SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Singapore lags in automated cyber threat validation

Singapore lags in automated cyber threat validation

Wed, 23rd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Filigran has published a global threat management report showing that Singapore had the lowest rate of automated threat validation among the countries surveyed. The study also found that every respondent in Singapore reported at least one barrier to improving cyber exposure management.

Conducted by Vanson Bourne, the survey covered 550 senior cybersecurity decision-makers and practitioners at large organisations across several markets, including 50 respondents in Singapore.

Singapore recorded an automated threat validation rate of 18%, compared with a global average of 38% and 51% in North America, the report found. Only 24% of respondents in Singapore said they had a fully consolidated view of cyber risk exposure, tying the city-state with the UK and placing it well below the US figure of 52.7%.

The data points to a gap between strategy and day-to-day operations in Singapore. Leadership support did not appear to be the main obstacle. Instead, respondents cited difficulties integrating existing tools and processes, limited visibility into real-world risk, constrained staffing, and budget pressure.

Integration with existing tools or processes was the most common barrier in Singapore, cited by 62% of respondents. A lack of visibility or validation into real-world risk followed at 52%, while 42% pointed to limited staff capacity and the same proportion cited budget constraints.

By contrast, only 22% of respondents in Singapore said a lack of executive or leadership buy-in was a barrier. That was below the global average of 33% and less than half the level reported in Australia, where 48% cited leadership support as an issue.

Regional gap

The findings also point to a broader pattern across Asia-Pacific. While 94% of respondents in the region believed automation would strengthen cybersecurity efforts, only 27.3% were using it. Filigran described this as the widest gap between belief and deployment of any region surveyed.

Across Asia-Pacific, 98% of organisations reported at least one obstacle to improving exposure management. Singapore stood out because every respondent reported barriers, making it the only country in the survey with a 100% rate on that measure.

The study assessed Continuous Threat Exposure Management, or CTEM, programmes as one marker of operational maturity. In Singapore, 34% of organisations said they had a fully established CTEM programme, compared with 58% in North America. Another 54% described their programme as partially established, while 12% said they had no programme or no plans to build one.

Japan showed a different pattern in the regional results. It had the lowest CTEM maturity in the study, with 22% reporting a fully established programme, though it posted stronger risk visibility than Singapore within Asia-Pacific at 38%. In Australia, the main weakness was leadership backing rather than tooling.

Global picture

Across the full sample, the report described a security environment in which companies have large volumes of data but struggle to turn it into action. Only 41% of organisations globally said they had a fully consolidated view of their cyber risk exposure.

According to the findings, 84% of respondents faced attacks that often exploited vulnerabilities already known but not prioritised. Another 97% had difficulty determining whether exposures were actually exploitable, while 88% agreed that without greater automation, security teams struggled to keep up with the volume of risks they needed to assess.

Security teams spend an average of 42% of their time investigating risks that later prove to be low priority or not exploitable. Most organisations also took more than a day to detect, respond to, and remediate incidents.

The report placed the results in a regulatory context for Singapore, where financial institutions are expected to actively monitor cyber intelligence and run scenario-based exercises under technology risk management rules. Owners of critical information infrastructure also face strict reporting requirements for certain incidents after detection.

Kevin Vanhaelen, SVP, Asia Pacific and Japan, Filigran, commented on the Singapore findings. “All Singapore respondents in this study face at least one barrier to improving their exposure management, which indicates issues with tooling and integration. Filigran's solutions give security teams a platform that meets data sovereignty requirements, connecting threat intelligence to validation to remediation in a single, continuous workflow, without requiring a 50-person Security Operations Centre or a three-year implementation programme to see value,” Vanhaelen said.

Kelvin Chin, ASEAN director, Filigran, also addressed the data. “Filigran's open-source model makes it accessible for teams at any stage of the journey. You do not need to have everything figured out before you start. You start with a flexible system of record for Threat Intelligence, understand what is actually targeting your environment, and you build from there. The data tells us Singapore is behind on this. The good news is that the starting point aggregates what you already have, correlates and operationalises towards a cost-efficient CTEM programme,” Chin said.