, in some ways more effectively than others. Security cannot be automated. However, as the Cost of Data Breach Report 2025 shows, AI is quantifiably important to your organization to the tune of potentially millions of dollars.

The Arms Race: AI in Attack and Defense

As discussed in a previous post, there is a “Lifecycle” to a data breach. Artificial Intelligence has the power to both drastically increase and decrease the cost and containment time of a breach, depending on who is using it and how it is being used. Breaches in organizations that had extensive use of security AI were almost a full 2 million dollars less expensive on average than breaches in organizations that used no security AI. Security AI vastly cut the time needed to contain a breach. Every day a breach lasts is more expensive. The ability of automated guardians to detect breaches a human might miss may be the most valuable aspect of the new technology. At the same time, AI is used by attackers to more easily breach security in an increasing percentage of breach cases. AI can be used maliciously in a variety of circumstances to increase both quantity and quality of breach attempts. 35% of AI-driven attacks were deepfake attempts, using computer-generated pictures, videos, or audio to attempt to trick personnel. 37% were AI generated phishing attacks. Grammar mistakes have long been a glaring red flag in phishing attempts. That early warning is rapidly becoming obsolete. You are already in an arms race, it is advisable to not fall behind.

Beyond the Data: Practical Implementation

While useful in many ways, there are some deficiencies in the IBM’s Report. While there is plenty of data on how AI in general harms or benefits a company. There is little about the best tools or strategies to use with AI. For example, there is ample warning against use of shadow AI without a comprehensive definition or example roster. There is quantifiable data showing how important it is to integrate Artificial Intelligence into your own security approach, without a whole lot of detail on exactly how to do so. Running out and buying the most expensive security software without proper integration or training is a poor plan.

AI as a Skills Multiplier, Not a Replacement

The Report does state that “AI tools act as a skills multiplier.” However, it is important to specify that AI tools cannot effectively replace security personnel. Humans and machines both make errors, but different ones. In the same way that two different doctors will look at the same injury and then collude to resolve it, your team and their Automated Security Tools will spot different details. Artificial Intelligence provides early warning, rapid reaction, and containment aid. It does not do what your team can. Working with your team to develop AI that can resolve current deficiencies may bring better success than developing a tool and then figuring out how to shoehorn it into your strategy. An AI tool or tools that both help you stay secure and minimize damage is advisable.

Moving Forward with AI

Hopefully, this series of blogposts have been helpful for your own planning and AI integration strategy. Remember that AI is neither plague nor miracle cure, but a tool that can be used by you and your attackers to opposite ends. Artificial Intelligence can save your organization millions of dollars in avoiding and containing breaches. Use it boldly but intelligently.

If your organization is trying to figure out how to strengthen your cybersecurity lifecycle to reduce your breach lifecycle, call Crimson Vista. We can help you with strategy and planning in order to achieve the best cybersecurity posture possible within the goals and parameters of your operating environment. Get expert guidance. It’s worth it.

Continue

Keep reading.