A new Mimecast study has found that 65% of surveyed IT and security decision-makers across Asia Pacific believe an AI-enabled attack against their organization is inevitable within the next 12 months. The State of Human Risk 2026 report, based on responses from 500 decision-makers in Singapore and Australia, paints a concerning picture of the gap between threat awareness and organizational readiness.
The State of Human Risk 2026 study was commissioned by Mimecast and conducted by Vanson Bourne in November and December 2025. It surveyed 2,500 IT security and IT decision-makers across nine countries, covering organisations with more than 250 employees across sectors including financial services, healthcare, IT, manufacturing, retail, and public sector. The APAC portion covers responses from Singapore (250) and Australia (250).
Findings From Mimecast’s State Of Human Risk 2026 Report

Concern about AI as an attack vector is widespread, with 79% of respondents saying they are worried about it being used against their organization. Despite this, 60% said they were not fully prepared to handle AI-driven threats that exploit human vulnerabilities. Of that unprepared group, 52% said they were somewhat prepared but still developing AI-specific defense strategies, while 9% were aware of the threats but lacked any concrete plan to address them.
Employees are identified as a significant point of exposure in the findings – two-thirds (66%) of respondents agreed that an employee within their organization was very likely to be fooled by a cybercriminal using AI as part of a social engineering attack.
Mimecast noted that AI-enabled cyber risk is placing growing pressure on employees to evaluate whether communications and requests they receive are genuine. According to Nicky Choo, Vice President and General Manager for APAC at Mimecast, attackers can now craft convincing, tailored messages that appear to come from colleagues, partners, or senior leaders, forcing employees to make real-time judgement calls in increasingly difficult circumstances.
The study found that AI-specific training and simulations remain uncommon. Only 40% of surveyed organisations provide training on how to use AI while avoiding exploitation, and just 42% conduct simulated AI-driven phishing attacks.
Mimecast clarified that these figures do not necessarily indicate a complete absence of cybersecurity training, but they do show that many organisations have yet to introduce measures specifically targeting AI-enabled threats. Choo noted that fewer than half of organisations are running AI-specific training or simulated phishing exercises, leaving many employees to navigate sophisticated deception without dedicated preparation.
Mimecast said the broader takeaway from the research is the need to treat human judgement as a core pillar of cyber defence, operating alongside technical controls, as AI continues to blur the distinction between legitimate and malicious communication.
Pokdepinion: Two-thirds of organisations think their staff will fall for an AI-powered scam, yet fewer than half have bothered to run a single simulated phishing exercise. At this point, the biggest vulnerability is not the software.

