SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Endpoint gaps cost Southeast Asian firms over USD $1m

Endpoint gaps cost Southeast Asian firms over USD $1m

Fri, 14th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Tanium has published research on endpoint management risks facing organisations in Southeast Asia, finding that some businesses lost more than USD $1 million from endpoint-related incidents.

The survey of 333 senior IT and security professionals in Singapore, Indonesia, Thailand, Malaysia and the Philippines points to operational disruption, patching delays and weak visibility over connected devices.

Across the region, 62% of organisations said endpoint issues had caused operational disruption. Among those affected, 63% reported downtime, 41% reported data exposure and 31% reported revenue loss.

The financial impact was significant for many respondents. Among organisations that suffered losses, 46% put the cost above USD $100,000, 17% reported losses above USD $500,000 and some exceeded USD $1 million.

The findings also suggest many companies do not have a full view of the devices connected to their systems. While 59% of respondents said they were very confident in their ability to track devices, 43% also said more than 10% of their endpoints were unknown, unmanaged or non-compliant. A further 13% said more than 30% of their endpoints fell into that category.

Real-time monitoring remains a weak point. Only 29% of organisations said they could detect a critical issue within minutes, while 55% said identifying a single threat indicator takes hours. Overall, 71% said they could not detect critical issues as they happen.

Patch delays

The research found similar delays in addressing vulnerabilities. Only 16% of respondents said they could patch critical vulnerabilities across most of their systems within 24 hours, while 60% said they still depend on partially automated processes.

Audit preparation also appears slow for many organisations. Half of those surveyed face quarterly IT asset audits, yet only 50% said they could prepare audit-ready data in less than a week. Another 46% said the process takes between one and four weeks.

The report links those delays to sectors with heavy reliance on legacy systems and complex infrastructure. In healthcare, older clinical equipment is being connected to enterprise networks. In financial services and telecommunications, patching and fault isolation can be constrained by the need to avoid service interruptions.

Singapore was cited as one market where compliance expectations are tightening, particularly for public sector bodies and operators of critical infrastructure. Manual audit preparation is leaving some organisations behind those expectations, according to the report.

Budget focus

Spending plans suggest boards are paying closer attention to the issue. According to the survey, 79% of respondents plan to invest in new security solutions within the next 12 months.

Respondents' main complaints were poor visibility, slow response times and the use of too many disconnected tools. The results suggest that, for many organisations, the problem lies less in overall spending than in fragmented systems and processes.

The study was commissioned by Tanium and carried out by PureProfile in early 2026. Respondents included management and IT operational managers, IT directors, vice presidents, heads of department and C-suite executives such as chief information officers and chief information security officers.

Commenting on the findings, Satyen Desai, RVP, ASEAN, Tanium, said: "Geopolitical conflict has gone digital, while AI is accelerating both innovation and attacks. The devices connecting it all are increasingly outside the visibility of the teams responsible for protecting them."

Desai added: "This research reaffirms what we hear from customers across the region. The gap between confidence and actual control is real, it is widening, and it is expensive. Organisations that consolidate onto a unified platform, automate their response cycles, and build continuous compliance into their operations are already seeing the difference. The question for every leader in this region is whether they act before an incident forces their hand."