Artificial intelligence is helping businesses become more productive, but there’s a new challenge. It is also making cyberattacks faster and harder to detect.
According to cybersecurity firm Kaspersky, organisations across Asia Pacific are facing a growing “visibility gap”, where attackers are able to infiltrate systems and remain undetected for extended periods of time.
Kaspersky’s Managing Director for Asia Pacific Adrian Hia highlighted that cybersecurity is no longer just about responding quickly to threats.
He said, “As speed and connectivity reshape modern enterprises and organisations in the region, driven mainly by AI and its applications, security teams face growing blind spots across IT and OT environments. As a result, cybersecurity today is no longer just a race against time. It’s a race against invisibility.”
AI is accelerating cyberattacks in the region

As shared by Kaspersky during its Cybersecurity Weekend 2026 event, the cybersecurity landscape is increasingly being shaped by AI-assisted attacks, cyber sabotage targeting both IT and operational technology (OT) environments, as well as more sophisticated cyberespionage campaigns.
The company said it detected and blocked around 500,000 unique malicious files daily in 2025, which represents a 7% increase compared to 2024.
Hia shared that just a few weeks ago, Japan’s Nichirei Corp suffered a cyberattack that disrupted its logistics network. Meanwhile, India’s manufacturing sector has become an APAC hotspot for industrial ransomware, with groups consistently paralysing factory floors and industrial IT services.
Kaspersky also claimed it has identified more than 15,000 malware samples disguised as agentic AI software this year alone.
It warns that AI agents often rely on third-party frameworks, APIs and plugins, meaning a single compromised upstream component could affect multiple downstream systems.
With threats becoming AI-native, Kaspersky says APAC organisations must look beyond just stopping attacks and ask themselves whether they have visibility into what’s already happening inside their environments.
Many cyber breaches remain undetected for months
Kaspersky also shared findings from its Compromise Assessment division, which suggests many organisations are taking too long to discover security incidents.
According to the report, 31% of analysed incidents had been active for more than three months before being discovered. It also highlighted that 52% of high-severity compromises were only detected after remaining unnoticed for over 90 days.
Meanwhile, the oldest incident investigated had gone undetected for as long as four years.
Kaspersky says the findings exposes a broader challenge in security operations and investing in security products alone is insufficient to compensate for gaps in monitoring, detection and operational readiness.
Hia added, “Our recent report highlights why modern, unified SOC is becoming business-critical. When organisations rely on reactive security practices or lack continuous monitoring, attackers gain valuable time to move laterally, escalate privileges, and compromise critical assets. A mature SOC shortens that window by providing the visibility, expertise, and operational discipline needed to detect threats before they become major incidents.”
Kaspersky says AI should strengthen security operations
To address these challenges, Kaspersky is advocating the use of a modern Security Operations Centre (SOC) supported by AI.
The company said it has built and refined advanced Machine Learning models into its cybersecurity products since 2004, using anonymised global telemetry collected ethically and responsibly to improve malware detection and automate threat analysis. Kaspersky describes this combination of AI and human expertise as “HuMachine Intelligence”.
Its enterprise offerings include the Kaspersky Next platform, which combines endpoint protection with EDR and XDR capabilities. The platform also uses generative AI models to transform raw data into structured, actionable intelligence for security teams and decision-makers to work more efficiently while reducing manual effort.
The company also offers managed security services such as Kaspersky Compromise Assessment, Kaspersky MDR and Kaspersky Incident Response to cover the entire incident management cycle from threat identification to continuous protection and remediation.
To enable successful SOC deployment and ongoing maintenance, they are offering early engagement through its Kaspersky SOC Consulting during the initial setup or to enhance existing security operations.






