Organizations across ASEAN paid an average of $4.12 million for a data breach in 2026, the highest amount recorded, according to IBM’s 2026 Cost of a Data Breach Report.
Almost three in 10 ASEAN organizations hit by malicious breaches said the attacks were generated using artificial intelligence (AI). The findings show how AI is helping cybercriminals launch attacks faster while companies struggle with increasingly complex IT systems.
Financial services firms recorded the highest average breach cost in the region at $6.53 million. Industrial organizations followed at $5.99 million, while communications companies averaged $4.28 million. These sectors provide essential services, making disruptions particularly costly to businesses and customers.
“As AI continues to lower the cost and increase the speed of cyberattacks, organizations across ASEAN are facing longer breach investigations and growing financial consequences,” said Catherine Lian, general manager, IBM ASEAN.
The 2026 Cost of a Data Breach Report was conducted by the Ponemon Institute and sponsored and analyzed by IBM. The ASEAN results were based on 26 organizations studied from March 2025 to February 2026. A follow-up study conducted in May covered 456 organizations worldwide.
Lian noted that the report findings underscore the value of AI and automation in cybersecurity. She said that organizations that have integrated these technologies into their security operations are containing breaches faster and reducing associated costs, at a time when critical infrastructure sectors face unprecedented levels of risk and pressure.
IBM found that organizations making extensive use of AI and security automation limited their average breach costs to $3.66 million. Those that did not use these tools spent an average of $4.86 million.
AI and automation also helped organizations find and contain breaches 123 days faster. Quicker detection can reduce business interruptions, recovery expenses, and the amount of data exposed.
Attacks involving stolen or compromised accounts remained among the most expensive entry points, with average costs exceeding $4.5 million. Encryption was another weak spot: Only 29% of affected organizations said their sensitive data was encrypted both when stored and while being transmitted.
Organizations that used offensive security testing, automated security operations, and stronger encryption-key management reported some of the biggest reductions in breach costs.
Following a breach, 71% of ASEAN organizations said they planned to spend more on security tools and governance. Separate global research by the Ponemon Institute found that 85% of organizations familiar with advanced AI cyber capabilities intended to increase security spending.