TALKING POINT
WHY SINGAPORE MUST LEAD THE NEXT PHASE OF CYBERCRIME DISRUPTION IN ASEAN
Jess Ng, Country Head of Singapore and Brunei, Fortinet, on why Singapore is positioned to lead ASEAN’ s push towards coordinated, cross-border disruption of cybercrime.
Industrialised ransomware, automated fraud networks and converged crime models are reshaping cybercrime today. According to the World Economic Forum( WEF), the global cost of cybercrime is expected to exceed US $ 23 trillion in the coming years.
Cybercriminal networks now operate with business-like precision. They specialise roles, outsource capabilities and scale across jurisdictions, with revenue-sharing models that mirror legitimate digital platforms. Profits are reinvested into new tools, including AI, further accelerating their operations.
Asia Pacific’ s rapid digitalisation has expanded this opportunity landscape. Sectors such as e-commerce and digital financial services are driving Southeast Asia’ s digital economy, projected to surpass US $ 300 billion.
However, digital acceleration without proportional coordination creates systemic friction. Criminal syndicates exploit regulatory gaps, inconsistent reporting requirements and uneven enforcement capacity across borders, creating an environment where rewards remain high while consequences are fragmented.
If cybercrime operates as an economy, disruption must focus on changing its incentives.
From IT issue to business risk
For many organisations, cybersecurity is still treated as an operational concern – a mindset increasingly outdated. The Global Cybersecurity Outlook 2026 found that 87 % of respondents view AI-related vulnerabilities as a key driver of cyber-risk.
Cyber incidents now have direct implications for market valuation, regulatory exposure and long-term competitiveness. In Singapore, a financial hub, logistics gateway and digital innovation centre, the impact of a major breach can extend beyond individual organisations, affecting supply chains, investor confidence and national reputation.
As regulatory expectations evolve and investor scrutiny intensifies, cybersecurity is becoming a core element of enterprise risk management and ESG oversight. Boards must move beyond viewing cybersecurity as a cost centre and instead treat it as economic risk management within a broader regional threat landscape.
Shifting the economics of cybercrime
The reality is that cybercrime persists because it remains low risk and high reward. Attackers operate across borders, while enforcement remains constrained by jurisdictional boundaries. Traditional strategies focused on strengthening organisational defences are necessary but no longer sufficient.
A more strategic approach must increase operational friction for cybercriminal networks. This includes accelerating cross-border intelligence sharing, improving incident reporting and disrupting the monetisation pathways that make attacks profitable.
Singapore has made significant progress in strengthening governance and public private collaboration. However, national efforts alone cannot address a fundamentally regional challenge.
Cybercriminal networks do not recognise borders and defensive strategies cannot afford to either.
Institutionalising collaboration through clear frameworks, legal protections and coordinated response mechanisms will be key. When organisations see tangible value in early reporting, whether through support, clarity, or reduced regulatory uncertainty, participation is likely to improve. Over time, this begins to shift the economics of cybercrime.
From dialogue to execution in ASEAN
Global forums such as the WEF have helped elevate cybersecurity from a technical issue to an economic and geopolitical priority. The challenge now is translating that momentum into execution.
Across ASEAN, disparities in digital maturity and regulatory development create uneven ground, gaps that cybercriminals are quick to exploit.
Closing this gap will require structured regional alignment, with stronger intelligence sharing mechanisms, faster cross border coordination and clearer reporting standards. As a trusted hub, Singapore has a unique opportunity to play a convening role, driving the practical collaboration needed to turn dialogue into action.
Securing growth in an AI-driven economy
Digital growth and cyber-risk are now inseparable. The region’ s long-term competitiveness will depend on its ability to build trust at scale through governance, coordination and aligned incentives.
For Singapore and ASEAN, this requires a shift from isolated defence to collective resilience.
If incentives remain skewed in favour of attackers, the region’ s digital momentum will be increasingly exposed to systemic risk. But if governments and industry can align efforts across borders, they can begin to tilt the balance.
The defining factor will be whether coordination can move as quickly and as effectively as the threats it seeks to contain. •
18
INTELLIGENT CIO APAC www. intelligentcio. com