Breaches at Machine Speed: a Canadian Read on IBM’s 2026 Cost of a Data Breach Report

Breaches at Machine Speed: A Canadian Read on IBM’s 2026 Cost of a Data Breach Report

IBM has just released its Cost of a Data Breach Report 2026, subtitled “The AI tipping point.” The story in the numbers is one every security team will recognize: attackers are moving faster, and their victims are paying more.

In Canada, the picture is worse than the global average. The average breach now runs $5.20 million (all figures USD), up from $4.84 million last year. That is the fourth-highest of any country or region in the study, and well above the $4.99 million global figure. The findings behind the numbers are worth a closer look: here are some of the key takeaways from the report, and what to do about each one.

Woman at a desk looking at a computer stressed

Getting Breached in Canada Carries a Rising Price

Two categories did most of the financial damage: detection and escalation, and lost business. Together, they made up 63% of the total and cover everything from crisis management to customers walking away. For the fourth year in a row, phishing held the top spot among initial attack vectors. While email phishing is still a risk, it was voice and SMS phishing that carried the highest average cost of any vector at $5.29 million.

Reducing the risks presented by phishing comes down to two things: people who do not click, and a team that moves quickly once someone gets in. Security awareness, regular phishing simulations, and offensive testing handle the first. They show you where an attacker would actually get through, before one does. Fast and efficient incident response handles the second, and IBM’s own figures make the case: organizations whose internal teams caught the breach themselves closed it out 15% faster than the global average.

AI Is Working for the Attackers, and It Can Work for You

AI-driven attacks jumped 56% over last year and added about $1 million to the average breach, with deepfake impersonation and AI-generated malware behind most of the volume. The good news is that AI technology is helping the defenders too. Organizations that used AI and automation heavily paid $1.93 million less per breach and found and contained incidents 65 days sooner than those that did not.

The problem is that not enough of them are doing it. Just 36% use these tools across the full breadth of their security operations. And of the teams already running AI agents in their SOC, only 18% have pointed them at vulnerability scanning, which is exactly where frontier AI is being used to hunt for weaknesses. AI-driven detection and response lets a smaller team watch more and react faster, and automating vulnerability management means you find the holes before an attacker does. This is the heart of what ISA Cybersecurity does across detection, response, and assurance.

The best practices we've known for years work - the limit is how much ground a human team can cover in a day. Automation and AI raise that ceiling, and the effect shows up fastest in detection, triage, and vulnerability management. Same people, more coverage, shorter time to detect, contain, and respond."

Andrew Buckles, Executive Vice-President, Services ISA Cybersecurity

You Can’t Secure the AI You Can’t See

The report is blunt on one point in particular. Of the organizations that suffered an AI-related breach, 92% had no proper access controls on their AI, meaning no role-based access and no multifactor authentication (MFA). And the trouble usually was not the model. IBM lays the blame on “weaknesses in surrounding systems”: exposed APIs, cloud misconfigurations, and connected applications. That is a governance failure, which is both frustrating and reassuring, because it is fixable.

Shadow AI makes it harder. When employees use tools nobody signed off on, security cannot protect what it does not know is there. Those incidents more than doubled this year, from 20% to 43%, at an average cost of USD 5.39 million. Finding where AI is actually running, putting access controls around the models and the data they touch, and backing that with real policy is the work of ISA Cybersecurity’s AI 360 practice, built on the same discipline as the rest of our security programs.

“Governance for AI requires many best practices familiar to cybersecurity teams. Digital systems already go through formal onboarding processes or change processes. An owner is named and accountable, a risk assessment is performed, risk decisions are made then controls are right sized. AI is no different and is often embedded into existing systems. These systems leveraging AI still have owners, still need risk dimensions assessed (including model-specific risks), and potentially new or modified controls to mitigate the identified risks.”
Andrew Buckles, Executive Vice-President, Services ISA Cybersecurity

The Fundamentals Still Decide Who Recovers

For all the deserved attention AI gets, some of the biggest gaps are old and familiar. More than half of the breached organizations (53%) were not encrypting sensitive data at rest and in motion when they were hit. Encryption is one of the surer ways to take the sting out of a breach, and most of the companies in this study simply were not using it.

Ransomware is still a major concern: it hit 39% of breached organizations, but the pressure tactics have shifted. The most common one now is reputational, with 41% of ransomware attacks involving threats to leak stolen data and shame the victim publicly, well ahead of the 23% that still leaned on encrypting systems. Holding that off takes two things: encryption and solid configuration on the engineering side, and an incident response and recovery plan you have actually tested for the day something slips through. Both are key parts of what ISA Cybersecurity does across engineering and response.

Professionals in an office collaborating happily

The Common Thread Is Speed

If there is one thread running through the whole 2026 report, it is speed. The window between finding a weakness and exploiting it keeps getting shorter, and the longer a breach goes unresolved, the more it costs. The organizations that come through this best are the ones treating governance, testing, engineering, detection, and response as parts of the same job, and getting on with it before an incident makes the decision for them.

ISA Cybersecurity helps Canadian organizations put those pieces in place. To talk through what the 2026 findings mean for your environment and where to act first, contact ISA Cybersecurity for insights and solutions across our Cyber 360 and AI 360 practices.

NEWSLETTER

Get exclusively curated cyber insights and news in your inbox

Contact Us Today

SUBSCRIBE

Get monthly proprietary, curated updates on the latest cyber news.