Businesses report high cyber confidence but poor response: study
More than 90% of organisations in Singapore and Malaysia claim they can withstand a cyber breach.
A new study has revealed a stark disconnect between how ready businesses in Asia think they are for a cyberattack and how well they actually perform when one strikes.
Despite high confidence levels—more than 90% of organisations in Singapore and Malaysia claim they can withstand a cyber breach—only 27% of Singaporean and 37% of Malaysian enterprises were able to respond effectively. Alarmingly, 12% had no response plan at all, reacting with panic instead.
The findings come from Commvault’s latest report, The State of Data Readiness – Continuous Business in Focus, conducted by Tech Research Asia. The research highlighted a critical resilience gap across Asia, the most attacked region globally in 2024, according to IBM
Businesses are increasingly operating in complex digital environments. Data volumes in Asia grew by 40% in the last year, and 63% of companies now rely on hybrid or multi-cloud infrastructures. Yet, 38% say they lack full visibility into the relationships and dependencies within these systems—an essential capability for mounting an effective recovery.
This disconnect is costing companies dearly. Whilst 72% of business leaders expect to recover within five days of a cybersecurity event—and 23% expect to do so in just one day—the reality is much harsher. IT leaders report it takes at least three to four weeks to restore even basic operations.
Even with incident response plans in place (85% of organisations have one), few are adequately tested. Only 30% test all mission-critical workloads, leaving dangerous blind spots. The fallout has been significant: 83% of companies experienced data exfiltration, 50% lost access to all their data, and only 40% were able to recover everything.
Those with immature recovery capabilities were more than twice as likely to fail to recover all data and were 34% more likely to be completely locked out.
The compliance burden is also growing. Over half of organisations in Asia (52%) now face at least four different regulatory frameworks, and 10% admit they don’t even know what’s required to be compliant.
Additionally, 53% report facing conflicting requirements for cross-border data transfers, showing that regulatory risk is now intertwined with operational risk.