Fri, 11 Sep 2026

97% of IT systems in APAC can scam from legit messages

IT decision-makers are complacent about risks to the business from phishing and BEC (Business Email Compromise – also known as CEO Fraud). Only 45% of APAC IT decision-makers say they are concerned about phishing as a risk to their organisation, while even fewer are concerned about BEC (34%).

When asked to determine whether example emails and SMS were real or fake, only three per cent of APAC IT decision-makers were able to correctly identify them all. Only 27% of APAC IT decision-makers use their work phones for personal activity and 25% use their work email address for personal activity.

Jacqueline Jayne

Concerned, Jacqueline Jayne, security awareness advocate for APAC at KnowBe4 said when those charged with keeping a business secure are unaware of the risks and unable to identify scam emails and SMS messages, their organisations are at significant risk.

Singapore’s Anti-Scam Centre states Singaporeans lost $201.7million in the first half of 2021. If those in charge of security are unaware of best practices, then they cannot educate and train employees. 

ā€œWhen employees are using their work email address for personal activities such as online shopping, they are much more likely to fall victim to a phishing attack that uses a hook such as delivery delays to entice the victim to click through. Having a clear separation between work and personal activities makes it much easier to spot when an email is a scam – if you know you never shop online using your work email address, then you know that email from Amazon cannot be real.ā€

Jacqueline Jayne

Data breach protocol

Only 46% of APAC IT decision-makers say they are confident they would know the steps they would need to take following a cyber incident or data breach in their organisation. 

Only 47% of APAC IT decision-makers believe the employees in their organisations understand the business impact of falling victim to a cyberattack, are confident their employees can identify phishing and BEC emails (42%) and that their employees report all emails they believe to be suspicious (39%). 

Security investment

The majority (77%) of APAC IT decision-makers say they plan on investing in/spending money towards cybersecurity in 2022. Those who plan on investing in/spending money towards cybersecurity in 2022: 

  • Are most likely to be investing in/spending money on new cybersecurity software solutions (48%).
  • Followed by a cybersecurity awareness training program with ongoing and relevant content (47%).Ā 

Other areas of investment include further investment in infrastructure (39%), employee policy changes related to cybersecurity (33%), cybersecurity insurance (35%) and simulated phishing and social engineering for end-users (29%).

Related:  Stopping Singapore's looming labour shortage

Related Stories

MORE STORIES

Subscribe