CISO Middle East Issue 03 | Page 28

I
DATA BREACH

Middle East breach costs hit $ 8 million as AI threats grow

I

BM has released its 2026 Cost of a Data Breach Report, revealing that the average cost of a data breach for organisations in the Middle East reached US $ 8 million.
According to the study, the three leading factors increasing the cost of data breaches for Middle East businesses were mismanaged secrets and keys, excessive privileges and poor role management and an inability to prioritise threats. By contrast, encryption, a DevSecOps approach and endpoint detection and response tools were the leading factors associated with lower breach costs.
Among malicious breaches, 26 % were AI-enabled, while another 11 % of respondents were unable to confirm whether attackers had leveraged AI. Organisations making extensive use of AI and security automation recorded average breach costs more than US $ 3 million lower than organisations that did not use these capabilities, yet 23 % had still not adopted them.
Lost business remained the largest cost category in the region in 2026, averaging US $ 3.57 million per breach. This was followed by postbreach response costs at US $ 2.17 million, detection and escalation at US $ 1.9 million and notification at US $ 0.36 million. These figures underscore the continued financial strain organisations face across the entire breach lifecycle, from discovery to containment.
The financial and technology sectors recorded the highest average breach costs, at US $ 10.67 million each, followed by the industrial sector at US $ 9.6 million.
“ As the number of cybercriminals harnessing the power of AI for malicious purposes rises, attacks are becoming faster and cheaper to launch, while breaches keep getting more expensive to find and fix. This growing imbalance is fundamentally changing the economics of cyber risk. Companies must invest in advanced threat detection and response technologies using AI and automation to stay ahead of emerging risks,” said Saad Toma, General Manager of IBM Middle East and Africa.
Other key findings from the 2026 Cost of a Data Breach Report for the Middle East include:
• Increased cybersecurity investment – Among the organisations surveyed, 59 % planned to increase investment in security tools and governance following a data breach. Of those planning to increase investment, the most common priority was identity and access management solutions, at 44 %, followed by incident
response planning and testing and quantum security for data and data transfer, at 39 % each.
• Encryption gaps – Core weaknesses in encryption and cryptographic management continue to expose organisations, even as quantum-safe investment grows. Only 35 % of breached organisations reported encrypting sensitive data both at rest and in transit at the time of the breach. However, 69 % of Middle East organisations reported having formal controls in place to monitor secure cryptography and cryptographic objects across the organisation.
• AI agents and machine identities – Among Middle East organisations with a security operations centre, 55 % reported having deployed agents within it. The most commonly reported controls for monitoring and securing non-human identities included machine identity inventory and lifecycle management, including automated tracking of service accounts and API keys, at 57 %, followed by extending zero-trust architecture to non-human identities, requiring continuous authentication and authorisation for all AI-driven processes, at 43 %.
• Top initial access vectors – The most common initial cause of data breaches in 2026 was phishing, including voice and SMS phishing, accounting for 18 % of incidents and carrying an average cost of US $ 10.41 million. Supply chain compromise and social engineering, such as IT helpdesk impersonation or multi-factor authentication fatigue, each accounted for 16 % of breaches, with average costs of US $ 8.45 million and US $ 7.32 million respectively.
Conducted by the Ponemon Institute and sponsored and analysed by IBM, the 2026 Cost of a Data Breach Report analysed real-world data breaches experienced by 602 organisations globally, including organisations in Saudi Arabia and the UAE, between March 2025 and February 2026.
28 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST