Agentic AI exposes Asia's cyber resilience gaps, Commvault finds

Agentic AI use is growing across Asia, but Commvault found gaps in identity management, AI governance, and cyber recovery.

AI Security Systems concepts. 3D render

Asian organizations are expanding the use of agentic AI across enterprise operations, while Commvault's latest research identifies gaps in resilience, governance, and recovery planning.

The State of Data Resilience Asia 2026 report was commissioned by Commvault and conducted by Omdia. It surveyed more than 1,200 organizations across Singapore, Indonesia, Hong Kong, Korea, Malaysia, Thailand, Vietnam, and the Philippines.

The report found that nearly all surveyed organizations in Asia plan to increase AI investment in 2026. More than one-third are already trialing or deploying agentic AI across IT, cybersecurity, and business operations.

AI spending is expected to rise through 2026, with 95% of organizations increasing their budgets and 36% raising spending by more than 25% compared with 2025, according to Omdia AI Market Maturity data cited in the report.

The report listed Indonesia, Thailand, and Hong Kong among the markets where organizations are deploying agentic AI across cybersecurity, data protection, and business operations. The report also cited a projection that Asia Pacific AI spending will reach US$175 billion by 2028.

Commvault said organizations face gaps in identity management, governance, and cyber recovery as AI systems become more autonomous.

"As autonomous systems become part of how organizations operate, resilience can no longer sit on the sidelines," said Martin Creighan, Vice President, Asia Pacific, Commvault. "Organizations need a new posture entirely, one where recovery isn't a backup plan, but how the modern business runs."

Data growth adds recovery pressure

The report said data growth remains a factor in resilience planning. It found that average yearly growth in data estates across Asia has stayed above 30% for three consecutive years, while most surveyed organizations continue to run data and workloads across multi-cloud or hybrid environments.

The report also identified operational gaps in multi-infrastructure environments. It found that 53% of organizations cited disparate skills across cross-cloud incident response teams, while 41% cited difficulty confirming the integrity and cleanliness of backups.

The report said organizations are adding AI agents, machine accounts, applications, APIs, and automated workflows, increasing the number of non-human identities with access to critical environments.

Machine identities now outnumber human identities by as much as 82 to 1 globally, according to the report. The report said resilience strategies still account for human identities more often than non-human identities.

The survey found that 73% of organizations have included human identities in cyber resilience planning. Only 34% have extended those strategies to non-human identities.

The gap was wider in several markets. The report found that only 22% of organizations in Korea, 23% in Hong Kong, and 28% in Malaysia had included non-human identities in resilience planning.

According to the research, 78% of organizations said agentic AI is increasing the complexity of identity management and resilience operations.

Governance remains another area of concern. Only 42% of organizations said they conduct comprehensive security, governance, and compliance reviews before deploying AI systems.

The report said fewer than half of organizations were very confident they could detect compromised or non-compliant AI systems. It also found that fewer than half were very confident they could detect AI mistakes, compromised tools, governance breaches, or compromised data access guardrails.

Recovery timelines still lag

Cyber recovery remains another unresolved issue. For the third consecutive year, the research found a gap between business expectations and actual recovery timelines across Asia.

Business leaders expect operations to resume within five days after a cyber incident, according to the report. The average recovery time remains 28 days.

Only 23% of organizations said they were able to continue operations without disruption during a cyber incident. Most said they had to operate in a degraded or limited state. The average time to recover to a minimal operational level fell from 42 days in 2023 to 28 days in 2026, according to the report.

Gareth Russell, Field CTO, Security, Asia Pacific at Commvault, said organizations need to prepare for incidents in environments where exposure and impact can move faster. "When attack surfaces can be mapped overnight and vulnerabilities emerge faster than organizations can respond, the question isn't whether organizations get hit. It's whether they can continue operating when they do," he said.

Ransomware and MVC planning shape resilience

Ransomware remains part of the recovery challenge. The report found that 44% of surveyed organizations in Asia had been targeted by ransomware in the past 12 months, while 40% said they had paid a ransom.

Among organizations that paid, 31% said the payment did not work because the threat actor did not release the data or returned with another demand. The most cited factor in deciding whether to pay or restore from backups was confidence in the integrity and completeness of backups, selected by 48% of respondents.

The report found that 68% of surveyed organizations had defined minimum viable business requirements for operating during an attack, while 46% had defined the technology requirements needed to support those operations.

Organizations that had defined minimum business requirements linked to clear technology capabilities were 3.2 times more likely to maintain operations during an attack and 1.6 times more likely to recover faster than those without a defined level, according to the report.