The new front line: Securing AI in a hyperconnected world
![]() |
| Source: Kyndryl. |
Innovation and exploitation have always evolved in tandem. Each time the world expands its digital footprint, attackers move in to occupy that new terrain. When business and government went online, they followed the data. When the cloud scaled globally, they followed the workloads. Now, as enterprises weave AI into the world’s IT infrastructure, attackers are following the algorithms, as well.
It’s a symbiotic pattern, almost evolutionary. Every gain in efficiency becomes a new surface to protect. The systems that make modern life seamless — real-time payments, personalised healthcare, automated logistics — are the same ones that render it fragile. Progress doesn’t eliminate risk, it redefines it.
Bad actors are already using AI to scale their phishing and reconnaissance operations. Meanwhile, if not strategically deployed and governed, our own AI systems can introduce new failure paths in the form of unintended behaviors, data leaks, or even model poisoning. Cybersecurity is a race of automation and resilience. The mission is clear: secure the AI itself, contain blast radius, monitor continuously, and recover quickly.
However, Kyndryl’s 2025 Readiness Report found that while enterprises in Singapore are seeing growing
returns from AI and cloud investments, only 24% of the country’s organisations feel fully prepared to
manage future risks, well below the global average of 31%. While many organisations in the country are
racing to modernise, workforce preparedness and growing regulatory complexity are slowing innovation.
This is a global story, but perhaps nowhere is it more visible — or instructive — than in Singapore. The city-state contains the challenges of the digital economy into a tight, highly networked testbed. As one of the world’s leading data hubs, hosting roughly 1.4 gigawatts of data centre capacity, the city underpins much of the flow of regional digital information. That position invites immense opportunity — and risk.
Unfortunately, 53% of projects on the island remain stuck in pilot stages as leaders face mounting pressure to prove returns. And while 54% of global organisations report positive ROI from AI, up 12 points from 2024, most Singapore leaders say foundational technology challenges are holding back progress, with 58% of the country’s respondents saying they struggle to keep pace with technological change.
The escalation of AI-driven threats
For bad actors, the opportunity has quickly come into view. In 2024, phishing cases in Singapore surged by 49% to more than 6,100, while ransomware incidents rose by 21%, according to the Cyber Security Agency of Singapore. In the three years between 2021 and 2024, advanced persistent threats targeting the country increased more than four-fold. Many of these intrusions have been attributed to espionage groups such as UNC3886, which focus on high-value targets that include critical infrastructure.
It's a trend that largely mirrors what’s happening globally: a steady escalation from opportunistic attacks to persistent, AI-assisted campaigns. In response, defenders must combat AI attacks with AI solutions. Sophisticated algorithms are used to sift through mountains of data points to detect subtle anomalies that signal any intrusion. But the equilibrium won’t last. The AI-assisted attacks of today will evolve into autonomous swarms of intelligent agents capable of identifying vulnerabilities, adapting in real time, and executing end-to-end operations without human direction.
Compounding the challenge is the rise of so-called adversarial AI, which can be designed with methods to deceive or corrupt defensive systems. To be clear, this is not a theoretical threat. By 2026, with deepfake and generative-forgery tools available to bad actors, the very notion of digital trust will come under strain.
Singapore’s wake-up call
Singapore’s leadership has responded. Coordinating Minister for National Security K. Shanmugam confirmed in mid-2025 that state-linked attackers had breached parts of the country’s critical information infrastructure. By publicising the attack, the government made the threat tangible for citizens and enterprises alike, underscoring a sense of urgency and the need for collective defence.
The Cyber Security Agency’s Singapore Cyber Landscape 2024/2025 Report followed, and it highlighted ransomware, phishing, and supply-chain vulnerabilities as some of the nation’s most pressing concerns. Such moves signaled a pivot from reactive management to proactive governance.
The city-state’s experience offers a preview of what every digitally mature economy will face: a tension between rapid innovation and systemic exposure.
AI that’s secure by design
It’s against this backdrop that Singapore emerged as a global reference point for AI security governance. The government’s Guidelines on Securing AI Systems published in 2024 stands out for its clarity and practicality. It sets out that AI should be ‘secure-by-design and used alongside existing IT security practices.’ At its core is a practical lifecycle approach:
Own it. Assign a clear owner and do a quick risk check before you build.
Keep sensitive data safe. Limit who can access models and data, separate test vs. production, encrypt everything.
Test before launch. Try to “break” the system, and only ship if it passes.
Know what’s inside. Keep a list of every model, dataset, library, and vendor you use; ask suppliers to list their software parts (“bill of materials”).
Watch it in the wild. Log prompts and outputs, alert on weird behaviour, and be ready to roll back quickly.
Be breach-ready. Write a short incident playbook (who does what, in what order) and practice it.
Update and retire cleanly. Treat model updates like change management; securely wipe data/models when you decommission.
It’s an approach that reframes AI security not as an add-on, but as part of the discipline of software engineering itself. It also reflects an important cultural shift in which maintaining security becomes a continuous process of learning, not a static state of compliance.
For leaders, the implications are profound. Cyber resilience is now a board-level concern, alongside financial and reputational risk. It demands collaboration across technology, compliance, and human resources; it requires re-training teams and re-imagining incident response. The question is no longer whether an attack will happen, but how fast an organization can adapt when it does.
The road ahead
Singapore’s experience underscores a larger truth: digital progress and digital exposure are two sides of the same coin. As nations and enterprises embrace AI to drive growth, they must also rethink what it means to be secure.
In a world where code can learn, defences must learn too. The frontier of cybersecurity is no at the perimeter of our networks or in the supply chains. Threats are looking for ways to sneak into the models and data that power them. The institutions that thrive in this new era won’t be those that deploy the most AI, but those that secure it most intelligently.

Comments
Post a Comment