Menu

Most APAC Organisations Expect AI-Powered Cyberattacks Within a Year, Yet Many Remain Unprepared

Terry KS 20 hours ago
New research from Mimecast finds that 65% of IT and security leaders in Singapore and Australia believe an AI-enabled cyberattack on their organisation is inevitable within 12 months, yet 60% say they are not fully prepared to defend against threats that exploit human judgement. The study also found that two-thirds of respondents believe an employee could easily be fooled by an AI-driven social engineering attack.

SINGAPORE, 24 JULY 2026 – Mimecast, a company specialising in securing humans, data and AI, has released new research showing that Asia Pacific organisations widely expect artificial intelligence to be used in attacks against them, even as many remain underprepared for threats that exploit human judgement.

The company’s State of Human Risk 2026 study found that 65% of surveyed IT and security decision-makers believe an AI-enabled attack against their organisation is inevitable within the next 12 months. The findings are based on responses from 500 IT security and IT decision-makers across Singapore and Australia.

Concern about the threat is widespread, with 79% of respondents saying they are worried about AI being used as an attack vector against their organisation. However, 60% said their organisation was not fully prepared to handle AI-driven threats that exploit human vulnerabilities. This includes 52% who described themselves as somewhat prepared but still developing AI-specific defence strategies, and 9% who were aware of the threats but lacked a concrete plan.

Employees seen as a key vulnerability

Employees are viewed as a particular point of exposure, with two-thirds of respondents agreeing that a staff member at their organisation would very likely be fooled by a cybercriminal using AI as part of a social engineering attack. Mimecast said the findings reflect how AI-enabled cyber risk is placing greater pressure on employees to determine whether the communications and requests they receive are genuine.

Nicky Choo, Vice President and General Manager, APAC at Mimecast, said AI is changing the way cybercriminals manipulate trust, allowing attackers to craft convincing, tailored messages that appear to come from a colleague, partner or senior leader. She noted that employees are increasingly required to make difficult decisions in real time, and that the challenge has shifted from simply stopping threats before they arrive to helping people recognise when the interactions they rely on may have been manipulated.

Limited AI-specific training

The study found that AI-specific training and simulations remain uncommon among surveyed organisations. Only 40% provide training on how to use AI while avoiding exploitation, and just 42% conduct simulated AI-driven phishing exercises. While this does not necessarily mean other forms of cybersecurity training are absent, it suggests many organisations have yet to introduce measures that specifically address AI-enabled threats.

Choo said employees should not be expected to identify increasingly sophisticated deception on instinct alone, adding that many organisations have not yet caught up, with fewer than half training staff to avoid AI-driven exploitation or running simulated phishing exercises. She said this leaves many employees making difficult judgement calls without adequate AI-specific preparation.

Mimecast said the findings underline a broader need to treat human judgement as a core part of cyber defence alongside technical controls, as AI continues to blur the line between legitimate and malicious communication.

%d