IBM published its Cost of a Data Breach Report last month, and the headline figure is the one everyone will quote: the global average cost of a breach has hit a record $4.99 million, a 12% increase on last year. In the UK specifically, that average sits at around $4.27 million (£3.13 million).
Numbers like that get shared widely, and for good reason. But after nearly two decades helping organisations prepare for exactly this kind of event, it soon becomes obvious that the headline figure is rarely the useful part of these reports. The useful part is buried further down, in the detail nobody quotes in the media post.
AI has changed the maths on both sides
This year’s report makes one thing clear: AI is reshaping breach economics for attacker and defender alike. AI-driven attacks increased 56% year over year and added around $1 million to the average cost of a breach. Deepfake impersonation, AI-generated phishing, and AI-enabled malware are no longer edge cases — they’re now a meaningful share of how organisations get breached in the first place.
The organisations that fared better weren’t the ones without AI in the picture. They were the ones using it deliberately. Organisations that extensively deployed AI and automation across their security operations reduced average breach costs by around $1.93 million (nearly £1.5 million) and identified and contained breaches roughly 65 days faster than those that didn’t. That gap is the difference between a bad quarter and a genuine crisis.
The Gap Nobody Wants to Talk About
Here’s the part that should worry procurement teams more than the headline figure. Shadow AI incidents — security incidents involving AI tools that weren’t sanctioned or governed by the organisation — affected 43% of breached organisations, more than double the share from the year before. And those organisations didn’t just pay more; they experienced greater operational disruption and increased data loss.
I raise this because it exposes something I see constantly in my own work: organisations that hold a certificate, tick the governance box, and then quietly lose track of what’s actually happening inside their own systems. An ISO 27001 ISMS is meant to catch exactly this kind of drift – new tools, new access points, new risks that didn’t exist when the last risk assessment was signed off. But a management system only works if someone is actually running it, not just maintaining it on paper for the annual audit.
Detection is only half the job
Ransomware attacks continued to rise, with 39% of breached organisations reporting at least one incident in the past year, up from 24% in 2023 — a 62.5% increase over four years. That trajectory alone should be enough to keep resilience on the board agenda. But what struck me most in this year’s report wasn’t the attack volume — it was recovery. Only around four in ten organisations reported complete recovery from their breach, and fewer than one in twenty managed it within seven weeks.
That’s not a detection problem. That’s a continuity problem. You can have excellent security controls and still take months to get back to normal operations if nobody has actually exercised what happens after the breach is contained – who’s authorised to make which decisions, how customers get told what, and which systems get prioritised for recovery first. Information security and business continuity keep getting treated as separate disciplines with separate owners, separate documents, and separate budgets. This report is one more piece of evidence that the organisations weathering these events best are the ones who’ve stopped treating them that way.
What this means if you're the one signing off the budget
If you’re evaluating a supplier, or being evaluated by one, a certificate alone won’t tell you any of this. It won’t tell you whether they’ve got a handle on the AI tools quietly running inside their business. It won’t tell you how fast they’d actually recover, because most organisations have never genuinely tested that under pressure. Ask instead: when did you last run a live exercise, not a tabletop discussion? Who is accountable for AI tools in use across the business, and do you actually know where they all are? If we were breached tomorrow, what would week one look like, in practice, and has anyone written it down before they needed it?
Those are harder questions than “are you certified?” – but they’re the ones that actually predict which organisations end up in that fewer-than-one-in-twenty group who recover fast, rather than the majority still picking up the pieces months later.



