Magazine

Read the latest edition of AIR and MEIR as an Interactive e-book

Sep 2026

Agentic AI raises cyber risk states

Source: Asia Insurance Review | Aug 2026

From autonomous AI agents to deepfake scams, cybercriminals are leveraging new technologies to launch faster, more convincing attacks that challenge traditional cyber defences. Delta Underwriting’s Mr Sebastian Phua tells us more. 
By Reva Ganesan 
 
 
The cyber threat landscape across Asia-Pacific has become significantly more complex over the past three years, fuelled by rapid digitalisation, widespread technology adoption and increasingly sophisticated cybercriminal networks. 
 
As organisations accelerate their digital transformation, the frequency, scale and sophistication of cyber attacks have continued to rise, creating new challenges for businesses across the region.
 
According to Delta Underwriting Head of Business Strategy Sebastian Phua, cybercrime has reached a level where it now accounts for more than 30% of all crimes recorded nationally. Across APAC, more than 6.5bn cyber threats were detected and mitigated over a 15-month period, highlighting the sheer scale of malicious cyber activity.
 
Mr Phua said the nature of cyber attacks has also evolved dramatically alongside technological advances. Activities that once required significant technical expertise can now be automated and executed within minutes, lowering the barriers to entry for cybercriminals.
 
He noted that threat actors are increasingly leveraging AI, ransomware-as-a-service models and sophisticated social engineering techniques to launch attacks on an industrial scale.
 
“What is particularly challenging for businesses is that every cyber risk is interconnected,” he said. “A single human error or technical vulnerability can compromise an entire operational network, making cyber resilience a business-wide priority rather than simply an IT concern.”
 
Growing use of AI by threat actors 
One of the most significant developments in the cyber risk landscape is the growing use of AI by threat actors, which is changing both the speed and sophistication of cyber attacks.
 
Mr Phua said one of the biggest shifts is the emergence of agentic AI, where AI systems are capable of independent reasoning, multi-step planning and autonomous execution.
 
He said cybercriminals are increasingly deploying agentic AI to manage the entire attack lifecycle. 
 
“These autonomous systems can reason through obstacles, adapt to defensive measures and modify their tactics without human intervention, significantly reducing the time needed to compromise a target while making attacks more complex to detect and contain,” he said. 
 
He also pointed to a widening speed gap between attackers and defenders. While cybercriminals are increasingly operating at machine speed, many organisations continue to respond at human speed, creating a critical window during which breaches can occur.
 
“The consequences extend well beyond data loss,” he said. Successful attacks can halt business operations, disrupt supply chains and damage trust among customers, partners and other stakeholders.
 
Another notable trend is the shift towards attacks that exploit human behaviour rather than purely technical weaknesses. 
 
Mr Phua said cybercriminals are increasingly using voice and video deepfakes in business email compromise scams, generating convincing real-time synthetic media of senior executives such as CEOs or finance directors to authorise urgent, high-value fund transfers.
 
“The focus is no longer solely on exploiting systems. It is increasingly about exploiting trust at scale,” he said. 
 
Interconnected cyber risks
Cyber risks in Asia-Pacific are becoming increasingly interconnected, with ransomware, supply chain vulnerabilities and AI-driven attacks reinforcing one another rather than operating as isolated threats.
 
Cyber risk today is best understood as “an interconnected matrix of risks”, where each threat acts as a force multiplier for the others, Mr Phua said. 
 
Among the most significant drivers is the growing use of AI by cybercriminals. 
 
Mr Phua said AI is enabling highly targeted, multilingual phishing campaigns and increasingly convincing deepfake audio and video impersonations at scale. 
 
While AI has not fundamentally changed how attacks are carried out, it has made them faster, more efficient and more difficult to detect.
 
Supply chain attacks also remain a major concern as businesses become more reliant on interconnected digital ecosystems, he said. 
 
“Rather than attacking organisations directly, cybercriminals are increasingly exploiting vulnerabilities in third-party vendors and trusted software providers to gain access to their intended targets. A single weakness in the supply chain can have cascading effects across multiple organisations,” he said. 
 
Undoubtedly, ransomware continues to be one of the region’s most persistent cyber threats. 
 
Mr Phua noted that APAC recorded more than 135,000 ransomware-related attacks in 2024, with criminal groups adopting increasingly decentralised operating models that make them more resilient and harder for law enforcement agencies to disrupt.
 
Moving beyond cybersecurity
AI is expected to remain one of the biggest drivers of cyber risk for businesses across Asia-Pacific over the coming years, creating new opportunities for growth while simultaneously expanding organisations’ exposure to increasingly sophisticated attacks.
 
The same technologies that are accelerating digital transformation are also widening the cyber attack surface. Advances in AI are making cyber attacks more accessible, automated and difficult to defend against.
 
Mr Phua believes small and medium-sized enterprises (SMEs) will remain particularly vulnerable. Many operate with limited cybersecurity resources, constrained budgets and incomplete cyber hygiene practices, yet they play critical roles within supply chains and digital ecosystems. As a result, cybercriminals increasingly view SMEs as gateways to larger organisations.
 
He said businesses will need to move beyond treating cybersecurity and cyber insurance as separate lines of defence. 
While technical controls remain essential and insurance provide financial protection, rapidly evolving AI-powered threats require a more proactive approach to cyber resilience.
 
This includes continuous risk assessments, preventive security measures, rapid incident response capabilities and financial protection that enables businesses to recover quickly when attacks occur.
 
Beyond traditional coverage
Looking ahead, Mr Phua expects cyber insurance to become a far more active component of organisations’ cybersecurity strategies rather than a product reviewed only at annual renewal.
 
He said future cyber insurance offerings are likely to place greater emphasis on continuous risk management, including regular employee awareness training, phishing simulations and ongoing monitoring of organisations’ attack surfaces to identify emerging threats and vulnerabilities before they can be exploited.
 
He also expects insurers to align their products more closely with government cybersecurity initiatives to encourage stronger risk management practices. 
 
In Singapore, for example, programmes developed by the Cyber Security Agency of Singapore, such as Cyber Essentials and Cyber Trust, provide SMEs with practical frameworks to strengthen their cybersecurity posture.
 
“As the threat landscape continues to evolve, cyber insurers will need to proactively identify emerging risks and develop solutions that help businesses remain protected,” he said. A 
 
CAPTCHA image
Enter the code shown above in the box below.

Note that your comment may be edited or removed in the future, and that your comment may appear alongside the original article on websites other than this one.

 

Recent Comments

There are no comments submitted yet. Do you have an interesting opinion? Then be the first to post a comment.