What makes a data breach more expensive in Latin America
The annual study by IBM and the Ponemon Institute records a rise in the average cost of breaches in its Latin American sample. Encryption, security automation and controls over AI are associated with lower costs.
Executive summary
The global average cost of a data breach reached USD 4.99 million in the 2026 study, an all-time high. In the Latin American sample, with organisations from Mexico, Argentina, Chile and Colombia, it rose 22% on the previous edition (own calculation).
Organisations in the region that make extensive use of AI and automation in security reported an average cost of USD 4.04 million, against 5.64 million for those that had not implemented them. Only 31% encrypted their sensitive data both at rest and in transit.
AI has also opened a new front. Worldwide, AI-related breaches rose from 13% to 21% of cases, and 92% of the organisations that suffered one lacked proper access controls for those tools.
In the region, almost one in five malicious attacks was AI-generated. Energy, technology and industrial companies had the highest average costs, above USD 5 million.
Context
The study by IBM and the Ponemon Institute has been published every year for more than two decades and includes a separate Latin American sample. It measures what organisations that have already suffered an incident pay, from detection to lost business.
For a company in the region, the useful part lies less in the average than in the factors that move it. Encryption, automation and AI governance are internal decisions that can be measured and prioritised.
Figure 1 · Average cost of a data breach by edition of the study
Table 1 · AI governance in organisations that suffered a breach
| Indicator, global sample | 2025 | 2026 |
|---|---|---|
| AI-related breaches | 13% | 21% |
| With an AI breach and no proper access controls | 97% | 92% |
| Without AI governance to manage it or detect unauthorised use | 63% | 68% |
| Average cost of breaches involving unauthorised AI, USD millions | 4.63 | 5.39 |
| Days to identify and contain a breach | 241 | 247 |
Business implications
Encrypt sensitive data at rest and in transit. It is still a minority practice in the regional sample, and a measure each company can verify on its own, system by system.
Control access to AI tools. Inventory which tools staff use, what data they may receive and who approves new ones. Breaches involving unauthorised AI cost more than the global average.
Rehearse the response against each country's legal deadlines. Identifying and containing a breach took more than eight months on average, while Peru requires notifying the authority within 48 hours and Chile without undue delay. The protocol has to be tested before the incident.
Methodology & data
IBM Cost of a Data Breach Report 2026, prepared by the Ponemon Institute with 602 organisations that suffered a breach between March 2025 and February 2026. The Latin American sample covers 28 organisations from Mexico, Argentina, Chile and Colombia; Brazil is reported separately. Changes between editions are own calculations.
These are averages for organisations that had breaches, not for all companies; IBM warns that the sample is not statistical.
References
IBM and Ponemon Institute (29 July 2026). Cost of a Data Breach Report 2026: The AI tipping point. · IBM Latin America (3 August 2026). Estudio de IBM: uno de cada cinco ataques maliciosos son habilitados por IA en América Latina. · IBM and Ponemon Institute (30 July 2025). Cost of a Data Breach Report 2025.