Nearly eight in ten organisations (79%) in Singapore encountered at least one AI-related cyber threat over the past 12 months, according to the ESET Enterprise Cybersecurity Report 2026.
The study, conducted in partnership with Blackbox Research across 400 local cybersecurity decision-makers, revealed that while 97% of enterprises are actively using or piloting artificial intelligence, defensive visibility and governance lag behind implementation.

Source: ESET 2026
Operational adoption outpaces security oversight
Enterprises are rapidly embedding AI across essential functions, including customer service, document processing, business analytics, software development, risk management, and threat detection. However, only 49% of surveyed organisations have implemented measures to monitor AI tool access and outputs, creating a critical oversight gap.
Organisations face mounting risks from both internal practices and external adversaries. Approximately four in ten businesses reported employee misuse of generative AI and data leakage via AI platforms. Externally, cybercriminals are weaponising AI to manipulate human judgement.
AI-generated phishing and impersonation emerged as the most prevalent threat (46%), followed by prompt injection and tool exploitation (41%), alongside deepfake and voice cloning attacks (39%). These tactics proved particularly acute in financial services and technology sectors, where 62% and 55% of respondents respectively reported AI-generated impersonation incidents.
Detection delays compound incident response challenges
Broader cyber risk remains elevated across the city-state: 71% of organisations suffered at least one major cybersecurity incident in the past year, and 25% sustained three or more. Cloud environment breaches, insider threats, and data exfiltration were the most common occurrences.
Phishing and social engineering remained the leading root cause of incidents (36%), trailed by IT environment visibility gaps (34%), cybersecurity skills shortages (34%), and human error (32%). While 76% of firms claimed the ability to detect and respond to threats within 24 hours, delayed detection was cited as a primary challenge by 55% of respondents, with 49% highlighting poor environmental visibility.
Strategic priorities shift towards detection and insurance
To mitigate mounting exposures and prevent substantial financial losses—reported by one in six firms—organisations are adjusting defensive investments. Managed Detection and Response (MDR) represents the top priority, with 43% planning adoption within 12 months. Furthermore, 36% aim to secure cyber insurance, though 97% encounter hurdles in obtaining or maintaining coverage due to stricter security criteria.
Parvinder Walia, president of the APAC region at ESET, remarked: "AI is becoming deeply embedded in how businesses operate. As we give it access to more data and greater influence over decisions, organisations must ensure the right oversight and safeguards are in place. Trusting AI also means knowing how and where it is being used."

He added that in cybersecurity, speed changes the outcome. "A threat left undetected for hours can quickly become a business-wide incident. Organisations need continuous visibility, rapid response and access to deep expertise to contain threats early and protect business continuity."









