A joint survey report by IBM and the Ponemon Institute found that AI-driven attacks now account for 25% of all malicious data breaches, representing a 56% year-over-year increase. The average cost per incident is $6 million—20% higher than the average cost of all data breaches. 62% of AI-driven cyberattacks target critical infrastructure such as financial services and energy institutions, triggering cascading effects on the economy, supply chains, and essential services. AI enables attacks to become faster and cheaper, while defense costs continue to rise. Over half of organizations use AI agents for threat detection, but only 18% apply them to vulnerability remediation, and more than 20% have experienced breaches of their AI models or application systems.Article author and source: IBM and the Ponemon Institute survey report
A recent joint survey by IBM and the Ponemon Institute reveals a alarming trend: AI-driven attacks now account for one-quarter of all malicious data breaches, a 56% year-over-year increase. These incidents cost an average of $6 million per occurrence—20% higher than the average cost of all data breaches.
IBM and the Ponemon Institute survey report reveals critical infrastructure faces significant challenges.
More concerning is the centralization of attack targets. 62% of AI-driven cyberattacks target critical infrastructure, with financial services and energy institutions facing the highest concentration of attacks, increasing the risk of cascading impacts on the economy, supply chains, and essential services.
Cost imbalance between attack and defense: attacks are cheaper, while defense is more expensive.
IBM Security Software Vice President Suja Viswesan aptly noted: "What's truly changing is the economics of cyberattacks—AI makes attacks faster and cheaper, while the cost of data breaches continues to rise." Data supports this assessment: applying AI and automation in security operations can save companies an average of nearly $2 million in breach costs, yet a quarter of enterprises still have not implemented them.
Current Status and Security Challenges of AI Agent Applications
In terms of agent applications, over half of enterprises have deployed AI agents for threat detection and containment, but only 18% have integrated them into vulnerability remediation and management. Additionally, more than 20% of enterprises have experienced intrusions targeting AI models or application systems, with the most common causes being weak peripheral systems and misconfigured cloud platforms. Viswesan emphasized that the top priority now is eliminating the time gap between vulnerability discovery and remediation by embedding remediation capabilities directly into the development process to match the speed of attacks—while defenders are still manually investigating, AI-driven attacks have already completed their infiltration.
