Tue, 28 Jul 2026

SG Faces a growing gap between AI risk and readiness

Source: State of Human Risk 2026, Mimecast

Mimecast’s State of Human Risk 2026 findings suggest Singapore organisations are increasingly aware of AI-enabled cyber threats, but many are still not ready to deal with them.

In Singapore, 61% of surveyed IT and security decision-makers said an AI-enabled attack on their organisation is inevitable within the next 12 months, while 79% are concerned about AI being used as an attack vector.

The survey, which covered 250 Singapore respondents, found a sizeable preparedness gap. While 69% said their organisations are not fully prepared to handle AI-driven threats that exploit human vulnerabilities, only 38% provide employees with training on how to use AI while avoiding exploitation, and 42% run simulated AI-driven phishing attacks.

The findings point to human judgement becoming a key battleground in cyber defence. Mimecast said 68% of Singapore respondents believe an employee is very likely to be deceived by a cybercriminal using AI in a social engineering attack, underscoring the risk posed by increasingly convincing impersonation and manipulation tactics.

Reflecting on the data, Nicky Choo, vice president and general manager, APAC, Mimecast, said: "The Singapore findings show a clear gap between recognising the risk and being ready for it. While 79% of respondents are concerned about AI being used in attacks, 69% say their organisation is not yet fully prepared."

Nicky Choo

"The problem is not simply that AI allows cybercriminals to create fraudulent messages more easily. It allows them to make those messages sound familiar, credible and urgent. That makes it harder for an employee to know whether a request that appears to come from a colleague, partner or senior leader is genuine." Nicky Choo

He added that employees should not be expected to make these decisions on instinct alone, and said organisations need to combine technical safeguards with practical training and realistic simulations to address AI-enabled deception.

Related:  Lumen pins upstream network visibility as next cyber battleground

The Singapore data also fits a wider regional pattern in which concern about AI as an attack vector is high, but formal AI-specific preparation remains limited.

For Singapore enterprises, the practical message is clear: as AI makes scams more believable, security strategies will need to treat people, processes and technology as one connected defence layer.

Related Stories

MORE STORIES