As geopolitical disruptions, tariff uncertainties, and economic slowdowns prompt organizations to reevaluate budgets, one area that remains non-negotiable is cybersecurity, risk, and compliance. Across Asia/Pacific, this domain has proven remarkably resilient to budget contractions, emerging as a critical enabler of AI-driven innovation, trust, and long-term business viability.

According to IDC’s Worldwide Security Spending Guide, Asia/Pacific enterprises are expected to invest USD $44.4 billion in cybersecurity in 2025, with spending projected to grow at a CAGR of 10.6%, reaching USD $60.6 billion by 2028. This upward trajectory underscores a critical shift: cybersecurity is no longer viewed as a discretionary cost, but as a strategic imperative that is deeply embedded into digital transformation, regulatory readiness, and AI adoption initiatives across the region.

While Asia/Pacific is home to four of the world’s top ten digital economies, it is also at the epicenter of a dual inflection: the aggressive integration of artificial intelligence (AI) into enterprise workflows and the intensifying complexity of the cybersecurity threat landscape. Enterprises across sectors, from banking and healthcare to manufacturing and public utilities, are experiencing the push and pull of this convergence. The accelerated adoption of GenAI, the rise of autonomous decision-making systems, and increased reliance on sensitive data have reshaped the risk surface.

This confluence of AI acceleration and security pressure is driving a new breed of enterprise questions:

  • How can we ensure our GenAI deployments are compliant, transparent, and ethically aligned?
  • How can AI be used to counter AI-driven threats while ensuring explainability and trust?
  • What does an integrated approach to AI risk governance, security operations, and regulatory compliance look like?

According to IDC’s Asia/Pacific Security Study, 2024, 76.5% of regional enterprises admit they are not confident in their ability to detect and respond to AI-powered attacks. The most pressing threats include AI-driven vulnerability scans, zero-day exploits, ransomware with adaptive extortion tactics, and highly personalized social engineering attacks. These risks are particularly acute in regulated industries such as financial services, telecom, and healthcare.

Despite the urgency, organizations in Asia/Pacific face several barriers in building AI-resilient security postures. These include:

1. Integration and cost complexities

AI holds immense promise for security automation, but its adoption is hindered by poor integration with legacy environments and high costs. IDC predicts that by 2027, only 25% of consumer-facing companies in Asia/Pacific will adopt AI-powered identity and access management (IAM) systems, citing operational complexity and financial constraints as core reasons. This growing trust gap makes consumer authentication and identity protection increasingly vulnerable.

2. Regulatory fragmentation and governance gaps

While countries like Singapore and Australia have advanced AI governance policies, the broader region remains fragmented. China’s regulations prioritize algorithmic transparency and national security. Japan emphasizes Responsible AI under self-regulation. India, meanwhile, is still shaping its framework under the Digital India mission. This patchwork of mandates creates compliance confusion, especially for multinational enterprises. A major shift ahead is the expected rise of AI Bills of Materials (AI BoM). By 2028, IDC expects 70% of data products will be accompanied by BoMs detailing consent trails, model training inputs, and risk assessments i.e. a new layer of accountability for enterprise AI deployments.

3. GenAI growth without guardrails

As organizations race to scale GenAI solutions beyond proof-of-concept, risk governance is often left behind. IDC forecasts that in 2025, one in five APJ enterprises will move to production with GenAI without a comprehensive risk-based trust assessment. This opens the door to data leakage, algorithmic bias, reputational damage, and hefty regulatory penalties. In the absence of structured governance, enterprises risk building innovation on a fragile security foundation.

A blueprint for AI-resilient security

Building a future-ready posture

Cybersecurity in Asia/Pacific is moving from reactive to predictive. It is no longer about responding to known threats but is about anticipating emerging risks in a world where AI shapes both offense and defense. Enterprises must future-proof their security architecture by investing not only in technologies but also in governance, skills, and regulatory alignment.

Organizations that embed trust into the core of their AI strategies will be the ones that lead in both innovation and resilience. AI-powered businesses must ensure that privacy, explainability, and compliance are not afterthoughts, but integral components of the design and delivery process. In this new era, cybersecurity is inseparable from AI transformation and trust is its ultimate currency.

Join the Responsible and Secure AI: The Cornerstone of AI-Driven Growth webinar on 23 July 2025 to stay ahead of evolving AI risks, CSO expectations, and regional regulations. Register today!

Partner with IDC | CSO to elevate your brand presence at Asia’s leading gathering of CISOs and IT security executives. Position your unique capabilities to become security leaders’ trusted vendor of choice in safeguarding their valuable corporate data in the cloud and in exploring the pivotal role of AI and quantum-proof technologies. Happening across 7 Asia/Pacific cities from April to November 2025, join us at the event to showcase your case studies, success stories, and more!

Sakshi Grover - Senior Research Manager - IDC

Sakshi Grover is a senior research manager for IDC Asia/Pacific Cybersecurity Services, supporting its research and client engagement activities across Asia/Pacific markets. Additionally, she serves as the lead security analyst for IDC India. Sakshi is responsible for delivering syndicated custom research and consulting engagements on next-generation emerging and disruptive technologies. Her tasks include developing and socializing IDC's point of view within security services, covering both legacy and modern cybersecurity technologies. Her role involves close collaboration with technology vendors and buyers, developing market insights, and providing research, consulting, and advisory services in the fields of security software and services. This includes partnering on research efforts with relevant country analysts in the local IDC offices. Sakshi's views on security have been quoted in numerous publications, such as the Economic Times, Business Standard, Data Quest, CRN, and others.
Jul 9, 2025

如何通过全方位安全检测与防护构建可信AI?——IDC发布中国大模型安全保护市场概览

北京,2025年7月10日——以DeepSeek为代表的GenAI的优秀性能表现、本地部署及推理成本的显著降低等特性极大加快了大模型在千行百业的落地应用,重点行业纷纷尝试将大模型接入自身业务系统,利用AI的力量加速技术创新、提高生产效率,创造差异化市场竞争优势。在基础大模型百花齐放的同时,辅助驾驶、AI智能体(Agent)、Agentic AI等创新应用更是如雨后春笋般不断涌现,切实融入具体应用场景与业务流程。

Read full release
Jul 9, 2025

IDC:GenBI从工具变“大脑”,谁将赢得更多市场?

北京,2025年6月30日——2025年,GenBI从概念验证迈入产品化落地阶段,厂商加速布局自然语言交互、多模态分析等核心能力,产品形态从辅助工具向决策中枢演进,部分头部企业已实现从数据洞察到策略建议的端到端闭环。国际数据公司(IDC)于近日发布了 《中国 GenBI 厂商技术能力评估, 2025 》( Doc# CHC53029925 , 2025 年 6 月 ) ,报告对整体市场进行了前景分析,收录并评估市场代表厂商,来为市场选型提供参考建议。

Read full release
Jul 8, 2025

从理念到能力的演进,IDC 2024年中国零信任网络访问解决方案市场份额系列报告发布

北京,2025年7月9日——国际数据公司(IDC)于近日正式发布了针对中国零信任网络访问解决方案的市场份额系列研究报告,即《中国零信任网络访问解决方案市场份额,2024:由新兴理念到基础能力的演进》(Doc # CHC53609525 ,2025年6月)、《中国零信任网络访问场景之软件定义边界市场份额,2024:安全大模型在零信任体系中初露锋芒》(Doc # CHC53609625 ,2025年6月)和《中国零信任网络访问场景之终端安全市场份额,2024:终端安全成为零信任一体化方案不可或缺的能力》(Doc # CHC53609725 ,2025年6月)。系列报告针对2024年中国零信任网络访问解决方案市场的规模、增长速度、主要玩家、市场与技术的发展趋势等内容进行了详细研究。

Read full release
Jul 7, 2025

IDC:Agentic AI推动低代码市场变革,有哪三大关键趋势?

北京,2025年7月7日——中国低代码市场已经走向成熟,用户认知从“陌生试探”走向“主动拥抱”;平台架构向云原生、微服务转型,以支持更复杂的应用和更高的性能需求;此外,大模型和Agentic AI的发展也推动了用户需求的变化和平台开发能力的升级,推动市场向下一个阶段发展。在此背景下,国际数据公司(IDC)发布了《低代码市场趋势洞察: Agentic AI 推动市场变革》( Doc# CHC53108325 , 2025 年 7 月) 研究报告,旨在洞察低代码市场发展的核心趋势。

Read full release
Jul 6, 2025

Multimodal Convergence and Full-Link Empowerment, Dual Trends Emerge – IDC Releases AI Agent Enterprise Application and Generative AI Marketing Report

北京, 2025年7月8日——近日,国际数据公司(IDC)正式发布了《 AI Agent 企业级 应用现状与推荐 ,2025》 (Doc#CHC53057525,2025年6月) )及《生成式AI+营销市场分析》( Doc #CHC53331226,2025年5月) 两本 研究报告 。报告显示,AI Agent与生成式AI正从技术概念迈向规模化应用,分别在企业级流程自动化与营销全链路等场景中实现商业价值突破,推动中国智能经济进入“场景深耕”关键期。

Read full release