AI-powered attacks double for over half of Singapore companies
Despite this rising threat landscape, most organisations are still operating with lean cyber teams.
More than half of organisations in Singapore (56%) say they’ve encountered AI-powered cyber threats in the past year—and many are seeing a steep rise in attack volume, according to new research released by Fortinet and IDC.
Among those affected, 52% reported a doubling of threat volume, whilst 42% said attacks tripled.
The report warned that these threats are growing harder to detect, as attackers exploit gaps in visibility, governance, and process to gain footholds, escalate privileges, and evade traditional defenses.
The findings point to a mounting burden on security teams, who now face more advanced attacks while grappling with limited staff and tools.
Despite this rising threat landscape, most organisations are still operating with lean cyber teams. Fewer than one in six have a standalone CISO, and only 6% maintain dedicated threat-hunting or security operations (SecOps) teams.
On average, just 13% of internal IT staff work in cybersecurity roles, leaving most teams stretched thin.
At the same time, AI is becoming central to defenders’ toolkits. The study found that 82% of organisations in Singapore already use AI in their cybersecurity operations, not just for threat detection but also for automated incident response, predictive threat modelling, behavioural analytics, and AI-driven threat intelligence.
Generative AI is being adopted for “light-touch” functions, such as writing detection rules, updating policies, and guiding investigations. Though fully autonomous remediation remains uncommon.
Whilst many are turning to AI for help, budget growth hasn’t kept pace with rising threats. 86% of surveyed organisations reported budget increases, but most of those were modest, with 68% seeing gains of less than 5%.
Over the next 12–18 months, key spending priorities include identity and network security, SASE/Zero Trust, cyber resilience, and cloud-native application protection (CNAPP).