As many as 65 percent of IT and security decision-makers in Singapore and Australia believe an AI-driven attack against their organizations is inevitable within the next 12 months, yet only 40 percent report being fully prepared with specific strategies for AI-driven threats.

UK-based cybersecurity company Mimecast revealed the “critical vulnerability” in its annual State of Human Risk report. The study surveyed 500 IT security and IT decision-makers across Singapore and Australia, as part of a broader global survey of 2,500 respondents across nine countries conducted in November and December 2025.

Concern about AI-driven threats is widespread, with 79 percent of respondents saying they are worried about AI being used as an attack vector. However, 60 percent said their organizations are not fully prepared to handle AI-driven threats that exploit human vulnerabilities. The figure included 52 percent are “somewhat” prepared but still developing AI-specific defense strategies and 9 percent are aware of the threats but lacked a concrete strategy.

Employees are seen as a particular point of exposure. Two-thirds of respondents agreed that an employee within their organization was very likely to be deceived by a cybercriminals utilizing AI.

AI-specific training and simulations are not yet widespread among surveyed organizations. Only 40 percent provide training on how to use AI while avoiding exploitation, and 42 percent conduct simulated AI-driven phishing attacks.

Nicky Choo, Vice President and General Manager for APAC at Mimecast, said AI enables attackers to create convincing, tailored messages that appear to come from colleagues, partners, or senior leaders, placing employees under pressure to make difficult real-time judgement calls. Fewer than half of organisations are training staff on how to avoid AI-driven exploitation or running simulated AI phishing exercises, leaving employees without AI-specific preparation, the executive added.

Beyond Singapore and Australia, the global figure is 69 percent.

Respondents estimate the average cost of a single insider-driven data exposure, loss, leak, or theft event at $13.1 million. For organizations experiencing an average of six such incidents per month, the report calculates a projected annual insider risk exposure of $943.2 million.

Harnessing AI in cybersecurity: Ways companies can stay ahead of AI-driven threats