For organisations that have not yet been impacted by cyberattacks and do not believe they will be targeted, think again. As technology and the digital landscape continue to advance at an exponential rate, so do cybercrimes. Masterminded by state actors or malicious hacktivist groups intent on causing harm, these attacks are evolving and becoming more sophisticated.
This outlook should be reason enough to compel a mindset shift across organisations to bolster their cybersecurity posture. With endless new vulnerabilities rapidly emerging, it becomes increasingly challenging for vulnerability management teams to address the overwhelming volume. Relying solely on traditional, legacy mechanisms will not be sufficient to detect and identify them. In many instances, organisations have been left to scramble from the back foot as teams scurry to take a reactive approach without having control of the reins, unable to make sense of what’s coming or what’s out there without intelligence-led cybersecurity services in place.
Today’s CIOs, CTOs, and CISOs stand at an important crossroad when deciding on the next technology to adopt or convincing the board of its necessity, while ensuring ROI is also achieved. This is understandable, as many organisations are experiencing so-called ‘technology bloat,’ given the number of cybersecurity solutions already deployed that do not necessarily integrate, resulting in disparate systems. Some may be redundant, while others are underutilised, necessitating a critical review so that those not yielding the desired outcomes can be replaced with a forward-looking architecture. This architecture should combine a dual strategy of threat mitigation (with threat-informed prioritisation for publicly exposed assets) and risk reduction (focused on systemic risk reduction for internal environments).
Both the threat mitigation and risk reduction concepts are supported by security practices like external attack surface management (EASM), or a combination of vulnerability scanning and informed threat and vulnerability intelligence. Time has shown it is near impossible to counter threats head-on by merely reacting to vulnerabilities. An evolved cyber landscape means cybersecurity today is less about containment and more about detection. This involves identifying potential risks to better mitigate, manage, and control the organisation’s system architecture.
Cyber extortion’s growth vector in APAC
Cyber extortion is defined as a computer crime in which the security of a corporate digital asset (confidentiality, integrity, or availability) has been compromised and exploited by criminals as a threat to extort payments. These groups further shame their victims by exposing the company’s name via dedicated data leak sites on the dark web.
The annual Orange Cyberdefense Security Navigator 2025 report highlights key trends in the global threat environment, with a section focused on Asia-Pacific (APAC) based on observed attacker behaviour and regional incident patterns.
The report found that APAC experienced a complex mix of cyber extortion and hacktivism impacts, suggesting that the region’s vast economic and technological diversity demands flexible and localised security strategies. There are notable variances within subregions. For example, East Asia (excluding China) ranks as the seventh most impacted subregion globally for cyber extortion, with 80 cases. Australia, India, and Japan are the most affected countries in APAC, accounting for 22.22%, 15.25%, and 10.85% of the incidents respectively.
Meanwhile, countries like South Korea and Singapore experienced moderate levels of such incidents, with cyber extortion targeting high-value manufacturing and industrial sectors. In China, internal threats made up a significant portion of incidents, with misuse as the primary action affecting end-user devices. This pattern emerged from regional incident data. In contrast, Southeast Asia saw a 9% decrease in cyber extortion incidents.
Cyber extortion is now firmly established as the main threat to operational technology (OT). Unlike IT, OT has specialised requirements that make traditional cybersecurity approaches inadequate. OT environments are especially vulnerable to the ripple effects of cyber extortion and other IT-originating incidents. This is because threats facing critical infrastructure, particularly within OT and mobile networks, present an expanded attack surface that calls for comprehensive, cross-functional defences. OT security is now a crucial theme, especially in industries where IT and OT systems are tightly integrated.
Manufacturing: the criminals’ playground
In terms of industry scorecard, manufacturing ranks as the most victimised sector, comprising 22% of all Cy-X victims and showing a 25% increase in incidents over the past year. This trend in OT-impacting cyberattacks has continued for more than 35 years, largely because manufacturing’s reliance on OT systems makes it particularly vulnerable to productivity loss, data encryption, and control manipulation. This is a troubling insight for APAC, considering that manufacturing is a key sector in markets like India, China, Malaysia, and Japan.
Next on the list is the professional, scientific, and technical services sector, which ranks second with a 20% increase, while healthcare ranks as the fourth most impacted this year, with a substantial 50% increase in victims. The finance and insurance sector ranks sixth, also a cause for concern, as BFSI remains a key industry in APAC countries like Singapore, Malaysia, Australia, and India.
Conclusion
As reality sets in that the next cybersecurity incident is a matter of when, not if, it calls on everyone to make fundamental changes to how we think and work. Incident response readiness means recognising that managed detection and response (MDR) is not merely a last line of defence, but part of continuous threat exposure management. Organisations must prepare proactively, integrating threat detection and response activities and using the data supplied to anticipate potential attack vectors and prioritise resources accordingly.
By understanding an organisation’s specific threat landscape, defence strategies can be tailored so that secure-by-design principles are used to address vulnerabilities at the source. Tools should be adopted according to the company’s maturity level. The real question for organisations today is this: can you afford to be caught off guard and become a target due to lack of preparedness, or would you rather embrace resilience and protect your business’s reputation by adopting proactive, round-the-clock, intelligence-driven services as the way forward?
Now that’s your food for thought.













