Seventy-nine percent of Singapore organizations surveyed for an ESET cybersecurity study reported experiencing at least one AI-related cyber threat in the past 12 months.

The ESET Enterprise Cybersecurity Report 2026 was commissioned by the cybersecurity vendor and conducted by Blackbox Research in the second quarter of 2026. It surveyed 400 cybersecurity decision-makers across organizations of different sizes and industries in Singapore.

The findings are self-reported and reflect the views of cybersecurity decision-makers rather than independently verified incident data.

Phishing and misuse among reported risks

According to the survey, 97 percent of respondents said their organisations were already using or piloting AI across business functions.

Forty-six percent reported AI-generated phishing or impersonation attacks, 41 percent cited exploitation of AI-powered tools such as prompt injection, and 39 percent reported AI-enabled deepfake or voice-cloning attacks.

The survey also found that around four in ten respondents had encountered employee misuse of generative AI or data leakage through AI platforms.

Only 49 percent said their organisations had measures in place to monitor AI tool access and outputs.

Incident response remains a broader issue

Beyond AI-specific threats, 71 percent of respondents said their organizations experienced at least one major cybersecurity incident during the previous year, while 25 percent reported three or more.

Cloud breaches, insider threats and data exfiltration were among the incidents reported. Fifty-five percent cited delayed detection as a challenge, while 49 percent pointed to limited visibility across IT environments and 41 percent reported shortages of cybersecurity skills.

Phishing and social engineering were the most commonly cited cause of incidents at 36 percent.

ESET said 43 percent of respondents planned to adopt managed detection and response services over the next 12 months, while 36 percent planned to obtain cyber insurance.

Account recovery as an identity problem: How to safely re-establish trust before a password reset