Picture this: it is the middle of the workday, and your security team is frantically responding to alerts. The target? A 15-year-old database server long overdue for decommissioning. Meanwhile, your data scientists have just deployed three new large language models (LLMs) through unofficial channels, creating API endpoints your security team doesn’t even know exist.
Welcome to what I call “the ball of fire” — the dangerous reality where organisations across Asia-Pacific juggle multiple generations of technology simultaneously, from decades-old mainframes to cutting-edge AI applications. This technological debt is not just accumulating; it is a firestarter ready to combust.
APAC organisations are investing heavily in AI, with budgets growing to support implementation. However, those adopting AI are also expanding their API connectivity, significantly increasing their attack surface. When legacy systems meet AI adoption, security gaps emerge that traditional approaches cannot address. As organisations race towards innovation, a “ball of fire” left unchecked can quickly overwhelm those unprepared for the complexity of legacy and AI convergence.
The legacy challenge in an AI world
While application delivery infrastructure isn’t new, it continues to play a critical role in ensuring that applications perform well, remain available, and stay secure, even in today’s complex and increasingly hybrid environments.
Application delivery controllers (ADCs), in particular, have continued to evolve with the times. While earlier generations focused on hardware-centric data centres and cloud migration, today’s modern application delivery platforms support hybrid and multi-cloud environments, including AI workloads. This evolution has led to infrastructure that combines traffic management with integrated security functions across environments — important when applications span multiple infrastructures.
However, the AI boom across APAC is creating significant blind spots in enterprise infrastructure. As organisations push to implement AI projects — open-source or otherwise — they often do so without proper integration.
One of the top concerns is shadow AI: when employees or teams deploy AI tools or models without approval or oversight from security or IT departments. Beyond creating unmonitored API endpoints and data flows, shadow AI significantly increases the risk of data exfiltration and introduces new vulnerabilities.
Breaches stemming from these blind spots have already occurred — incidents that might have been prevented with better visibility and control. These underscore the importance of securing digital tools and AI systems as part of a broader enterprise security strategy, with visibility across legacy, cloud-native, and AI platforms alike.
This is where advanced application delivery infrastructure can help, offering the centralised control needed to manage growing complexity across both traditional and AI systems.
Bridging two worlds: Building a unified security framework
APAC organisations face a dual challenge: securing traditional infrastructure while simultaneously protecting AI systems. Doing so requires strategies that address both conventional threats and AI-specific vulnerabilities, particularly those related to LLMs and exploits such as model context protocol manipulation.
The way forward lies in unified security frameworks that maintain consistent policies across all environments, including on-premises, cloud, and edge deployments. By integrating security and performance within a single platform, modern application delivery solutions can support the intersection of legacy and AI systems.
Beyond technology, these frameworks can also help dissolve organisational silos between development and security teams. When security becomes an embedded operational component rather than a separate function, protection is integrated from the outset, rather than bolted on later.
After the smoke clears: The future of APAC security
The collision of legacy systems with AI-driven innovation is introducing new security challenges, but also creating opportunities. Organisations that address existing security debt while embracing innovation will not just navigate this transition; they will accelerate through it.
If your security strategy has remained largely unchanged over the past two years, consider this a wake-up call. Your attack surface has already evolved, and that change is accelerating as AI projects move from pilot to production. Many enterprise applications are beginning to incorporate AI features, increasing complexity and risk exposure across environments. While some organisations are still reacting to yesterday’s threats, others are beginning to reshape their security posture around platforms designed to bridge legacy and modern systems. For these organisations, modern application delivery capabilities are not just defences; they are enablers of faster, safer innovation.
When the smoke from the “ball of fire” finally clears, these organisations will not simply have endured. They will be helping define what enterprise security looks like in one of the world’s most dynamic and competitive regions. The question is not whether you will need to adapt, but whether you will do it in time.



