Press ReleaseGovernance & Compliance

Singapore Has the Lowest Automated Threat Validation Rate of Any Country Surveyed—New Global Research Finds

Filigran’s inaugural State of Threat Management report finds that only 18% of Singapore organisations surveyed use automated threat validation—the lowest rate among countries in the study. 98% of Asia Pacific respondents face at least one barrier to improving their exposure management.

Filigran, the open-source threat management company, today released its inaugural State of Threat Management report, based on an independent survey of 550 senior cybersecurity decision-makers and practitioners across eight countries. The findings reveal a striking paradox at the heart of Asia Pacific’s foremost digital and financial hub: despite Singapore’s status as a global leader in financial services technology and critical infrastructure, its organisations rank last among the eight countries surveyed in automated threat validation and consolidated cyber risk visibility.

The research was conducted independently by Vanson Bourne between February and March 2026, and surveyed organisations with a minimum of 1,000 employees across financial services, technology, government, energy, healthcare, and retail sectors in the United States, Canada, the United Kingdom, France, Germany, the UAE, Australia, Japan, and Singapore. Singapore contributed 50 respondents.

Singapore: A Paradox at the Heart of APAC Cybersecurity

The data from the report reveals a structural disconnect between Singapore’s cybersecurity ambitions and its operational reality. On the two most critical metrics—automated validation and consolidated risk visibility—Singapore sits at or below every other country in the study.

Singapore at a Glance—State of Threat Management 2026

● 18% of Singapore organisations use threat intelligence within a continuous, fully automated validation process—the lowest of all 8 countries surveyed (global average: 38%; North America: 51%)
● 24% have a fully consolidated view of cyber risk exposure—joint lowest with the UK (global average: 41%; North America: 52%)
● 98% of Asia Pacific respondents face at least one barrier to improving their exposure management—the highest regional rate in the global study
● 34% have a fully established CTEM programme—compared to 58% in North America and 48% in Australia

Singapore’s barriers are operational and technical, not strategic.
The top barriers reported by Singapore respondents are integration with existing tools or processes (62%), lack of visibility or validation into real-world risk (52%), limited staff capacity (42%), and budget constraints (42%).

Notably, only 22% of Singapore respondents cite a lack of executive or leadership buy-in as a barrier. That is significantly below the global average of 33% and well below Australia’s 48%, demonstrating that Singapore’s leadership is engaged. The problem is the tooling and the workflows that connect intelligence to action.

Singapore’s Operational Exposure: What the Data Shows

The finding that 100% of Singapore respondents face barriers to improving their exposure management is the most striking single data point in the study. It stands alone: the next closest countries are Canada and Japan at 98%, while the global average is 94%, and North America reports 92.5%.

The 18% automated validation rate places Singapore nearly three times below the North American rate of 51%, and below the already underperforming Asia Pacific regional average of 27%. Combined with a consolidated risk visibility rate of 24% (against a global average of 41% and a North American rate of 52%), the data suggests that Singapore organisations are not only starting from a lower operational baseline than their global peers, but that they face a higher density of structural barriers to closing that gap.

Only 34% of Singapore organisations have a fully established CTEM programme, a figure that rises to 58% in North America. A further 54% describe their CTEM capability as partially established, and 12% have either no programme or no plans to build one.

The Broader APAC Picture

The Singapore findings sit within a broader Asia Pacific pattern but represent the most acute expression of a regional problem.

Across Asia Pacific, the study found a 66.7-percentage-point gap between the belief that automation is essential (94% of APAC respondents) and its actual deployment (27.3%). These figures represent the widest belief-adoption gap of any region surveyed, and nearly 20 points wider than North America’s equivalent figure.

Within the Asia Pacific region, country-level findings reveal distinct failure modes:
● Singapore combines the region’s lowest automated validation rate with its worst consolidated risk visibility and the highest barrier prevalence of any country globally
● Japan has the lowest CTEM maturity of any country in the study (22% fully established), but relatively stronger risk visibility within APAC (38%)
● Australia’s primary challenge is executive buy-in: 48% of Australian respondents cite lack of leadership support as a barrier, more than double Singapore’s equivalent figure (22%)

Global Findings: Visibility Without Action

The full global dataset of 550 respondents reveals a security landscape characterised by abundant data and insufficient operationalisation. Key global findings include:
● Only 41% of organisations globally have a fully consolidated view of their cyber risk exposure
● 84% say the attacks they face often exploit vulnerabilities that are already known but not prioritised
● 97% report difficulties determining whether exposures are actually exploitable
● 88% agree that without greater automation, it is difficult for security teams to keep up with the volume of risks they need to assess
● Security teams spend, on average, 42% of their time investigating potential risks that later prove to be low priority or not exploitable
● The majority of organisations take longer than a day to detect (72%), respond (71%), and remediate (83%) security incidents
● Only 38% of organisations use threat intelligence within a continuous, fully automated validation process—a figure that falls to 27% across Asia Pacific and 18% in Singapore

Regulatory Context

The Singapore findings arrive against a backdrop of tightening regulatory obligations. The Monetary Authority of Singapore’s 2021 Technology Risk Management Guidelines require financial institutions to engage cyber intelligence monitoring services actively, analyse threat intelligence on an ongoing basis, and conduct regular scenario-based exercises to test incident response—capabilities that depend directly on the kind of continuous validation the survey finds Singapore organisations are least likely to have deployed. At the same time, the Cybersecurity (Amendment) Act 2024, whose key provisions came into force on 31 October 2025, now requires owners of Critical Information Infrastructure to report certain cyber incidents to the Cyber Security Agency within two hours of detection. The CSA has separately mandated that CII owners achieve Cyber Trust Mark Level 5 certification by the end of 2027.

Spokesperson Quotes

Kevin Vanhaelen, SVP Asia Pacific and Japan, Filigran, said: “All Singapore respondents in this study face at least one barrier to improving their exposure management, which indicates issues with tooling and integration. Filigran’s solutions give security teams a platform that meets data sovereignty requirements, connecting threat intelligence to validation to remediation in a single, continuous workflow, without requiring a 50-person Security Operations Centre (SOC) or a three-year implementation programme to see value.”

Kelvin Chin, ASEAN Director, Filigran, said: “Filigran’s open-source model makes it accessible for teams at any stage of the journey. You do not need to have everything figured out before you start. You start with a flexible system of record for Threat Intelligence, understand what is actually targeting your environment, and you build from there. The data tells us Singapore is behind on this. The good news is that the starting point aggregates what you already have, correlates, and operationalises towards a cost-efficient CTEM programme.”

About the State of Threat Management Report

Filigran’s State of Threat Management report is based on an independent quantitative survey commissioned by Filigran and conducted by Vanson Bourne between February and March 2026. The study surveyed 550 senior IT security decision-makers and practitioners across organisations with a minimum of 1,000 employees in the United States (150), Canada (50), France (50), Germany (50), the United Kingdom (50), Australia (50), Singapore (50), Japan (50), and the UAE (50). Respondents spanned financial services, technology, government and public sector, energy and utilities, healthcare, and retail sectors. The full report is available here.

About Filigran

Filigran, a cybersecurity company, delivers a unique open-source, threat-informed approach to Continuous Threat Exposure Management (CTEM). Underpinned by an agentic foundation, Filigran’s eXtended Threat Management (XTM) platform delivers proactive security by combining threat intelligence, exposure validation, and cyber risk quantification. The platform includes OpenCTI, OpenAEV, and OpenGRC (forthcoming).

About Vanson Bourne

Vanson Bourne is an independent specialist in market research for the technology sector. Their reputation for robust and credible research-based analysis is founded upon rigorous research principles and their ability to seek the opinions of senior decision-makers across technical and business functions, in all business sectors and all major markets.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *