Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Cyber insurers and legal professionals prepare for claims over harms b...
CyberDSA Sets 19 – 21 October 2027 Return as Industry Participat...
The “Awareness Gap” in Australian enterprise security
How CISOs can set human boundaries for autonomous cybersecurity
Securing the agentic enterprise – at machine speed
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      How CISOs can set human boundaries for autonomous cybersecurity

      How CISOs can set human boundaries for autonomous cybersecurity

      Wednesday, October 7, 2026, 11:05 AM Asia/Singapore | Features, Newsletter, Tips
    • Featured

      Securing the agentic enterprise – at machine speed

      Securing the agentic enterprise – at machine speed

      Tuesday, October 6, 2026, 5:00 PM Asia/Singapore | Features, Newsletter
    • Featured

      Why businesses need to treat AI agents like privileged insiders

      Why businesses need to treat AI agents like privileged insiders

      Thursday, October 1, 2026, 10:00 AM Asia/Singapore | Features, Opinions, Sponsored
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

FeaturesOpinionsSponsored

Why businesses need to treat AI agents like privileged insiders

By Jack Wang, Senior Director - ASEAN & East Asia, Tenable | Thursday, October 1, 2026, 10:00 AM Asia/Singapore

Why businesses need to treat AI agents like privileged insiders

Agentic AI is reshaping enterprise security in APAC, making identity, privilege and access controls critical as AI agents gain the ability to act autonomously across business systems.

AI adoption across APAC is entering a new phase. For the past two years, much of the enterprise conversation has focused on chatbots, copilots and productivity tools. The main risks were familiar: inaccurate outputs, data leakage, prompt injection and employees entering sensitive information into public AI tools.

Agentic AI changes that equation. Unlike traditional AI tools that generate answers, AI agents can plan tasks, call tools, access data, interact with APIs, trigger workflows, write code and make decisions with varying degrees of autonomy. In practical terms, they are moving from assistance to action. Once an AI agent can act on behalf of a user or business function, it starts to behave less like ordinary software and more like a non-human privileged user.

Jack Wang, Senior Director – ASEAN & East Asia, Tenable

The security question has changed

Many organisations still approach AI security as primarily a model problem. They ask whether the AI tool is accurate, whether it might leak data, or whether it can be manipulated through prompts. These are important questions, but they are incomplete once the AI system is connected to enterprise tools and workflows.

The more important issue is authority. Can the agent access customer data, query internal systems, connect to cloud environments or code repositories, or trigger actions without human review? If so, the organisation is no longer just managing an AI tool. It is delegating access and decision-making power to a machine. A chatbot that gives a wrong answer may create confusion. An AI agent that takes the wrong action can create business impact.

This is why AI agents should be viewed as part of the broader identity problem. Organisations already struggle to manage non-human identities such as service accounts, bots, API keys and automation scripts. These identities often have persistent access, multiply quickly and retain permissions long after their original purpose has changed.

AI agents add a more complex layer because they may rely on service accounts, plugins, APIs, cloud permissions, third-party packages and enterprise integrations. They may also operate across several systems to complete a task, often without constant human oversight. If their access is too broad, poorly monitored or difficult to revoke, they can become a powerful source of exposure. A compromised or misconfigured agent may give attackers a new route into sensitive data, internal systems or business workflows.

Tenable’s 2026 Cloud and AI Security Risk Report highlights this emerging challenge. It found that 18% of organisations have overprivileged AI identities expanding their cloud attack surface, while 86% use third-party code packages with critical vulnerabilities.

The point is clear: AI risk is increasingly connected to cloud, identity, code, permissions and business process risk.

Why this matters now

Agentic AI is moving from experimentation into real enterprise use cases. Across APAC, organisations are exploring agents for customer service, software development, IT operations, finance, HR, cybersecurity and internal productivity. The business case has already been made; faster processes, less manual work and greater efficiency.

The challenge is that adoption can move faster than control. Many companies are still focused on AI policies, acceptable-use guidelines and governance frameworks. These are useful, but they do not answer the operational question security teams need to resolve: what authority has this agent been given inside our environment?

Regulators are starting to recognise the issue. Singapore’s Cyber Security Agency recently released guidance on securing agentic AI systems, noting that these systems introduce additional risks because they can plan and take actions through access to tools and data. That is an important signal for the region as AI agents become more autonomous and more deeply connected to enterprise systems.

The concern is practical. An overprivileged AI agent could access more data than required. A compromised plugin could become a route into enterprise systems. A prompt injection attack could become more damaging if the agent can retrieve sensitive data or trigger workflows. A poorly scoped service account could allow an agent to act outside its intended role.

From AI policy to AI control

The answer is not to slow AI adoption. Businesses will continue to deploy AI agents because the productivity gains are too significant to ignore. What has to change is what AI security means in practice. It is no longer only a question of whether the model behaves as expected, but of what the agent is permitted to do once it is inside the business, and that is a question of privileged access and enterprise exposure, managed with the same discipline organisations already apply to both.

Security teams need to know which AI agents exist, who owns them, what systems they can access, what actions they can perform and which identities or permissions they rely on. They also need clear controls around least privilege, access reviews, monitoring, permission scoping and rapid revocation.

This requires a shift from policy-led AI governance to control-led AI governance. A policy may state what employees should or should not do with AI, but controls determine what AI can actually do inside the business. That distinction will become more important as agents are embedded into critical workflows.

Before scaling agentic AI, organisations should be able to answer a simple set of questions: what can the agent access, what can it change, what actions can it trigger, who owns it, how is its access reviewed, how quickly can that access be revoked, and what happens if it is misused or compromised?

Agentic AI can bring real benefits to APAC organisations. But those benefits will only be sustainable if businesses understand and control the authority they are giving to machines. If an AI agent can act on behalf of the business, it needs to be secured like a privileged insider, not treated like ordinary software.

Share:

PreviousKaspersky and Best Telecom expand strategic cooperation to strengthen digital security in Laos
NextEvilTokens takedown leaves compromised accounts unresolved

Related Posts

How to Back Up Your Microsoft 365

How to Back Up Your Microsoft 365

Thursday, December 15, 2022

Behind-the-scenes look at securing Paris Olympics facilities

Behind-the-scenes look at securing Paris Olympics facilities

Tuesday, August 13, 2024

Some threat actor innovations to watch out for

Some threat actor innovations to watch out for

Tuesday, February 6, 2024

“Good rain knows the best time to fall”: fraudster motto

“Good rain knows the best time to fall”: fraudster motto

Monday, November 1, 2021

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

LEARN MORE

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • CyberDSA Sets 19 – 21 October 2027 Return as Industry Participation Builds at Fourth Edition

    Thursday, October 8, 2026
    CyberDSA moves towards its milestone …Read More »
  • CyberLogitec Brings Tag-Free Collision Prevention to Busan New Port

    Tuesday, October 6, 2026
    Digital twin places workers and …Read More »
  • Aligning with Global Regulations: iMQ Technology’s SQ713x Secure Element Achieves SESIP and PSA Certified Level 3

    Monday, October 5, 2026
    Passes Keysight’s physical attack testing …Read More »
  • Cymulate Receives Frost & Sullivan’s 2026 Indian Competitive Strategy Leadership Recognition for Advancing Continuous Security Validation

    Monday, October 5, 2026
    The recognition highlights Cymulate’s competitive …Read More »
  • CyberDSA 2026 Opens in Kuala Lumpur as Malaysia’s AI Ambition Puts Cybersecurity, Trust and Sovereign Capability in Sharper Focus

    Monday, October 5, 2026
    As CyberDSA opens its fourth …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.