Data Breach Costs in India Hit Record Rs 25.5 Crore Average: IBM Report
NEW DELHI: The average cost of a data breach for organisations in India has reached an all-time high of Rs 25.5 crore, according to a new report by global technology firm IBM. This marks a 16 per cent increase from the Rs 22 crore average recorded in the previous year, the report said.
The report, released on Monday, also highlighted that the scale of data breaches in India has grown. On average, 39,500 records were compromised per breach in 2026, compared to 38,200 in 2025, IBM said.
According to IBM, this is the highest average cost of a data breach ever recorded in the country. The financial impact includes expenses related to detection and escalation, notification, post-breach response, and lost business, among others. As data protection regulations become stricter, the costs of compliance and customer notification also contribute to the overall figure.
The report also examined the role of artificial intelligence (AI) and automation in managing cyber security. Organisations that had not deployed AI and automation in their security operations faced a significantly higher average breach cost of Rs 31.6 crore. In contrast, companies with extensive use of AI and automation reported an average cost of Rs 21.3 crore, while those with limited deployment faced Rs 23.1 crore. This difference of more than Rs 10 crore between the two extremes suggests that AI-driven security tools can meaningfully reduce the financial burden of a breach.
Gaurav Agarwal, Vice President of Technology at IBM India and South Asia, said that the adoption of AI is enabling cyber threats to evolve rapidly. He emphasised the need for businesses to integrate AI with agentic capabilities across the entire security lifecycle.
“AI with agentic capabilities must be embedded across the full security lifecycle, from detection and analysis to prioritisation and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage,” Agarwal said.
The findings come at a time when Indian organisations are increasingly digitising their operations, making cyber security a critical concern. Data breaches can have long-lasting effects on customer trust and regulatory compliance, in addition to immediate financial losses. The growing reliance on digital platforms across sectors such as banking, healthcare, and e-commerce has expanded the potential attack surface for malicious actors.
The report suggests that investment in AI-driven security measures can help mitigate the financial impact of data breaches. However, it also notes that organisations without such measures are not only at higher financial risk but also face challenges in detecting and responding to incidents quickly.
While the report does not specify which industries were most affected, it provides a broad overview of the escalating costs associated with data breaches in India. Companies are advised to assess their security frameworks and consider adopting advanced technologies to protect sensitive data. Regular security audits, employee training, and incident response planning remain essential components of a comprehensive cyber security strategy.
IBM’s report adds to a growing body of evidence that cyber security is not just a technical issue but a financial and strategic one. As threats become more sophisticated, the cost of inaction appears to be rising. For Indian businesses, the message is clear: investing in robust cyber security measures may be more cost-effective than dealing with the aftermath of a breach.