In my recent conversation with CISOs across Southeast Asia, they shared with me a pragmatic view of 2026. Attackers are shifting tactics, AI is amplifying both risk and response, and IT-OT boundaries are blurring. Three priorities stand out to me, hardening cloud and AI infrastructure, treating identity as the active perimeter, and operationalizing resilience as capability and, in select sectors – as a service.
Cloud and AI become high‑value targets
Multi‑cloud adoption and sprawling SaaS create visibility gaps where a single misconfiguration or leaked credential can expose sensitive data and expensive compute, including AI GPUs. CISOs mandate is to tighten configurations, expand telemetry, and assume adversaries are probing the weakest link.
Identity and Trust Are the New Perimeter
We expect fewer “break‑ins” and more impersonation such as AI‑crafted lures, voice scams, session hijacks, and token theft that bypass traditional Multi-Factor Authentication. Southeast Asian CISOs are prioritizing continuous verification, session integrity controls, and trust checks embedded in workflows.
Supply chain risk multiplies
Open‑source components, model repositories, CI/CD pipelines, and cloud platforms widen exposure. A single compromised vendor can cascade across customers; ransomware and data theft increasingly arrive via “trusted” integrations. Organizations must strengthen vendor controls and harden pipelines.
Agentic AI raises the stakes on offense and defense
Autonomous agents can make poor decisions at machine speed unless constrained. Guardrails now include scoped, time‑bound access; human‑in‑the‑loop; kill‑switches; and behavioural monitoring. On defense, Security Operations Centers (SOCs) are automating correlation, summarisation, containment, and remediation, elevating analysts to strategic hunting and validation.
Instrument the browser
As AI works through browser sessions, responders need session reconstruction and richer telemetry to investigate fast‑moving incidents.
People remain decision makers
With manipulation accelerating, boards are investing in targeted awareness, deception detection, and decision‑support training that complements technical controls.
IT- OT convergence expands cyber‑physical risk
Industrial control systems require OT‑specific resilience such as segmentation, rigorous change control, and rehearsed recovery to be prioritized at the board level.
In financial services, resilience becomes a revenue stream
Large institutions may productize security assurance by packaging cyber resilience, AI‑enabled fraud controls, and compliance automation as subscription services.
Zero Trust extends to non‑human identities
Enterprises will manage thousands of AI agents. Expect formal AI identity and access governance, including least privilege for agents, authentication models for non‑human actors, and continuous behavior monitoring.

Shutterstock
CSO ASEAN Final Take
2026 will test whether organisations can secure what they automate. In my view, this collective Southeast Asia CISOs’ message is consistent: harden cloud and SaaS, elevate identity‑centric controls, instrument agents and browsers for forensic clarity, and treat resilience not only as defense but, where it makes sense, treat it as a product.
Enjoy reading these top predictions for 2026 by our region’s most eminent CISOs who are also our CSO30 ASEAN & Hong Kong Award 2025 winners:
| Jason Lau Chief Information Security Officer Crypto.com Board Director at ISACA |
| Yohannes Glen Dwipajana SVP Head of Enterprise Security Indosat Ooredoo Hutchison Prediction 5 |
| Michael Saw Chief Information Security Officer, APAC Siemens Energy Prediction 8 |
| Primitivo Nufable VP & Head – IT, Information & Cyber Security Group St Luke’s Medical Centre Prediction 9 |
| Chhay Yaroth SVP and Head of Information Security Division ACLEDA Bank Plc. Prediction 12 Prediction 13 |

Innovation and technology, Hand of robot touching a padlock of security on network connection of business, Data exchange, Financial and banking, AI, Cyber crime and internet security.
iStock/ipopba
