267 views
Photo from Unsplash

AI-powered attacks double for over half of Singapore companies

Despite this rising threat landscape, most organisations are still operating with lean cyber teams.

More than half of organisations in Singapore (56%) say they’ve encountered AI-powered cyber threats in the past year—and many are seeing a steep rise in attack volume, according to new research released by Fortinet and IDC.

Among those affected, 52% reported a doubling of threat volume, whilst 42% said attacks tripled.

The report warned that these threats are growing harder to detect, as attackers exploit gaps in visibility, governance, and process to gain footholds, escalate privileges, and evade traditional defenses.

The findings point to a mounting burden on security teams, who now face more advanced attacks while grappling with limited staff and tools.

Despite this rising threat landscape, most organisations are still operating with lean cyber teams. Fewer than one in six have a standalone CISO, and only 6% maintain dedicated threat-hunting or security operations (SecOps) teams.

On average, just 13% of internal IT staff work in cybersecurity roles, leaving most teams stretched thin.

At the same time, AI is becoming central to defenders’ toolkits. The study found that 82% of organisations in Singapore already use AI in their cybersecurity operations, not just for threat detection but also for automated incident response, predictive threat modelling, behavioural analytics, and AI-driven threat intelligence.

Generative AI is being adopted for “light-touch” functions, such as writing detection rules, updating policies, and guiding investigations. Though fully autonomous remediation remains uncommon.

Whilst many are turning to AI for help, budget growth hasn’t kept pace with rising threats. 86% of surveyed organisations reported budget increases, but most of those were modest, with 68% seeing gains of less than 5%.

Over the next 12–18 months, key spending priorities include identity and network security, SASE/Zero Trust, cyber resilience, and cloud-native application protection (CNAPP).
 

Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

If you've been wondering whether SBR could work for your company — yes, probably.

A lot of the companies we partner with started as readers. They'd been following our coverage for a while, saw their own customers and competitors in it, and eventually asked the obvious question: could we do something with you? The answer is usually yes. The shape of it depends on what you're trying to do.


The options are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. Some partners use one channel; most use a mix. We figure out the right combination by starting with your brief, not with our rate card.


So if the question has been on your mind, here's the easy way to ask it.

We'll tell you honestly whether we can help, and how. It's a better use of everyone's time.