Home Technology Security The cybersecurity paradox: Budgets up, defences down

The cybersecurity paradox: Budgets up, defences down

As digital transformation evolves, cybersecurity is no longer just an IT concern. It is fundamental to Singapore’s national resilience and economic growth. With more organisations increasingly relying on technologies like AI, ensuring a secure and trusted digital environment is more essential than ever. While Singapore has emerged as a leader in AI governance, fostering digital trust and equipping individuals and businesses with initiatives such as the Model AI Governance Framework and the National AI Strategy (NAIS 2.0), a paradox has appeared in the nation’s cybersecurity landscape.

Analysis from Palo Alto Networks’ 2025 Cybersecurity Resilience in Mid-Market Organisations report suggests a strong focus on cybersecurity. Cyber budgets among mid-market organisations in Singapore are rising, now accounting for 15.2% of total IT budgets, with significant increases in data protection, security software, and application security/identity access. However, more needs to be done. The Cyber Security Agency of Singapore (CSA) noted that only one in three organisations has fully implemented at least three of the five categories outlined in Cyber Essentials, the nation’s baseline cybersecurity standard.

Globally, a gap persists. Many organisations remain vulnerable and have yet to adopt robust cybersecurity practices. At the same time, they continue to grapple with ransomware. According to Palo Alto Networks’ Unit 42 Incident Response Report 2025, 86% of attacks between January and March 2025 resulted in business disruptions.

The root of the problem lies in the nature of modern threats. Ransomware and extortion have become more sophisticated, compounded by the surge in generative AI traffic. A particularly concerning tactic used by threat actors is AI-generated insider threat extortion, where attackers pose as remote IT workers with fabricated digital identities, enabling them to steal proprietary code and extort companies by threatening public disclosure.

Cybersecurity gaps in mid-market organisations

For mid-market organisations, these threats are made worse by tight budgets and small IT teams. Many rely on traditional security tools and juggle separate systems from multi-vendor environments, leading to fragmented, siloed information and complex security management. On average, organisations in APAC are using four cybersecurity vendors at once, with plans to add more tools in the next two years. This cycle of inefficiency and risk creates duplicate data entries, higher error rates, and inconsistent security policies that complicate compliance.

Additionally, many are still in the early stages of integrating AI into their security workflows. Without the resources or expertise to deploy and sustain these tools effectively, they lack the ability to detect and mitigate threats in real time, leaving critical gaps that cybercriminals are quick to exploit.

This raises an important question: Are mid-market organisations investing in the right measures to keep pace with today’s threats? Even with ongoing investments, many continue to struggle against increasingly sophisticated ransomware attacks.

Establishing a proactive, stronger cybersecurity posture

Mid-market organisations in APAC increasingly view cybersecurity as a core business priority. They are focused on safeguarding their customers and intellectual property while driving digital transformation. As the saying goes, prevention is better than cure. To bridge the gap and build resilience, organisations must move beyond traditional approaches and adopt a more proactive, AI-driven model for threat detection. Integrating security functions more closely helps improve visibility and enables real-time threat identification, which in turn strengthens data protection and resilience. Beyond technology, ongoing education and training are also crucial to cultivate a security-aware culture among employees.

Organisations should also automate their security operations and carefully monitor how AI is used within their environments. This includes strengthening identity verification, monitoring for unusual insider activity, and enforcing least-privilege access policies.

Ultimately, zero trust must extend inside the organisation to fortify defences and detect advanced malware and threats embedded in generative AI responses. One of the most critical components of a zero-trust framework, multi-factor authentication (MFA), enhances security by adding layers of verification before access is granted. This significantly reduces the risk of unauthorised entry, even if login credentials are compromised through phishing, credential stuffing, or AI-generated attacks, by ensuring identity validation goes beyond a username and password.

Mid-market organisations, in particular, often need external support to navigate this complex landscape. Faced with limited budgets and a smaller pool of in-house expertise, many are turning to managed security service providers (MSSPs) for real-time monitoring and AI-powered threat detection. These partnerships provide access to specialised expertise and resources, allowing businesses to focus on core operations while strengthening their security posture.

By adopting an AI-driven strategy, cultivating a strong cybersecurity culture, and leveraging external expertise, organisations can close the gaps that leave them vulnerable to cyber threats. This holistic approach ensures their investments in cybersecurity translate into a resilient defence against today’s sophisticated attacks.

- Advertisement -