Singapore – Nearly eight in 10 organisations in Singapore experienced at least one AI-related cyber threat in the past 12 months, according to the ESET Enterprise report.
The report, released by cybersecurity company ESET on the 26th of August, found that 79% of organisations surveyed had experienced an AI-related cyber threat during the period. The research was commissioned by ESET and conducted by Blackbox Research, which surveyed 400 cybersecurity decision-makers across Singapore in Q2 2026.
At the same time, AI adoption is widespread among Singapore organisations, with 97% already using or piloting AI across functions including customer service, document processing, business analytics, software development, risk management and threat detection.
“AI is becoming deeply embedded in how businesses operate. As we give it access to more data and greater influence over decisions, organisations must ensure the right oversight and safeguards are in place. Trusting AI also means knowing how and where it is being used,” said Parvinder Walia, President of the APAC region at ESET.
Despite the widespread adoption of AI, the report found that organisations have limited visibility into how the technology is being used. Only 49% said they had implemented measures to monitor access to AI tools and their outputs.
The research identified risks arising both internally and externally. Around four in 10 organisations reported employee misuse of generative AI and data leakage through AI platforms, while attackers were also using AI to manipulate human judgement and target everyday decisions.
AI-generated phishing and impersonation attacks were the most commonly reported AI-related threats, cited by 46% of organisations. This was followed by exploitation of AI-powered tools, including prompt injection, at 41%, and AI-enabled deepfake or voice-cloning attacks at 39%.
Financial services organisations reported the highest rate of AI-generated phishing and impersonation attacks at 62%, followed by technology companies at 55%.
Major cyber incidents remain widespread
The report also found that cyber incidents remain a significant concern beyond AI-related threats. More than seven in 10 organisations, or 71%, experienced at least one major cybersecurity incident during the past year, while 25% experienced three or more.
Cloud environment breaches, insider threats and data exfiltration were among the most commonly reported major incidents.
Although 76% of respondents said their organisations could detect and respond to threats within 24 hours, delayed detection remained a major challenge, cited by 55%. A lack of visibility across environments was reported by 49%, while 41% identified shortages of skilled cybersecurity professionals as a challenge.
“In cybersecurity, speed changes the outcome. A threat left undetected for hours can quickly become a business-wide incident. Organisations need continuous visibility, rapid response and access to deep expertise to contain threats early and protect business continuity,” Walia said.
Phishing and social engineering were identified as the leading causes of cyber incidents, cited by 36% of respondents. This was followed by a lack of visibility across IT environments and limited cybersecurity resources or skills shortages, both at 34%, while user actions or human error accounted for 32%.
ESET said its telemetry from the first half of 2026 also identified phishing as the leading threat observed globally.
“Phishing remains effective because it targets people, and AI is making those attacks significantly more convincing. Deepfakes, impersonation and highly personalised messages are increasingly difficult to distinguish from legitimate communication,” said Walia.
“Organisations must move beyond annual awareness exercises and continuously build their human layer of defence through relevant training and realistic simulations. Technology can stop many threats, but a well-prepared employee can stop the one that gets through,” he continued.
Organisations plan further cybersecurity investment
The report found that cybersecurity priorities are also shifting as AI, cloud platforms and connected technologies become more widely adopted.
Managed Detection and Response (MDR) was the most widely planned cybersecurity capability for the next 12 months, with 43% of organisations planning to adopt it. Cyber insurance was another area of planned investment, with 36% intending to obtain coverage.
However, 97% of organisations reported challenges in obtaining or maintaining cyber insurance. Stricter security requirements were cited as a challenge by 43% of respondents.
The financial impact of cyber incidents also remains significant, with one in six organisations reporting substantial financial losses.
“Cybersecurity is now essential to keeping businesses running. As AI and connected technologies grow, organisations need to understand where their risks are, react quickly when something goes wrong, and adopt new technology with confidence,” Walia concluded.

