When Innovation and Risks Collide: Hexnode and Asia’s Cybersecurity Paradox
Digitalisation Is Far Outgrowing Security, and It Is Putting Organisations, Especially Those in APAC, at Great Risk

Asia is undeniably home to some of the world’s fastest-growing digital economies, and this is precipitating progress and presenting the region with countless growth opportunities. But there is a trade-off that comes with a robust, ever-growing digital footprint: with this growing digital presence comes a vastly large and equally growing attack surface. Apu Pavithran, CEO and Founder of Hexnode, described this situation in an exclusive interview with Cybersecurity Asia as “a real paradox” where digitalisation has far outgrown cybersecurity—to the point that security measures have not kept pace at all with innovation.
The increase in the number and sophistication of attacks proves as much, with recent research revealing that the APAC region had the most cyberattacks in 2024. Ransomware, malware, and phishing continue to be the top threats, with ransomware particularly evolving into something more sinister than just encrypting data. Now, according to Pavithran, attackers use double and triple extortion tactics where they steal an organisation’s data, threaten to leak it publicly, and even disrupt critical business operations to force a payment. These tactics have been particularly effective in countries like Thailand, Indonesia, and Vietnam.
But there’s more reason to be worried, if not alarmed by this threat-filled cybersecurity landscape. Threats, Pavithran pointed out, have become more intelligent with the use of Artificial Intelligence (AI) while states themselves are also sponsoring massive attacks in cyberspace.
“We’re now seeing AI-generated phishing emails that are so well-crafted, they’re almost impossible to tell apart from legitimate ones. This allows them to bypass traditional defences. AI is also being used to create malicious code that can adapt and evade detection in real-time…,” Pavithran told Cybersecurity Asia. “Beyond the cybercriminals, we also see state-sponsored groups actively exploiting the cyberspace. These nation-state actors are conducting persistent cyber espionage campaigns to target intellectual property, government systems, and critical infrastructure. These aren’t simple smash-and-grab attacks; they are highly targeted and incredibly difficult for a standard enterprise to detect and defend against.”

Why Enterprises Remain Vulnerable
The question is this: Why do enterprises find it hard to defend cyber threats in the first place—even with a growing awareness of cyber risks. Pavithran identified four key reasons:
- The human element. Employees are often described as the first line of defence, but they can also be the weakest link. The global cybersecurity talent gap—estimated at 4.8 million unfilled roles by the ISC—means many organisations lack the expertise to build robust defences. Sophisticated social engineering tactics, from deepfakes to spear-phishing, exploit this weakness with alarming success.
- Legacy systems. Outdated software and unpatched systems provide fertile ground for attackers. Known vulnerabilities are actively scanned and exploited, often through supply chain compromises. In this instance, asmaller vendor with weaker defences can become the gateway to a larger enterprise.
- Reactive mindsets. Even with heightened cybersecurity risks, too many companies still focus on responding to breaches rather than preventing them. The statistics are sobering: IBM’s 2023 Cost of a Data Breach Report found that it takes an average of 277 days to identify and contain a breach. Attackers, by contrast, can move laterally across networks in hours. This means that while cyber criminals are already wreaking havoc, the victim organisation is likely still unaware that it has been breached.
- Fragmented regulation. Compliance standards vary across jurisdictions, creating what Pavithran calls a “compliance trap.” Organisations pour resources into ticking regulatory boxes, but this does not necessarily translate into better security. Greater alignment and consistency are needed to build true resilience.
The Strategic Imperative That Is Zero Trust

This situation, particularly in APAC, is certainly alarming. But it is not without solutions. One of these solutions is adopting a Zero Trust model whose premise is so simple yet so powerful: Never assume trust, always verify. Every access request, whether from inside or outside the network, must be authenticated and authorised.
“The way we work today has completely reshaped how we think about security. With hybrid work, employees are no longer confined to the office—they’re logging in from home Wi-Fi, hotel lobbies, coffee shops, and often on personal devices,” Pavithran noted. “All of that is well outside the corporate firewall, which means the old “castle-and-moat” approach—where everything inside the network was automatically trusted—just doesn’t hold up anymore. That’s where Zero Trust (ZT) comes in. Instead of assuming trust, ZT verifies every access request, no matter where it comes from or what device is being used. So, before anyone accesses sensitive resources, both the user and the device have to be authenticated and authorised.”
Put simply, Zero Trust prevents attackers from moving freely once they compromise an account. By segmenting networks and requiring re-authentication at each step, it dramatically reduces the options available to intruders.
“If you look at the way most cyberattacks happen today—take ransomware, for example—they often begin with one compromised account. From there, attackers try to move laterally across the network, hunting for high-value data or systems. By segmenting the network and requiring re-authentication at each step, ZT essentially blocks that free movement. It’s a “verify first, then grant access” philosophy, and it dramatically reduces the attacker’s options,” Pavithran explained.
Unfortunately, way to many organisations still view Zero Trust as a tool rather than a strategic framework. Others believe it requires ripping out existing infrastructure. In reality, however, Zero Trust can be implemented incrementally and is both adaptable and scalable. It integrates technologies such as multifactor authentication, microsegmentation, and identity and access management into a cohesive architecture. Crucially, Zero Trust is not a one-off project. It is a continuous process of monitoring, verification, and fine-tuning. As threats evolve, so too must policies and controls.
“Zero Trust isn’t a box you check and move on from,” Pavithran emphasised. “It’s a continuous, evolving process. Threats evolve, technologies evolve, and so do business needs. That means policies and controls need to be constantly reviewed and fine-tuned. It’s about continuous monitoring and ongoing vigilance—making sure that every access request, every single time, is both appropriate and secure.”
Best Practices for Implementation
For organisations still second guessing the wisdom of implementing the Zero Trust approach, Pavithran offered up this structured approach:
- Identify the crown jewels. Organisations must first determine their most valuable assets—data, applications, and services that attackers covet. Protecting these high-value targets is more effective than attempting to secure sprawling networks indiscriminately.
- Breaking networks into isolated zones limits the “blast radius” of a breach. Even if attackers penetrate one area, they cannot move laterally to others.
- Identity and Access Management (IAM). The principle of least privilege ensures users receive only the access rights necessary for their role. Just-in-Time access can further reduce risk by granting privileges temporarily.
- Endpoint management. Every device, whether corporate or personal, must be verified. Patch status, configuration, and malware checks are essential.
- Policy frameworks. Using methods such as the Kipling Method (Who, What, When, Where, Why, and How) helps define precise conditions under which access is granted.
These practices transform Zero Trust from a theoretical concept into a practical defence strategy.
Hexnode and Its Role in the Zero Trust Ecosystem
Hexnode, the cybersecurity company Pavithran himself founded, is incidentally a key enabler of Zero Trust. Its unified endpoint management solution establishes device trust by maintaining a comprehensive inventory of every device in an organisation. Then, continuous monitoring ensures that only compliant devices can access resources.

Granular control is central to Hexnode’s approach. Hexnode allows administrators to configure Wi-Fi networks and certificates, ensuring endpoints connect only to authorised networks. Web Content Filtering restricts access to approved sites, reducing exposure to phishing and malware.
Continuous verification is then supported by Hexnode’s compliance engine, which enforces multi-condition rules. Integration with Microsoft Intune and Okta Device Trust enhances conditional access, ensuring that even correct credentials cannot bypass device compliance checks.
Finally, Hexnode addresses data exfiltration. By restricting transfer functions and supporting containerisation, it separates corporate data from personal data—a vital feature in Bring Your Own Device (BYOD) environments.
The Bigger Picture and What Lies Ahead
The cybersecurity paradox in Asia is not merely a regional issue; it is a global concern. As the region continues to drive digital innovation, its vulnerabilities have implications for supply chains, financial systems, and geopolitical stability.
As Pavithran emphasised to Cybersecurity Asia, the future of cybersecurity lies in proactive, continuous, and adaptive strategies. Zero Trust is not a silver bullet, but it is a powerful framework for resilience. Companies that embrace it will not only protect themselves but also contribute to the stability of the digital ecosystem on which modern economies depend.
The stakes could not be higher. In a world where data is currency and trust is fragile, the ability to defend against unseen adversaries may well determine the winners and losers of the digital age.



