• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Resources Blogs

Southeast Asia cybersecurity trends

Jinan Budge by Jinan Budge
April 29, 2024
Photo by Jeda Hutchison: https://www.pexels.com/photo/photography-of-singapore-skyscrapers-723032/

Photo by Jeda Hutchison: https://www.pexels.com/photo/photography-of-singapore-skyscrapers-723032/

Share on FacebookShare on Twitter

It should come as no surprise that the challenges and opportunities differed from country to country. Region-specific factors can vastly impact cybersecurity threats and practices such as business cultural norms, language, geopolitical issues, the regulatory landscape, and cybersecurity maturity.

The luxury of physical presence and time meant that I learned things I simply can’t intuit from press reports or even virtual calls. In this blog, I will share my key learnings and takeaways from the key challenges and opportunities for CISOs in Southeast Asia:

Narrative attacks and deepfakes

With 2024 touted as “Asia’s year of elections,” with seven highly populous Asian countries holding elections, narrative attacks are expected to be especially popular here. Indonesia saw this when an AI-generated deepfake video of late President Suharto that cloned his face and voice, trying to influence a political agenda, went viral. Speaking of deepfakes: According to a Sumsub report, deepfakes surged by 1,530% in APAC! We discussed the Hong Kong finance worker who attended a video call in which deepfake technology was used to imitate his colleagues, part of a scheme to prompt him to transfer US$25 million. We also discussed the concern about the use of deepfakes in biometrics, with security leaders bringing to my attention banking victims identified in Vietnam and Thailand.

Human element and AI software supply chain threats

 Generative AI’s talent for breaking down language barriers means that non-English-speaking countries will no longer be able to avoid some human-related attacks such as business email compromise (BEC) and other forms of social engineering (for example, Japan saw a 35% year-over-year increase in BEC attempts). The security leaders we spoke to agreed that they anticipate a significant rise in human-related attacks. Another imminent threat related to AI and the software supply chain: Forrester predicted that in 2024, at least three data breaches will be publicly blamed on AI-generated code.

Related:  Cybernomics 101 - Uncovering the financial forces driving cyberattacks

A chaotically evolving regulatory landscape

 Regulators in APAC can no longer ignore these breaches. In 2022–23, Australian regulators announced amendments to the Privacy and Telecommunications Acts, and Australia also refreshed the federal government’s Essential Eight threat mitigation strategies and strengthened industry-focused regulations such as Security of Critical Infrastructure Act.

The Indian Parliament passed the much-awaited Digital Personal Data Protection bill. Singapore amended its Personal Data Protection Act, Indonesia passed its first ever Personal Data Protection Law, and even Japan strengthened its Act on the Protection of Personal Information. This is causing havoc for CISOs in these regions, who shared with us what they called “a significant regulatory burden” — these compliance activities consume precious resources, time, and energy, all of which CISOs wish could be diverted into more strategic initiatives.

Protecting CISOs and their teams

 All of the above dynamics — combined with low budgets, still emerging levels of organizational influence, a widening cybersecurity workforce gap (one that increased by 11.8% in APAC this year), and many CISOs in the region still reporting to technology departments — led to discussions about how CISOs will protect themselves and their teams.

Cybersecurity burnout started rearing its ugly head, particularly in our Singapore and Hong Kong discussions, an issue discussed only in hushed tones in previous visits. Leaders discussed the feasibility of retaining their own counsel to negotiate compensation and insurance, as well as for consultation when making decisions as a senior security leader. They also discussed retaining and upskilling existing talent.

Generative AI aspirations

 Security leaders discussed how they have been supporting their organizations to adopt generative AI (genAI) safely and their wishes to protect their organizations without getting relegated to being seen as the “department of no,” while some even spoke about warning their firms against being too genAI-conservative and advising their firms on the many business and productivity benefits of genAI. All of them wanted to know how to engage and influence their organizations on the appropriate behaviors of using genAI (such as what can and cannot be shared with genAI), particularly as employees embrace the technology, creating a shadow genAI situation.

Related:  Microsoft gets cybersecurity boost from Sophos and Veeam

Zero trust

 Forrester predicted that in 2024, roles with Zero Trust (ZT) titles will double across public and private sectors in some countries and emerge in others. This was not a popular prediction for which our attendees have been preparing, at least not in the short term. While our research shows that ZT is finally moving from concept to reality in Asia Pacific, there was still a broad range of sentiment and skepticism in the deep discussions.

Originally posted on Forrester

Tags: Artificial IntelligencecybersecurityForrester
Jinan Budge

Jinan Budge

Jinan Budge leads Forrester’s security and risk research in Asia Pacific. Her research focuses on enabling chief information security officers (CISOs) and technology executives to lead a high-performing security organisation and culture. Budge globally leads Forrester’s awareness, behaviour, and culture coverage, using strategic and innovating thinking to shape the market. She is also an advocate for diversity and inclusion in security. Budge focuses on ensuring that cybersecurity teams not only attract but also retain the best talent, and she brings a local and global perspective and cultural lens to her research and practice. Previous Work Experience Budge’s research remains pragmatic, as she recently returned to Forrester after several years as director of cyber strategy at Transport for NSW and a similar role with Qantas Airlines. She has built, stood up, and delivered significant Cyber Transformation strategies across the public and private sectors. She is an experienced people leader and international keynote speaker, and she's passionate around her purpose in the security field. Education Budge holds two bachelor’s degrees in science and commerce from the Australian National University.

No Result
View All Result

Recent Posts

  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl