{"id":70115,"date":"2026-07-20T08:22:23","date_gmt":"2026-07-20T00:22:23","guid":{"rendered":"https:\/\/sgbuzz.com\/?p=70115"},"modified":"2026-07-20T08:22:23","modified_gmt":"2026-07-20T00:22:23","slug":"identity-breaches-plagued-7-in-10-singapore-firms-in-the-past-year","status":"publish","type":"post","link":"https:\/\/sgbuzz.com\/?p=70115","title":{"rendered":"Identity breaches plagued 7 in 10 Singapore firms\u00a0in the past year"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n            <!-- image --><\/p>\n<div class=\"td-post-featured-image\"><a href=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026.png\" data-caption=\"\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"696\" height=\"648\" class=\"entry-thumb td-modal-image\" srcset=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-696x648.png 696w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-300x280.png 300w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-1024x954.png 1024w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-768x716.png 768w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-451x420.png 451w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-1068x995.png 1068w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026.png 1200w\" data-lazy-sizes=\"(max-width: 696px) 100vw, 696px\" alt=\"\" title=\"Sophos_State_of_Identity_Security_2026\" src=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-696x648.png\"\/><img loading=\"lazy\" decoding=\"async\" width=\"696\" height=\"648\" class=\"entry-thumb td-modal-image\" src=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-696x648.png\" srcset=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-696x648.png 696w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-300x280.png 300w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-1024x954.png 1024w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-768x716.png 768w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-451x420.png 451w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026-1068x995.png 1068w, https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/07\/Sophos_State_of_Identity_Security_2026.png 1200w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" alt=\"\" title=\"Sophos_State_of_Identity_Security_2026\"\/><\/a><\/div>\n<p>            <!-- content --><\/p>\n<p class=\"wp-block-paragraph\">Seven in every 10 (71%) of\u00a0organisations\u00a0globally\u00a0suffered at least one identity-related breach in the past year, and\u00a0on average\u00a0organisations\u00a0reported\u00a0three separate incidents, according to Sophos.<\/p>\n<p class=\"wp-block-paragraph\">This is based on a vendor-agnostic survey\u00a0conducted in the first quarter of 2026\u00a0which covered\u00a05,000 IT and cybersecurity leaders across 17 countries, including the United States, the United Kingdom, Germany, France, Australia, Japan, India, Brazil and Singapore, in\u00a0organisations\u00a0with 100 to 5,000 employees across 14 industries.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The survey found that identity attacks are rarely one-off events with repeat victimisation reaching a notable level, with\u00a05%\u00a0of global respondents\u00a0reporting\u00a0six or more\u00a0breaches. These attacks are\u00a0driven primarily by human error and weak management of non-human identities (NHIs),\u00a0a challenge that is accelerating rapidly as agentic AI\u00a0accelerates attack processes.<\/p>\n<p class=\"wp-block-paragraph\">Two thirds of\u00a0the\u00a0ransomware victims (67%)\u00a0responding\u00a0to this survey\u00a0confirmed their ransomware incident\u00a0stemmed from an\u00a0identity attack,\u00a0establishing\u00a0identity compromise as a primary delivery mechanism for ransomware. Sophos X-Ops researchers have observed this consistently over the past year.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The financial\u00a0consequences are steep: the mean recovery cost reached\u00a0US$1.64 million, with a median of\u00a0US$750,000, and 73% of those affected faced costs of $250,000 or more.<\/p>\n<p class=\"wp-block-paragraph\">In Singapore, identity breaches were slightly higher than the global average, with\u00a072% of\u00a0organisations\u00a0reporting at least one identity-related security breach in the past 12 months, compared with\u00a071% globally.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cIdentity has become the primary attack surface in modern cybersecurity, and this data shows most\u00a0organisations\u00a0are losing ground,\u201d said Ross McKerchar, CISO at Sophos. \u201cThe non-human identity problem is particularly urgent. AI agents are\u00a0being granted privileges faster than security teams can\u00a0track them, and\u00a0organisations\u00a0that\u00a0fail to\u00a0get ahead of this will find it an increasingly costly gap to close.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Findings also show that, overall, 10% of\u00a0organisations\u00a0reported an identity breach that\u00a0impacted\u00a0their business in the last year with the primary consequences being data theft (49%) and ransomware (48%), and financial theft (47%).<\/p>\n<p class=\"wp-block-paragraph\">Also, visibility remains a critical weakness.\u00a0Only 24% of\u00a0organisations\u00a0continually\u00a0monitor for\u00a0unusual login attempts, and more than half check every three months or less.<\/p>\n<p class=\"wp-block-paragraph\">In addition, detection gaps persist as\u00a014% of breached\u00a0organisations\u00a0could not detect and stop their most significant identity attack before damage was done.<\/p>\n<p class=\"wp-block-paragraph\">Further, critical infrastructure are the most exposed.\u00a0Energy, oil\/gas, and utilities (80%) and federal\/central government (78%) reported the highest breach rates across all industries surveyed.<\/p>\n<p class=\"wp-block-paragraph\">The study also found that compliance struggles signal a broader risk.\u00a0Organisations\u00a0that found compliance requirements\u00a0very challenging\u00a0had a breach rate of 82.4%, a full 14 percentage points higher than those with lower compliance difficulty (68.3%).<\/p>\n<p class=\"wp-block-paragraph\">Human error (employees tricked into providing credentials) was cited in\u00a0nearly\u00a043%\u00a0of incidents. Weak NHI management, including API keys stored in code, static credentials, and orphaned service accounts, was cited in 41%.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Organisations\u00a0with weak NHI management are\u00a022% more likely to experience financial theft and pay approximately $150,000 more to recover than average.<\/p>\n<p class=\"wp-block-paragraph\">The NHI management problem is intensifying. AI agents can autonomously spin up sub-agents, each generating new credentials with broad, persistent access and inconsistent human oversight.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Existing identity frameworks were not built for this, and\u00a0organisations\u00a0are already behind: only one in three organisations regularly rotate or audit service accounts and non-human identities, and just 11% do so continuously.<\/p>\n<div class=\"td-a-rec td-a-rec-id-content_bottom  tdi_2 td_block_template_1\">\n<span class=\"td-adspot-title\">&#8211; Advertisement &#8211;<\/span><a href=\"https:\/\/leapeast.com\/?utm_source=partner&amp;utm_medium=referral&amp;utm_campaign=eme26lst-hk-frontierenterprise&amp;utm_term=promotion&amp;utm_content=platform\" onclick=\"getOutboundLink(&#039;https:\/\/leapeast.com\/?utm_source=partner&amp;utm_medium=referral&amp;utm_campaign=eme26lst-hk-frontierenterprise&amp;utm_term=promotion&amp;utm_content=platform&#039;); return false;\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/06\/LEAP-East-PR-pack_728x90-scaled.png\"\/><img decoding=\"async\" src=\"https:\/\/p7q8s5f8.rocketcdn.me\/wp-content\/uploads\/2026\/06\/LEAP-East-PR-pack_728x90-scaled.png\"\/><\/a><\/div>\n<\/p><\/div>\n<p><br \/>\n<center><br \/>\n<br \/><a href=\"https:\/\/www.frontier-enterprise.com\/identity-breaches-plagued-7-in-10-singapore-firms-in-the-past-year\/\" target=\"_blank\" rel=\"noopener\">Read Full Article At Source <\/a><br \/>\n<center\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Seven in every 10 (71%) of\u00a0organisations\u00a0globally\u00a0suffered at least one identity-related breach in the past year, and\u00a0on average\u00a0organisations\u00a0reported\u00a0three separate incidents, according to Sophos. This is based&#8230;<\/p>\n","protected":false},"author":1,"featured_media":70116,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","footnotes":""},"categories":[2611],"tags":[],"class_list":["post-70115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-buzz-headlines","wpcat-2611-id"],"_links":{"self":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/posts\/70115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=70115"}],"version-history":[{"count":0,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/posts\/70115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/media\/70116"}],"wp:attachment":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=70115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=70115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=70115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}