Cost of a data breach report 2026 – IBM

by SPAC Alliance | September 2026 | Access Control, Cyber security, Library, Physical Security, SSCP

IBM’s 2026 Cost of a Data Breach Report confirms a rise in the cost of data breaches, but more importantly highlights several issues that directly align with SPAC Alliance’s work: physical security, access management, and the encryption of data and communications, at a time when artificial intelligence is rapidly increasing attackers’ capabilities.

The global average cost of a data breach has now reached USD 4.99 million, up 12% year on year.

At a glance

  • 30% of breaches involved data stored on premises, with IBM explicitly citing physical security and access management among the key responsibilities for protecting these environments.
  • Nearly 10% of breaches involved the illicit replication of data onto removable media.
  • 53% of breached organizations did not encrypt their sensitive data at rest and in transit.
  • Malicious AI-driven attacks increased by 56% and now account for more than one in four malicious attacks.

30% of breaches involve on-premises data

This share continues to grow, rising from 20% in 2024 to 28% in 2025, before reaching the level recorded this year.

IBM explicitly notes that protecting these environments depends in particular on patching, physical security and access management.

This is a reminder that digital infrastructure still depends on the physical protection of servers, network equipment, controllers and sensitive areas. Access control is one of the first lines of cyber defence.

Nearly 10% of breaches involve removable media

Copying data onto removable media remains a significant route for data theft, highlighting the need to control physical access to sensitive equipment.

These attacks are among the hardest to detect: they take an average of 258 days to identify and contain, as they can bypass conventional cyber defences.

For the most critical areas, equipment and data, access must therefore rely on an authentication level proportionate to the risk. Stronger mechanisms, including biometrics, can help reduce the risk of impersonation and improve access traceability.

53% of organizations did not encrypt their sensitive data

This protection gap affected information stored within systems as well as data exchanged between them. A further 10% of breached organizations did not know whether their data was properly encrypted.

Data and communications must therefore remain protected in their own right, including those used by access control systems. This further illustrates the value of our SSCP protocol and of mechanisms designed to protect against relay and replay attacks.

Offensive AI is surging

AI-driven attacks increased by 56% in a single year and now account for more than one in four malicious attacks. On average, they add USD 1 million to the cost of a malicious breach.

Conclusion

Whether physical, cyber or hybrid, an attack will always seek out the weakest link. Protecting data therefore requires a consistent end-to-end security chain: physical access control, trusted technologies, secure communications and controlled use.