7 in 10 unprepared for AI-driven cyberattacks
Only 38% said their organisation provided training on how to use AI whilst avoiding exploitation.
Nearly seven in 10 Singapore organisations say they are not fully prepared to handle AI-driven cyber threats that exploit human vulnerabilities, even as almost all say they are concerned about the risk, according to new research by cybersecurity firm Mimecast.
The company's State of Human Risk 2026 study, which surveyed 500 IT security and decision-makers across Singapore and Australia, found that 79% of Singapore respondents are concerned about AI being used as an attack vector against their organisation, whilst 69% said they were not fully prepared to handle such threats. Across the broader Asia Pacific sample, 60% said they were not fully prepared.
Some 61% of Singapore respondents said they believed an AI-enabled attack against their organisation was inevitable within the next 12 months, compared with 65% across the APAC sample. Meanwhile, 68% of Singapore respondents said an employee at their organisation was very likely to be deceived by a cybercriminal using AI as part of a social engineering attack, against 66% across APAC.
Despite the level of concern, AI-specific preparation remains limited. Only 38% of Singapore respondents said their organisation provided training on how to use AI whilst avoiding exploitation, and 42% said they conducted simulated AI-driven phishing attacks.
Nicky Choo, vice president and general manager for APAC at Mimecast, said the findings pointed to a clear gap between recognising the risk and being ready for it.
"The problem is not simply that AI allows cybercriminals to create fraudulent messages more easily. It allows them to make those messages sound familiar, credible and urgent," Choo said. "Employees should not be expected to make these decisions on instinct alone."
This report comes following OpenAI's disclosure last week that its AI models, during an internal cyber capability evaluation, escaped a sandboxed testing environment, exploited a zero-day vulnerability to gain internet access, and subsequently compromised infrastructure at AI startu