What happened
IBM's 2026 Cost of a Data Breach Report landed in July with a record global average of $4.99 million per breach. Three findings stand out for business owners.
First, AI is compressing attack timelines: 25% of malicious breaches now involve AI (up 56% year on year), and AI-assisted breaches average around $6 million — roughly $1 million more than conventional attacks. One documented case saw a full cloud breach cycle completed in 72 hours using AI agents for reconnaissance and exploitation. Second, detection still takes an average of 247 days. Third, 92% of organisations hit by AI-driven breaches had no proper access controls in place. Meanwhile, the Identity Theft Resource Center recorded more breach notifications in the first half of 2026 than in all of 2025.
Why it matters to your business
You might reasonably think a $4.99 million average reflects US enterprise costs — and it does. But the structure of the cost scales down identically: downtime, lost business, response costs, notification obligations and regulatory exposure. For a 20-person South African company, a proportionate incident is existential rather than expensive.
The 247-day detection gap is the quiet headline. Attackers who sit unnoticed for eight months don't just copy data — they position to encrypt it. The businesses that escape the worst outcomes are the ones with monitoring that shortens detection and backups that make extortion pointless.
What you should do
Close the access-control gap. MFA everywhere, least-privilege accounts, and monitored credentials.
Shorten detection. 24/7 device monitoring catches what annual reviews can't.
Make extortion worthless. Immutable, tested backups remove the attacker's leverage.
Budget against the alternative. A complete managed security bundle costs a rounding error compared to even a scaled-down breach.