Singapore
Breadcrumb navigation

Cybersecurity Threats Doubled: How APAC Businesses Can Stay Secure
Digital transformation is accelerating across Asia Pacific, but with greater use of technology comes greater risk.
Consumer scams are surging, leading to significant losses. In Singapore alone, over S$456 million was lost in the first six months of 2025, with 20,000 cases reported. Approximately 1,000 of those incurred losses of S$100,000 or more.
As for businesses, ransomware now accounts for more than half of all data breaches in the region. Some enterprising criminal groups even offer ransomware-as-a-service, providing others access to their hacking tools for a fee.
For corporate IT departments, the challenge is complicated by hybrid working patterns, which make corporate networks more complex, and supercharged by the proliferation of cheap and even free AI tools which dramatically lower the cost of entry for hackers and other bad actors.
Southeast Asia in the Spotlight
Cyberattacks are rising steeply around the world. Organisations in APAC face the
second highest number of weekly attacks, behind only Africa. In the last four years alone, the average number of weekly attacks targeting businesses and other organisations has doubled, according to the World Economic Forum’s
Global Cybersecurity Outlook 2025Businesses are under threat too, with organisations in the Asia Pacific region now facing the second highest number of weekly attacks, behind only Africa.
Defence relies on individuals as well as IT teams to be aware of potential threats. Unfortunately these are becoming harder to detect, particularly as AI makes generating content faster and effectively free. Just a few years ago, scam emails were relatively easy to spot, with broken English and unlikely claims of long-lost relatives bequeathing huge fortunes.
But thousands of convincing emails can now be produced in seconds with no coding knowledge thanks to freely available AI tools. And police in Malaysia
warned in December that just a few seconds of audio can be enough to clone a person’s voice for use in deepfakes.
Nor is it just individuals who are at risk. Companies have hired remote workers who later turn out to be bad actors,
even North Korean cyber criminals.
With technology causing an exponential increase in both the quality and quantity of phishing and deepfakes, while simultaneously lowering the barrier to entry for would-be cyber criminals, what can companies do to protect themselves?
Managed Security

Senior Consultant Cyber Security at NEC APAC
NEC offers a managed security service though its Advanced Response Centres in Singapore and Malaysia. Clients’ networks are monitored 24-7, providing proactive threat detection, rapid response, and ongoing protection.
Much has been made of the increased capabilities that AI grants to attackers, but AI also has tremendous potential to streamline cybersecurity, dealing with lower level threats autonomously and leaving human operators free to focus on higher level issues.
“Traditionally you would get many alerts and an analyst needs to look at them one by one,” says Masaki Kawamichi, Senior Consultant Cyber Security at NEC APAC. “That’s very time consuming, and it also means that it’s easier to miss something with the potential for a big impact. So we’re bringing in automation to free up analysts to focus on the right areas.”
AI-powered security tools can analyse vast amounts of data and identify suspicious activity that might escape human notice - detecting unusual login patterns, flagging anomalous network behaviour, or spotting the signatures of known malware.
However, Kawamichi cautions against over-reliance on technology. "Attackers are using AI, too. They're constantly developing new techniques designed to evade detection. It's an arms race."
And crucially, even the most sophisticated attacks typically begin with a human target - a convincing phishing email or a deepfake voice call designed to exploit trust. That’s where regular training becomes vital. NEC works with companies and government bodies across the region to train staff on cybersecurity, and how to be vigilant against potential threats.
With attackers using AI to generate flawless phishing emails and convincing deepfakes, Kawamichi stresses that the human element remains the critical vulnerability. "Yes, we need sophisticated tools to detect and respond to threats. But no matter how good our technology is, attackers will always try to exploit human trust. Employees need to understand this, and that understanding has to be reinforced regularly, not just once a year."
The Challenge of Hybrid Working

The challenge is exacerbated by remote working. Before the pandemic the vast majority of those accessing a company network were using company-issued devices from a company-controlled location such as an office or factory. There would likely also be some sort of physical security preventing unauthorised people from entering the premises, while devices would be behind a company firewall.
Today, IT has to deal with people using a much wider range of devices from multiple locations, ranging from the company’s secure office to the free Wi-Fi at a local coffeeshop.
"Ideally, companies should be moving toward a zero-trust architecture," says Kawamichi. "But we're seeing many small and medium businesses suffer breaches simply because they haven't applied the latest security patches to their VPNs.
“Before thinking about zero trust, these fundamentals need to be in place. Multifactor authentication and keeping your VPN software updated are simple steps, but they're surprisingly effective. Once those basics are covered, I'd strongly recommend planning a transition to zero trust, given the sophistication of today's threats."
Companies should also recognise that even the best cybersecurity can never be 100% effective, and plan accordingly, including by backing up their data.
“Backups should be offsite, and ideally offline,” says Kawamichi. “There’s no point in having a backup that’s on the same corporate environment. How are you going to restore a backup if that’s been encrypted by a hacker too?”
Creating What’s Ahead
Cybersecurity risks are only likely to increase in the future as AI tools continue to make hacking, scams and other attacks easier to carry out. The good news, says Kawamichi, is that with proper prevention in place, those risks can be mitigated.
“We can never afford to be complacent, but with the right combination of technology, policies and training, companies are in a strong position to mitigate whatever threats they may face, enabling them to focus on their core business and creating what’s ahead.”