← All posts

Breaches Now Cost $5 Million. Your Board Needs to Know Why.

IBM dropped its annual Cost of a Data Breach Report last week, and the headline number should make every executive sit up straight: $4.99 million. That's the average cost of a data breach in 2026, a new record, up more than ten percent from the year before.

But the headline number isn't the one that should worry you most.

The AI Gap Is Now a Dollar Figure

For the first time, IBM's report breaks out breaches driven by AI-powered attacks from those that aren't. More than one in four organizations hit by a malicious attack said AI drove it. Those AI-driven breaches cost roughly $1 million more than conventional ones.

Read that again. Attackers using AI tools are inflicting materially more damage per incident. And on the defensive side? Close to seven in ten breached organizations told Ponemon's researchers they have no governance policies for managing AI or spotting unapproved use.

In Cyber Risk Is Business Risk, I describe the Three Questions framework that every board should be asking their CISO. The first question — What are we doing about it? — just got a lot harder to answer if your organization has no AI governance in place while your attackers do.

Shadow AI Doubled. Costs Followed.

Here's a number that should trigger an emergency board conversation: workers using unapproved AI tools figured in 43% of security incidents this year. That's more than double last year's share.

Those shadow AI incidents aren't theoretical. Half the time they ended in data loss or compromise. Four out of ten disrupted operations. About one in five drew a regulatory fine.

I've spent years telling executives that cybersecurity isn't an IT problem — it's a business risk problem. Shadow AI proves the point in real time. When your marketing team spins up an unapproved AI tool and feeds it customer data, that's not a technology failure. That's a governance failure. And it's happening in 43% of incidents now.

Meanwhile, 92% of organizations that experienced a security incident involving an AI model or application were missing role-based access controls, multifactor authentication, or similar protections on those systems. The security basics we've been preaching for twenty years aren't being applied to the newest attack surface.

The Clock Is Going Backward

For five straight years, mean time to identify and contain a breach had been declining. Progress. This year? It rose to 247 days.

That reversal matters because the math is punishing. Breaches that ran past 200 days cost about a third more than the ones closed sooner. Every week your team doesn't know about a breach, the bill gets bigger. Organizations running AI and automation across prevention, detection, investigation, and response close breaches roughly two months faster and pay close to $2 million less than those running none.

This Week's Example: Your Firewall's Back Door

If you want a concrete illustration of why these numbers keep climbing, look no further than this week's news. Cisco disclosed that its Secure Firewall Management Center — the console that manages your entire firewall infrastructure — shipped with hard-coded static credentials for a built-in account (CVE-2026-20316). Attackers found those credentials and exploited them as a zero-day before Cisco even knew about the flaw. CISA added it to the Known Exploited Vulnerabilities catalog on July 29 and gave federal agencies until August 1 to patch.

Think about what that means for a board member. The tool your team bought to protect the network had a built-in password that attackers used to walk through the front door. And it gets worse: Cisco says the flaw can be chained with a separate critical authentication bypass vulnerability (CVE-2026-20079, CVSS 10.0) that could give an attacker root access — no credentials required.

This is exactly the kind of vendor oversight gap I write about in the chapter on supply chain risk. Your security is only as strong as the weakest link in your vendor stack, and sometimes that weakest link is the security product itself.

What to Ask Your CISO This Week

The IBM report and the Cisco disclosure together give boards a concrete agenda for their next security conversation:

On AI governance: "Do we have a written policy governing AI use across the organization — including tools employees may have adopted on their own? What percentage of our AI systems have role-based access controls?"

On detection speed: "What is our current mean time to detect and contain a breach? Is that number improving or getting worse? Where are we deploying automation to close the gap?"

On vendor oversight: "When was the last time we audited our security vendors for known vulnerabilities in their own products? Are our firewall management consoles exposed to the public internet?"

On budget: "IBM found that 85% of breached organizations plan to raise security spending. Are we investing before the breach, or are we going to be one of the 85% reacting after one?"

The Bottom Line

$4.99 million is an average. US breaches run more than double the global figure. Healthcare has been the costliest industry for thirteen consecutive years, with financial services close behind. Supply chain compromises — where a business partner becomes the attack path — add more to the breach bill than any other single factor.

These aren't IT metrics. They're business metrics. They belong on the board agenda next to revenue projections and regulatory risk.

The question isn't whether your organization will face a cyber incident. It's whether your board is governing the risk with the same rigor it applies to every other material business threat. Because at $5 million a pop, "we were briefed" isn't going to cut it anymore.