Cyberthreat telemetry suggests that organizations in the region should prioritize advanced email protection, sandboxing credentials, identity security as primary control plane, and investing in AI and automation. But are organizations heeding?
Based on its study of cyberthreat telemetry in the second half of 2025, ESET recommended that enterprises should prioritize:
- Stronger delivery layer defenses: Advanced email protection, attachment sandboxing and real-time URL inspection before credentials are captured or malware is delivered.
- Treating identity as the primary control plane: Mandatory MFA and conditional access across corporate and mobile environments to limit infostealer-driven compromise.
- Investments in automation to counter automation: Behavioral analytics and XDR-level visibility to contain threats early and reduce dwell time before persistence is established.
But are Asia Pacific organizations heeding this advice, and which industry sectors are most at risk? We find out more from Tony Anscombe, Chief Security Evangelist, ESET.
ESET’s latest data suggests phaishing and credential abuse are now the primary entry points for breaches. What does this mean for organizations in APAC, and how should they rethink cyber risk in 2026?
Anscombe: Phishing, credential abuse and automated attack infrastructure are now central to current risk patterns across APAC.
In Singapore, ESET telemetry grouped under “HTML/Phishing.Agent” alone accounted for 31.86% of all detected threats in H2 2025, reinforcing that phishing remains the primary method cyber-attackers use when attempting to breach corporate environments.
Across Australia, Malaysia, New Zealand and India, HTML/Phishing.Agent also ranked as the top detected threat, which suggests this is not a local spike but a broader APAC pattern.
At the same time, infostealers such as Formbook at 23.45% highlight how closely phishing and credential theft now work together in the early stages of compromise. This is shifting the conversation for organizations in 2026. The dominant enterprise risks are less about exceptional attack methods and more about how easily attackers can gain initial access at scale. While zero-days and major incidents attract attention, most attackers focused on initial access still rely on socially engineered emails, malicious links and compromised logins to gain access. What has changed is the speed and scale at which these tactics can now be deployed.
For organizations across APAC, the priority is to reduce attacker opportunity before persistence is established. That starts with the delivery of strong layered defenses, including advanced email protection, attachment sandboxing and real-time URL inspection to disrupt phishing campaigns before they reach the inbox.
It also means treating identity as the primary control plane, with mandatory multi-factor authentication and conditional access across corporate and mobile environments to limit infostealer-driven compromise.
Beyond that, organizations should invest in defensive-automation to counter act attack-automation, using behavioral analytics and XDR-level visibility to contain threats early and reduce dwell time before attackers can move laterally across the environment.
We’re seeing increased use of infostealers and automated phishing infrastructure. What does this shift towards “scalable initial access” mean for how attacks are carried out today?
Anscombe: Attackers are increasingly relying on speed, automation and volume to gain access. Rather than depending only on bespoke intrusion methods, they are using disposable infrastructure, high-velocity campaigns and commodity malware to create repeated opportunities for compromise.
Infostealers are a key part of that shift because credential theft enables immediate access and creates options for follow-on activity. Once credentials are exposed, attackers are in a position to broker the compromised credentials to another party or directly move into account takeover, internal reconnaissance, financial fraud or broader compromise. Automated phishing campaign infrastructure supports this with faster deployment, easier to rotate and harder to disrupt at scale.
This is also changing the economics of attack. High-quality phishing content, polished lures and rapidly changing domains mean even lower-skilled attackers can orchestrate convincing campaigns. The automation and content tools are moving towards every phishing email evolving to be a spear-phishing email. The challenge for organizations is the volume and velocity of these attacks, which continuously test for weaknesses in the environment.
For defenders, that raises the importance of automated detection, behavioral analytics and XDR-level visibility. At this scale, the challenge is no longer just prevention, but decision-making — identifying which signals matter and responding at machine speed as attackers continuously test for valid access across the environment.
Where are organizations still getting it wrong when it comes to cyber resilience, despite increased investment and awareness? For instance, ransomware remains prevalent but is often the result of earlier compromise. Are organizations still too focused on end-stage attacks rather than the initial breach point?
Anscombe: Many organizations are still too focused on the headline-producing phase of the incident rather than the earlier compromise that made it possible.
Ransomware remains prevalent and costly, but it is often deployed opportunistically following initial compromise. By the time ransomware is executed, attackers have usually already gained access through phishing, weak credentials, unpatched systems or exposed services – and may have even exfiltrated sensitive company data.
This is where prevention-first thinking still matters. The most effective strategy starts with shrinking the attack surface and making it harder for attackers to gain an initial foothold. That requires robust protection across email, endpoints, cloud applications, mobile devices and networks, as well as better visibility into suspicious behavior early in the intrusion.
In many environments, the challenge is not lack of investment but complexity. As security stacks expand, fragmented visibility and alert fatigue can create gaps in control and slow down response.
Resilience improves when organizations focus on better integration and harmonization across their security stack, ensuring tools work together to provide clearer visibility and faster, coordinated response.
ESET’s data revealed that certain sectors such as construction, manufacturing and IT are more affected. What makes these industries particularly vulnerable, and what can they do differently to reduce risk and improve resiliency?
Anscombe: These industries tend to combine operational pressure, interconnected systems and operational technology (OT) environments as well as broader third-party exposure, which increases the likelihood that a routine weakness can lead to wider disruption.
In construction and manufacturing, organizations often deal with distributed environments, legacy technology and multiple external relationships across suppliers and contractors.
In IT service providers, the concentration of privileged access and interconnected systems makes compromise particularly valuable because it can create opportunities beyond the immediate target. In each of these sectors, attackers do not always need a sophisticated entry point if common weaknesses remain unaddressed.
Reducing risk starts with the fundamentals. Stronger identity controls, better patch management, tighter segmentation and closer oversight of third-party access all help reduce the likelihood of successful compromise. These sectors also benefit from advanced email protection, credential monitoring and earlier detection of suspicious behavior, especially where operational continuity matters.
Improving resiliency is not about adding more controls for the sake of it. It is about strengthening overall security posture across both technology and human factors, so that opportunistic compromise is harder to achieve and easier to contain. In sectors where downtime, business continuity and trust carry immediate consequences, that shift is critical.
