Canada CRE News In Your Inbox.
Sign up for Connect emails to stay informed with CRE stories that are 150 words or less.

Canadian Data Breach Costs Hit Record High of $7.1M on Average
The average cost of a data breach in Canada has reached a record $7.1 million, driven by larger attacks, longer recovery times and increasing cyber threats targeting critical infrastructure, says IBM.
The company’s 2026 Cost of a Data Breach Report found the average breach cost climbed to its highest level since the study began. The average number of compromised records increased 8% year over year to 28,500, while the average breach lifecycle rose 6% to 205 days.
The energy sector became Canada’s most expensive industry for cyber breaches, with an average cost of $9.21 million per incident. Technology organizations followed at approximately $9 million, while industrial organizations averaged about $8.9 million.
“The shift we’re seeing is significant. Attackers are increasingly targeting sectors where disruption creates real operational and economic consequences, while also looking for the weakest link in the supply chain,” said Chris Sicard, IBM Canada’s security leader. “When breaches affect energy, industrial and technology organizations, the impact can extend far beyond the organization itself. Every connected supplier, partner, and third-party platform expands the attack surface.”
The report identified supply-chain compromise as the largest driver of higher breach costs in Canada, adding an average of approximately $367,900 per incident. Security skills shortages and difficulties prioritizing threats were the next-largest cost drivers.
IBM said organizations that extensively deployed artificial intelligence (AI) and security automation recorded average breach costs of $5.5 million, compared with approximately $8.9 million for organizations without AI deployment, a difference of about $3.4 million. Those organizations also detected and contained breaches more quickly.
“The organizations gaining the biggest security advantage are the ones using AI and automation extensively across their operations,” said Sicard. “They’re finding threats sooner, responding faster and reducing the financial impact of breaches by millions of dollars.”
The report also found that 28% of Canadian organizations experienced an AI-generated attack, highlighting the growing use of AI-powered techniques by cybercriminals.
The report, conducted by the Ponemon Institute and sponsored and analyzed by IBM, examined breaches experienced by 602 organizations worldwide between March 2025 and February 2026.
