Singapore organisations face cyber recovery gaps as AI threats evolve

by

Ansherina Baes

-

5 minutes ago

Singapore – Only 2% of Singapore organisations are confident they can withstand cyberattacks accelerated by frontier artificial intelligence (AI) models, according to the latest Cohesity report.

The research found that 82% of Singapore organisations had experienced a material cyberattack in the previous 12 months. At the same time, 95% said their recovery plans were based on assumptions not proven under real-world conditions.

While 99% of organisations surveyed said they have a cyber resilience strategy, 60% acknowledged it still needs improvement, including 12% who said significant improvement is needed.

Forty per cent said significant changes are required to prepare for cyberattacks accelerated by frontier AI models, compared with 32% globally.

Existing attacks expose recovery gaps

The findings indicate that organisations are already struggling to recover from current cyber threats, before the wider adoption of frontier AI.

Among organisations that experienced an attack in the past 12 months, 93% said their existing recovery plans would likely require workarounds or improvisation during an incident.

Sixty-three per cent reported taking longer than expected to recover, with recovery taking around six hours longer than their target objective on average. Meanwhile, 72% said more systems were affected than they had initially assessed.

The most frequently identified gaps involved skills and knowledge, cited by 73% of respondents, followed by identity and access management tools such as Okta at 71%, and AI models, pipelines and workflow tools at 69%.

Restoring systems is only part of recovery

The research also highlights challenges that can continue after organisations restore systems.

Among organisations that experienced a material cyberattack, 68% encountered moderate or significant delays because they lacked confidence that restored data and systems were clean and safe to use. A further 67% reported identity or access problems after restoring systems.

Seventy-two per cent said the scope of affected systems expanded beyond their initial assessment.

The research also found that 71% identified moderate or significant gaps in how their recovery plans accounted for dependencies spanning cloud infrastructure, SaaS applications, identity services, security tools, third-party integrations and AI systems.

These dependencies can affect which systems are restored, the order in which they are brought back and whether previously completed recovery work needs to be revisited.

Business recovery remains less formalised

The report also examined the concept of a Minimum Viable Company (MVC), defined as the smallest version of a business that can continue to serve customers while broader recovery work is underway.

In Singapore, 15% of organisations said they have a formally documented and tested MVC. Another 19% have a formally documented MVC that has not been tested, while 30% rely on an informal or partially documented approach.

Among organisations with an MVC, 41% said it directly determined which systems and operations were prioritised for recovery.

AI adoption outpaces recovery planning

AI is already widely used across Singapore organisations, but the research suggests that recovery planning has not kept pace with its adoption.

Ninety-nine per cent of respondents said their organisations use AI systems, applications, workflows or machine learning models. However, only 44% said their cyber response and recovery plans comprehensively account for attacks targeting these technologies.

More than half of respondents (55%) said they were not well prepared to detect, contain, and recover from unintended or incorrect actions taken by AI agents, copilots, or AI workflows.

Another 51% said they were not very confident in their ability to verify the integrity of AI models and related data following a cyberattack.

As AI becomes increasingly embedded in internal and customer-facing processes, the report highlights the importance of including AI systems and their dependencies in recovery planning alongside conventional infrastructure.

“Cyber resilience across ASEAN is no longer simply a technology challenge — it is a business imperative. As organisations across the region accelerate their adoption of AI and deepen digital interconnectivity, the ability to continue operating, meet customer commitments, and recover quickly during a cyber crisis has never been more critical,” said Lim Hsin Yin, Vice-President and General Manager, ASEAN at Cohesity

“The growing complexity of third-party integrations, AI models, and automated workflows means organisations must ensure recovery is given the same level of attention as protection. AI is increasing the speed and scale of cyber threats, but it can also be part of the answer — strengthening how organisations detect, recover, and restore trust at machine speed,” Yin continued.

The findings point to a growing distinction between restoring IT systems and restoring a functioning business, particularly as organisations add AI, cloud services and third-party platforms to their operational environments.

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

Singapore organisations face cyber recovery gaps as AI threats evolve
Zendesk appoints David Hall-Johnston as Chief Technology Officer to lead APJ AI strategy 
Fujitsu outlines new Uvance model for AI-driven business transformation
Comviva taps Sanjiv Patankar to Product Unit Head for fintech business
AI fluency, not AI engineering: Jack Madrid's blueprint for the Philippines' CX future
Ellipse 3

RELATED ARTICLES

U MOBILE X OPENAI
Cohesity introduces MCP-based Maestro platform for AI-driven cyber resilience operations
Cohesity, Google Cloud expand multi-year partnership to advance cyber resilience, enterprise AI, and data sovereignty
Ellipse 3

FEATURED ARTICLES

'Retail & E-Commerce Innovation Summit' returns for its 2nd edition in the Philippines — initial speaker lineup revealed
‘Retail & E-Commerce Excellence Awards Asia Pacific
EW2025_(UT)Launch Article_Feature Image_11zon

Subscribe to UpTech Media Newsletter

JOIN OUR NEWSLETTER

Subscribe to our newsletter to get the latest APAC marketing news.