Organisations without security automation pay 48 percent more per breach: IBM
Average breach cost in India hits a record INR 255 million, with automation gaps and shadow AI driving up losses.
The average cost of a data breach in India reached an all-time high of INR 255 million (25.5 crore) this year, up 15.9 percent from last year, according to IBM's 2026 Cost of a Data Breach report.
The report points to a clear reason behind the rise. Most Indian organisations still have not adopted AI-driven security automation in any meaningful way. Only 32 percent reported extensive use, while the remaining two-thirds are running with either limited automation or none.
That gap is now showing up directly in breach costs. Organisations with no automation paid an average of INR 316 million per breach, compared to INR 213 million for those with extensive automation. That works out to a 48 percent higher cost for organisations with no automation, based on IBM's figures.
Breaches also took noticeably longer to identify without automation in place, stretching out the window during which attackers have access to systems and data.
IBM India & South Asia vice president of technology Gaurav Agarwal said most organisations currently apply AI in security in narrow ways, largely limited to detection.
He said the bigger opportunity lies in embedding AI with agentic capabilities across the entire security lifecycle, from detection through to remediation, rather than treating it as a point solution.
The report also found that a meaningful share of malicious breaches in India now involve AI-generated attack techniques, making them faster to execute and harder to catch with older detection methods.
At the same time, shadow AI, or AI tools employees use without any IT oversight, is quietly adding to breach costs wherever it shows up.
IBM ranks it among the top cost-drivers in India this year, alongside regulatory non-compliance and cloud migration. Together, these findings suggest Indian enterprises are dealing with a security problem and a governance problem, arriving at the same time.
Certain sectors are feeling this acutely than others.
Financial services recorded the highest average breach cost in India, followed by technology and communications, industries that also happen to be sitting on the largest volumes of sensitive customer data.
Phishing remains the most common way attackers get in, a reminder that basic entry points haven't changed even as attack sophistication has.
Where the investment is headed next
Not every finding in the report is about rising costs. Offensive security testing, such as red teaming, emerged as the single largest cost-reducing factor in India this year, followed by proactive threat hunting and AI governance tooling. Organisations that invest before a breach happens are clearly getting a return on it.
Most organisations surveyed said they now plan to increase investment in security following a breach, with incident response readiness, threat detection platforms, identity and access management, and AI governance topping the list of planned spend.
A large automation gap in India is not just a security statistic, it is an unclosed market. Every enterprise still running with limited or no automation is sitting on an avoidable liability worth crores. That gap does not close on its own.
It closes through system integrators and managed security providers who can turn this into a budget conversation, and, through partners who can also help govern the AI tools enterprises are already using informally, whether their security teams know it or not.
The investment priorities named in the report, from detection platforms to AI governance, read less like a wish list and more like where enterprise security budgets are already headed over the next year.