Skip to content

AI NewsPublished 6 min read

Gartner Forecasts $244B; Breach Costs to Weigh

data streams converging into a single bright signal
Listen to this article · 10:00 · AI-generated narration
0:00 / 10:00
Chapters

Gartner's projection puts 2026 spending at $244 billion

Followict reported on September 22, 2026, that Gartner expects worldwide information security spending to reach approximately $244 billion in 2026, up from around $213 billion in 2025. Gartner's projections put global information security expenditure on track to reach that total, Martincid reported the same day.

AI-related breaches have surged 89% year over year and cloud intrusions are up 37%, Martincid reported. Expanded attack surfaces and more capable adversarial tooling produced that AI-fueled increase, according to Martincid. Demand for security products keeps rising amid growing threats and the expanding use of artificial intelligence, Followict said.

The short version

Followict reported that Gartner expects worldwide information security spending to reach approximately $244 billion in 2026. Martincid reported that AI-related breaches have surged 89% year over year and cloud intrusions are up 37%. Infotechlead reported a record global average breach cost of $4.99 million, drawn from IBM and Ponemon Institute research on 602 breached organizations.

  • Gartner expects worldwide security spending of about $322 billion by 2029, up from around $213 billion in 2025, Followict reported.
  • Verizon's 2026 Data Breach Investigations Report put software vulnerability exploitation first among initial entry points, at 31% of breaches, Followict reported.
  • AI-enabled malicious breaches cost organizations roughly $6 million on average, Infotechlead reported.
  • Fortinet's second-quarter 2026 materials size the AI security opportunity at $172 billion, The Globe and Mail reported.
  • Researchers used Anthropic's Claude technology against OpenAI's ChatGPT systems in a bug-hunting program, Nai500 reported.

IBM and Ponemon record a $4.99 million average breach

Infotechlead reported on September 22, 2026, that the global average cost of a data breach reached a record $4.99 million in 2026, a 12% increase. IBM and the Ponemon Institute studied 602 organizations affected by breaches between March 2025 and February 2026, Infotechlead said, describing the result as a global benchmark. Detection and escalation plus lost business accounted for 63% of total breach costs, according to Infotechlead.

IBM found that one in four malicious breaches was AI-enabled, a 56% increase from the previous year, Infotechlead reported. AI-enabled breaches cost affected organizations an average of $6 million, about $1 million more than the overall global figure, Infotechlead said. AI-enabled malware and deepfake impersonation were major attack methods in that group, the same Infotechlead report said.

Companies making extensive use of AI-driven security automation saved nearly $2 million per incident, Infotechlead reported. IBM's annual security research puts the average cost of a corporate data breach at $5 million per incident, Martincid reported.

Verizon's DBIR ranks vulnerability exploitation first

Verizon's 2026 Data Breach Investigations Report found that software vulnerability exploitation became the most common initial entry point in data breaches for the first time, accounting for 31% of breaches, Followict reported. Exploitation of software vulnerabilities has overtaken stolen credentials as the leading way attackers gain access to organizations, Nai500 reported on September 19, 2026.

The Verizon report also found that AI is accelerating exploitation of known vulnerabilities, shrinking the window between discovery and exploitation from months to hours, according to Followict. Breaches involving third parties increased by 60%, reaching 48% of all breaches analyzed, Followict said.

Researchers used Anthropic's Claude technology to break into OpenAI's ChatGPT systems as part of a bug-hunting program, Nai500 reported. Nai500 described that case as the latest in a string of AI-aided breaches facing organizations worldwide.

Security vendors pitch platforms against those numbers

CrowdStrike anchored its model at the endpoint, covering devices and identities, and expanded outward through 33 cloud modules spanning threat intelligence, identity protection, and log management, Martincid reported. Fortinet began at the network perimeter and extended into cloud, operations technology, and AI capabilities, Martincid said. Palo Alto Networks combines network, cloud, identity, and AI security into a single converged suite positioned as the consolidation choice for CIOs rationalizing vendor count, according to Martincid.

The Globe and Mail reported on September 22, 2026, that Fortinet's second-quarter presentation identifies a $148 billion 2029 SASE Firewall total addressable market with a 13% compound annual growth rate from 2025 to 2029. Fortinet's materials size AI security as a $172 billion opportunity, The Globe and Mail said.

A cloud provider selected Fortinet to secure generative-AI data centers in an eight-figure deal, and a global pharmaceutical company signed a seven-figure FortiSASE deal covering more than 45K users, The Globe and Mail reported. FortiSASE billings grew more than 100% in the second quarter of 2026 and free cash flow reached $966 million, according to The Globe and Mail. Fortinet is deepening its AI-security ecosystem through collaborations with Intel, Anthropic, OpenAI and NVIDIA, The Globe and Mail said.

Tron's take

My read is that the headline spending forecast is a market size, not a budget instruction for a small or mid-sized company. Infotechlead described the IBM and Ponemon figures as a global benchmark, and I treat that average as context for pricing risk rather than as a prediction for any single business. That is my reading of the news, not a reported result.

The parts of this news I would act on are the entry-point findings, not the vendor comparisons. Verizon's ranking of software vulnerability exploitation ahead of stolen credentials, plus its finding that AI compresses the gap between disclosure and exploitation, argues for boring work that was already proven last quarter: an inventory of internet-facing systems, a patch cadence measured in days, and multifactor authentication on remote access. The third-party share of breaches in the same Verizon report is an argument for knowing which vendors hold your data and what their notification terms say.

IBM's savings figure for organizations using AI-driven security automation is a reason to look at detection tooling, but Infotechlead reports it as an average across a global sample, and I would not assume the same per-incident result at a 60-person firm. The platform consolidation stories from CrowdStrike, Fortinet, and Palo Alto Networks are enterprise procurement narratives, and I would not treat them as a buying signal this week.

XL.net sells managed IT, security assessments, and incident response, so my advice to test your patch cadence points at work we are paid to do. We covered IBM's earlier breach-cost research in IBM: AI-Enabled Breaches Push Average Costs and the shrinking exploitation window in CrowdStrike: AI Weaponizes Bugs, Buffer Shrinks.

Questions I'd expect

What is Gartner's projection for 2026 security spending?

Gartner expects approximately $244 billion in worldwide information security spending in 2026, Followict reported, continuing to about $322 billion by 2029.

How much does the average data breach cost in 2026?

Infotechlead reported that IBM and the Ponemon Institute measured a record global average of $4.99 million per breach in 2026, a 12% increase, based on 602 organizations breached between March 2025 and February 2026.

How are attackers most often getting in?

Verizon's 2026 Data Breach Investigations Report found software vulnerability exploitation is the most common initial entry point, at 31% of breaches, Followict reported. Nai500 reported the same shift, noting exploitation has overtaken stolen credentials.

Does security automation reduce breach costs?

Companies making extensive use of AI-driven security automation are saving nearly $2 million per incident, Infotechlead reported on September 22, 2026, citing IBM's research on breached organizations.

All AI news