AI cyber threats affect 79% of Singapore organizations
79% of Singapore organizations experienced an AI-related cyber threat in the past year, but only 49% monitor access to AI tools and their outputs.
Nearly eight in 10 organizations in Singapore encountered at least one AI-related cyber threat over the past year, according to research commissioned by cybersecurity company ESET.
The ESET Enterprise Cybersecurity Report 2026, conducted by Blackbox Research, surveyed 400 cybersecurity decision-makers in Singapore during the second quarter of 2026. The survey found that 79% had experienced at least one AI-related cyber threat during the previous 12 months.
AI use was widespread among the organizations surveyed, with 97% using or piloting the technology across business functions including customer service, software development, risk management, and threat detection.
Only 49% had measures in place to monitor access to AI tools and their outputs.
"AI is becoming deeply embedded in how businesses operate. As we give it access to more data and greater influence over decisions, organisations must ensure the right oversight and safeguards are in place. Trusting AI also means knowing how and where it is being used," Parvinder Walia, president of the APAC region at ESET, said.
AI-related attacks target users and systems
Employee misuse of generative AI and data leakage through AI platforms were each reported by 39% of organizations.
AI-generated phishing and impersonation were the most frequently reported AI-related threats, affecting 46% of organizations. Exploitation of AI-powered tools, including prompt injection, was reported by 41%.
Another 39% reported deepfake or voice-cloning attacks. AI-generated phishing and impersonation were reported by 62% of financial services organizations and 55% of technology companies, the highest rates among the sectors covered by the study.
Incident response remains a security challenge
Beyond AI-related threats, 71% of organizations experienced at least one major cybersecurity incident over the previous 12 months. One-quarter experienced three or more, with cloud environment breaches, insider threats, and data exfiltration among the most commonly reported incidents.
About 76% of organizations said they detected and responded to threats within 24 hours.
Among organizations that experienced a major incident, 55% cited delayed detection as a containment challenge, while 49% pointed to limited visibility across their environments. Coordination between teams was cited by 44%, followed by limited internal resources at 40% and alert fatigue at 38%.
"In cybersecurity, speed changes the outcome. A threat left undetected for hours can quickly become a business-wide incident," Walia said.
A shortage of skilled cybersecurity professionals was reported by 41% of respondents.
Phishing and social engineering were the leading reported cause of cyber incidents, cited by 36% of respondents. Lack of visibility across IT environments and limited cybersecurity resources or skills were each cited by 34%, while 32% pointed to user actions or human error.
Among user actions linked to cybersecurity incidents, 57% cited clicking phishing links or opening malicious attachments. Sharing sensitive data and installing unauthorized applications or software were each cited by 44%, while 43% reported employees falling for social engineering tactics and 40% cited misconfigured settings.
ESET telemetry for the first half of 2026 also identified phishing as the leading threat globally.
"Phishing remains effective because it targets people, and AI is making those attacks significantly more convincing. Deepfakes, impersonation and highly personalised messages are increasingly difficult to distinguish from legitimate communication," Walia said.
Email security was the most widely used security measure among respondents, at 68%, followed by firewalls at 67% and endpoint or antivirus protection at 62%.
MDR was the most commonly considered security capability for the next 12 months, cited by 43% of respondents. Threat intelligence, cloud-based sandboxing, and EDR/XDR were each cited by 41%.
The most commonly cited reasons for using MDR were faster incident response at 59% and 24/7 threat monitoring and response at 58%. Another 50% cited cost efficiency compared with building an internal team.
Cyber insurance was another planned investment, with 36% of organizations intending to obtain coverage. The report said 97% had encountered challenges obtaining or maintaining cyber insurance, with 43% citing stricter security requirements.
One in six organizations also reported significant financial losses from cybersecurity incidents.