The average cost of a data breach for organisations in the Middle East has risen to US$8 million, according to IBM’s 2026 Cost of a Data Breach Report, highlighting the growing financial impact of cyberattacks as AI becomes increasingly embedded in both enterprise operations and attacker tactics.
Conducted by the Ponemon Institute and sponsored and analysed by IBM, the report found that 26 percent of malicious breaches in the region involved AI-enabled attacks, while another 11 percent of organisations were unable to determine whether AI had been used by attackers.
According to the report, organisations that extensively deployed AI and security automation recorded average breach costs more than US$3 million lower than those that had not adopted these capabilities. However, nearly a quarter (23 percent) of respondents had yet to implement AI and security automation.
“As the number of cybercriminals harnessing the power of AI for malicious purposes rises, attacks are becoming faster and cheaper to launch, while breaches keep getting more expensive to find and fix. This growing imbalance is fundamentally changing the economics of cyber risk. Companies must invest in advanced threat detection and response technologies using AI and automation to stay ahead of emerging risks,” said Saad Toma, General Manager of IBM Middle East and Africa.
Lost business remained the largest contributor to breach costs, averaging US$3.57 million, followed by post-breach response (US$2.17 million) and detection and escalation (US$1.9 million).
The financial and technology sectors recorded the highest average breach costs at US$10.67 million each, while the industrial sector followed at US$9.6 million.
IBM’s report also identified phishing as the leading initial access vector, accounting for 18 percent of breaches and carrying the highest average cost at US$10.41 million. Following a breach, 59 percent of organisations said they planned to increase cybersecurity investment, with identity and access management emerging as the top priority.






Discussion about this post