The voice of the ASEAN people

INSIDE·ASEAN

Connecting ASEAN with the World

ASEAN

AI-Driven Cyber Threats Surge in ASEAN, Report Reveals

A recent study highlights the increasing prevalence of AI-generated cyberattacks across ASEAN, with significant financial implications for organizations.

By Paolo Mercado16 August 20262 min read
AI-Driven Cyber Threats Surge in ASEAN, Report Reveals

According to IBM’s 2026 Cost of a Data Breach Report, organizations in the ASEAN region are grappling with unprecedented cyber threats, with nearly three in ten reporting experiences of AI-generated malicious breaches. The average cost of a data breach in the region is $4.12 million, marking the highest level recorded to date. This alarming trend underscores the operational and financial pressures organizations face as cybercriminals increasingly leverage AI technologies to exploit complex digital environments.

Catherine Lian, general manager of IBM ASEAN, emphasized the critical role of AI and automation in cybersecurity, stating that the report findings underscore the value of AI and automation in cybersecurity. She noted that organizations that have integrated these technologies into their security operations are containing breaches faster and reducing associated costs at a time of unprecedented levels of cyber challenges and pressure. Organizations that use AI and security automation extensively reported average breach costs of $3.66 million, compared to $4.86 million among those without such tools. Furthermore, they were able to identify and contain breaches 123 days faster.

The financial services sector emerged as the most vulnerable, with breach costs averaging $6.53 million, followed by industrial organizations at $5.99 million and communications firms at $4.28 million. This trend reflects heightened cyber risks across critical infrastructure sectors, highlighting the need for robust cybersecurity measures.

Following a breach, 71 percent of organizations indicated plans to increase investments in security tools and governance. Globally, 85 percent of organizations are also looking to enhance their spending on advanced frontier AI cyber capabilities, prioritizing proactive measures to mitigate potential risks rather than waiting for incidents to occur.

“The report findings underscore the value of AI and automation in cybersecurity. Organizations that have integrated these technologies into their security operations are containing breaches faster and reducing associated costs at a time of unprecedented levels of cyber challenges and pressure.”Catherine Lian, General Manager, IBM ASEAN

Despite these efforts, significant vulnerabilities persist. The report revealed that 53 percent of breached organizations failed to encrypt sensitive data at rest and in transit at the time of the incident. Additionally, only 29 percent of organizations reported proper encryption practices, indicating a critical gap in data protection strategies. The findings also highlighted that breaches involving AI systems, training data, or infrastructure accounted for 21 percent of all breaches, a notable increase from 13 percent the previous year.

Moreover, the report pointed out that identity-based attacks remain one of the costliest initial attack vectors, with breach costs averaging more than $4.5 million. As organizations continue to adopt AI technologies, the lack of proper governance and controls against cyber threats is a growing concern. Of those that experienced an AI-related incident, 92 percent lacked adequate AI access controls, and 68 percent did not have AI governance policies in place.

These findings serve as a stark reminder of the importance of prioritizing data-centric security measures, including encryption, data classification, and access controls, as organizations navigate an increasingly perilous cyber landscape.