Cyber Visibility Gaps Leave Singapore Firms Exposed as AI Complicates Detection
Source: Singapore Business Review
Almost half of Singapore organisations only discover cyber breaches after attackers have exfiltrated data, as fragmented security tools and premature AI adoption create widening visibility gaps.

Singapore organisations are investing heavily in cybersecurity tools, but a new report from ExtraHop and Gartner suggests that spending alone isn't closing the gap. Almost half (47%) of companies in Singapore only discover breaches after attackers have already exfiltrated corporate data — a statistic that points less to a lack of tools and more to a fundamental visibility problem in how those tools are deployed and governed.
The Singapore Business Review reports that the core issue, according to ExtraHop's Darren Chen, is that organisations continue to invest in point products that operate independently rather than providing a unified view of network activity. "Singapore is spending more on tools rather than visibility," Chen said. Gartner's Niyati Daftary adds that organisations manage 40 to 45 cybersecurity tools across different environments, creating fragmented visibility that attackers can exploit. Roughly 40% of security alerts are closed or bypassed without detailed investigation because teams lack the capacity to process them.
Artificial intelligence is often held up as the solution to cybersecurity's scale problem, but the ExtraHop findings suggest AI adoption in security may be making things worse before it gets better. 85% of respondents had linked security incidents to AI systems, while 30% said AI generated more false positives that delayed investigations. Only 23% of organisations have piloted AI security operations agents, and just 18% have deployed them at scale. The warning from analysts is clear: deploying AI before fixing visibility and data quality risks compounding the problem.
The findings arrive at a time when Singapore is overhauling its cybersecurity posture across multiple fronts. CSA recently updated the Cybersecurity Code of Practice to address AI-powered threats, and MAS has established an AI-Cyber taskforce with ABS. But the ExtraHop data suggests that regulatory frameworks are only part of the solution — internal operational discipline around tool consolidation, alert triage, and data governance may matter just as much.
Why it matters for Singapore: The visibility gap is a particularly Singaporean problem in the sense that the city-state's organisations are early and aggressive adopters of new security tools, but that same enthusiasm creates fragmentation when governance doesn't keep pace. The 47% exfiltration-before-discovery rate is a reminder that in cybersecurity, more tools don't automatically mean better protection — and that AI, deployed prematurely, can actually widen the gap it was meant to close.