APAC Cybersecurity Spending Turns Toward Identity Risk
Identity governance is moving into the center of APAC security planning as session theft, AI-enabled impersonation and uneven regional maturity weaken older perimeter-heavy defenses.

Frontier Enterprise framed the latest APAC security planning problem around identity, not stolen passwords: attackers are increasingly exploiting trusted sessions, tokens and authentication flows after perimeter tools have already done their job.
The shift is visible in regional crime data.
Interpol’s 2025/2026 assessment for Asia and the South Pacific covered 18 member countries; in more than half, cybercrime now makes up 30% of all nationally reported offences.
Phishing and social engineering sit at the front of that damage because they exploit trust before technical controls can decide whether an access request is genuine.
Two-factor authentication and single sign-on link the login event to a user; the identity risks described by Frontier Enterprise extend to sessions that have already been authenticated.
Session hijacking, token theft and SSO exploitation can move around those checks once a trusted session is captured, while password reuse across cloud applications gives attackers more places to turn one compromise into wider access.
Frontier Enterprise describes identity verification as a distinct task alongside endpoint protection, firewalls and network monitoring.
It concerns whether a person, service account or AI agent requesting access remains legitimate at the point of use.
Spending plans are starting to move in that direction.
IDC puts the Asia-Pacific security market outside Japan at US$39.5 billion for 2026 and projects a 10% compound annual growth rate through 2029.
Identity governance is one of the faster-growing parts of that forecast, placing access controls in the same budget conversation as core infrastructure rather than a supporting layer around it.
The planning consequence is practical.
CISOs and finance teams setting 2026 and 2027 roadmaps have to decide whether privileged access management, identity governance and continuous verification receive enough funding to match the exposure.
A perimeter-heavy budget can still leave the access layer under-resourced if attackers are entering through sessions that already look trusted.
AI adds pressure on both sides of the ledger.
Generative tools make impersonation easier and cheaper, and Interpol tracked a 600% jump in deepfake chatter from February to June 2024 across criminal forums and Telegram channels popular with Southeast Asian threat actors.
The result is a larger pool of fraud attempts that can look more personal, timely and convincing.
The same technology is also being built into defenses for anomaly detection, behavioral analysis and alert triage.
Deloitte’s 2026 Global Technology Leadership Study, based on more than 660 senior technology executives, found 81% confidence that current operating models can deploy and govern AI across the enterprise, even as 75% acknowledged those models will need to change within 12 to 18 months to create more value.
That confidence gap matters because identity programs now have to cover more than employees and contractors.
Machine identities, automated workflows and AI agents are being added to the same access environment, increasing the number of entities that need verification and governance.
Regional maturity also varies.
Singapore and Australia have deeper regulatory frameworks and larger security budgets, while Vietnam, Indonesia and the Philippines are adding digital infrastructure and new threat exposure at the same time.
A control model built for a mature hub may not transfer cleanly to a faster-digitising market with less institutional capacity.
The operating condition for APAC enterprises is therefore narrower than a general cyber budget increase.
Identity has become the control plane that determines whether cloud, AI and remote-work defenses can be trusted; without stronger governance at that layer, attackers can use legitimate-looking access to bypass much of the security stack around it.




















