Nearly four in five organisations in Singapore experienced at least one AI-related cyber threat over the past 12 months, according to the ESET Enterprise Cybersecurity Report 2026, which surveyed 400 cybersecurity decision-makers across the country.
The study, commissioned by ESET in partnership with Blackbox Research, found that 97% of organisations are already using or piloting AI across functions including customer service, document processing, business analytics, software development, risk management and threat detection — even as visibility into how those tools are used remains limited.
AI risk emerging from both inside and outside the business
Only 49% of organisations have implemented measures to monitor AI tool access and outputs, a gap the report frames as a core visibility challenge as AI adoption accelerates. Around four in ten organisations reported employee misuse of generative AI or data leakage through AI platforms.
- AI-generated phishing and impersonation was the most common AI-related threat, reported by 46% of organisations
- Exploitation of AI-powered tools such as prompt injection affected 41%
- AI-enabled deepfake or voice cloning attacks affected 39%
- Financial services (62%) and technology companies (55%) reported the highest levels of AI-generated phishing and impersonation
“Trusting AI also means knowing how and where it is being used,” said Parvinder Walia, President of the APAC region, ESET.
Detection speed remains the biggest gap
Beyond AI-specific threats, 71% of organisations experienced at least one major cybersecurity incident in the past year, and 25% experienced three or more. Cloud environment breaches, insider threats and data exfiltration were the most common incidents reported.
While 76% of organisations said they could detect and respond to threats within 24 hours, delayed detection remained a top challenge for 55% of respondents. Nearly half cited a lack of visibility across environments, and 41% reported shortages of skilled cybersecurity professionals.
Walia said undetected threats can escalate quickly into business-wide incidents, and that organisations need continuous visibility and rapid response to contain them early.
Phishing and social engineering were the leading cause of incidents at 36%, followed by lack of visibility across IT environments and limited cybersecurity resources, both at 34%, and user error at 32%.
Security spending shifts toward visibility and response
Managed Detection and Response (MDR) was the most widely planned cybersecurity capability over the next 12 months, with 43% of organisations planning to adopt it, while 36% are planning to obtain cyber insurance. Almost all respondents, 97%, reported challenges in obtaining or maintaining cyber insurance coverage, with 43% citing stricter security requirements as a barrier.
One in six organisations reported significant financial losses from cyber incidents over the period covered by the study, which was conducted in the second quarter of 2026.



Share your thoughts