How large is the cybersecurity market in 2026, and is the money buying safety? The direct answer: Gartner forecasts worldwide end-user spending on information security of US$239.8 billion in 2026, up 12.5% on 2025; the Verizon 2026 Data Breach Investigations Report finds that vulnerability exploitation opens 31% of breaches and a third party is involved in 48%; IBM puts the global average breach cost at US$4.99 million; and Cisco finds that only 4% of organisations reach the top tier of its readiness index. Spending is compounding. Readiness is not. The gap between the two is the entire subject of this outlook.

Outlook at a glance: Market: US$239.8bn forecast information-security spend in 2026 (Gartner, July 2025; revised to about US$244bn in September 2025) · Entry: 31% of breaches begin with vulnerability exploitation, 48% involve a third party (Verizon DBIR 2026) · Speed: 29-minute average eCrime breakout, fastest lateral move 27 seconds (CrowdStrike) · Cost: US$4.99m average breach (IBM), but a median insured claim of US$38,000 for firms under US$25m revenue (Verizon Breach Impact Study) · Readiness: 4% mature (Cisco), 59% report critical or significant skills gaps (ISC2) · Singapore: ransomware cases reported to CSA rose to 165 in 2025, phishing reports fell 21% to about 4,800.

This outlook rebuilds an executive market and risk report dated 11 August 2026 against its primary sources. Nine clusters of claims — Verizon, IBM, Gartner, CrowdStrike, Mandiant, Microsoft, Chainalysis, the survey houses, and the regulators — were checked against the original research, with a second adversarial pass on anything that did not confirm on the first attempt. Most of the report held. Five claims did not, and the corrections are stated in the open, in the section on how to read these numbers. Where a figure could not be traced to a primary source, it is not printed here.

Where the money goes: US$239.8 billion, and a forecast that keeps moving

Gartner's July 2025 forecast puts worldwide end-user spending on information security at US$239.8 billion in 2026, against US$213.0 billion in 2025 and US$193.4 billion in 2024 — growth of 12.5% year on year. The 2026 composition splits three ways: security software at US$121.2 billion, security services at US$92.8 billion and network security at US$25.8 billion. Software takes just over half the market; services take almost two-fifths.

Segment2024 (US$m)2025 (US$m)2026 (US$m)
Security software94,960105,940121,154
Security services77,13083,81292,780
Network security21,31723,27325,825
Total193,408213,025239,759

Table 1 — Gartner, “Forecasts Worldwide End-User Spending on Information Security to Total $213 Billion in 2025”, 29 July 2025. Forecast, not audited market revenue.

One caveat matters more than the headline. That US$239.8 billion is a July 2025 vintage, and Gartner has revised it upward since: a September 2025 update raised 2026 to about US$244 billion at 11.6% constant-currency growth, and further updates followed through the first half of 2026. Any figure quoted from this market without its forecast date is a figure quoted carelessly. Treat the number as a directional read on demand, not a settled measurement of revenue.

The composition tells you more than the total. Growth is not concentrated in more alerts; it is concentrated in control of attack surfaces that change daily and in evidence that controls actually operate. Cloud security posture management, identity and entitlement controls, data-security posture, application and API protection, software supply-chain assurance, exposure management and managed detection all answer that demand. At the same time, buyers are rationalising overlapping endpoint, network, cloud and security-operations tools. Platforms win where they genuinely improve telemetry and workflow; specialists keep their value where depth, independence or adversarial expertise is the product.

The attack surface is a dependency graph, not a perimeter

The most consequential shift in the 2026 DBIR is that patchable software has overtaken stolen credentials as the way in. The Verizon 2026 DBIR — which analyses breaches in the year to 31 October 2025 — puts vulnerability exploitation at 31% of breaches as an initial access vector, up from 20% in the 2025 edition. Third-party involvement reaches 48% of breaches — a 60% rise on the prior edition's 30% — and ransomware appears in 48%, up from 44%.

Google Cloud's Mandiant, working from a different population (incidents it was hired to investigate rather than reported breaches), reaches a compatible conclusion: exploits led at 32% of investigated intrusions, followed by voice phishing at 11%, prior compromise at 10% and email phishing at 6%. Two datasets, two methodologies, one direction of travel.

Initial access pathVerizon DBIR 2026Verizon DBIR 2025Mandiant M-Trends 2026
Vulnerability exploitation31%20%32%
Third-party involvement48%30%not measured this way
Ransomware present in breach48%44%not measured this way
Voice phishing (vishing)not broken outnot broken out11%
Prior compromisenot broken outnot broken out10%
Email phishingnot broken outnot broken out6%

Table 2 — Verizon DBIR 2026 and 2025; Google Cloud / Mandiant M-Trends 2026. The two sources draw on different incident populations and are not directly additive.

The practical consequence is that the inside-versus-outside model has stopped describing reality. A payroll provider, a SaaS administrator with tenant-wide rights, a long-lived cloud token, an API key committed to a repository, a remote-management agent and an unpatched edge appliance are each a viable enterprise entry point. A control map that follows network boundaries will miss all six. A control map that follows identities, data and business processes across organisational boundaries will not.

This is also why supplier due diligence without technical containment fails. A completed questionnaire does not constrain what a compromised supplier account can reach. Contractual rights, least-privilege integration, named individual accounts, continuous monitoring, emergency revocation, exit plans and rehearsed recovery have to work together. Our enterprise cybersecurity buyer's guide sets out how that translates into an actual scope of work.

Why speed has become a control requirement

CrowdStrike reports an average eCrime breakout time of 29 minutes in 2025 — the interval between initial compromise and lateral movement — with the fastest observed lateral movement at 27 seconds. It also reports that 82% of detections were malware-free, relying on legitimate tools and valid credentials rather than a dropped binary, and that cloud-conscious intrusions rose 37%.

Mandiant measures a different handoff and finds it collapsing faster still: the median time between an initial access event and handoff to a secondary threat group fell from more than eight hours in 2022 to 22 seconds in 2025. Note the word median — this is not an average, and it is not the fastest case. It is the midpoint.

What this changes: A next-business-day escalation path and a human-only triage queue are not slow. They are structurally incompatible with a 29-minute breakout and a 22-second broker handoff. The governance question is not whether to automate, but which actions may execute without a human, under what policy, with what evidence trail, and how they are reversed.

Organisations do not need to automate every decision. They need high-confidence automation around a short list: containment, credential revocation, malicious session termination, device isolation and emergency blocking — each bounded by policy and human oversight. Decide in advance which actions may run unattended, when executive or legal escalation is mandatory, and how forensic evidence survives the containment action that destroys it.

What AI actually changed on both sides of the line

On the attack side

CrowdStrike reports AI-enabled adversary operations up 89%. IBM finds that one in four malicious breaches in its 2026 study were AI-enabled, and that AI-enabled malicious breaches cost an average of US$6 million against the US$4.99 million global average. Generative models improve message quality, localisation, reconnaissance, impersonation and malware adaptation. Voice phishing is now a first-rank initial-access path at 11% of Mandiant investigations, and deepfake-enabled fraud has changed the evidentiary standard for payment instructions and executive requests.

Correction: The underlying executive report stated that generative AI “is already supporting 15% of observed attack techniques.” That is a misreading. Verizon's finding, drawn from an analysis of 793 threat actors, is a median count: threat actors sought generative-AI assistance across a median of about 15 distinct MITRE ATT&CK techniques each, with some spanning 40 to 50. It is a measure of breadth per actor, not a share of all attack activity. The distinction matters, because the corrected reading is the more alarming of the two.

On the defence side

In the World Economic Forum's Global Cybersecurity Outlook 2026, a survey of 804 leaders across 92 countries, 77% report using AI for cybersecurity — phishing detection, anomaly response and behavioural analytics above all — and the share conducting AI-security assessments rose from 37% to 64% in a single year. IBM associates extensive security AI and automation with US$1.93 million lower breach cost than no such deployment.

That is not a blanket business case for autonomous agents. It is evidence that well-integrated automation compresses detection and containment when it has reliable telemetry, correctly scoped permissions, evaluation against abuse cases and a human override. Automation layered onto incomplete asset data mostly produces confident wrong actions faster.

AI systems are themselves an attack surface

IBM reports that more than one-fifth of surveyed organisations had experienced a breach targeting AI models or applications, with APIs, applications, plugins and cloud misconfiguration each prominent causes. Meanwhile Verizon finds that frequent employee use of AI tools has risen from 15% to 45% in a year, with 67% of that use going through non-corporate accounts.

Shadow AI is a data-governance and identity problem before it is a model problem. The controls that work are unglamorous: inventory sanctioned and unsanctioned AI use, restrict sensitive inputs, review data provenance, test agents for excessive authority, monitor for prompt and model abuse, and govern third-party AI as a supplier dependency with the same access review any other integration receives. Our deep dive on AI agents and security covers the agent-authority problem in detail, and API security covers the interface most of these breaches actually came through.

The 2026 record: what happened while the forecasts were being written

Annual reports describe the year that closed. The year in progress keeps moving, and 2026 moved hard. Five developments between January and August 2026 changed assumptions that any outlook written from 2025 telemetry would still be carrying. They are set out here because a forecast that omits them is already dated.

1. Autonomous AI agents ran a state-scale intrusion

On 12 August 2026 the Israeli security firm Dream published a reconstruction of an operation against Taiwanese government infrastructure in which suspected Chinese operators ran autonomous AI models built on two open-source frameworks, Hermes and OpenClaw. The system extracted personnel data — more than 2,500 personnel records — and expanded from the initial foothold to supply-chain vendors, a nuclear safety agency, a government email system and energy-sector companies. Its distinguishing feature was what the researchers called learning cycles: autonomous sessions in which the system searched vulnerability databases, GitHub repositories and security research for techniques applicable to that specific target.

It was not isolated. On 30 July 2026 Palo Alto Networks' Unit 42 documented a Chinese-speaking actor running DeepSeek inside the same Hermes agent framework across 460-plus targets in three countries, with confirmed exfiltration from three Citrix NetScaler targets and command execution on eleven Marimo notebook instances. The actor had benchmarked several frontier coding agents before selecting one for the role.

Why this matters more than the AI statistics: Every AI figure earlier in this outlook measures AI as an assistant to human operators. These two campaigns measure something different: AI as the operator. The cost of running a multi-week, multi-target, nation-state-grade intrusion campaign has collapsed toward the cost of free open-source agent frameworks and inference. Threat models that assume a human analyst behind each session, working business hours, in one timezone, are the ones this invalidates.

2. The AI middleware layer became a supply chain

In March 2026 a leaked automation token for the open-source scanner Trivy allowed an actor group to poison Trivy releases, which then flowed into the build pipeline of LiteLLM, a widely deployed LLM gateway. Malicious LiteLLM versions 1.82.7 and 1.82.8 reached PyPI and executed automatically on install. The exposure window was roughly forty minutes. CloudSEK's analysis puts 2,500-plus companies and around 434,000 CI/CD pipelines at risk, with cloud credentials, SSH keys, Kubernetes tokens, repository tokens and — the novel category — AI provider API keys harvested.

This is the first widely documented incident in which the AI middleware layer was the blast radius: not the application, not the operating system, but the gateway sitting between an enterprise and its models. It makes two things concrete board actions rather than backlog items: inventory every LLM gateway and proxy in the estate, and rotate every AI provider key on a defined schedule with a tested revocation path. It also puts a number on the software supply-chain tail risk quantified earlier — a median insured impact of US$252,666, with a top 2.5% above US$100 million.

3. Model Context Protocol became a named attack surface

On 20 April 2026 OX Security disclosed that unsafe defaults in the Model Context Protocol's STDIO transport enable arbitrary command execution through configuration-to-command pathways, including zero-click prompt injection. The disclosure covered 7,000-plus publicly accessible servers and packages with roughly 150 million cumulative downloads, and produced ten CVEs across the ecosystem. Anthropic declined to change the protocol architecture, characterising the behaviour as expected. Whether or not that is the right call, it settles the question for buyers: MCP deployment security is the deploying organisation's responsibility, not the protocol's.

The taxonomy caught up in the same window. The OWASP Top 10 for LLM Applications 2026, published on 3 August 2026, keeps prompt injection at LLM01 and sensitive information disclosure at LLM02, but moves Excessive Agency from LLM06 to LLM03 — the largest jump in the list — and broadens system-prompt leakage into LLM08, Hidden Context Exposure, covering developer instructions, internal configuration, retrieved policies, workflows, user roles, tool schemas and permission models. OWASP's June 2026 state-of-agentic-AI review adds the structural finding: prompt injection maps to six of the ten agentic risk categories, and of 53 tracked agentic projects, 28 are coding agents. Only 37% of organisations have a policy capable of detecting shadow AI at all.

4. Identity is where the breach happens, not only where it starts

The most productive extortion franchise of 2026 has not been running exploits. The ShinyHunters and Scattered LAPSUS$ Hunters cluster works a repeatable identity chain: voice phishing, adversary-in-the-middle credential capture, single sign-on account takeover at the identity provider, persistence by enrolling a new MFA factor on an attacker-controlled device, then lateral movement across every SaaS application connected to that identity provider. The 2026 victim list reported by TechCrunch includes Instructure's Canvas platform in May 2026, affecting more than 30 million students and staff; Charter, at around 40 million records; and Carnival, at more than 6 million customer records.

Set that beside Microsoft's finding that more than 97% of identity attacks are password attacks and the case for phishing-resistant FIDO2 authentication stops being a roadmap item. The identity provider, not the endpoint, is the crown jewel — and the specific control that breaks this chain is restricting who can enrol a new authentication factor, and alerting when one is enrolled.

5. The network edge is where patch policy quietly fails

VulnCheck's 23 March 2026 analysis of exploited edge-device vulnerabilities produced the most uncomfortable finding of the year for anyone running a patch programme: 42.5% of exploited edge-device vulnerabilities affect end-of-life or likely end-of-life devices, 65% of botnet-exploited vulnerabilities target unsupported devices, and — the one that should change policy — only 23.7% of exploited edge-device vulnerabilities ever appear in CISA's Known Exploited Vulnerabilities catalogue.

Two 2026 campaigns show the operational tempo. Ivanti Endpoint Manager Mobile carried CVE-2026-1281 and CVE-2026-1340, both rated CVSS 9.8 and disclosed in late January 2026; by 17 February, Unit 42 was observing widespread, largely automated exploitation against 4,400-plus internet-exposed instances across government, healthcare, manufacturing, professional services and technology. Fortinet's FortiClient EMS carried CVE-2026-35616, also CVSS 9.8: exploitation was first observed on 31 March 2026, a hotfix landed over the weekend of 5–6 April, CISA added it to the KEV catalogue on 6 April — and exploitation increased after the hotfix shipped, against roughly 2,000 publicly exposed instances.

The policy correction: Using the CISA KEV catalogue as the definition of the urgent patch backlog is not a sufficient policy for edge devices, because roughly three-quarters of exploited edge vulnerabilities never enter it. Pair KEV with an own-estate control: an inventory of internet-facing appliances, their support status, and a hard replacement date for anything past end-of-support. The security-management console — the thing that administers your endpoints — is now itself a first-rank initial-access target.

Ransomware is fragmenting, not receding

Blockchain-traced ransomware payments fell to roughly US$820 million in 2025, from an upward-revised US$892 million in 2024. Read that as good news at your peril. Over the same period claimed attacks rose about 50%, the median observed payment rose 368% to US$59,556, and only 28% of known victims paid at all. Chainalysis notes that on-chain totals are lower bounds, revised upward as new wallets are attributed.

So the aggregate fell while attack volume rose, the typical payment multiplied, and most victims refused. That is a market fragmenting across access brokers, data-theft crews, affiliates and extortion brands — not one in retreat. Mandiant's finding that prior compromise became the leading ransomware entry vector at 30% completes the picture: closing an incident without eliminating persistence or rotating stolen credentials converts yesterday's intrusion into tomorrow's extortion event.

Verizon's insured-claim analysis shows how unevenly the burden lands. Ransomware accounts for 64% of public-administration claims, 45% in manufacturing, 39% in healthcare, 39% among small businesses and 32% in retail. Those categories are not mutually exclusive — small business is a size band and the others are industries — but the ordering is stable and it maps to operational dependence, not to data sensitivity.

What a breach actually costs: a distribution, not an average

IBM's US$4.99 million global average, up 12% year on year, is the most-quoted number in the industry and the least useful for budgeting. It is a standardised cost model across interviewed organisations, excellent for tracking a consistent methodology over time and poor as a proxy for what a breach would cost your company.

Insured-loss data gives the size-sensitive view. Across Verizon's 2026 Breach Impact Study — produced with claims data partner CyberAcuView — the median paid impact scales sharply with revenue, and the tail dominates the mean.

Organisation revenueMedian paid impactWhat the tail looks like
Below US$25mUS$38,000Extreme losses can exceed 7% of annual revenue
US$25m – US$250mUS$96,000
Above US$250mUS$283,000Top 2.5% of large-company claims exceed US$22m
All organisationsAbove US$83,000Top 10% above US$920,000; top 2.5% above US$5m

Table 3 — Verizon 2026 Breach Impact Study: The Financial Costs of Data Breaches (with CyberAcuView). Values are insured paid or reserved losses excluding zero-dollar claims; they are not total economic loss.

Two structural findings should reset the board conversation. First, business interruption is becoming the dominant loss component: its share of known paid loss rose from 21% in 2023 to 32% in 2024, and it accounts for roughly half of known loss in supply-chain and third-party claims. Manufacturing's median business-interruption loss is about US$232,000 — 158% above the overall median.

Second, software supply-chain claims are the textbook low-frequency, high-severity risk. They are about 2% of claims in the dataset, but carry a median paid impact of US$252,666 and a top 2.5% above US$100 million. Insurance limits and sublimits mean even those figures may understate total impact. This is the argument for concentration analysis — who supplies identity, cloud, code, payments, communications and remote management — over generic supplier scoring.

The executive translation: stop asking what the average breach costs. Ask which critical services would stop, for how long, what the manual workaround is, what it costs per day, which customer obligations trigger, and how the restoration sequence runs. Forensics and notification are the small numbers.

Why spending is not readiness

Cisco's Cybersecurity Readiness Index — a double-blind survey of 8,000 business leaders with cybersecurity responsibilities across 30 markets — places only 4% of organisations in its top “Mature” tier. ISC2's 2025 Workforce Study, drawn from 16,029 practitioners and decision-makers, finds 59% reporting critical or significant skills needs and 88% reporting at least one consequential security problem traceable to a skills deficiency.

Zero trust shows the same pattern of adoption without completion. A SANS network-security survey found 12.7% of respondents had fully implemented zero trust and 31.4% were actively implementing it. That survey dates from February 2024 and was vendor-sponsored, so treat it as a floor rather than a current reading; it is cited here because nothing more recent with a comparable sample has replaced it. Gartner's standing prediction — that only 10% of large enterprises would have a mature and measurable zero-trust programme by 2026 — points the same way.

Correction: The underlying report cited 13.1% as the share that had fully implemented zero trust. In the SANS data, 12.7% is the fully-implemented figure; 13.1% is the share that answered “no, and we have no desire to implement.” Two adjacent percentages with opposite meanings.

Adoption percentages across surveys are not a league table. “Purchased,” “piloted,” “deployed in one business unit” and “mature across the enterprise” get reported under the same label by different houses. The pattern is what holds: AI use is widespread, formal AI-security assessment is catching up fast, zero trust remains an implementation journey, and overall maturity is scarce. That combination creates execution risk — a new capability can add complexity faster than it removes exposure. Gate every addition on named ownership, integration, an operating metric and the decommissioning of whatever it replaces.

The minimum viable security core

The highest-return programme is not the largest tool portfolio. It is the smallest coherent system that measurably reduces exposure, contains business interruption and accelerates recovery. For most organisations that core is seven things:

  1. Identity hardening — phishing-resistant MFA for privileged and remote access, privileged access management, joiner-mover-leaver automation, session analytics.
  2. Rapid patching of internet-facing systems — a time-bound, executive-approved service level for critical exposed vulnerabilities, not a best-effort queue.
  3. Protected and tested backups — immutable or offline copies, and a restore that has actually been performed against a clock.
  4. Endpoint and cloud telemetry — EDR or XDR coverage with tamper protection, forensic retention, and cloud posture and entitlement visibility.
  5. An exercised incident-response plan — named incident commander, materiality decision group, external IR retainer, and a tabletop that has been run this year.
  6. Supplier-risk controls — tiering by access and business impact, named accounts with MFA, emergency revocation, concentration analysis.
  7. Continuous validation of high-value paths — scanning plus targeted manual testing plus control-health metrics, on the paths that actually matter.

Larger enterprises add formal external attack-surface management, detection engineering, zero-trust segmentation, product and application security, data-security posture, red teaming and quantitative risk analysis. They do not skip the seven.

CapabilityWhat good looks likeBusiness outcome
Governance and riskApproved risk appetite; named service owners; quantified scenarios; tested decision rightsCapital aligned to material exposure
Identity securityPhishing-resistant MFA; PAM; lifecycle automation; session analyticsLower account-takeover and fraud risk
Exposure managementAsset discovery; attack-surface monitoring; risk-based patching; control validationFaster closure of exploitable paths
Endpoint and workload defenceEDR/XDR coverage; tamper protection; containment automation; forensic retentionShorter dwell time and blast radius
Cloud and SaaS securityPosture, entitlement, workload and data controls across cloud and SaaSReduced misconfiguration and token abuse
Application, API and product securitySecure SDLC; dependency governance; secrets control; coordinated disclosureLower product and supply-chain exposure
Data securityClassification; least privilege; encryption; DLP; immutable audit evidenceReduced loss, fraud and regulatory impact
Security operationsCentral telemetry; detection engineering; 24/7 triage; threat-informed playbooksFaster detection and containment
Resilience and recoverySegmentation; isolated backups; recovery exercises; alternate proceduresLower business-interruption loss
AssuranceIndependent penetration tests; red and purple teams; supplier and control auditsEvidence that critical controls work

A programme over-weighted toward prevention produces false confidence. One over-weighted toward monitoring produces alerts without containment. One focused on backup without identity and segmentation restores the attacker along with the data. What executives should require is a traceable chain from each critical business service to its assets, dependencies, preventive controls, detection logic, response authority and recovery evidence.

Zero trust, SASE, XDR and MDR: what to buy, and when

Why choose zero trust over perimeter segmentation?

Zero trust replaces implicit trust based on network location with explicit, continuously evaluated access decisions: identity verification, device and workload health, least privilege, per-application access, telemetry and policy enforcement. It is an architecture, not a product line, and the failure mode is treating it as an enterprise-wide slogan rather than a sequence. Start where consequence is highest — administrators, remote users, sensitive applications, service accounts and third parties — then widen. The implementation order that works: remove public administrative access, enforce phishing-resistant MFA, inventory privileges, segment critical services, then add adaptive policy and measurement.

Why choose MDR over building a security operations centre?

Secure access service edge brings network and security policy closer to users, branches and cloud applications. Extended detection and response correlates endpoint, identity, email, cloud and network telemetry. Managed detection and response wraps people and process around detection, investigation and containment. All three earn their place when they remove blind spots and simplify operations. All three disappoint when the deployment is treated as a licensing exercise rather than as data engineering, policy migration and incident-process redesign.

For most organisations under a few hundred staff, a well-scoped MDR service plus hardened fundamentals beats building 24/7 in-house capacity, and it beats it decisively on cost per hour of genuine coverage. The selection question is never “which platform is best.” It is whether your operating model can maintain policy, integrate identity and asset context, tune detections, exercise containment, preserve evidence and manage vendor concentration. If it cannot, a better platform will not fix it.

What continuous validation actually replaces

An annual penetration test still provides independent evidence, but a point-in-time test cannot keep pace with cloud deployments, identity changes, new APIs and vendor integrations. Strong programmes combine secure-development testing, vulnerability scanning, external attack-surface monitoring, breach-and-attack simulation, control-health metrics, targeted manual penetration tests and periodic red teams.

The procurement distinction is worth stating precisely, because vendors blur it. Automated scanning finds known exposures. A penetration test demonstrates exploitability within an agreed scope. A red team tests whether a defined objective can be achieved across people, process and technology, including whether anyone notices. Buyers should specify scope, tester qualifications, manual exploitation expectations, evidence quality, remediation support, retesting and separate technical and executive reporting. Our guide to buying cybersecurity services in Singapore covers how to write that into a statement of work.

On published price ranges: Indicative penetration-testing price bands circulate widely for the Singapore market. We attempted to verify them and could not: no authoritative published benchmark exists from CSA, IMDA, SGTech or any industry body, and every figure in circulation traces back to marketing pages published by firms selling the service. This outlook therefore prints no price range. Scope competitively across at least three licensed providers and price against your own attack surface, not against a number you found on a vendor's blog.

How to calculate cybersecurity ROI without pretending

Cybersecurity return on investment is genuinely hard to compute, because avoided losses are unobserved and controls interact. What is defensible is a decision boundary built from scenarios rather than vendor claims:

The two lines that matter: Annualised loss expectancy (ALE) = estimated annual event frequency × expected loss per event.
Maximum break-even annual control cost = baseline ALE × expected risk reduction.

If a scenario carries a baseline ALE of US$1 million and independent evidence supports a 50% reduction, the break-even annual spend is US$500,000 before secondary benefits. That is a ceiling, not a promised return. Show uncertainty as a range, make control dependencies explicit, and refuse point estimates that hide them.

Secondary benefits are real and routinely omitted: shorter audits, faster enterprise sales cycles, lower insurance friction, fewer outages, less operational rework. So are hidden costs — implementation, identity cleanup, telemetry storage, training, integration, tuning and retained staffing, none of which appear on a licence quote. After the investment, track exposure removed, mean time to contain, recovery performance, false-positive burden and tools actually retired.

Eight failure modes that survive every budget cycle

The metric hierarchy that avoids the last one has four layers. Outcome indicators: critical-service downtime, loss exposure, customer or safety impact, material incidents. Risk indicators: exploitable paths to critical assets, privileged-account exposure, supplier concentration, unsupported systems. Control indicators: phishing-resistant MFA coverage, time to remediate exposed critical vulnerabilities, EDR and logging coverage, backup restoration success, containment speed. Execution indicators: overdue risk acceptances, recurring findings, unowned assets, remediation aging.

Every one of those needs a denominator and a trend. “97% EDR coverage” is meaningful only if the remaining 3% is not the payment platform. A healthy mean time to remediate can conceal a single critical internet-facing defect that has been open for months. Pair aggregates with explicit exception lists.

What good looks like by organisation size

DimensionSmall business (1–50)Mid-market (51–500)Large enterprise (500+)
Primary riskBusiness-ending outage, fraud, credential compromiseRapid complexity growth, SaaS and cloud sprawl, customer assurance demandsSystemic concentration, supply chain, regulatory and geopolitical exposure
Operating modelAccountable owner plus managed service provider or MDR, and specialist testsSmall internal team with co-sourced 24/7 operationsFederated three-lines model with dedicated engineering and response
First controlsManaged identity, MFA, patching, EDR, secure email, isolated backupAdd PAM, cloud posture, central logging, segmentation, supplier tiers, secure SDLCAdd attack-surface management, data security, product security, detection engineering, red team
Assurance cadenceAnnual independent test plus quarterly recovery testRisk-based tests after material change; annual executive exerciseContinuous validation; scenario red teams; board-level crisis exercises
Investment logicReduce existential tail risk; prefer predictable managed serviceSupport growth, contracts and operational resilienceOptimise portfolio against quantified scenarios and concentration risk

Small businesses: build a survivable core, not a small enterprise programme

Small firms are attractive targets because they often hold monetisable data, payment access or a route into larger customers, with limited defensive depth. The insured data puts their median paid loss near US$38,000, while extreme claims can exceed 7% of annual revenue — which is the number that ends companies. The goal is survivability, not sophistication.

In practice: a managed business suite with enforced MFA and separate administrator accounts; managed endpoint protection; automatic patching of browsers, operating systems and internet-facing devices; a password manager; email domain protection; immutable or offline backups; and a named external incident-response contact secured before you need it. Verify bank-detail changes and urgent payment instructions through a known second channel, every time. Test restoration quarterly. Do not build a security operations centre; buy a clearly scoped service with defined response hours, containment authority, log coverage, incident notification, evidence retention and exit provisions.

Mid-market: control the complexity inflection

Between roughly 51 and 500 employees, cloud services, APIs, remote work, acquired systems and enterprise-customer requirements expand faster than the security team. The priority is replacing informal knowledge with repeatable ownership. Build a service and data inventory; implement privileged access management; centralise identity and endpoint telemetry; establish cloud configuration and entitlement controls; segment critical services; tier suppliers by access and business impact; embed security checks in software delivery. Co-source 24/7 monitoring while retaining architecture, incident command and the customer relationship in-house.

Use customer assurance requests as a product signal rather than an administrative burden. A control that keeps appearing in security questionnaires is a control that is gating revenue, and it should be funded from that budget line.

Large enterprises: govern systemic risk

Large enterprises need federated governance because the risk sits in business units, products, regions and suppliers. Central teams set standards, provide shared platforms, measure control evidence and manage enterprise incidents; product and service owners own remediation and continuity. Quantitative scenario analysis should cover destructive attack, identity-provider failure, cloud or SaaS concentration, software supply-chain compromise, material data loss and operational-technology disruption.

Portfolio governance is the underused lever. Require each major platform to state, in writing, the exposures it reduces, the dependencies it introduces, the operating capacity it consumes and the legacy tools it retires. Then test whether the organisation can actually revoke supplier and privileged access at scale, restore priority services in sequence, and communicate while the facts are still uncertain.

Sector priorities: what the board should ask to see

SectorHighest-consequence scenariosPriority capabilitiesBoard-level proof
Financial servicesFraud, identity takeover, payment disruption, third-party outageTransaction analytics, strong customer and workforce identity, DORA-aligned resilience, supplier concentration controlsRecovery of critical operations; fraud-loss trend; tested third-party exit
HealthcareRansomware, patient-data loss, clinical-system downtime, device compromiseSegmentation, asset visibility, controlled vendor access, downtime procedures, immutable backupClinical continuity exercise; restore evidence; privileged-access review
ManufacturingPlant disruption, remote-access abuse, engineering-data theft, unsafe stateIT/OT zoning, passive monitoring, jump hosts, vendor controls, engineering backupsSafe degraded operation; plant recovery sequence; remote-session evidence
Retail and commerceAccount takeover, payment fraud, e-commerce outage, loyalty-data theftBot and fraud controls, API security, PCI-aligned segmentation, seasonal capacity and responseCheckout recovery; fraud rate; customer notification readiness
Technology and SaaSProduct or build compromise, tenant isolation failure, secret leakage, cloud concentrationSecure SDLC, dependency and secret governance, tenant controls, cloud detection, coordinated disclosureBuild integrity; tenant-isolation tests; software bill of materials coverage
Critical infrastructureDestructive attack, service outage, geopolitical targeting, legacy-system exploitationResilient architecture, manual fallback, spare strategy, network zones, national coordinationBlack-start or fallback evidence; crisis command; dependency map

Across every sector the governing unit should be the critical business service, not the server. A hospital protects patient care; a bank protects payment and trust; a manufacturer protects safe production; a SaaS provider protects tenant isolation and availability. That framing aligns security with operations and makes the recovery priority order explicit before the incident rather than during it.

Regulatory mappings should be built once and reused. NIST Cybersecurity Framework 2.0, released on 26 February 2024 with the added Govern function, provides the broad structure; sector regimes layer specific reporting, resilience, product or privacy requirements on top. A common control library with mapped evidence reduces duplicated audit effort and shows executives where one capability satisfies several obligations. Our guide to international cybersecurity standards maps the main frameworks against each other.

Singapore: what is actually in force, and what is not

This is where most published summaries go wrong, and the error is consequential. Singapore's Cybersecurity (Amendment) Act 2024 (Act 19 of 2024) was passed on 7 May 2024, and Commencement Notification S 677/2025 brought a defined subset of it into operation on 31 October 2025. It was a partial commencement, not a wholesale one, and two of the headline categories remain enacted but dormant.

ProvisionWhat it coversStatus as at 18 August 2026
“Virtual computer” and “virtual computer system” (s2)Extends critical information infrastructure regulation to cloud-hosted and virtualised systems used to deliver essential servicesIn force, 31 October 2025
Part 3B — systems of temporary cybersecurity concernDesignation of systems at heightened risk because of a temporary event or situationIn force, 31 October 2025
Part 3C — entities of special cybersecurity interestDesignation of entities whose disruption would have significant national impactEnacted but NOT in force (s16 not commenced)
Part 3D — major foundational digital infrastructure service providersCloud computing and data centre facility services specified in the Third ScheduleEnacted but NOT in force (s17 not commenced)

Table 4 — Cybersecurity (Amendment) Act 2024 (Act 19 of 2024) and Commencement Notification S 677/2025. Verified against the Singapore Statutes Online consolidated text on 18 August 2026.

For a cloud-hosted critical system that is in scope, the amendment moves the compliance burden in a specific way: for virtual critical information infrastructure, the “owner” is the person with exclusive control of the system, including responsibility held under a contract with a cloud computing service provider. Running the workload on someone else's infrastructure does not transfer the obligation. It relocates the evidence you need from your provider.

The Digital Infrastructure Bill is the piece to watch

The gap left by the dormant Part 3D is being filled from a different direction. In July 2026 the Ministry of Digital Development and Information and IMDA ran a public consultation on a draft Digital Infrastructure Bill, with submissions closing on 22 July 2026. It proposes new IMDA-administered licensing for significant cloud and data centre providers, covering security, business continuity and incident notification — complementing rather than duplicating the Cybersecurity Act amendments. We covered the proposal and its implications in our analysis of the Digital Infrastructure Bill. Any organisation that buys cloud or colocation in Singapore should be reading the eventual licence conditions as procurement requirements, not as somebody else's compliance problem.

Two codes of practice are coming in the second half of 2026

On 22 July 2026 the Cyber Security Agency of Singapore announced that the Cybersecurity Code of Practice for critical information infrastructure will be updated, and that a new code of practice for cloud will be introduced, both later in the year. The CCoP has not been substantively updated since 2022. The signalled direction includes board and senior-management accountability for cyber resilience, Cyber Trust Mark certification expectations for CII owners, oversight of interconnected systems, threat detection across CII network segments and a comprehensive exercise plan. If your organisation owns designated CII, the 2027 budget cycle is the one that has to absorb this.

Licensing, penalties and the local threat picture

Two cybersecurity services have been licensable in Singapore since the framework commenced on 11 April 2022: penetration testing and managed security operations centre monitoring. That scope is unchanged as at August 2026. Buying either from an unlicensed provider is a procurement failure you can check for in ten seconds against CSA's public register — and it is worth checking, because the licence is one of the few binary quality signals in this market. Our IT compliance guide walks the four Singapore regimes side by side.

On the privacy side, the Personal Data Protection Act allows the Commission to impose a financial penalty of up to S$1 million, or 10% of annual turnover in Singapore for organisations with local turnover above S$10 million — whichever is higher. That raised cap has been in effect since 1 October 2022, having been legislated in 2020 and deferred. It is not new, and it is not theoretical.

For the local threat picture, CSA's Singapore Cyber Landscape 2025/2026, published on 30 June 2026, is the citable source. Ransomware cases reported to CSA rose to 165 in 2025, from 159 in 2024 — a marginal increase against a global picture of fragmenting extortion. Phishing reports fell 21%, to roughly 4,800, from about 6,100. But the number that should worry a Singapore board is neither of those: infected infrastructure detected in Singapore rose 142%, to 284,300, driven by malware-as-a-service and unpatched consumer IoT. Fewer people are being phished and more machines are compromised. Beware of secondary summaries here: many circulating articles labelled “SCL 2025/2026” quote the previous edition's numbers for calendar year 2024.

CSA's accompanying commitments are procurement-relevant and dated, which makes them budget items rather than sentiment. All critical information infrastructure owners must attain Cyber Trust Mark certification by end-2027, and residential routers must meet Cybersecurity Labelling Scheme Level 2 by end-2027. For smaller organisations, a CISO-as-a-Service programme offers eligible SMEs up to 70% co-funding on cybersecurity advisory services — the single most under-used subsidy in this market. More than 800 organisations now hold at least one Cyber Essentials or Cyber Trust certification. CSA has also published Guidelines on Securing AI Systems and a discussion paper on agentic AI systems, which is the local regulatory hook for everything in the agentic-AI section above.

Two things about the financial-sector rulebook are worth stating plainly, because vendors get both wrong. The Monetary Authority of Singapore's Technology Risk Management Guidelines remain at the January 2021 revision — institutions planning 2027 controls should not budget for a refresh that has not been announced. And the cyber-hygiene obligations have moved: MAS cancelled Notice 644 and Notice 655 with effect from 10 May 2024, reissuing the requirements under the Financial Services and Markets framework as Notice FSM-N05 (technology risk management) and Notice FSM-N06 (cyber hygiene), so which notice binds a firm now depends on its licence class. A provider still marketing “Notice 655 compliance” is quoting a cancelled instrument — which is a useful signal about how current the rest of its compliance knowledge is.

The global compliance clock, and what it demands as evidence

Regulation has stopped asking whether you have a policy and started asking for time-stamped proof. Four regimes set the pace for any organisation with international exposure.

RegimeCore obligationDate that matters
SEC cyber disclosure rules (US)Disclose material cybersecurity incidents on Form 8-K, generally within four business days of determining materiality, plus annual risk-management, strategy and governance disclosureIn force
DORA (EU financial sector)Operational-resilience testing, ICT third-party risk management, incident reportingApplies since 17 January 2025
NIS2 (EU)Governance, risk management, supply-chain security and incident reporting across 18 critical sectorsIn force; national transposition ongoing
Cyber Resilience Act (EU)Reporting of actively exploited vulnerabilities and severe product incidents; secure defaults, support periods, SBOM, coordinated disclosureReporting from 11 September 2026; full application 11 December 2027
EU AI Act, Article 50 transparencyDisclosure when AI interacts directly with people; machine-readable marking of synthetic audio, image, video and text; deepfake and emotion-recognition noticesIn effect since 2 August 2026; marking duty for systems already on the market from 2 December 2026

The common operational demand across all four is the same short list: a trustworthy asset and service inventory, documented decision rights, time-stamped incident facts, a tested materiality and notification workflow, supplier visibility, and defensible proof that controls actually operated. Build that once and every regime becomes a mapping exercise rather than a project.

Enforcement is not decorative. European supervisory authorities issued roughly €1.15–1.2 billion in GDPR fines during 2025 — the range reflects methodology (the CMS GDPR Enforcement Tracker snapshot vs the DLA Piper January 2026 survey), because the EDPB itself does not publish an annual fines total. The Irish Data Protection Commission's €530 million TikTok decision — €485m for unlawful transfers to China under Article 46(1) plus €45m for transparency failures under Article 13(1)(f) — was adopted 30 April 2025. The Irish High Court, in [2026] IEHC 347 on 3 June 2026, upheld both findings but vacated and remitted the corrective and transfer-suspension order; TikTok's appeal on the fine amount is still live. Anyone still describing the whole penalty as “subject to appeal” is working from a stale note; anyone describing the case as closed is running ahead of the record.

There is no global compliance failure rate: Regimes differ in scope, thresholds and enforcement, so no defensible single benchmark exists and none is printed here. Use observable indicators instead: reporting performance against your own deadlines, control-test results, audit findings, overdue remediation and regulator actions in your sectors.

Outlook 2026–2030: five things that will still be true in three years

1. AI agents reshape operations and control design

Defensive agents will triage alerts, enrich investigations, propose detections, review code and orchestrate containment. Offensive agents will scale reconnaissance, social engineering, vulnerability discovery and persistence. The durable advantage comes from trustworthy context and controlled execution, not from access to a capable model — everyone has that. The market will split between copilots that advise and agents that act, and the buying criteria differ sharply. For anything that acts, demand evidence on false-action rates, prompt injection resistance, data retention, model-update policy, tenant separation and human takeover. Log every agent action, constrain its tools and data, require approval for high-impact steps and design revocation before deployment rather than after the first incident.

2. Identity becomes the universal control plane

Human users, service accounts, workloads, APIs, devices and AI agents all need identity, and Microsoft's finding that more than 97% of identity attacks are password attacks shows how much of the problem is still unglamorous. Passwordless and phishing-resistant authentication will expand, but legacy protocols, account recovery flows and machine credentials will stay exploitable. Identity resilience — alternate administration, break-glass controls, token revocation, directory recovery, supplier isolation — will matter as much as identity prevention. Most organisations have never tested how fast they can revoke every privileged session. That is a one-afternoon exercise with a genuinely useful answer.

3. Product security becomes a market-access requirement

The EU Cyber Resilience Act and enterprise procurement together push vulnerability handling, secure defaults, support periods, software bills of materials and coordinated disclosure into product management. Security responsibility moves earlier — into architecture, build systems and release decisions. Product leaders will need measurable security requirements and funded maintenance rather than a late-stage testing gate that slips whenever the ship date does.

4. Quantum readiness moves from research to inventory

NIST finalised its first three post-quantum cryptography standards on 13 August 2024 and urged organisations to begin transition. The 2026–2030 task is crypto-agility, not wholesale replacement: identify where long-lived sensitive data, embedded systems, certificates, protocols and supplier products depend on vulnerable public-key algorithms; assign ownership; map upgrade paths; test hybrid transition; and write algorithm requirements into procurement now, so the next hardware refresh does not lock in another decade of exposure. Immediate replacement is rarely practical. Unmanaged dependence is equally imprudent.

What changed in 2026 is that the timetable stopped being advisory. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” signed 22 June 2026, sets 31 December 2030 for post-quantum encryption of the most sensitive US federal systems and 31 December 2031 for post-quantum authentication, with a pilot programme inside 180 days and cryptographic bill-of-materials guidance inside 270 days. The clause that reaches commercial buyers everywhere is the one directing federal contractors to comply with post-quantum FIPS by the end of 2030. Once that flows down a supply chain, it becomes a de facto commercial deadline for anyone selling into it — including from Singapore, where CSA is running a national quantum-safe initiative and MDDI has named post-quantum cryptography, benchmarked to NIST, as the mainstream approach.

5. Cyber resilience converges with enterprise resilience

Cloud concentration, AI dependencies, geopolitical disruption and digital supply chains have blurred the lines between cyber, technology, operational and third-party risk. The World Economic Forum finds 64% of leaders now factor geopolitical cyberattacks into strategy, and that fraud and phishing have overtaken ransomware as the top CEO cyber concern, with 73% having been directly affected by fraud or knowing someone who was. Crisis command, business continuity, disaster recovery, fraud, privacy and product safety will increasingly share scenarios and evidence. Mature organisations will measure service resilience end to end, across internal and external dependencies.

The market itself will keep consolidating as enterprises seek integrated telemetry and lower operating friction, but independent depth survives, because buyers need objective evidence and adversarial expertise that a platform vendor cannot credibly self-certify. The likely winning architecture is a limited platform core, well-governed data flows, and specialist capabilities applied where the risk justifies them.

Consolidation is not a forecast here; it already happened. Palo Alto Networks completed its acquisition of CyberArk on 11 February 2026, and Google completed its acquisition of Wiz on 11 March 2026 — identity security and cloud security, the two fastest-growing segments, absorbed into platform companies within thirty days of each other. If either sits in your stack, the practical consequence is a renewal negotiation and a concentration-risk question, not a technology one. Meanwhile the funding side cooled: security and privacy startups raised US$10.6 billion in the first half of 2026 — US$6.2 billion in Q1 and US$4.4 billion in Q2, roughly a 30% decline quarter on quarter and year on year — and no major cybersecurity IPO priced in the period. Fewer, larger, later-stage bets, into a market whose two biggest gaps have just been bought.

The next 90 days: seven decisions, in order

  1. Confirm accountability. Name the executive incident commander, the materiality decision group, critical-service owners and the board oversight forum. Write the names down.
  2. Prioritise services. Select the ten services whose disruption would create the greatest cash, safety, legal or customer impact, and map their identities, data, infrastructure and suppliers.
  3. Close the common entry paths. Enforce phishing-resistant MFA for administrators and remote access; patch critical exposed vulnerabilities to an executive-approved service level; remove unused external access.
  4. Prove recovery. Restore priority systems and identity services from isolated backups, record the actual elapsed time, and remediate the gap between that number and the approved objective.
  5. Constrain suppliers. Review high-impact supplier access, require named accounts with MFA, establish emergency revocation, and identify where one provider creates systemic exposure.
  6. Exercise the decisions. Run a tabletop covering extortion, data theft, deepfake-enabled payment fraud and regulatory notification — with finance, legal, communications and operations in the room.
  7. Baseline AI. Inventory sanctioned and unsanctioned AI use, restrict sensitive inputs, and evaluate any agent that holds execution authority.

Over twelve months, build centralised identity, endpoint, cloud and asset context; establish risk-based vulnerability remediation and secure-development standards; co-source continuous monitoring where internal coverage is inadequate; link supplier tiers to technical controls and recovery obligations; define a control library mapped to NIST CSF 2.0 and applicable sector rules; and retire duplicate tools, reinvesting the saving in integration, remediation and exercises.

Over three years, move from control deployment to control evidence: continuous exposure validation, quantified scenarios, business-service resilience metrics, phishing-resistant authentication extended to the broader workforce and high-risk customers, crypto-agility, and credible exit or fallback plans for identity, cloud, communications and critical SaaS.

Executive decision matrix

DecisionAct now when…Evidence to requireEscalate if…
Fund identity modernisationPrivileged or remote access still relies on phishable methodsCoverage by identity type; exception list; token-revocation testCritical services or suppliers remain outside control
Expand MDR or SOC capabilityDetection or containment is not continuousTelemetry coverage; response SLA; containment exercise; exit planProvider cannot act, preserve evidence or support a major incident
Prioritise resilience investmentRecovery objectives are assumed rather than provenSuccessful restore by service; dependency sequence; actual elapsed timeIdentity, backup or supplier failure blocks recovery
Commission a penetration testA material exposed application, cloud or identity change occurredManual exploitation; business impact; remediation; retestScope excludes critical paths, or findings repeatedly recur
Commission a red teamControls appear mature and leadership needs objective evidenceThreat-aligned objective; safety rules; detection and response outcomesBasic hygiene gaps would make the exercise low-value
Approve AI agents with authorityBounded automation materially reduces response delayEvaluations; least privilege; audit logs; human override; revocationThe agent can expose data or take irreversible action without control
Accept residual riskTreatment cost exceeds defensible scenario benefitTime-bound owner, rationale, compensating controls, review triggerPotential loss exceeds appetite or legal and safety duties

How to read these numbers

Five categories of evidence appear in this outlook and they are not interchangeable. Incident datasets (Verizon DBIR) describe reported breaches. Vendor telemetry (CrowdStrike, Mandiant, Microsoft) describes activity those vendors observed, shaped by their customer base. Surveys (WEF, ISC2, Cisco, SANS) describe perception and claimed adoption. Insurance claims (Verizon Breach Impact Study) describe paid or reserved losses, excluding zero-dollar claims, which is not the same as total economic loss. Forecasts (Gartner) describe expected demand and are not audited revenue. “Breach,” “incident,” “claim,” “intrusion,” “attack,” “adoption” and “maturity” are defined differently by each. Combining them into a single baseline produces a number that means nothing.

This outlook was rebuilt from an executive report dated 11 August 2026 by checking each claim against its primary source, with a second adversarial pass on anything that did not confirm first time. Most of the source report held up. Five corrections were material enough to state in the open:

Two smaller fixes: Mandiant's 22-second access-broker handoff is a median, not an average; and European data-protection fines for 2025 are approximately €1.2 billion rather than €1.15 billion. Where a figure below could not be traced to a primary source at all, it does not appear in this outlook.

Cite this outlook: Tech Directory SG (2026). Cybersecurity Market Outlook 2026: Proof Over Purchase. https://techdirectory.sg/insights/cybersecurity-market-outlook-2026 (sources verified 18 August 2026). Figures belong to the cited primary sources; please attribute those directly where you quote them.

The executive objective is not perfect security. It is a defensible level of residual risk, supported by evidence that critical operations can continue or recover. Attackers are faster, more specialised and increasingly AI-enabled; dependencies are broader; regulators expect proof. But the control path is clearer than the threat landscape makes it look: reduce exposed paths, harden identity, see and contain activity quickly, isolate critical services, recover reliably, and validate continuously. The most common executive error is still to equate spending with safety.

Shortlisting a cybersecurity provider in Singapore?

Tech Directory SG maintains directory profiles of Singapore's cybersecurity providers, system integrators and managed service providers — with UENs where recorded, and profile signal scores derived from documented fields rather than paid placement.

Share a brief with listed providers →

Frequently asked questions

How big is the cybersecurity market in 2026?

Gartner's July 2025 forecast put worldwide end-user spending on information security at US$239.8 billion in 2026, up 12.5% from US$213.0 billion in 2025, split across security software (US$121.2bn), security services (US$92.8bn) and network security (US$25.8bn). Gartner revised the 2026 figure upward to about US$244 billion in a September 2025 update, so always quote the forecast vintage alongside the number. These are forecasts of expected demand, not audited market revenue.

What is the average cost of a data breach in 2026?

IBM's Cost of a Data Breach Report 2026, released on 29 July 2026, puts the global average at US$4.99 million, up 12% year on year, with AI-enabled malicious breaches averaging US$6 million. That average is a standardised research model, not a budgeting proxy. Insured-claim data from Verizon's 2026 Breach Impact Study is more size-sensitive: the median paid impact is about US$38,000 for organisations below US$25m revenue, US$96,000 between US$25m and US$250m, and US$283,000 above US$250m.

What is the most common way attackers get in?

Vulnerability exploitation. Verizon's 2026 DBIR finds it initiates 31% of breaches, ahead of stolen credentials, and up from 20% in the 2025 edition. Mandiant reaches a compatible figure of 32% across the intrusions it investigated, followed by voice phishing at 11%, prior compromise at 10% and email phishing at 6%. A third party is involved in 48% of Verizon-recorded breaches, a 60% rise on the prior edition.

Is ransomware declining in 2026?

No. Blockchain-traced payments fell to roughly US$820 million in 2025 from an upward-revised US$892 million in 2024, but claimed attacks rose about 50%, the median observed payment rose 368% to US$59,556, and only 28% of known victims paid. Ransomware still appears in 48% of Verizon-recorded breaches. Falling aggregate payments reflect more victims refusing to pay, not less operational risk.

How fast do attackers move once they are inside?

CrowdStrike reports an average eCrime breakout time of 29 minutes in 2025, with the fastest observed lateral movement at 27 seconds, and 82% of detections were malware-free. Mandiant reports that the median time between an initial access event and handoff to a secondary threat group fell from more than eight hours in 2022 to 22 seconds in 2025. Manual triage queues and next-business-day escalation cannot match those timelines.

Does AI make cyberattacks worse?

It measurably improves attacker productivity. CrowdStrike reports AI-enabled adversary operations up 89%, and IBM finds one in four malicious breaches in its 2026 study were AI-enabled, averaging US$6 million. Defenders are adopting it at similar speed: 77% of World Economic Forum respondents use AI for cybersecurity, and IBM associates extensive security AI and automation with US$1.93 million lower breach cost. AI systems are also targets in their own right — more than a fifth of surveyed organisations reported a breach touching AI models or applications.

What did Singapore's 2025 Cybersecurity Act amendments actually bring into force?

Commencement Notification S 677/2025 brought a defined subset of the Cybersecurity (Amendment) Act 2024 into operation on 31 October 2025 — a partial commencement. In force: the extension of critical information infrastructure regulation to virtual and cloud-hosted systems, and Part 3B covering systems of temporary cybersecurity concern. Not in force: Part 3C on entities of special cybersecurity interest, and Part 3D on major foundational digital infrastructure service providers. Both are enacted but uncommenced as at August 2026.

Is penetration testing a licensed activity in Singapore?

Yes. Since the licensing framework commenced on 11 April 2022, two cybersecurity services require a licence from the Cyber Security Agency of Singapore: penetration testing, and managed security operations centre monitoring. That scope is unchanged as at August 2026. Buyers should verify a provider's licence against CSA's public register before contracting.

What are the maximum penalties under Singapore's PDPA?

The Commission may impose a financial penalty of up to S$1 million, or 10% of the organisation's annual turnover in Singapore where that turnover exceeds S$10 million — whichever is higher. The raised cap has applied since 1 October 2022, having been legislated by the Personal Data Protection (Amendment) Act 2020 with commencement deferred.

How much cyber crime is actually reported in Singapore?

CSA's Singapore Cyber Landscape 2025/2026, published on 30 June 2026, reports that ransomware cases increased marginally to 165 in 2025 from 159 in 2024, while phishing attempts reported to CSA fell about 21% to roughly 4,800 from 6,100. Note that many secondary summaries labelled with the 2025/2026 edition actually quote the previous edition's calendar-2024 figures.

How do you calculate return on cybersecurity investment?

Start from scenarios, not vendor claims. Annualised loss expectancy equals estimated annual event frequency multiplied by expected loss per event. The maximum break-even annual control cost equals baseline annualised loss expectancy multiplied by expected risk reduction. A US$1 million baseline with a defensible 50% reduction gives a US$500,000 annual ceiling before secondary benefits. That is a decision boundary, not a promised return — show uncertainty as a range and make control dependencies explicit.

What should a small business prioritise first?

Survivability over sophistication. Enforce MFA with separate administrator accounts, deploy managed endpoint protection, patch browsers, operating systems and internet-facing devices automatically, use a password manager, protect the email domain, keep immutable or offline backups, and secure an external incident-response contact before you need one. Verify bank-detail changes through a known second channel and test restoration quarterly. Do not build a security operations centre — buy a clearly scoped managed service with defined response hours and containment authority.

Sources and further reading

  1. Primary source Verizon — 2026 Data Breach Investigations Report
  2. Primary source Verizon — 2026 Breach Impact Study: The Financial Costs of Data Breaches
  3. Primary source IBM — Cost of a Data Breach Report 2026
  4. Primary source Gartner — Forecasts Worldwide End-User Spending on Information Security to Total $213 Billion in 2025 (29 July 2025)
  5. Primary source CrowdStrike — 2026 Global Threat Report
  6. Primary source Google Cloud / Mandiant — M-Trends 2026
  7. Primary source Microsoft — Digital Defense Report 2025
  8. Primary source World Economic Forum — Global Cybersecurity Outlook 2026
  9. Primary source Chainalysis — Ransomware in 2026
  10. Primary source Cisco — Cybersecurity Readiness Index 2025
  11. Primary source ISC2 — 2025 Cybersecurity Workforce Study
  12. Primary source Cyber Security Agency of Singapore — Singapore Cyber Landscape 2025/2026 (30 June 2026)
  13. Primary source CSA — Provisions in the Cybersecurity (Amendment) Act to come into force on 31 October 2025
  14. Primary source Singapore Statutes Online — Cybersecurity (Amendment) Act 2024 (Act 19 of 2024)
  15. Primary source Singapore Statutes Online — Cybersecurity (Amendment) Act 2024 Commencement Notification 2025 (S 677/2025)
  16. Primary source Singapore Statutes Online — Cybersecurity Act 2018 (consolidated)
  17. Primary source CSA — Licensing framework for cybersecurity service providers
  18. Primary source CSA — Cybersecurity Code of Practice for CII to be updated; new code of practice for cloud (22 July 2026)
  19. Primary source MDDI / IMDA — Public consultation on the Digital Infrastructure Bill (July 2026)
  20. Primary source PDPC — Advisory Guidelines on Enforcement of Data Protection Provisions (section 48J financial penalties)
  21. Primary source MAS — Technology Risk Management Guidelines (January 2021 revision)
  22. Primary source MAS — Notices 644, 655, 644A, 655A, 1114, 1118 (Cancellation) 2024, effective 10 May 2024
  23. Primary source US SEC — Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
  24. Primary source ESMA — Digital Operational Resilience Act (DORA)
  25. Primary source European Commission — NIS2 Directive
  26. Primary source European Commission — Cyber Resilience Act
  27. Primary source NIST — Cybersecurity Framework 2.0 (26 February 2024)
  28. Primary source NIST — First three finalized post-quantum encryption standards (13 August 2024)
  29. Primary source Unit 42 (Palo Alto Networks) — Autonomous AI cyber attack campaign (30 July 2026)
  30. Primary source OWASP GenAI Security Project — Top 10 for LLM Applications 2026 (3 August 2026)
  31. Primary source VulnCheck — Network edge device report 2026 (23 March 2026)
  32. Primary source Unit 42 (Palo Alto Networks) — Ivanti EPMM CVE-2026-1281 and CVE-2026-1340 exploitation
  33. Primary source CSA — Initiatives to strengthen Singapore's cyber defences amid an AI-driven threat landscape (30 June 2026)
  34. Primary source The White House — Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026)
  35. Primary source Palo Alto Networks — Completes acquisition of CyberArk (11 February 2026)
  36. Primary source Google Cloud — Google completes acquisition of Wiz (11 March 2026)
  37. Primary source Irish Data Protection Commission — DPC fines TikTok €530 million
  38. SANS Institute — The Future of Network Security Technology (February 2024)
  39. CyberScoop — Near-autonomous AI agents used in attack on Taiwanese government (12 August 2026)
  40. CloudSEK — AI supply-chain breach: 2,500 companies and 434,000 CI/CD pipelines (LiteLLM / Trivy, March 2026)
  41. The Hacker News — Model Context Protocol design vulnerability disclosure (OX Security, 20 April 2026)
  42. Help Net Security — OWASP State of Agentic AI Security and Governance (June 2026)
  43. TechCrunch — The worst hacks and breaches of 2026 so far (7 July 2026)
  44. CyberScoop — Fortinet FortiClient EMS CVE-2026-35616 zero-day, hotfix and KEV listing
  45. Baker McKenzie — Singapore cybersecurity regulatory developments ahead (MDDI Committee of Supply, March 2026)
  46. Cooley — EU AI Act transparency obligations take effect 2 August 2026
  47. Crunchbase News — Cybersecurity startup venture funding, H1 2026
  48. DLA Piper — GDPR fines and data breach survey, January 2026

Related resources

Go deeper on this topic

Knowledge base

Vendor directories

Ready to move

Directory next step

Find Singapore providers for this work

Compare Singapore cybersecurity providers for managed detection, penetration testing, compliance and incident response.

Browse cybersecurity providers →

Share with your friends:

Reader notes

Questions, corrections, and field notes

Curated notes from verified readers. Submissions are reviewed before publication.

Loading reader notes...