SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Singapore's security teams are losing a race they don't know they're running

Singapore's security teams are losing a race they don't know they're running

Thu, 27th Aug 2026 (Today)
Kelvin Chin
KELVIN CHIN Regional Director - Asia Filigran

Singapore consistently punches above its weight on almost every measure of a mature digital economy, from financial competitiveness and digitalisation to regulatory sophistication. Cybersecurity is no exception. Boards take the risk seriously. CISOs have the mandate and budgets to act. Regulators are among the most forward-thinking in the world. 

Which makes it all the more striking that Singapore ranked last among eight markets surveyed on the measures that matter most for automated cyber defence.

Filigran's inaugural State of Threat Management report surveyed 550 senior security decision-makers across eight countries, including 50 in Singapore, and assessed organisations across two capabilities that underpin automated cyber defence: automated threat validation and consolidated risk visibility.

On both measures, Singapore ranked lowest among the markets surveyed. Only 18% of Singapore respondents reported using a continuous, automated process to validate whether their defences could withstand relevant threats, compared with a global average of 38% and 51% in North America. Alongside that, just 24% said they had a fully consolidated view of their cyber risk exposure, versus a global average of 41%. 

If this were a story about disengaged leadership or underfunded teams, the explanation would be straightforward. But only 22% of Singapore respondents cited a lack of executive buy-in as a barrier, well below the global average of 33% and less than half of Australia's 48%. The intent is there. Something else is getting in the way. The findings suggest the issue may lie less in intent than in execution.

From threat awareness to threat readiness 

Most organisations have established processes for collecting cyber threat intelligence. The challenge is often not gathering threat intelligence but operationalising it in a way that enables faster, more confident decisions. That means translating awareness of threats into a continuous, tested understanding of an organisation's own exposure.

When a significant vulnerability is disclosed, or an indicator of compromise is flagged, a security team needs to answer three questions quickly: Does this affect us? How exposed are we? And are our existing defences capable of stopping an attack that exploits it? In many organisations, answering those questions still requires manual investigation across multiple systems.

The operational impact is reflected in the survey findings. Globally, security teams reported spending an average of 42% of their time investigating risks that ultimately prove to be low-priority or irrelevant to their environment. In a region where cybersecurity talent remains in short supply, such inefficiencies can place additional strain on already stretched security teams.

A framework gaining traction is Continuous Threat Exposure Management, or CTEM. The name is technical; the idea is not. Rather than treating cyber risk as something you assess periodically and hope remains accurate, CTEM makes threat identification, exposure assessment, defence validation, and remediation prioritisation a continuous, automated cycle. The goal is simple: organisations should know at any given moment which threats are relevant to them, how exposed they actually are, and whether their defences would hold. 

In practice, organisations adopting CTEM seek to complement risk assessments with continuous validation and testing, enabling security teams to make decisions based on observed exposure rather than assumptions alone.

Why the regulatory context matters

Regulators have steadily raised the bar on what organisations are expected to demonstrate, including timely incident reporting, continuous threat monitoring, and regular testing of security controls to ensure they work.

Each of these obligations rests on the same foundation: validating your exposure and being able to move fast when something goes wrong. That becomes acutely difficult when a security team must manually piece together information from multiple disconnected systems before it can even begin to assess what has happened – let alone report it within a two-hour window.

The barriers to automation

Organisations across the Asia Pacific largely agree that automation can strengthen cybersecurity, but most have not yet adopted it. This disconnect between recognition and implementation (a 67-percentage-point gap) is the largest of any region surveyed. For respondents from Singapore specifically, the barriers are identifiable and instructive.

For organisations in Singapore, the barriers are operational, not strategic. The top challenge, cited by 62% of respondents, is integrating disparate security tools and systems. Close behind it: the difficulty of determining which vulnerabilities represent genuine, exploitable risks (52%), and skills and capacity constraints cited by around four in ten respondents. 

None of these issues are insurmountable. But together, they create a compounding drag: fragmented tools make it harder to see the full picture, gaps in visibility make it harder to prioritise, and stretched teams have less capacity to fix either. The result is an organisation that is working hard but moving slowly; precisely the wrong posture when threats move at machine speed.

While CTEM does not address every barrier identified in the survey, it is intended to help organisations improve visibility into cyber exposure, validate which risks are most relevant, and establish more continuous security processes.

Among the 50 Singapore organisations surveyed, only one-third reported having a fully established CTEM programme. This suggests a substantial gap between current cybersecurity practices and the expectations set by emerging regulatory requirements, with organisations facing increasing pressure to close that gap in the years ahead.

Singapore's challenge is not a lack of awareness, executive support or regulatory pressure. The survey makes that plain. The gap lies between recognising the value of automated cyber defence and embedding it into day-to-day security operations. The organisations that close that gap first - that stop accumulating isolated tools and start connecting them into a coherent, continuous system - will be more resilient, more compliant, and better placed to compete. The regulatory clock is already running. The question is not whether to act, but how quickly.