India’s Average Data Breach Cost Hits Record as AI Security Falls Behind
- Aisha Washington

- Aug 4
- 14 min read
IBM put a hard number on India’s widening AI security gap: the average organizational cost of a data breach reached INR 220 million in 2025. The finding, now resurfacing through Google News coverage, represents a 13 percent increase from 2024 and a record for India.
The timing makes the number more troubling. Indian companies are rapidly adding generative AI tools, automated workflows, and machine identities. Yet only 37 percent of surveyed organizations had AI access controls, according to IBM’s India findings.
That means roughly one in three had the controls needed to regulate who or what could reach AI systems. Nearly 60 percent either lacked an AI governance policy or were still developing one.
The result is not a simple contest between companies and increasingly capable attackers. The central conflict sits inside the enterprise: fast AI adoption versus slow security governance.
Newer research suggests that the exposure has continued to expand. AI applications now hold credentials, query sensitive databases, operate cloud services, and trigger business actions. Security teams must defend both the AI system and everything it can reach.
Google News Puts India’s Record Breach Cost Back in Focus
India’s breach record shows that faster incident response has not stopped the financial damage from rising.
IBM released its India findings on August 7, 2025. The company said the average total organizational breach cost had increased from INR 195 million in 2024 to INR 220 million.
The increase occurred even as organizations reduced the average breach lifecycle. IBM defines that lifecycle as the time needed to identify and contain an incident, including restoring services.
India’s average lifecycle fell to 263 days, 15 days shorter than in 2024. That improvement matters, but 263 days still gives attackers a long period to explore systems, collect credentials, and reach valuable data.
The apparent contradiction is central to the story. Companies are finding and containing breaches sooner, yet the average cost continues to climb.
That can happen when each day of exposure becomes more expensive. Enterprises now connect data across cloud services, software platforms, application programming interfaces, and AI tools. A single compromised identity can cross several of those systems.
IBM’s India breach data also identifies the sectors carrying the greatest financial impact. Research organizations recorded the highest average cost at INR 289 million.
Transportation followed closely at INR 288 million. Industrial organizations averaged INR 264 million, after leading the country’s sector rankings in 2024.
These sectors combine valuable information with operations that cannot remain offline for long. Research organizations hold intellectual property and sensitive datasets. Transportation companies depend on continuously available booking, logistics, and operational systems.
Industrial environments add another complication. Their technology often connects business networks with operational equipment, where containment decisions can interrupt physical processes.
The most common entry methods remain familiar. Phishing accounted for 18 percent of the studied breaches in India. Third-party and supply-chain compromise accounted for 17 percent, while vulnerability exploitation represented 13 percent.
That breakdown challenges the idea that record costs require a highly specialized AI attack. Attackers can still enter through an email, a supplier, or an unpatched application.
AI changes what happens around those established methods. It can improve phishing messages, automate reconnaissance, process stolen information, and help attackers repeat techniques across more targets.
Google News is the discovery channel for the latest headline, not the original source of the numbers. IBM and the Ponemon Institute produced the underlying research.
That distinction matters because aggregation can flatten several findings into one dramatic claim. The evidence supports a record average cost and a serious readiness gap. It does not show that every breach in the sample was caused by AI.
AI Adoption Is Expanding Faster Than Access Control
The most immediate risk comes from granting AI systems access before organizations can inventory, restrict, and monitor that access.
Enterprise AI no longer sits inside an isolated chat window. Companies connect models to document repositories, customer records, development environments, messaging platforms, and cloud administration tools.
Every connection creates a new path to data. It also creates another identity, token, service account, plugin, or permission that someone must govern.
IBM found that only 37 percent of organizations in India reported having AI access controls. Access controls determine which users and systems can reach an application, what actions they can perform, and which data they can retrieve.
The absence of those controls does not automatically produce a breach. It does increase the damage available after an account, token, or AI integration becomes compromised.
Governance is also incomplete. Nearly 60 percent of breached organizations in India either lacked an AI governance policy or were still developing one.
Among organizations with policies, only 34 percent used AI governance technology. A written policy can define permitted behavior, but technical enforcement determines whether systems follow it.
This gap becomes more significant as companies deploy agents. An AI agent is software that can select and perform actions through connected tools, often with limited human involvement.
Traditional software usually follows a defined sequence. An agent can decide which tool to call, what information to retrieve, and how to proceed based on changing input.
That flexibility creates value, but it also complicates permissions. An agent may need database access, a cloud token, an email account, and a ticketing integration to complete one workflow.
Giving the agent permanent access to every connected system is convenient. It also creates a concentrated target.
The Cloud Security Alliance reported in April 2026 that 82 percent of surveyed enterprises had discovered previously unknown AI agents in their environments. Its AI agent survey covered 418 IT and security professionals.
Sixty-five percent reported at least one AI agent-related incident during the previous year. Among those incidents, 61 percent involved data exposure, 43 percent caused operational disruption, and 35 percent produced financial losses.
The survey was commissioned and financed by Token Security, which co-developed its questionnaire. That commercial involvement deserves disclosure, and the results should not be treated as an exact measurement of every enterprise.
Still, the findings describe a recognizable governance problem. Security leaders may believe they can see their AI deployments while unknown agents remain active in scripts, development tools, SaaS platforms, or internal automation.
The same study found that only 21 percent had formal processes for decommissioning agents. An abandoned agent can retain credentials after its original project ends.
This creates what the report calls retirement debt. The company stops using the workflow, but its permissions remain available to an attacker or an unauthorized employee.
Human accounts already create similar problems when access survives a role change. AI adds many more non-human identities, often created faster and documented less carefully.
For Indian enterprises, this expands the breach problem beyond blocking malicious prompts. Security teams must know which agents exist, who owns them, which credentials they hold, and when those credentials should expire.
Shadow AI Turns Convenience Into a Cost Multiplier
The core tradeoff is speed versus control: employees gain immediate productivity while the company loses visibility into where its information travels.
Shadow AI refers to AI applications used without approval or oversight from an organization’s technology department. It can include public chatbots, browser extensions, meeting assistants, coding tools, and unauthorized internal agents.
Employees rarely adopt these tools intending to create a breach. They usually want to summarize a document, analyze a spreadsheet, prepare a presentation, or accelerate a repetitive task.
The security problem begins when confidential material enters a service the company has not reviewed. Teams may not know how the service stores prompts, manages uploaded files, or separates customer data.
IBM identified shadow AI as one of India’s three largest breach-cost drivers. Its presence added INR 17.9 million to the average breach cost.
Yet only 42 percent of surveyed organizations had policies to manage AI or detect shadow AI. That leaves many companies unable to measure the activity associated with one of their largest reported cost factors.
Blocking every AI service is unlikely to solve the problem. Employees can move to personal accounts, unmanaged browsers, or mobile devices, making activity harder to observe.
A workable response needs approved alternatives and enforceable boundaries. Employees should know which tools they can use, which information remains prohibited, and how to request a reviewed integration.
The organization also needs technical visibility. That includes discovering unsanctioned applications, monitoring data transfers, and identifying unusual access by human and machine accounts.
Data classification becomes essential here. Classification assigns information a sensitivity level so systems can apply different rules to public, internal, confidential, and regulated data.
Without classification, a company cannot reliably distinguish a harmless product description from customer identity records. It may apply the same weak control to both.
The 2026 threat report from Thales shows how widespread that visibility problem has become. Only 34 percent of surveyed organizations knew where all their data resided.
Just 39 percent could fully classify it. The report also found that 47 percent of sensitive cloud data remained unencrypted.
Those are global findings rather than India-only measurements. They still explain why AI adoption increases the pressure on data controls.
A model or agent can retrieve information only through the access it receives. However, excessive permissions let one compromised system reach material that should have remained outside its task.
Thales reported that 61 percent of organizations said attackers were targeting their AI applications. Sensitive data was the leading target.
The same research found that 67 percent of organizations experiencing cloud attacks cited credential theft as the leading attack technique against cloud management infrastructure.
Credentials include passwords, API keys, session tokens, and other secrets that prove an identity can access a system. AI workflows depend heavily on these machine-readable secrets.
A stolen cloud token can be more useful than a sophisticated attack against the model itself. It may provide direct access to storage, databases, computing resources, or administrative functions.
This is why shadow AI is not merely an employee-policy issue. It is part of a larger identity and data-management problem.
Companies need a reliable record of approved tools, connected information sources, system owners, and access decisions. A searchable knowledge base can help technical teams retain that operational context.
Documentation alone cannot enforce security, but poor documentation slows containment. Responders lose time when they cannot identify an agent’s owner, data sources, or credentials.
The costly scenario is therefore easy to understand. An employee connects an unreviewed tool, the tool receives broad access, and the integration persists without monitoring.
An attacker does not need to defeat a carefully designed AI defense. The attacker only needs to find the forgotten credential surrounding it.
The AI Security Paradox Is Getting Harder to Ignore
AI is increasing the attack surface while also becoming one of the strongest tools available to reduce breach costs.
IBM’s findings do not support a simple anti-AI conclusion. Organizations using AI and automation extensively in security recorded major savings compared with those that did not.
Globally, IBM associated extensive security AI and automation with USD 1.9 million in average savings. In India, the company said these tools reduced breach costs by more than half.
Despite that advantage, 73 percent of respondents in India reported limited or no use of AI and security automation.
The same technology family therefore appears on both sides of the breach equation. Poorly governed business AI adds exposure, while well-governed security AI helps defenders identify and contain attacks.
Security AI can correlate alerts, detect unusual identity behavior, find exposed data, and prioritize incidents. It can reduce the time analysts spend sorting repetitive signals.
Automation can also isolate a device, revoke a token, or block a suspicious connection faster than a human team can coordinate those actions manually.
However, defensive automation needs boundaries. A detection system that can disable accounts or change network policies carries operational risk if its decision is wrong.
Companies should distinguish between low-risk automated actions and high-impact changes requiring review. Collecting evidence may be automatic, while shutting down a production service may need human approval.
The Cloud Security Alliance found that 53 percent of surveyed organizations allowed agents to operate autonomously on low-risk tasks with human review for higher-risk actions. Another 24 percent used human review for most tasks.
Only 13 percent reported fully autonomous models. Those results suggest most security teams already recognize that autonomy should depend on the consequence of an action.
The challenge is implementing that principle consistently. Different departments may create agents without applying the same risk categories, logging rules, or approval requirements.
AI also gives attackers scale. Generative systems can produce message variations, translate scams, adapt social engineering, and process stolen documents more quickly.
Thales found that nearly 60 percent of surveyed companies had experienced deepfake-driven attacks. Forty-eight percent reported reputational damage linked to AI-generated misinformation or impersonation.
Deepfakes are synthetic audio, video, or images designed to imitate a real person. Their business value to attackers often comes from identity deception rather than technical novelty.
A convincing voice message can pressure an employee to transfer information, reset credentials, or bypass a normal approval process. The attack still depends on weak verification.
AI-driven bots add another scale problem. Thales reported in April 2026 that automated traffic accounted for more than half of internet activity, with 40 percent classified as malicious.
Its bad bot findings describe APIs and identity systems as primary targets. Bots can repeatedly test credentials or abuse business workflows without using a conventional malware payload.
These findings help explain why one defensive product will not close the gap. The attacker can combine automation with familiar weaknesses across identity, vendors, cloud configurations, and employee behavior.
The appropriate comparison is governed AI versus ungoverned AI, not AI versus no AI.
Governed defensive systems receive defined permissions, monitored data access, tested response procedures, and accountable owners. Ungoverned systems grow through convenience and remain difficult to inventory.
Security teams also need to test whether AI actually improves detection rather than adding another dashboard. A tool that produces more alerts without improving decisions can increase analyst workload.
Vendor-sponsored reports introduce another reason for caution. IBM sells security and governance products, while Thales sells identity and data-protection technology.
Their data can reveal useful patterns, but it does not independently prove that purchasing a particular platform will deliver the reported savings.
Organizations should validate claims against their own incident history. Useful measures include time to detect, time to contain, repeated incident types, credential age, and the percentage of sensitive data covered by encryption.
The paradox has a practical answer. Companies should use AI where it improves measurable security outcomes, while denying every AI system unnecessary and permanent access.
What the Record Cost Does Not Prove
The evidence shows a serious governance gap, but it does not establish AI as the direct cause of India’s record average breach cost.
The most important limitation is attribution. IBM said AI-related breaches represented a small portion of the global organizations in its researched population.
The 2025 report studied AI governance, AI-related security incidents, and shadow AI for the first time. That provides an early baseline rather than a mature historical trend.
The headline can therefore overstate the connection between AI attacks and the Indian cost record. Phishing, supply-chain compromise, and vulnerability exploitation remained the leading initial vectors.
AI can strengthen those attacks, but the published India data does not quantify how many phishing incidents used generative AI. It also does not show that AI caused the entire 13 percent increase.
Average cost creates another limitation. A small number of very expensive incidents can move an average upward, especially within high-impact sectors.
The figure should not be read as a prediction that every Indian company will lose INR 220 million. It is an average across the organizations studied by IBM and Ponemon.
Cross-report comparisons also require care. IBM, Thales, and the Cloud Security Alliance used different samples, dates, questions, and definitions.
An AI-related incident in one survey may include an unauthorized agent. Another report may focus on data loss, model access, or an attack enhanced by AI.
Combining their percentages into one unified readiness score would be misleading. The reports are more useful as evidence of recurring control problems.
Those recurring problems include incomplete inventories, weak access governance, unclassified data, persistent credentials, and limited monitoring.
The “one in three” framing also needs precision. IBM found that 37 percent of organizations in India had AI access controls. That is close to one in three, but access controls are not a complete measure of cyber readiness.
A company can have an access-control product and still configure it poorly. Another organization may lack a dedicated AI control platform while applying effective restrictions through existing identity systems.
Preparedness includes prevention, detection, containment, recovery, communication, and regulatory response. No single survey percentage captures all six.
The source chain deserves scrutiny as well. Google News aggregates and ranks links from publishers, but it does not independently validate every statistic in a headline.
Readers should trace major claims to the underlying study. In this case, IBM’s primary release supports the record INR 220 million figure, the 37 percent access-control figure, and the shadow AI cost finding.
The company’s methodology also provides context. IBM says its Cost of a Data Breach research has examined nearly 6,500 breaches over 20 years.
That long history gives the study value, but annual samples are not a census of every publicly known incident. Organizations willing to participate may differ from those that do not.
Vendor research can also emphasize problems aligned with the vendor’s products. That does not make the findings false, but it makes independent measurement important.
Regulatory data, insurance claims, corporate disclosures, and incident-response records could provide additional checks. Public reporting in India remains uneven, which limits comparison.
India’s changing privacy framework will eventually improve the amount of structured breach information. The Digital Personal Data Protection Rules were notified in November 2025 with a staged enforcement schedule.
The DPDP rules include requirements concerning security safeguards and breach notification. Many substantive provisions have delayed commencement dates.
Organizations should not confuse publication with immediate enforcement of every obligation. They need to map each requirement to its applicable start date.
The skepticism does not erase the central warning. It refines it.
India’s record average breach cost is real within IBM’s study. The AI governance gap is also documented. What remains uncertain is the exact portion of financial damage directly caused by AI-enabled attacks.
Three Signals Will Show Whether India Is Closing the Gap
The next test is whether companies convert concern into measurable control over identities, data, and incident response.
The first signal is access-control coverage for AI applications and agents. IBM’s 37 percent figure provides a clear baseline for Indian organizations.
The number should rise as enterprises inventory their AI systems and connect them to centralized identity controls. Progress should include human users, service accounts, plugins, models, and autonomous agents.
A stronger figure would support the view that organizations are closing the adoption-governance gap. A stagnant figure would suggest that new AI deployments continue to outpace security work.
Companies should measure more than whether a control exists. They should track how many AI identities have named owners, limited permissions, credential expiration, and continuous monitoring.
They should also review whether inactive agents are removed. Unknown or abandoned agents can preserve access long after their business purpose disappears.
The second signal is the relationship between breach lifecycle and financial impact. India reduced its average lifecycle to 263 days, but the average cost still rose.
Another reduction would be encouraging only if costs and operational disruption also begin falling. Faster discovery that arrives after attackers reach critical systems may produce limited savings.
Organizations should separate detection time from containment time. They should also track restoration, customer notification, legal work, and lost business.
Those measures reveal where cost continues accumulating. A company may detect an incident quickly but spend months rebuilding systems or validating data integrity.
Regular simulations can expose those delays before an actual breach. The exercise should include executives, technical responders, legal teams, communications staff, and affected business units.
A response plan stored but never rehearsed offers little evidence of readiness. Teams need to know who can revoke credentials, isolate systems, contact regulators, and communicate with customers.
The third signal is implementation of India’s data-protection requirements. The DPDP framework moves breach handling from a technical concern toward a broader accountability obligation.
Organizations must follow the notified commencement schedule carefully. During the transition, they should build the safeguards, records, and notification processes needed for later enforcement.
The strongest indicator will be operational evidence. Companies should be able to identify affected data, determine who received it, document containment, and notify the required parties.
That depends on data discovery and classification before an incident begins. A company cannot provide a reliable breach assessment if it never mapped its information.
These regulatory preparations should also reach vendors. Supply-chain compromise represented 17 percent of the initial vectors in IBM’s India findings.
A company may secure its own systems while a service provider retains excessive access or weak incident procedures. Contracts should define security responsibilities, notification duties, and evidence requirements.
The broader forecast remains mixed. Attackers now have cheaper automation, more convincing impersonation tools, and a growing number of machine identities to target.
Defenders also have better detection, faster analysis, and more automated containment. The deciding factor is whether organizations deploy those capabilities with enforceable governance.
The record INR 220 million average will matter less if it becomes a peak rather than the start of a trend. That outcome requires companies to reduce both breach frequency and the damage available after access occurs.
For business leaders, the immediate question is concrete: can the organization list every AI system that can reach sensitive data today?
If the answer requires a long investigation, the readiness gap remains open. If the inventory is current, permissions are limited, and response plans are tested, the company has moved beyond a Google News warning toward defensible control.


