π Mimecast: AI is rewriting cybersecurity, and humans are becoming the main target
Artificial intelligence is making cyberattacks increasingly convincing, yet many organizations across Asia Pacific remain unprepared for attacks that exploit human vulnerabilities.
π The Main Takeaway
Findings from the latest State of Human Risk 2026 by Mimecast show that 65% of surveyed organisations in Singapore and Australia believe an AI-enabled cyberattack is inevitable within the next 12 months, while 60% admit they are not fully prepared to defend against AI-driven threats targeting employees.
The findings suggest that people have become the new frontline of cybersecurity.
π Why It Matters
π€ Trust Is Under Attack: AI enables cybercriminals to create increasingly convincing emails, messages, and requests that closely resemble legitimate communications from colleagues, executives, and business partners.
π₯ People Become the Frontline: Cybersecurity is no longer just about stopping malware. Employees are increasingly expected to distinguish genuine interactions from AI-generated deception.
π± Beyond Email: Modern cyberattacks now extend across collaboration platforms, messaging apps, shared documents, and internal communication channels.
π A Regional Wake-Up Call: As AI adoption accelerates across Asia Pacific, strengthening human resilience is becoming just as important as strengthening technology.
π Survey Methodology
The findings draw on both regional and global survey data, offering insights into how AI-driven cyber risks are evolving across different markets.
πΈπ¬ Regional Findings: The regional findings are based on responses from 500 IT and security decision-makers in Singapore and Australia, examining how organisations perceive AI-enabled cyber threats across the two markets.
π Global Study: The broader State of Human Risk 2026 surveyed 2,500 respondents, including 1,922 IT decision-makers and 578 IT security decision-makers, across the United States, United Kingdom, Germany, France, Spain, Italy, South Africa, Singapore, and Australia.
π’ Enterprise Focus: All participating organisations employed at least 250 employees and 250 email users, with company sizes ranging from 250 to more than 10,000 employees.
π Industry Coverage: Respondents represented financial services, healthcare, IT and telecommunications, manufacturing, retail, the public sector, energy and utilities, business services, construction, consumer services, and media and entertainment.

π Regional Findings
The regional findings reveal growing concern over AI-enabled cyberattacks, but also expose significant gaps in organisational readiness.
β οΈ Attack Expectations: 79% of respondents are concerned about AI being used as an attack vector, while 65% believe an AI-enabled cyberattack is inevitable within the next year.
π Preparedness: 60% say their organisations are not fully prepared to respond to AI-driven threats exploiting human vulnerabilities.
π₯ Employee Exposure: 66% believe employees are likely to fall victim to AI-assisted social engineering attacks.
π Training Gap: Only 40% provide AI-specific employee training, while 42% conduct simulated AI phishing exercises.
π Global Insights
While the regional findings focus on Singapore and Australia, the broader global survey suggests these challenges extend well beyond the region.
π Execution Gap: 91% of organisations struggle to ensure employee compliance, 96% acknowledge incomplete protection, yet only 28% combine regular security awareness training with continuous monitoring.
π° Human Risk Costs: Insider-related incidents cost organisations an average of US$13.1 million per incident. With an average of six insider incidents each month, annual exposure could reach US$943.2 million, excluding regulatory fines and reputational damage.
π Growing Exposure: Around 71% expect collaboration tool attacks to have business impact in 2026, yet 38% still rely solely on native security controls despite 64% believing those protections are insufficient.
β οΈ Mimecast: Five Critical Gaps Defining 2026
Beyond the headline figures, the report identifies five structural gaps that continue to shape cybersecurity risks in 2026.
π± Attack Surface: Threats increasingly target collaboration platforms and internal communication channels alongside email.
π₯ Insider Risk: Just 8% of employees account for 80% of security incidents, showing how a small group of users can create disproportionate organisational risk.
π Integration: Although 65% say security integration is too complicated, organisations that succeed achieve 40% faster threat remediation.
ποΈ Governance: 59% lack confidence that they can quickly retrieve communications data to satisfy regulatory requirements.
π€ AI Readiness: Organizations continue adopting AI technologies faster than they prepare employees to respond to AI-enabled threats.
βοΈ Regional Stakes
πΈπ¬ Singapore Leads: Singapore is one of only two markets globally classified as an AI Adopter, reflecting stronger defensive AI deployment and closer coordination between government and industry.
π Challenges Remain: Even among leading markets, governance and human-risk challenges persist, showing that technology adoption alone does not guarantee cyber resilience.

π The Bigger Picture
The findings are also echoed by other cybersecurity research, reinforcing concerns that organisations are struggling to adapt to the rapidly evolving AI threat landscape.
π Human Error Persists: The 2026 Thales Data Threat Report found that human error remains the leading cause of data breaches (28%), surpassing technical vulnerabilities.
π€ AI Threats Expand: 59% of organisations have observed deepfake-related attacks, 61% report AI applications becoming attack targets, and 48% have experienced reputational damage linked to AI-generated misinformation.
β‘ Keeping Pace: Around 70% say the rapidly evolving AI ecosystem itself has become one of their greatest cybersecurity challenges, reinforcing concerns that organisations are struggling to keep pace with AI-driven threats.
π Whatβs Next?
As AI continues to reshape cyber threats, organisations will need to rethink how they balance technology, governance, and human resilience.
π€ Prioritise Human Risk: Organizations should combine employee awareness training with continuous monitoring instead of relying on one approach alone.
π€ Strengthen AI Readiness: AI-specific training and phishing simulations should become standard as AI-generated deception becomes increasingly sophisticated.
π Reduce Fragmentation: Integrated security platforms can improve visibility, accelerate incident response, and strengthen governance.
ποΈ Embed Governance: Cybersecurity strategies should align people, technology, and governance rather than treating them as separate priorities.
π Measure Human Risk: Monitoring employee behaviour, policy compliance, and organisational risk should become as important as tracking technical vulnerabilities.
π€ Beyond the Numbers
The future of cybersecurity may depend less on stronger technology than on better human resilience. As AI makes cyberattacks increasingly convincing, human judgment is becoming one of the strongest lines of defence.
The challenge is no longer whether organisations should invest in human risk management, but whether they can keep pace with AI-driven threats.
π° Need More Angle?
Cyber Security Asia 65% of Surveyed APAC Organisations See an AI-Enabled Attack as Inevitable Within a Year
Mimecast The State of Human Risk 2026
Thales Group 2026 Data Threat Report
(BRZ/QOB)




