Image: Getty Images
IBM has unveiled its 2025 edition of the Cost of a Data Breach Report, which indicates a decrease in the average cost of data breaches in the Middle East to $7.29 million (SAR 27 million). This represents a significant 18% reduction from the previous year’s average of $8.86 million (SAR 32.80 million). The report attributes this decline primarily to enhanced use of AI and machine learning insights, robust encryption methods, and the implementation of a DevSecOps strategy.
Lost business continues to be the largest factor contributing to breach-related expenses in the region, averaging $3.14 million (SAR 11.63 million) per incident. Following this, the costs for post-breach responses were $2.03 million (SAR 7.50 million), detection and escalation expenses were $1.77 million (SAR 6.55 million), and notification costs stood at $356,400 (SAR 1.32 million).
The financial services sector experienced the highest breach costs in 2025, totaling $9.18 million (SAR 34 million), closely followed by the energy and industrial sectors at $8.64 million (SAR 32 million). These data underscore the ongoing financial risks organizations encounter throughout the entire breach lifecycle.
“The noticeable reduction in data breach costs across the Middle East is encouraging. It’s no coincidence that as some of the world’s most ambitious AI initiatives are taking shape in this region, breach costs are also decreasing. Organizations are advancing their adoption of AI-powered security tools, improving their capability to identify and manage threats proactively. However, as cybercriminals become increasingly sophisticated, continuous investment in AI security technologies, skilled personnel, and governance frameworks will be crucial to maintaining this positive trend,” stated Saad Toma, general manager of IBM Middle East and Africa.
According to the report, 41% of respondents from organizations in the Middle East have put access controls on AI systems to reduce the risks associated with AI model attacks, compared to a mere 3% on a global scale. This highlights a forward-thinking approach to AI security and governance within the region.
AI governance initiatives are also becoming more prevalent, with 38% of organizations having established policies, and another 24% in the process of developing them. Among those with formal governance in place, common practices include rigorous approval protocols for AI utilization (45%), adversarial testing (44%), and the usage of AI governance technologies (43%).
On the cost front, organizations managing complex security frameworks witnessed an average increase of $234,200 (SAR 867,378) in breach-related expenses. Breaches concerning IoT or operational technology systems added an additional $226,730 (SAR 839,750), while staffing shortages in cybersecurity contributed an extra $221,130 (SAR 818,997) per incident.
Compromises involving third-party vendors and supply chains emerged as the leading initial breach method, responsible for 17% of incidents with an average cost of $7.99 million (SAR 29.60 million). Denial-of-service and phishing attacks each constituted 14% of cases, incurring costs of approximately $7.34 million (SAR 27.20 million) and $7.56 million (SAR 28 million), respectively. Malicious insider attacks, though less frequent at 11%, resulted in the highest average costs at $8.91 million (SAR 33 million).
The 2025 Cost of a Data Breach Report is based on the analysis of over 600 breaches globally, including data from organizations in Saudi Arabia and the UAE, occurring between March 2024 and February 2025. This study, conducted by the Ponemon Institute and supported by IBM, draws on more than 20 years of research and data from nearly 6,500 real-world breach incidents.