ASEAN breach costs climb to record as AI attacks intensify, IBM study finds, ETCIOSEA


ASEAN companies are paying more than ever when cyber defences fail, and the latest IBM research suggests artificial intelligence is now amplifying both sides of the contest. The region’s average breach cost climbed to US$4.12 million in 2026, a record high for the sample, even as organisations that used AI and security automation more extensively were able to limit losses more effectively than peers with weaker toolsets.AI is reshaping the economics of cyber riskAccording to crnasia.com, the 2026 Cost of a Data Breach Report by the Ponemon Institute, sponsored and analysed by IBM, found that 29 per cent of ASEAN organisations that suffered malicious breaches said the attacks had been generated using AI. That pattern matters because the technology is helping attackers move faster, while also giving defenders a way to shorten investigations and cut the bill when incidents occur.The regional figure rose from US$3.67 million in the previous year, placing ASEAN ninth among the 16 country and regional samples covered in the study. The same report put Japan at US$4.01 million, South Korea at US$3.03 million, India at US$2.79 million and Australia at US$2.96 million, highlighting how breach economics continue to vary sharply across markets.What the ASEAN numbers say about readinessThe ASEAN results were drawn from 26 organisations across Singapore, Indonesia, the Philippines, Malaysia, Thailand and Vietnam. In the full study, the regional sample represented 4 per cent of the 602 organisations surveyed across 16 countries and regions and 17 industries. That relatively small base means the figures should be read as directional, but the trend line is clear: cyber incidents are becoming more expensive, and the gap between prepared and unprepared organisations is widening.IBM said organisations that used AI and security automation extensively had an average breach cost of US$3.66 million, compared with US$4.86 million for those that did not use those technologies. They also identified and contained breaches 123 days faster. Catherine Lian, general manager of IBM ASEAN, framed the issue as a race between offensive AI and defensive capability, saying that AI is lowering the cost and increasing the speed of attacks while making investigations longer and more costly for businesses in the region.The global comparison points in the same direction. Organisations that relied heavily on AI and automation for security recorded an average breach cost of US$4 million, versus US$5.93 million among those that reported no use of the tools. Their average time to identify and contain a breach was 215 days, compared with 280 days for organisations without such capabilities.High-risk sectors are paying the steepest priceSector data in the ASEAN sample shows that the financial services industry remained the most expensive target, with an average breach cost of US$6.53 million. Industrial organisations followed at US$5.99 million, while communications companies recorded US$4.28 million. The concentration of higher costs in these sectors is consistent with the global pattern, where critical infrastructure industries accounted for 62 per cent of AI-driven attacks studied, with financial services and energy among the most heavily affected.The report also found that some attack paths are especially expensive once criminals get in. In ASEAN, abuse of valid accounts emerged as one of the costliest initial vectors, with average breach costs of more than US$4.5 million. Globally, that vector carried an average cost of US$5.07 million. Voice or SMS-based phishing averaged US$5.29 million, while social engineering tactics such as helpdesk impersonation or multi-factor authentication fatigue averaged US$5.23 million.Encryption and controls remain unevenOne of the more concerning findings for the region was the low level of data protection at the time of breach. Only 29 per cent of ASEAN organisations said sensitive information was encrypted both at rest and in transit when the incident occurred. Globally, 37 per cent of breached organisations reported the same, while 34 per cent said they had controls in place to monitor and secure cryptographic assets such as keys and certificates.IBM’s report also pointed to specific control areas that helped reduce losses, including offensive security testing, security orchestration and automation, and key lifecycle management. These measures were associated with some of the sharpest reductions in breach-related costs, reinforcing the view that cyber resilience is increasingly a governance issue rather than just a technology purchase.Supply-chain compromise remained another stubborn problem in the global findings. Such breaches took an average of 258 days to identify and contain, making them among the longest-running incidents tracked in the study. They were also the second most common initial attack vector after phishing, underlining how third-party exposure continues to complicate corporate risk management.Defenders are also preparing for frontier AI threatsThe study suggests that concern over AI is not limited to attackers. After a breach, 71 per cent of ASEAN organisations said they intended to raise spending on security tools and governance. In the broader follow-on research, 85 per cent of organisations that were aware of advanced frontier AI threats said they planned to increase security spending because of those capabilities.IBM’s global analysis distinguished between AI-driven attacks and incidents involving an organisation’s own AI models or applications. It found that 21 per cent of organisations experienced a security incident tied to an AI model or application, up from 13 per cent a year earlier. Among organisations that faced an AI-related breach, 92 per cent lacked proper AI access controls, while only 40 per cent of organisations overall said they used access controls on AI models and data.The costliest AI-related incidents in the global study involved model inversion and prompt injection, with average breach costs of US$6.07 million and US$5.89 million, respectively. Other cases included cloud misconfigurations affecting AI workloads, malicious models, model evasion, insecure deployment and data poisoning. More than one in four organisations that experienced a malicious attack said it was AI-driven, a 56 per cent increase from the previous year. Deepfake impersonation accounted for 45 per cent of those attacks, followed by AI-enabled malware at 19 per cent and AI-generated phishing or related communications at 17 per cent.The report also showed that security teams are using AI unevenly across the incident lifecycle. Among breached organisations globally, 77 per cent reported either limited or extensive use of AI and automation for threat investigation, compared with 69 per cent for threat prevention. That gap suggests many enterprises are still better at analysing incidents after the fact than stopping them before damage is done.Why the latest findings matter for Indian and regional businessesFor businesses in India and across Asia, the message is less about any single attack type and more about the rising cost of delay. Breach containment is becoming a competitive capability, especially for banks, industrial groups, telecom operators and infrastructure-linked firms that face both high-value data exposure and complex supplier ecosystems. The IBM study indicates that modern security controls can materially reduce losses, but only if they are deployed broadly enough to matter.The follow-on survey, conducted in May 2026, received responses from 456 of the 602 organisations included in the Cost of a Data Breach research. Of those respondents, 356, or 78 per cent, said they were aware of recent reports about highly advanced frontier models such as Mythos. That awareness is likely to keep pressure on boards and technology leaders to move faster on access controls, monitoring and automated response.For ASEAN organisations, the record breach cost is therefore more than a statistical milestone. It is a warning that cyber risk is no longer just about preventing intrusion, but about whether enterprises can limit the financial fallout when AI-powered attacks inevitably get through.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *