AI powered cyber attacks seen as inevitable by most APAC organisations within a year, Mimecast study finds
Nearly two thirds of organisations surveyed across Singapore and Australia expect to face an AI enabled cyber attack within the next 12 months, but most admit they are not yet fully prepared to defend against increasingly sophisticated threats targeting human judgement.
SINGAPORE – Artificial intelligence is rapidly reshaping the cyber threat landscape across Asia Pacific, with a new Mimecast study revealing that most organisations believe AI enabled attacks are no longer a distant possibility but an imminent reality.
Mimecast's State of Human Risk 2026 report found that 65 per cent of surveyed IT and security decision makers expect their organisation to experience an AI enabled cyber attack within the next 12 months, reflecting growing concern over how cyber criminals are using generative AI to manipulate employees and bypass traditional security controls.
The research, based on responses from 500 IT security and IT decision makers in Singapore and Australia, found that 79 per cent of respondents are concerned about AI being used as an attack vector against their organisation.
Despite widespread awareness of the threat, many organisations acknowledge significant gaps in their readiness. Sixty per cent said they were not fully prepared to deal with AI driven attacks that exploit human vulnerabilities. More than half described themselves as only somewhat prepared and still developing AI specific defence strategies, while a further nine per cent admitted they were aware of the risks but had yet to establish a concrete response plan.
The report highlights employees as one of the most significant vulnerabilities. Two thirds of respondents believe an employee within their organisation is likely to be deceived by an AI generated phishing or social engineering attack, underlining the growing sophistication of cyber criminals who are using AI to produce convincing emails, messages and voice communications impersonating colleagues, business partners or senior executives.
Nicky Choo, Vice President and General Manager for Asia Pacific at Mimecast, said AI has fundamentally changed how attackers exploit trust within organisations.
"AI is changing the way cybercriminals manipulate trust. Attackers can now create highly convincing and personalised messages that appear to come from colleagues, partners or senior leaders, forcing employees to make increasingly difficult decisions in real time. The challenge is no longer just preventing threats from entering an organisation but helping people identify when trusted communications have been manipulated."
While many organisations have strengthened their technical cyber defences, the research suggests employee preparedness has not kept pace with the rapid evolution of AI powered attacks.
Only 40 per cent of organisations surveyed provide staff with training on using AI safely while avoiding exploitation, and just 42 per cent conduct simulated AI driven phishing exercises designed to prepare employees for emerging threats.
Mimecast said these findings indicate that although conventional cybersecurity awareness programmes may exist, many organisations have yet to introduce dedicated training focused specifically on AI enabled attacks.
Choo said organisations could no longer rely on instinct alone to protect employees from increasingly sophisticated deception.
"Employees should not be expected to identify increasingly sophisticated deception on instinct alone. Yet fewer than half of organisations are training staff to recognise AI driven exploitation or testing their readiness through simulated AI phishing attacks. That leaves many employees making critical judgement calls without the preparation they need."
The report concludes that organisations should view human judgement as a core component of cybersecurity strategy alongside technology investments. As AI continues to blur the distinction between legitimate and malicious communications, businesses will need to strengthen employee awareness, introduce AI specific training and adopt security measures that address both technical and human risks.
Mimecast commissioned independent research firm Vanson Bourne to conduct the global survey between November and December 2025. The study gathered responses from 2,500 IT security and IT decision makers across nine countries, including Singapore and Australia, representing organisations with more than 250 employees across sectors ranging from financial services and healthcare to manufacturing, government and technology.