Organizations across ASEAN faced an average data breach cost of US$4.12 million in 2026, the highest level recorded, according to IBM’s 2026 Cost of a Data Breach Report. The findings highlight growing operational and financial pressure as attackers increasingly use AI-enabled tactics and exploit complex digital environments. Nearly three in ten ASEAN organizations that experienced malicious breaches reported the attacks were AI-generated.
Organizations with extensive use of AI and security automation reported lower average breach costs of US$3.66 million, compared to US$4.86 million among those with no use of these tools. They also identified and contained breaches 123 days faster.
“As AI continues to lower the cost and increase the speed of cyberattacks, organizations across ASEAN are facing longer breach investigations and growing financial consequences,” said Catherine Lian, General Manager, IBM ASEAN. “The report findings underscore the value of AI and automation in cybersecurity. Organizations that have integrated these technologies into their security operations are containing breaches faster and reducing associated costs, at a time when critical infrastructure sectors face unprecedented levels of risk and pressure.”
Critical Infrastructure Faces Higher AI-Driven Risk
Financial services organizations reported the region’s highest average breach costs at US$6.53 million, followed by industrial organizations at US$5.99 million and communications organizations at US$4.28 million, reflecting heightened cyber risk across critical infrastructure sectors.
Frontier AI Threats Driving Earlier Action
In ASEAN, 71% of organizations said they planned to increase investments in security tools and governance following a breach. Globally, separate research by Ponemon Institute found that 85% of organizations aware of advanced frontier AI cyber capabilities planned to increase security spending. This shows that organizations are starting to act on future risk, rather than waiting for an incident.
Other Key Findings
- Identity-Based Attacks Remain Costly. Abusing valid accounts was one of the costliest initial attack vectors in ASEAN, with breach costs averaging more than US$4.5 million.
- Encryption Gaps Persist as Quantum Risk Looms. Core weaknesses in encryption and cryptographic management also persisted. Only 29% of organizations said sensitive data was encrypted both at rest and in transit at the time of the breach.
- Security Testing and Automation Help Reduce Costs. Organizations that invested in offensive security testing, security orchestration and automation, and key lifecycle management reported some of the largest reductions in breach-related costs.
The 2026 Cost of a Data Breach Report is by Ponemon Institute and sponsored and analyzed by IBM. The ASEAN findings are based on data from 26 organizations studied between March 2025 and February 2026. The follow-on study was conducted in May 2026, where 456 organizations of the 602 from the CODB research responded. Of these organizations, 78% or 356 of organizations were aware of recent reports about highly advanced frontier models such as Mythos.






















































































