Ask most executives where their next major cyber incident will come from, and they will point outward, toward ransomware syndicates, nation-state operatives, or sophisticated phishing campaigns engineered to exploit a single distracted employee. The threat, in the corporate imagination, always arrives from beyond the walls. The data tells a different story.
New research from Fastly reveals that software bugs contributed to 54% of cyber incidents across Asia Pacific in 2025, surpassing external attackers, which accounted for 43%. It is a striking inversion, and one that points directly to a tension most organisations have yet to honestly confront: that the faster they build, the more exposed they become – often to themselves.
Research from Fastly found that software bugs contributed to 54% of cyber incidents across Asia-Pacific in 2025, surpassing external attackers, which accounted for 43%. It is a striking inversion, and one that points directly to a tension most organisations have yet to confront: The faster they build, the more exposed they become, often to themselves.
Speed without guardrails is a liability
The rise of AI-assisted development has dramatically compressed release cycles while quietly expanding operational complexity. Sometimes called “vibe coding,” this approach has reshaped how engineering teams work, but not always in ways that benefit security. Fastly’s research found that many senior developers believe a significant portion of productivity gains is being consumed by the time and effort required to diagnose and repair code that AI generated in the first place.
More code, infrastructure changes, and automation inevitably create more opportunities for mistakes to enter production environments. As organisations race to ship new digital services and AI-enabled products, the central security question is whether those systems are being introduced safely.
Scale amplifies self-inflicted risk
The core problem is not that AI-generated code is inherently insecure. It is that compressed timelines, combined with insufficient review processes, substantially raise the odds that defects, vulnerabilities, or misconfigurations will slip through. Development teams under delivery pressure routinely deprioritise code review, testing rigour, and resilience planning in favour of shipping.
The consequences scale accordingly. Fastly’s research found that organisations with more than 10,000 employees averaged 57 cyber incidents in 2025, nearly 40% above the overall mean of 40 incidents. Larger budgets and broader security tooling do not necessarily compensate for flawed development and release practices, and, in many cases, they simply create larger and more complex environments where errors can occur.
Modern enterprises operate across sprawling environments built on cloud platforms, API dependencies, third-party integrations, and automated deployment pipelines. As AI-driven tooling accelerates the pace of change across all of those layers simultaneously, the probability that bugs or configuration errors escape detection before reaching production rises considerably.
The impact of those failures rarely stays contained within engineering. A single faulty deployment can trigger outages, expose sensitive data, or invite regulatory scrutiny well before the team responsible has finished its post-mortem. Reputational damage and loss of customer confidence tend to follow quickly.
What makes this particularly significant is that governance gaps and weak operational controls can create serious vulnerabilities entirely independent of any malicious external actor. Organisations do not need an adversary to suffer a damaging incident. The conditions for one can be built into their own development and release practices.
Security must live where the risk is built
Many organisations still structure cybersecurity around centralised security teams focused primarily on compliance checks, perimeter defences, and incident response. However, the sources of modern security risk increasingly sit elsewhere: in source code repositories, infrastructure-as-code templates, continuous integration and continuous delivery (CI/CD) pipelines, and AI-enabled development workflows.
Still, few Asia-Pacific organisations have shifted security responsibilities towards platform engineering or DevOps teams, despite the growing role that bugs and misconfigurations play in incidents.
A more resilient operating model embeds security directly into software delivery processes. Instead of operating as a separate gatekeeping function, security teams work alongside engineering and platform teams to influence architectural decisions, tooling choices, and AI adoption policies from the outset.
This also requires clearer governance. Policies governing code review, testing, and deployment approval need to apply equally to AI-generated and human-written code. Under delivery pressure, these controls are often treated as optional rather than essential.
Ownership gaps remain a stubborn obstacle. Fastly found that more than 31% of AI-first organisations are still unclear about who owns incident response, and those businesses were significantly more exposed to cybersecurity risks than their peers. Establishing clear accountability for escalation procedures and incident handling before systems go live transforms governance from a reactive formality into an operational control.
Stop bolting security on and start building it in
Building security in from the beginning rather than retrofitting it later is not a new idea. What is new is the cost of ignoring it. Many Asia-Pacific organisations currently prioritise speed to market over resilience, placing fragile systems under sustained pressure regardless of how much they invest in security tooling downstream.
The exposure is not hypothetical. Gartner warned last year that by 2027, more than 40% of AI-related data breaches will stem from the improper use of generative AI across borders. For Asia-Pacific organisations operating across multiple regulatory jurisdictions, that is not a distant risk to be managed later. It is a governance problem that needs addressing now.
A genuine secure-by-design approach demands earlier involvement. Security architects and technology leaders need to shape how AI is integrated into products and development pipelines before those decisions harden into technical debt.
Resilience and innovation speed are not in opposition. Organisations that invest in resilience initiatives believe they can accelerate innovation more safely as a result. When done well, these practices reduce dependence on individual developers catching every issue manually, while allowing organisations to move with confidence.
AI systems deserve particular attention. They should be treated as privileged assets from day one, subject to strong access controls, continuous monitoring, and rigorous change management across their full operational lifecycle.
Resilience and speed are not a trade-off
The faster AI accelerates development velocity, the more visible and costly these internal weaknesses become. Keeping security structurally separate from engineering while relying on perimeter controls to carry the load is a reliable way to accumulate hidden risk at scale.
The more durable path is to treat software errors as first-class security risks and redesign delivery practices around that reality. Embedding security into engineering workflows and investing in resilience earlier in the lifecycle reduces operational fragility without sacrificing momentum.
In an era defined by AI-driven competition, long-term advantage will belong to organisations that can deploy new capabilities consistently without eroding the customer trust that everything else depends on.
















