
ARTIFICIAL intelligence-driven cyberattacks are expected to become a growing threat across the Asia-Pacific region, but many organizations remain inadequately prepared to defend against attacks that exploit human behavior, according to new research released recently.
The State of Human Risk 2026 study found that 65 percent of surveyed IT and security decision-makers in Singapore and Australia believe an AI-enabled attack against their organization is inevitable within the next 12 months. Nearly eight in 10 respondents said they were concerned about AI being used as an attack vector, while 60 percent acknowledged they were not fully prepared to respond to AI-driven threats targeting human vulnerabilities.
The regional findings form part of a global survey of 2,500 IT security and IT decision-makers across nine countries conducted in late 2025. The accompanying report found that insider threats, credential misuse and user-driven errors have become the leading causes of cybersecurity incidents, with organizations estimating the average cost of a single insider-driven breach at $13.1 million. Respondents also reported experiencing an average of six such incidents each month, equivalent to an estimated annual exposure of $943.2 million.
The APAC survey also found that 66 percent of respondents believe employees are highly likely to be deceived by cybercriminals using AI in social engineering attacks. However, AI-focused workforce preparation remains limited. Only 40 percent of organizations provide training on using AI safely while avoiding exploitation, while 42 percent conduct simulated AI-driven phishing exercises.
Globally, organizations are investing more heavily in AI-powered security tools than in employee readiness. The report found that 55 percent use AI for threat detection and real-time monitoring, but only 44 percent train employees to recognize AI-enabled attacks and just 41 percent have established AI usage policies. It also found that 69 percent of organizations expect AI to be used in attacks against them within the next year.
Researchers also identified a gap between awareness and execution. Although 91 percent of organizations reported governance and compliance challenges and 96 percent acknowledged gaps in their overall protection, only 28 percent combine regular security awareness training with continuous monitoring for policy violations. The report said this disconnect leaves organizations more vulnerable to increasingly sophisticated attacks.
The report also found that collaboration platforms are becoming a growing target for attackers. Seventy-one percent of respondents expect attacks on workplace collaboration tools to negatively affect their organizations in 2026, while many continue relying primarily on native security controls despite recognizing their limitations.
The study recommends strengthening protection across email and collaboration platforms, adopting integrated human risk management, improving data governance and compliance, simplifying security tool integration, and expanding AI-specific governance and employee training.
Mimecast commissioned market research firm Vanson Bourne to survey 2,500 IT security and IT decision-makers from organizations with more than 250 employees in the United States, the United Kingdom, Germany, France, Spain, Italy, South Africa, Singapore and Australia between November and December 2025. The APAC findings are based on responses from 500 decision-makers in Singapore and Australia.



