SINGAPORE, 29 AUG 2026 — IBM's annual breach-cost study puts the average cost of a data breach in Southeast Asia at a record US$4.12m, up 12 per cent on last year's US$3.67m. The regional figure is drawn from 26 organisations.
That is stated in the report and almost never in the coverage of it, and it changes what the number can be used for.
What 26 organisations can and cannot tell you
The ASEAN findings were based on 26 organisations studied between March 2025 and February 2026. Southeast Asia has a combined population above 680 million and several hundred thousand enterprises of the size that appears in a study like this.
A sample of 26 can indicate direction, and it cannot support a precise regional average. A 12 per cent year-on-year change is well inside the range composition alone would produce: a different mix of participating firms, or one large incident more or fewer, would move the figure.
The sector breakdowns are where this bites hardest. The figures for financial services (US$6.53m), industrial (US$5.99m) and communications (US$4.28m) are subsets of those 26 organisations, which means each rests on a handful of companies.
This is a criticism of the reporting, not the report
IBM discloses its sample size. The study is a survey of participating organisations rather than a census, it has never claimed otherwise, and the methodology is published.
What happens next is the problem. The regional figure enters circulation stripped of its denominator, gets cited in board papers and vendor decks as the cost of a breach in ASEAN, and by the third repetition it is a fact about the region rather than an average across 26 firms that agreed to participate.
We have watched a similar shape before, from the other direction, when an extortion group claimed 25 million records and 218,000 appeared. Large numbers travel; the qualifications do not.
The finding that survives the sample problem
One finding survives the small sample, because it is a comparison inside the same group rather than a projection out of it.
Organisations using AI and automation extensively in security operations recorded average breach costs of US$3.66m, against US$4.86m for those not using them, and identified and contained breaches 123 days faster. Both groups are drawn from the same small pool, so the composition effects that undermine the absolute figure largely cancel in the comparison.
A 123-day difference in detection and containment is also too large to be a statistical artefact. Unlike the headline average, it is the figure a regional security leader should be looking at.
Why regional samples are small in the first place
The reason the ASEAN sample holds only 26 firms is structural rather than sloppy.
Participation requires an organisation to admit it was breached, quantify the cost internally, and hand those figures to a researcher. In jurisdictions with mandatory disclosure and mature breach-notification regimes, a large pool of companies has already made the first admission publicly and the marginal cost of the other two is low. Across most of Southeast Asia that is not the position: notification obligations vary widely by country, several regimes are recent, and an admission carries commercial and regulatory consequences that have not been normalised.
The result is a sample skewed toward organisations mature enough to measure a breach properly and confident enough to disclose it, which is not a random draw from the region's enterprises. If anything that biases the average downward on cost and upward on capability, since the firms least able to detect an intrusion are also the ones least likely to appear in the study at all.
The AI-attack figure needs its own caution
Nearly three in ten ASEAN organisations suffering malicious breaches reported the attacks as AI-generated. That is a striking proportion and it is a self-assessment.
Determining that an attack used a generative model is difficult. A phishing message in fluent English with no spelling errors is consistent with an AI-drafted lure and equally consistent with a competent human writer, and few victims have the forensic basis to distinguish them. Attribution is also a factor. An organisation breached by a sophisticated AI-enabled adversary sounds better internally than one breached by an ordinary phishing email.
None of that means the finding is wrong. Regional reporting has independently found rising incident volumes across APAC, and AI-assisted phishing is well documented. It means three in ten measures what respondents believe, not what was forensically established.
What a better regional number would require
The gap this exposes is not IBM's to close. A dependable cost figure for Southeast Asia would have to come from the regulators who already receive breach notifications.
Singapore's Personal Data Protection Commission, Malaysia's Department of Personal Data Protection, the Philippines' National Privacy Commission and their counterparts each hold notification records that no vendor study can match for coverage, because reporting is compulsory rather than voluntary. None of them publishes an aggregate cost series, and several publish little beyond enforcement decisions.
That is a policy choice with a consequence. In the absence of a published regulatory baseline, the number that circulates in regional board papers is a vendor survey of 26 companies, and it circulates because it is the only figure on offer.
How to use this study properly
Take the comparisons and leave the levels. The AI-and-automation delta, the detection-time gap and the sector ordering are internally consistent and useful. The absolute dollar figures are indicative at best.
If you need a regional cost figure for a business case, build it from your own numbers: records held, regulatory exposure under the applicable regime, revenue per day of the systems that would go offline, and what your own last incident cost. That is a smaller and less quotable number, and it is about your organisation rather than about 26 others.
And when a vendor deck quotes US$4.12m as the cost of a breach in ASEAN, ask about the sample size. The report itself gives the answer.