Everyone Is a Target. That's New.

Published: June 2025Audience: ASEAN Business Leaders & ExecutivesTerritory: ASEANCybersecurity & AI Risk

What the Five Eyes AI Cyber Warning Means for ASEAN Businesses Without a Security Team

By Sunny Chua, Ewashi

Everyone becomes a target because attacking anyone becomes cheap.

That's the line buried in the Five Eyes warning that most business commentary missed. The Five Eyes — intelligence agencies of the US, UK, Australia, Canada, and New Zealand — don't do public panic. So when they release a joint statement telling leaders to "act now" on AI's cyber threats, every word in their timeline deserves full attention.

This warning wasn't written for Fortune 500 security teams with 40-person SOCs and million-dollar SIEM stacks. It was written for everyone. And in ASEAN, that "everyone" includes tens of thousands of mid-market companies — trading firms, logistics providers, professional services outfits, manufacturers, distributors — running on ageing systems, lean IT teams, and the quiet assumption that they're not interesting enough to attack.

That assumption is the vulnerability.


Section 1

The ASEAN Reality Check

Most cybersecurity commentary is written with a Western enterprise lens. Large budgets. Dedicated security teams. Regulatory compliance frameworks that force baseline hygiene whether the organisation wants it or not. ASEAN mid-market operates in a different reality.

If you're running a 200-person manufacturing business in Johor, a regional logistics company out of Jakarta, or a professional services firm in Manila, the honest picture looks something like this: your IT function is two people handling everything from printer jams to server patches; your "cybersecurity strategy" is a firewall and an antivirus subscription you renewed last year; and your board's last conversation about cyber risk ended with "we've never been hacked before."

This is not a criticism. It is a structural fact. And AI-enabled attackers are about to exploit that profile at scale.


The Friction That Once Protected You Is Gone

Before AI

Sophisticated attacks required sophisticated attackers. Targeted intrusions demanded expertise, patience, and significant resources. Smaller organisations were, perversely, protected by not being worth the effort.

After AI

An amateur attacker with access to a capable AI model can now generate convincing phishing campaigns, discover system vulnerabilities, write malware, and sequence an attack — in the time it once took a professional crew to do reconnaissance.

Meanwhile, sophisticated threat actors — nation-states, organised crime — can scale campaigns that previously required armies of analysts. The Five Eyes put it plainly: AI "shrinks the window between discovering a vulnerability and acting on it." The grace period between a patch release and active exploitation — once measured in weeks — now compresses to hours or days. For organisations that patch quarterly, or never, this is an existential shift.


Section 2

The Math Has Changed

The economic calculus of cybercrime has been rewritten. Where attacking a small business once required a skilled adversary willing to invest time for modest return, AI collapses that cost structure entirely. Volume becomes the strategy. Every unpatched system, every untrained employee, every unmonitored vendor access point is now worth targeting — because targeting everything is now nearly free.


Four Vulnerabilities the Mid-Market Cannot Afford to Ignore

Your Backups Are Probably Broken

Ransomware remains the most damaging attack vector for mid-market organisations. AI-speed attacks mean less time to detect and respond before encryption completes. If your backups are untested, connected to your primary network, or outdated, a ransomware incident is not a disruption — it is a business-ending event.

Your People Are Your Biggest Attack Surface

AI makes phishing emails indistinguishable from legitimate correspondence — same writing style, correct names, contextually relevant content pulled from your company's own LinkedIn page. A mid-market company without email security controls and without trained staff is presenting an open door.

Your Vendors Are Your Perimeter

Supply chain attacks — where attackers compromise a software vendor or service provider to reach their customers — are one of the fastest-growing attack categories globally. You are only as secure as your least-secure supplier.

Legacy Systems Are a Gift to Attackers

Many ASEAN mid-market organisations run systems years or decades old, because "it works and we can't afford the migration." AI models trained on vulnerability databases identify and exploit known weaknesses in legacy systems faster than any human red team. "It works" and "it's secure" are no longer the same sentence.


Section 3

What to Do Now

Foundational work. Not consultants, not an enterprise platform, not an infrastructure rebuild. The unglamorous, disciplined basics that make the difference between surviving an attack and not. Seven steps — concrete, sequenced, and achievable without a dedicated security team.

Each of these steps is within reach for any mid-market organisation. None requires a large budget. All of them require someone to own the action and follow through. Start with step one. Complete it before moving to step two.


The Seven Steps — In Detail

Know What You Have

Inventory every device, system, and service that touches your business data or network — cloud accounts, employee laptops, operational technology, the NAS drive in the back room. Ask one question: if someone wanted our most sensitive data, what would they need to compromise?

Patch. Actually Patch.

Implement a disciplined patching process for operating systems, applications, and network devices. Turn on automatic updates where you can; assign a human owner and a monthly schedule where you can't. Most damaging attacks exploit vulnerabilities for which patches have been available for months.

Back Up Properly. Then Test It.

Three copies of your data, on two different media types, with one copy offsite or air-gapped. Then — the step most organisations skip — run a test restore. A backup you have never tested is a backup you cannot trust. Quarterly, at minimum.

Control Access

MFA on everything that matters: email, banking, cloud services, remote access. Beyond that, least privilege — staff access only what their role requires. When someone leaves, revoke access the same day. Not the same week. The same day.

Train Your People

Staff need to recognise a phishing email, know not to click suspicious links, and understand that urgent wire transfer requests from "the CEO" warrant a phone call. One simulated phishing exercise a year. Brief your finance team specifically — they are the most targeted. Half a day. Nearly free.

Write a Response Plan Before You Need One

One page: who do we call first? Who can take systems offline? Who communicates to customers? Where are the backups? What's the number for our cyber insurer? It doesn't need to be sophisticated. It needs to exist — before an incident, not during one.

Know Your Third-Party Exposure

List your critical software vendors and service providers. Check whether they hold SOC 2, ISO 27001, or equivalent certification. Require MFA for any vendor with access to your systems. Most organisations haven't done this. It is the most undermanaged risk on this list.


Section 4

On AI for Defence

AI is a defensive tool as well as an offensive one. Threat detection platforms, automated patching tools, and managed security services are becoming more accessible and more affordable than they were even two years ago.

In Singapore and Malaysia, the MSSP market has matured enough that AI-assisted monitoring is a realistic option for organisations without internal security capacity. Outsourced SOC services, automated vulnerability scanning, and AI-powered email filtering are no longer enterprise-only tools.

But the principle holds: foundations first. Automating a mess produces a faster mess. No detection platform compensates for untested backups. No AI monitoring tool replaces a staff member who knows not to click a suspicious link. Sequence matters. Get the basics right, then layer intelligence on top.

AI-Assisted Monitoring

Realistic for ASEAN mid-market via MSSP partnerships

Automated Patching

Reduces human error and closes the vulnerability window

Email Filtering

AI-powered tools catch AI-generated phishing at scale


Section 5

Controls ≠ Confidence

"It is not enough to have controls. Leaders must be confident those controls will perform during a real incident."
— Five Eyes Joint Advisory

That is the gap that matters most in the ASEAN mid-market. Not the absence of security measures — most organisations have something. The absence of any meaningful test of whether those measures actually work under pressure.

The antivirus hasn't been checked in two years.

Installed during onboarding, renewed automatically, and never reviewed. Whether it covers your current threat surface is unknown.

The firewall was configured by a vendor who no longer supports it.

Rules written for a network that no longer exists, protecting a perimeter that has since expanded to the cloud and every employee's home router.

The backup runs nightly but no one knows if restores succeed.

A backup job completing without errors is not the same as a backup that recovers your business. These are different things. Most organisations have never tested the difference.

One person holds every password and every key.

The IT manager knows the password to everything and is the only person who does. That is a single point of failure in both a security incident and a personnel incident.


"We're too small to be a target" is now simply false.

With AI-scale attacks, volume is the strategy. The machine is coming at machine speed. Matching that speed isn't the requirement. Creating enough friction to send attackers looking for an easier target is.

Most attackers are rational actors optimising for return on effort. They will take the easier target. The question every ASEAN mid-market leader needs to answer honestly is: have we done enough to ensure that easier target isn't us?

The seven steps above are not a guarantee. No control is. They are the difference between being trivially easy to compromise and being more trouble than you're worth. In a world where everyone is targeted, that distinction is everything.


Ready to assess your security posture?

Ewashi works with ASEAN mid-market organisations to identify gaps, prioritise action, and build defensible security foundations — without the enterprise overhead.

Assess your security posture →