CYBERSECURITY | AI-powered cyberattacks seen as inevitable by many APAC firms

0

The findings are based on a broader global study of 2,500 IT security and IT decision-makers across nine countries, including Singapore and Australia, conducted in November and December 2025.

employees working

Artificial intelligence is expected to become a major cybersecurity threat for organizations across Asia-Pacific within the next year, according to new research that found many companies remain unprepared for attacks targeting employees through AI-enhanced social engineering.

Mimecast’s State of Human Risk 2026 study found that 65% of IT and security decision-makers surveyed in Singapore and Australia believe an AI-enabled cyberattack against their organization is inevitable within the next 12 months. Nearly four in five respondents, or 79%, said they are concerned about AI being used as an attack vector, while 60% acknowledged they are not fully prepared to defend against AI-driven threats that exploit human judgment.

The findings are based on a broader global study of 2,500 IT security and IT decision-makers across nine countries, including Singapore and Australia, conducted in November and December 2025. The survey covered organizations with more than 250 employees and at least 250 email users.

Beyond the Asia-Pacific findings, the report suggests that organizations increasingly view human behavior, rather than technology alone, as the primary cybersecurity challenge. According to Mimecast, insider threats, credential misuse and user-driven errors now account for most security incidents as attackers increasingly exploit people instead of technical vulnerabilities.

Respondents estimated experiencing an average of six insider-driven security incidents each month, with each incident costing an average of $13.1 million. The report projects that this translates to an annual exposure of about $943.2 million per organization.

The study found a gap between awareness and action. While 91% of organizations reported challenges in ensuring employee compliance with security policies and 96% acknowledged incomplete protection against cyber threats, only 28% said they combine regular security awareness training with continuous monitoring for policy violations.

Researchers identified five major cybersecurity challenges expected to shape 2026: the expanding attack surface across email and collaboration platforms, insider risk, fragmented security tool integration, governance shortcomings, and insufficient preparedness for AI-powered attacks.

Globally, 69% of respondents said AI-driven attacks against their organizations are inevitable within the next 12 months, yet only 40% reported being fully prepared with strategies to address them. Although 55% already use AI-powered tools for threat detection and real-time monitoring, fewer organizations have adopted complementary measures such as employee training and AI governance. Only 44% provide training to help employees recognize AI-enabled attacks, while 41% have established policies governing AI use.

Employees remain a significant point of exposure as cybercriminals increasingly use AI to generate convincing phishing emails, fraudulent messages and voice impersonations. In the Asia-Pacific survey, 66% of respondents said an employee in their organization would likely be deceived by an AI-assisted social engineering attack.

“AI is changing the way cybercriminals manipulate trust,” said Nicky Choo, vice president and general manager for APAC at Mimecast. “Attackers can now use it to create convincing, tailored messages that appear to come from a colleague, a partner or a senior leader, which means employees are being asked to make difficult decisions in real time. The challenge is no longer just stopping threats before they arrive. It’s helping people recognise when the interactions they rely on may have been manipulated.”

The research also found that AI-specific cybersecurity training remains limited. Only 40% of surveyed organizations provide training on the safe use of AI while avoiding exploitation, and 42% conduct simulated AI-driven phishing exercises to prepare employees for increasingly sophisticated attacks.

The report recommends that organizations adopt an integrated human risk management strategy that combines employee awareness, behavioral analytics, governance and AI-powered security technologies. Among its recommendations are securing email and collaboration platforms under a unified security framework, strengthening insider risk management, improving compliance automation, integrating security tools and preparing employees and systems for AI-driven threats.


Full disclosure: All news articles published on the TechSabado website are written by human journalists, unless otherwise specified. Final text editing is also performed by human editors, with artificial intelligence (AI) used only to assist with additional grammar and style guide corrections..


————————————————————————-
TEN YEARS OF TECHSABADO!


PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE & SPOTIFY channels.



WATCH TECHSABADO ON OUR YOUTUBE CHANNEL:




















WE ARE ALSO ON SPOTIFY



WATCH OUR OTHER YOUTUBE CHANNELS:




PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE CHANNEL.

roborter
by TechSabado.com editors
Tech News Website at  | Website

Leave a Reply

Your email address will not be published. Required fields are marked *