Press ReleaseArtificial IntelligenceThreat Detection & Defense

65% of Surveyed APAC Organisations See an AI-Enabled Attack as Inevitable Within a Year

Mimecast Study Finds 79% Are Concerned About AI as an Attack Vector, While 60% Are Not Fully Prepared for Threats Exploiting Human Vulnerabilities

Asia Pacific, Mimecast, a leader in securing humans, data, and AI, today released new research showing that Asia Pacific organisations widely expect artificial intelligence (AI) to be used in attacks against them, while many are not fully prepared for threats that exploit human judgement.

The company’s State of Human Risk 2026 study found that 65% of surveyed IT and security decision-makers believe an AI-enabled attack against their organisation is inevitable within the next 12 months. The findings are based on responses from 500 IT security and IT decision-makers across Singapore and Australia.

Concern about the threat is widespread, with 79% of respondents saying they are worried about AI being used as an attack vector against their organisation.

However, 60% said their organisation was not fully prepared to handle AI-driven threats that exploit human vulnerabilities. This includes 52% who said they were somewhat prepared but still developing AI-specific defence strategies, and 9% who were aware of the threats but lacked a concrete strategy.

Employees are seen as a particular point of exposure. Two-thirds (66%) of respondents agreed that an employee within their organisation was very likely to be fooled by a cybercriminal using AI as part of a social engineering attack.

Mimecast said the findings demonstrate how AI-enabled cyber risk is placing greater pressure on employees to assess whether the communications and requests they receive are genuine.

“AI is changing the way cybercriminals manipulate trust,” said Nicky Choo, Vice President and General Manager, APAC, Mimecast. “Attackers can now use it to create convincing, tailored messages that appear to come from a colleague, a partner, or a senior leader, which means employees are being asked to make difficult decisions in real time. The challenge is no longer just stopping threats before they arrive. It’s helping people recognise when the interactions they rely on may have been manipulated.”

AI-Specific Employee Preparation Remains Limited

The study found that AI-specific training and simulations are not yet widespread among surveyed organisations.

Only 40% provide training on how to use AI while avoiding exploitation, while 42% conduct simulated AI-driven phishing attacks.

These results do not necessarily mean that other forms of cybersecurity training are absent, but they indicate that many organisations have yet to introduce measures specifically addressing AI-enabled threats.

“Employees should not be expected to identify increasingly sophisticated deception on instinct alone,” Choo said. “Yet many organisations have not yet caught up. Fewer than half are training staff on how to avoid AI-driven exploitation or running simulated AI phishing exercises. That leaves many employees making difficult judgement calls without the benefit of AI-specific preparation.”

Mimecast said the findings point to a broader need to treat human judgement as a core part of cyber defence, alongside technical controls, as AI continues to blur the line between legitimate and malicious communication.

Mimecast’s State of Human Risk 2026 study examines how human behaviour, insider activity, and organisational practices are influencing cyber risk across APAC, North America, and Europe, the Middle East, and Africa.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *