12% Increase in Costs
Data breaches in 2026 have cost Southeast Asian companies 12% more compared to the previous year. This year, breaches have cost institutions in the region 4.1 million dollars. This is in comparison to the global average of nearly 5 million dollars—and the US average of 11.5 million dollars. Though overall costs are lower than the global average, financial companies are hit hardest: attacks cost them 6.5 million dollars.
There is, however, a telling insight. Institutions that extensively utilize artificial intelligence for their security protocols and systems are left less exposed and have thus had their cost-per-breach lowered to 3.66 million dollars. This marks a turning point that has driven more organizations to invest heavily towards more advanced controls—be it A.I. or other means.
Cyberthreat Landscape in SEA
In a paper from the Yusof Ishak Institute, the cyberthreat landscape in the region has evolved in connection to several factors such as geopolitical tensions in Ukraine and Russia, internal frictions within governments, and—significantly—the COVID pandemic. The latter has forced institutions to move an increasing amount of their operations online, where vulnerabilities in migrating systems were exposed. There are also other crucial insights from the report. One is that state-sponsored attacks make up the highest proportion of threats in Southeast Asia. Though the key players are not definitively identified, some are observed to have originated from Iran, India, and China. Another is the lack of a cohesive legal framework within individual nations in the region for securing cyber threats.
The article’s thesis is that Southeast Asia is becoming an increasingly strategic hub for global operations. Where globalization has brought interconnectivity, and Southeast Asia has grown in presence, the opportunities for vulnerability have proportionately increased. The data from the research points out:
“Southeast Asia is not yet a high-frequency cyber conflict zone like North America or Europe, but its strategic significance ensures it remains persistently targeted, particularly for espionage and information operations. Unlike the Middle East, where cyber operations are more openly aggressive and destructive, Southeast Asia’s cyber battles are subtler but no less impactful, with a focus on long-term strategic gains rather than immediate sabotage.”
These being said, the ASEAN region has taken strides in holistically creating charters and plans-of-action that guide constituents in drafting their own frameworks. There are ASEAN-sponsored training programs, research grants, and diplomacy-related synergies. There are also periodic summits and talks among ministers that urge individual nations to allocate more resources towards countering threats.
Still, Southeast Asia is hindered by an environment—despite collective actions—of state-sponsored espionage, hacktivist disruption, and persistent legal and institutional gaps, all compounded by the region’s political culture of non-interference and sovereignty sensitivity.
Cyberthreat Landscape in The Philippines
The cybersecurity and cyberthreat culture of the country may also stem from the culture itself – Filipinos, and the dynamic development of usage of digital platforms and systems requiring use of internet, with around 98 million internet users and an internet penetration rate of roughly 83.8%. These being said, one can say that the country’s culture and the cyberthreat landscape it has is interconnected with each other, as threat actors form and launch cyber-attacks by mapping its demographic activities.
The cybersecurity and cyberthreat culture of the country may also stem from the culture itself – Filipinos, and the dynamic development of usage of digital platforms and systems requiring use of internet, with around 98 million internet users and an internet penetration rate of roughly 83.8%. These being said, one can say that the country’s culture and the cyberthreat landscape it has is interconnected with each other, as threat actors form and launch cyber-attacks by mapping its demographic activities.
This statement is supported by a 2025 Philippine Threat Landscape Report from Villanueva shows the cybersecurity critical alerts received from 2021-2024, with 66% from Banking and Financial Services, 11% from Media and Entertainment, and 8% from Technology and IT, and many follows. With the rise and promotions of digital applications which aim to provide convenience, speed, and delivery, threat actors have now developed to attack these industries in cyber domain. In present, government and regulators continue to roll out management systems and circulars for strengthening cybersecurity preventive measures. To reach common folks, the information for bringing cyber training and education continues to develop and vary – in forms of advertisements, digital infographics posted on social media platforms, physical educational campaigns, and use of televisions and radios are present. These are only a few of the government’s responses to address growing cyber concerns.
In addition, ASEAN’s growing concern for state-sponsored cyberthreats also concern the country, as 78.3% of dark web threats targeting the country are either domestic-focused or state-linked. Context such as the Philippines’ and South China Sea friction validates this data as the friction between two is not only in maritime space but also interjects physical and digital disruptions by China’s state-sponsored espionage, infrastructure targeting, and GPS interference.
ASEAN’s proposed cyber security measures
The primary proposal of ASEAN, which is practiced daily, is building partnerships with members of countries with historical disputes. This is called Confidence-Building Measures (CBM). CBMs are important for countries with uneven cyber capabilities and historical disputes leading to tension between countries. Aside from this, cross-border exchanges made with trust and support will help each country involved to further enhance cyber security networks and measures. A primary example of CBM is ASEAN Summit, a popular diplomatic public dialogue within leaders convened every two years is committed and attended by members aiming to conduct dialogue addressing public and national concerns, build rapports among head of state, and maintain regional stability by staying updated and informed.
DOPAY, a financial service secured app
DOPAY is an application which provides financial services with crypto trading, international and domestic remittance, e-wallet, and fund transfers. DOPAY is regulated by the Bangko Sentral ng Pilipinas and has robust cybersecurity measures to ensure a secured and protected experience of DOPAY users. Furthermore, DOPAY is licensed by the Bnagko Sentral ng Pilipinas as an Electronic Money Issuer (EMI) and Virtual Assets Services Provider (VASP). All transactions are verified by DOPAY’s strict security and screening measures.
By using DOPAY, everyone can enjoy DOPAY’s benefits while knowing they’re secured.
Download the DOPAY app today!






