Organisations cite BEC, phishing as top threats for 2025
The report found that 72% of organisations experienced an increase in BEC attempts
A sharp rise in business email compromise (BEC) and phishing attacks is putting Singapore’s corporate cybersecurity under growing pressure, according to the newly released Cybersecurity Assessment Report 2025 – Singapore.
The report found that 72% of organisations experienced an increase in BEC attempts, with more than half (52%) naming BEC and targeted phishing as the top cybercrime threats they face this year.
Other leading concerns include data breaches, disruption of critical operations, and financial theft—each cited by 48% of respondents—as well as supply chain vulnerabilities (40%).
Whilst 85.5% of organisations report greater confidence in their ability to respond to security incidents, the report raises red flags about underreporting. Among those that experienced breaches, three in four (75.7%) said they were instructed to keep the incident confidential, even when disclosure to authorities may have been warranted.
The top cybersecurity priority for 2025 is improving risk management and program maturity, identified by 36% of participants. This is followed by concerns around IoT and operational technology (33.5%), cyber-resilience (28.5%), and ransomware protection (26%).
The report also underscores mounting pressure on cybersecurity teams. 59% say the talent gap has worsened over the past year, and 64% report burnout from continuous threat monitoring—more than half are considering leaving their jobs within 12 months.
AI-related threats are emerging as a serious concern. 71% experienced cyberattacks involving AI, while 70% noted a rise in AI-enhanced attacks such as intelligent phishing and malware. Deepfakes, data leaks from large language models, and AI-generated malicious code are among the top risks flagged by respondents.
Cloud security also features prominently. 39% of organisations experienced a cloud breach in the past year—making it the most common incident reported—followed by BEC (37%), unauthorised access (32%), and ransomware (27.5%).