Cyberattacks don’t always begin with a dramatic breach. Sometimes they begin with noise. Earlier this week, I experienced a subscription bombing attack with more than 100 text messages and emails arriving in a short period from companies I had never signed up for. It wasn’t catastrophic, but it was a reminder of how attackers can use automation, volume and distraction to make important signals harder to identify. Now consider what happens when AI amplifies that same equation at large enterprises giving attackers greater speed, scale and precision. IBM’s newly released 𝗖𝗼𝘀𝘁 𝗼𝗳 𝗮 𝗗𝗮𝘁𝗮 𝗕𝗿𝗲𝗮𝗰𝗵 𝗥𝗲𝗽𝗼𝗿𝘁 𝟮𝟬𝟮𝟲 quantifies the impact: ⬥ $4.9M average global cost of a data breach ⬥ $6.3M average breach cost in financial services ⬥ $6.0M average cost of an AI-enabled breach ⬥ 56% increase in AI-driven attacks There is another side to the AI equation: organizations making extensive use of security AI and automation 𝘳𝘦𝘥𝘶𝘤𝘦𝘥 𝘣𝘳𝘦𝘢𝘤𝘩 𝘤𝘰𝘴𝘵𝘴 𝘣𝘺 $1.9M compared with organizations with little or no adoption. For insurers managing sensitive policyholder data, complex technology ecosystems, and increasingly AI-enabled operations, cybersecurity can no longer be treated simply as a defensive function. Cyber resilience, AI governance, identity, security automation and rapid response increasingly need to be 𝗱𝗲𝘀𝗶𝗴𝗻𝗲𝗱 𝗶𝗻𝘁𝗼 𝘁𝗵𝗲 𝘁𝗲𝗰𝗵𝗻𝗼𝗹𝗼𝗴𝘆 𝗳𝗼𝘂𝗻𝗱𝗮𝘁𝗶𝗼𝗻 itself. The report presents an excellent action guide with four key approaches to start if not already: operate security at the new speed of attack; shift identity security to continuous, runtime verification; strengthen AI control through AI sovereignty; and prepare for post-quantum security risks. Check out the report for more details. 📘 Read the report: https://lnkd.in/eZjbvadN Dimple Ahluwalia Dave McGinnis Jeff Crume, PhD, CISSP Giovanny Moreano #CostofaDataBreach #AIsecurity #cybersecurity #insurance
Organizations treating security automation as an afterthought are already losing, just not visibly yet. The $1.9M gap isn't about budget, it's about how fast you can detect and respond when it matters most.
Great post, Don. The example you shared really drives the point home. While security teams are trying to find a needle in the haystack, attackers are busy making the haystack bigger. AI only amplifies that dynamic.
Here’s another report by the IBM Institute for Business Value entitled - “Cybersecurity 2028: Your workforce, built for the AI frontier” - which is an excellent guide on how to think about ups killing your workforce on emerging AI in security trends: https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/cybersecurity-ai-workforce