Cyber visibility gaps leave Singapore firms exposed
Organisations are adding security tools, but fragmented environments, weak governance and slow AI adoption are giving attackers more time inside networks.
Singapore organisations are expanding their cybersecurity stacks, but adding tools is not improving their ability to detect attacks before data is stolen, according to ExtraHop and Gartner.
ExtraHop found that 47% of organisations in Singapore discover breaches only after attackers have exfiltrated corporate data, indicating that security spending has not closed widening visibility gaps.
Darren Chen, Sales Engineering Manager at ExtraHop, said organisations continue to invest in point products that operate independently instead of providing a unified view of network activity.
“Singapore is spending more on tools rather than visibilities,” Chen said.
He said disconnected platforms make it harder to spot malicious behaviour as attackers use encrypted communications, stolen credentials and legitimate workflows to blend into operations. One in six respondents only discovered an attack after receiving a ransom note.
Niyati Daftary, Principal Analyst at Gartner, said organisations manage 40 to 45 cybersecurity tools across different environments, creating fragmented visibility that attackers can exploit.
She added that companies remain focused on perimeter security whilst security posture management remains underdeveloped. Roughly 40% of security alerts are closed or bypassed without detailed investigation because teams lack capacity.
“I feel governance is something which, if prioritised, the remaining two will absolutely align,” Daftary said.
Chen said technology, staffing and governance all contribute to alert fatigue, but argued that poor data quality is the root problem. ExtraHop found that 28% of Singapore respondents cited alert fatigue.
Daftary and Chen said artificial intelligence will strengthen cyber defence, but attackers are benefiting first.
Daftary said 23% of organisations have piloted AI security operations agents and 18% have deployed them. Chen added that 85% had linked security incidents to AI systems, whilst 30% said AI generated more false positives and delayed investigations.
He warned that deploying AI before fixing visibility and data quality risks worsening the problem.
Commentary
Can controlled sandboxes prepare Singapore organisations for production AI?
What the latest sanctions regimes mean for Singapore businesses
Singapore’s tourism economy depends on security infrastructure most never see
Where does value creation really happen?
Managing the cost of diverging standards: Why Singapore matters
Singapore’s AI ambition has an intelligence problem
Singapore is deploying AI at speed – and security risks are catching up
Precious metal boom is a stress test for Singapore’s gold ambitions
Singapore’s global dispute fault lines
‘Tokenmaxxing’ – The wrong AI race to run in Singapore