Kylie Watson, Head of Cybersecurity, DXC Technology, examines why Asia-Pacific is the world’s most attacked region and outlines the resilience strategies needed to counter growing cyber-risks.
During the past few decades, we’ve seen significant technological advancements that have impacted every industry and aspect of our lives.
However, this convergence of innovation has also created a perfect storm of opportunity for hackers, data breaches and other cybercrimes to occur. Attackers are exploiting security gaps in everything from remote work platforms to Smart Devices. Meanwhile, the widespread adoption of cloud computing, Artificial Intelligence and connected devices has created a larger attack surface and made it easier for even low-skilled hackers to launch increasingly sophisticated attacks.
This is leaving organisations everywhere scrambling to keep up. For example, in Australia there was a notable rise in cybercrime incidents during the 2022-2023 financial year with over 94,000 cybercrimes reported to law enforcement agencies – a 23 percent increase from the previous year. In Asia, cybercrime rates significantly increased from 2020 to the present day with the region becoming a prime target. In 2022, Asia-Pacific accounted for approximately 31 percent of global cyberattacks, making it the most attacked region in the world.
Navigating the increasing number of industry-specific cyberattacks is crucial, particularly in sectors such as government, healthcare, education, professional, utility services and telecommunications services. Ransomware attacks made up 11 percent of all incidents, an increase of 3 percent from 2022-2023.
This challenging cybersecurity environment prompted the Australian government to develop the 2023-2030 Australian Cybersecurity Strategy and introduce the Cybersecurity Act to address the increasing threats and vulnerabilities. Recent incidents in Asia-Pacific highlight the urgent need for a shift in strategies. For example, a major Australian airline was hit by a cyberattack that exposed the personal data of millions of customers. Meanwhile, Singapore is currently facing cyberattacks targeting critical infrastructure like power, water, telecommunications and transport.
Investing in resilience
The Australian government is already making strides in securing the nation’s cyber landscape and protecting critical infrastructure. By strengthening protections for individuals and businesses, addressing existing cyber-risks and enhancing its understanding of the evolving threat landscape, the government is taking a proactive approach to guiding security measures.
Efforts to combat cybercrime in Asia are also intensifying. ASEAN has implemented a Cybersecurity Strategy Plan focusing on cyber readiness, policy harmonisation and capacity building. The plan includes establishing an ASEAN Regional Computer Emergency Response Team by 2024.
Singapore and Malaysia are leading initiatives with Singapore launching public awareness campaigns like Better Cyber Safe than Sorry. The region is also enhancing co-operation with initiatives like the ASEAN Cybersecurity Resilience and Information Sharing Platform promoting threat information sharing between central banks.
There is also a push for improved national regulations, stronger leadership and continuous investment in cybersecurity measures across the region.
Overcoming advanced security implementation challenges
While many businesses recognise the importance of a zero-trust security approach, implementation challenges often hinder adoption. The complexity of zero trust is a significant barrier as it requires a complete understanding of an organisation’s data flows, resources and endpoints.
To make zero trust effective for critical infrastructure, resilience must be built into every layer of security. This means adopting a proactive approach that addresses vulnerabilities, ensures systems can recover quickly and limits the impact of breaches.
For example, when a breach occurs, it is crucial for leaders to conduct a thorough investigation and gather information from each part of the business to understand the full extent of the damage. By doing so, they can prioritise their efforts and allocate resources efficiently to minimise the impact.
If the breach affected customer data, leaders may need to notify customers, provide credit monitoring services and implement additional measures to prevent future incidents.
Preparing for what’s ahead
In 2025 and beyond, Artificial Intelligence will become a powerful tool for enhancing cybersecurity in Asia-Pacific. Businesses will increasingly use it to detect malicious activity in a system or network, spot anomalies or suspicious behaviours, automate responses and even secure AI models against various security threats.
However, alongside its advancements, AI brings forth a myriad of security challenges that cannot be ignored. For example, attackers have been successful at using methods like Deep Learning-powered deepfakes – a form of AI that can be used to create convincing hoax images, sounds and videos – to fool systems and trick people into trusting fake identities.
And with Asia-Pacific countries investing heavily in quantum computing, the same things that make this technology powerful also make current cryptographic defences vulnerable to cyberattacks.
These trends indicate that the future of cybersecurity in the region will be driven by advanced technologies, increased regulation, a growing emphasis on co-operation and trust-building measures and a zero-trust approach that protects applications and systems at every layer.


