IBM just put a price on a problem SAP teams have carried for twenty years. It is sitting in your production system right now, and nobody has taken attendance since go-live.
The 2026 Cost of a Data Breach Report reads like a bill arriving for a decade of deferred maintenance.
Those numbers will get quoted in a hundred board decks this quarter. Alongside them, the finding that is driving the AI-governance conversation: AI-driven attacks rose 56% year over year, and among organizations reporting a security incident involving an AI model or application, 92% were missing basic access controls — role-based access, multifactor authentication, and the like — on those models and applications.
The industry read that and started bracing for a wave of ungoverned machine identities.
The non-human identity problem is not arriving. It has been in production since your last go-live, and it has a name you already use every day.
Open any large SAP landscape and count the identities that are not a person logging in:
RFC connection users wiring system to system · Batch and background job users running the nightly load · Technical, service, and communication users behind every interface · Integration accounts for middleware, Ariba, SuccessFactors, Fiori, third-party tools
These are non-human identities in every sense that matters. They act. They hold authorizations. They move data at machine speed. And most were created for a go-live in 2018, granted broad access “to be safe,” and never reviewed since. Passwords that do not expire. Wide profiles nobody dares to trim. Owners who left the company in 2022.
Industry estimates put non-human identities at roughly 50 to 1 against human ones in large enterprises. Whatever your exact ratio, the governance question is identical — and in SAP it is not a forecast. It is an inventory you already own.
Mean time to identify and contain rose to 247 days — reversing five consecutive years of improvement. Breaches running past the 200-day mark cost about a third more than those closed sooner.
Where a business partner becomes the attack path, IBM finds it adds more to the bill than any other factor measured — and those breaches take the longest to identify and contain.
And that share has grown two years running.
The dormant RFC user with SAP_ALL is the whole report in one object. It is a non-human identity. It has no owner. Its credential does not expire. Its traffic is indistinguishable from normal operations. It is on-premises. And it is frequently the account a third party was given during a project that ended four years ago. Every aggravating factor IBM measured, converging on one line in USR02.
One more, for anyone still arguing this is a technology purchase rather than a governance program: IBM ranks identity and access management second among all cost-reducing factors measured, behind only a DevSecOps approach. The control that pays is the one your team already knows how to run.
You cannot govern what you have not inventoried. The first concrete, do-it-this-quarter step is simple to say and rarely done.
Produce a complete inventory of every non-dialog and technical user in your SAP systems — and for each one, answer four questions: who owns it, what can it do, when was it last used, and does its access still match its job?
That single scan surfaces the ungoverned population: the dormant RFC user with SAP_ALL, the interface account nobody claims, the technical ID whose owner left in 2022. It turns an abstract ratio into a named list you can act on — expire, scope down, or retire.
Our SAP-native security practice has spent two decades on exactly this discipline. The four commitments we bring to AI agents apply one-for-one to the non-human identities already in your system.
No anonymous RFC or technical user. Each one carries a named accountable owner who is still employed.
The dormant-account door closed. Access that was granted for a project ends when the project does.
Machine-speed activity you can actually audit — what the identity did, not only what it was permitted to do.
Or it gets scoped down or retired. Entitlement is re-earned on a cycle, not inherited from a 2018 cutover.
There is a sequencing argument buried in this report, and it is the most useful thing in it.
Close to seven in ten breached organizations lack governance policies for managing AI or spotting unapproved use, and fewer than one in five coordinate their governance teams with their security teams at all. Meanwhile shadow AI — staff using unapproved tools — figured in 43% of security incidents, more than double the prior year's share.
The instinct is to answer that with a new AI governance program, a new platform, a new budget line.
The better move is to notice that the discipline you need already exists inside your SAP GRC practice — and that its first customer is the non-human population you already have. Inventory. Ownership. Expiry. Evidence. Prove the control plane works on the technical users sitting in production today, then extend it to agents as they arrive.
That order is cheaper, it is auditable now, and it does not depend on a technology you have not bought yet.
Count your non-dialog users. Ask who governs them. If the honest answer is “no one, and not since go-live,” you have found your share of IBM's $11.5M — and it is cleanable now, without waiting for the AI-agent future to arrive.
The breach report is a bill for a workforce nobody onboarded. In SAP, that workforce has been on the payroll for years.
| Claim | Source | Year | Status |
|---|---|---|---|
| Global average breach cost $4.99M, up 12%, record high | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| US average ≈ $11.5M, more than double global | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| AI-driven attacks up 56% year over year | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| 92% of orgs with an AI-related incident lacked RBAC / MFA-class controls on AI models and apps | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| Mean time to identify and contain rose to 247 days — first rise in five years | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| Breaches past 200 days cost ~⅓ more | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| Supply chain compromise adds more to breach cost than any other single factor | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| On-prem data in largest share of breaches by location, growing two years | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| IAM ranks second among cost-reducing factors, behind DevSecOps | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| ~7 in 10 breached orgs lack AI governance policies; <1 in 5 coordinate governance and security | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| Shadow AI present in 43% of security incidents, more than double prior year | IBM / Ponemon — Cost of a Data Breach | 2026 | VERIFIED |
| Non-human to human identity ratio ~50:1 in enterprise environments | Identity Defined Security Alliance — not IBM | 2026 | RE-SOURCED |
Sampling note. IBM and the Ponemon Institute studied roughly 602 organizations breached between March 2025 and February 2026. Figures describe organizations that suffered a breach — not all organizations. Cost figures exclude certain regulatory penalties. We publish this ledger because a governance argument that cannot show its own sources is just an opinion with a statistic attached. Every row carries its report year, because the single easiest way to get an annual benchmark wrong is to quote last year’s edition of it.