Skip to content
Predictive Systems
PSI Daily

The breach report that complicates the on-premise case

PrivacyRobert Voltaire Javier

IBM puts the average breach at $4.99 million, with AI-assisted incidents adding about a million on top. The finding worth sitting with: on-premises systems were breached more often than public, private or hybrid cloud.

IBM’s annual report puts the global average cost of a breach at $4.99 million. Incidents involving AI add roughly a million dollars to that. A quarter of malicious breaches now involve AI somewhere in the chain, up 56 per cent year on year.

The number that deserves more attention than it will get: on-premises systems were breached more often than public cloud, private cloud or hybrid environments, and most of the victims had not encrypted the data.

That cuts against the reflex that keeping data in the building keeps it safe. It does not. On-premise removes one category of risk, the third party you cannot audit, and hands you another, the infrastructure you now have to defend yourself. A server in your own rack is only as protected as the team maintaining it.

We deploy on-premise because some clients cannot legally do anything else, and because privileged material should not cross a boundary it does not need to cross. Neither of those is a security guarantee, and a vendor who sells on-premise as one is selling the wrong thing. Encryption at rest, access control and audit trails are what make it defensible. The location is the constraint, not the answer.

Source: IBM Cost of a Data Breach Report 2026