India's average data breach cost rises to record Rs 25.5 crore in 2026: IBM report
Bengaluru, August 3
The average cost of a data breach in India rose to a record Rs 25.5 crore in 2026, marking a 15.9 per cent increase from Rs 22 crore last year, according to IBM's 2026 Cost of a Data Breach Report released on Monday.
The report said the average scale of a data breach also increased, with nearly 39,500 records compromised per incident in 2026 compared to 38,200 records in 2025.
According to the findings, 26 per cent of malicious data breaches in India were AI-generated, highlighting the growing role of artificial intelligence in making cyberattacks faster, more sophisticated and scalable.
Commenting on the findings, Gaurav Agarwal, Vice President, Technology, IBM India & South Asia, said, "India's accelerating AI adoption is creating immense opportunities for innovation, but it is also enabling cyber threats to evolve rapidly. The findings underscore that organizations using AI and strong governance, were significantly better positioned to fend off cyberattacks."
He added, "Today, most organizations apply AI in limited ways, often focused on detection. To keep pace, AI with agentic capabilities must be embedded across the full security lifecycle--from detection and analysis to prioritization and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage."
The report found that only 32 per cent of organisations in India have extensively deployed AI and security automation, while 36 per cent reported limited adoption and 32 per cent reported no adoption at all.
Organisations without AI and security automation incurred an average breach cost of Rs 31.6 crore, significantly higher than the Rs 21.3 crore reported by organisations with extensive AI deployment, the report said.
It further noted that phishing, including voice and SMS phishing, remained the most common initial attack vector in India, accounting for 19 per cent of breaches, followed by drive-by compromise and supply chain compromise.
Among sectors, the financial services industry recorded the highest average breach cost at Rs 40.9 crore, followed by the technology sector at Rs 35.7 crore and communications at Rs 34.5 crore.
The report also highlighted that offensive security measures such as red teaming and penetration testing emerged as the biggest cost-saving factor, reducing breach costs by an average of Rs 2.47 crore.
According to IBM, nearly 73 per cent of organisations surveyed said they plan to increase investments in security tools and governance following a breach, with incident response, threat detection technologies, identity and access management, AI security and employee awareness among the top investment priorities.
— ANI
Reader Comments
Interesting that companies using AI extensively had lower breach costs (21.3 crore vs 31.6 crore). But only 32% have fully adopted it! We're still relying on legacy systems. Made in India digital infrastructure needs more investment in cybersecurity. Otherwise Digital India dream will become Digital India risk. 🤔
Classic case of spending on fancy tech but ignoring the basics. 19% attacks via phishing? That means people are still clicking on random links. We need better awareness campaigns in regional languages too. Cybersecurity is not just IT department ka kaam hai, sabka responsibility hai.
The 15.9% increase mirrors what we're seeing globally, but the AI angle is concerning. 26% of malicious breaches were AI-generated - that's a new battlefield. Indian companies need to collaborate more with global cybersecurity firms and adopt zero-trust architecture as standard practice.
Offensive security measures like red teaming saved 2.47 crore - good to see investments in proactive testing working. But I wish small and medium businesses could afford these. Right now, only big players can protect themselves. Cyber insurance bhi costly hai. Government should provide subsidized security tools for startups.
Financial sector at Rs 40.9 crore is a wake-up call. UPI adoption has been phenomenal, but that also means more attack surface. Need stricter security audits for third-party payment gateways. Also, the 73% planning to increase investments post-breach - why wait for a breach to take action?
<
We welcome thoughtful discussions from our readers. Please keep comments respectful and on-topic.