James Henderson

Shattering the ‘sea of green’ illusion… strengthening cyber resilience in Singapore

For many organisations, cyber security is still viewed as a compliance exercise – a series of policies signed, audits passed and boxes ticked.

Yet true resilience goes beyond regulation.

The rise of AI is adding further urgency. As threat actors use AI to increase the speed, scale and sophistication of attacks, organisations must ensure their people can recognise, respond and adapt at a similar pace.

According to Moxie Research, 54% of businesses in Singapore lack confidence that cyber security preparedness matches actual readiness. On paper, this is a mature market but in practice, alarming quantification gaps exist.

In response, forward-thinking organisations are reframing cyber resilience as a workforce-wide capability. Every employee is part of the attack surface – and therefore part of the defence.

This requires continuous education, real-world simulation and a platform where accountability is embedded, not enforced – testing team knowledge, skills and judgement in response to threat actors.

“The big shift is that cyber resilience has become a permission layer for AI adoption,” observed Tom Goldenberg, Regional Director of Asia Pacific at Immersive.

“The business is not going to wait for security to catch up, and security cannot succeed by simply saying no. The organisations that move fastest will be the ones that can prove they are moving safely.”

Tom Goldenberg (Immersive), Wei Kang Lee (C.K. Tang), Dr. Jenny Tan (Institute of Risk Management) and James Henderson (Moxie Insights)

For Goldenberg, that is why “proof” is becoming the new currency of resilience.

Boards, regulators and insurers increasingly want evidence that the workforce can use AI safely, defenders can operate at AI speed, and leaders have rehearsed the decisions they will need to make in a crisis.

“In that sense, resilience is no longer something you declare once a year, it is an operational capability you continuously assess, build and prove,” Goldenberg added.

“The organisations best placed to thrive in the AI era will not be the ones with the thickest compliance binders; they will be the ones with the evidence, muscle memory and leadership confidence to take a punch, adapt and keep moving.”

Goldenberg tackled this topic alongside the most influential CISOs in Singapore at Beyond Box Ticking: Strengthening Cyber Resilience in Singapore – an Executive Roundtable in association with Moxie Insights and Immersive Labs.

This exclusive session outlined how businesses can close the cyber resilience gap in Singapore, moving beyond corporate compliance to match confidence with readiness.

Shattering the ‘sea of green’ illusion


For years, cyber security reporting has provided boards and executives with reassurance. Training completion rates are high. Policies have been acknowledged. Audits have been passed. Dashboards are green.

But what does that actually tell us about resilience?

“A ‘sea of green’ can tell you that controls have been documented and an audit has been completed but it doesn’t prove that the organisation can perform under pressure when a real incident unfolds,” Goldenberg cautioned.

“That distinction matters more in the AI era. AI adoption is changing employee workflows, engineering practices, security operations and attacker behaviour faster than traditional assurance models can validate them. The business is moving quickly; security now has to make that speed safe.”

The danger is a growing disconnect between compliance and competence.

An employee completing mandatory training demonstrates participation, not necessarily an ability to make the right decision when faced with a sophisticated phishing attempt, AI-enabled social engineering or a live security incident.

The numbers expose the gap.

While 94% of organisations feel prepared, Immersive data shows teams can achieve only 22% decision accuracy when tested under real-world pressure. That creates a potentially dangerous ‘sea of green’ – confidence built around what has been completed rather than what an organisation can actually do.

Tom Goldenberg (Immersive)

Regulation and compliance remain essential, but they represent the floor rather than the ceiling of cyber resilience.

“Compliance is important as a baseline and helps organisations establish structure, governance, and accountability,” outlined Wei Kang Lee, Head of IT at C.K. Tang.

“However, a ‘sea of green’ can sometimes create a false sense of security if organisations become overly focused on passing audits rather than building real operational resilience. True cyber resilience is tested during actual incidents like how quickly teams detect, respond, recover, and communicate under pressure.

“In many cases, gaps only surface during real-world scenarios such as phishing attacks, ransomware incidents, third-party compromises, or operational disruptions. Organisations should therefore complement compliance exercises with practical simulations, continuous monitoring, recovery testing, and strong cross-functional collaboration between IT, business, operations, and leadership teams.”

The challenge for leaders is therefore to look beyond traditional indicators and establish a more accurate picture of operational capability – continuously testing how people recognise threats, make decisions and respond when conditions become unpredictable.

“True resilience can only be tested during a real crisis,” advised Dr. Jenny Tan, Chair of Institute of Risk Management, Singapore Group.

“However, we don’t wish any crisis upon any organisation. So, the quality of testing helps to create a very important difference between being prepared versus getting prepared. And to be prepared, leadership management teams need to cooperate and play their roles accordingly.”

In short, true resilience is not a static dashboard or an annual training record.

“It is the ability to generate evidence that your workforce can use AI safely, your technical teams can defend at the speed AI demands, and your leadership team can make the right decisions when an AI enabled crisis hits,” Goldenberg added. “That requires simulation, benchmarking and pressure testing, not just compliance reporting.”

Cyber resilience as a business value protector


Cyber risk can no longer be contained within the technology function.

In a hyper-connected economy such as Singapore, organisations operate across increasingly complex webs of employees, customers, partners, suppliers, cloud platforms and digital services. A cyber incident can move rapidly across those connections – disrupting operations, eroding customer trust, exposing sensitive data and ultimately destroying business value.

AI is increasing the stakes further.

Beyond Box Ticking: Strengthening Cyber Resilience in Singapore – an Executive Roundtable in association with Moxie Insights and Immersive Labs

Threat actors can use AI to operate with greater speed and scale, creating more convincing social engineering, accelerating reconnaissance and adapting attacks faster than traditional security processes can respond. At the same time, employees are adopting AI across everyday workflows, creating new questions around data, access, identity and accountability.

“AI-driven threats should not be viewed purely as an IT or cyber security issue,” Wei Kang recommended.

“The speed, scale, and sophistication enabled by AI means that every business function can potentially become a target. My advice would be to translate cyber risks into business risks that stakeholders can relate to.”

As outlined by Wei Kang, discussions become far more effective when framed around operational disruption, financial impact, reputational damage, or customer trust rather than purely technical terminology.

“It is also important to create shared ownership across the organisation,” Wei Kang expanded.

“Cyber resilience works best when business units, leadership teams, and employees understand their role in managing risk, especially with emerging threats such as AI-generated phishing, impersonation, and social engineering attacks.

“Cyber resilience is increasingly becoming a business continuity and organisational resilience discussion, not just a technology discussion. As digital ecosystems become more interconnected, organisations must also pay closer attention to third-party risks, supply chain dependencies, and recovery preparedness.

“In today’s landscape, resilience is not defined by whether an organisation can prevent every incident, but by how effectively it can respond, adapt, and recover while maintaining business confidence and customer trust.”

This changes the resilience equation.

Cyber security cannot simply be the responsibility of the CISO, CIO or security team. When an incident occurs, accountability may ultimately converge on technology and security leaders, but organisational exposure is created – and resilience demonstrated – across the entire business.

“The first step is to stop positioning AI cyber risk as only an IT issue,” Goldenberg clarified.

“The business is already adopting generative AI, copilots and agentic tools across functions, often faster than central security teams can govern. The conversation has to move from ‘how do we slow this down?’ to ‘how do we prove we can move safely?’

“For the CxO and broader business, the most effective language is business risk, not technical jargon. Talk about data leakage, AI generated code risk, impersonation, deepfakes, automated social engineering, agentic workflows and compressed response timelines. Those are issues every function can understand because they touch revenue, trust, operations and governance.”

Wei Kang Lee (C.K. Tang)

The Cyber Security Agency of Singapore has described cyber security as a “team marathon”.

In this context, resilience is not built through a single annual training exercise, compliance cycle or technology investment. It requires sustained organisational capability – developed, tested and strengthened continuously.

That means shifting the C-suite conversation from cyber security as a cost of compliance to cyber resilience as a protector of business value.

The question is no longer simply whether an organisation has the right controls. Leaders need to understand whether their people can recognise emerging threats, whether teams know how to respond under pressure and whether different business functions can coordinate effectively when an incident moves beyond the security operations centre.

“Practically, CISOs and CIOs should bring the business into realistic exercises,” Goldenberg shared.

“That means role specific live fire scenarios for the workforce, technical ranges for security and engineering teams, and leadership crisis simulations for executives. The goal is not another awareness module; it is auditable evidence that people know what to do, where the gaps are, and what needs to change before a real incident occurs.”

AI makes that need for adaptability even more urgent. Organisations cannot expect static resilience strategies to protect against dynamic threats. If attacks can evolve at the speed of AI, the capability to respond must evolve with them.

For business leaders, this requires a different question: what are we actively changing?

Not what policies have been approved or what training has been completed, but what capabilities are being strengthened across the organisation today to protect the business tomorrow?

“CISOs and CIOs engaging with the whole of business is a good goal to start with,” Tan acknowledged.

“However, the reality may not allow the CISO or CIO to engage with the whole of business in the short-term. Perhaps a more practical position is to communicate the strategy to leadership team to get buy-in first and then develop a roll-out plan. People may respond and associate better when they can “see” the potential threat implications.

“Hence, CISOs and CIOs need to be grounded and demonstrate the potential implications with real-life examples and how their organisations may be subjected to such risks. In short, plan wide but execute narrow. Every execution success will give the CISOs and CIOs motivation to convince other people to adopt the program.”

The human layer in cyber resilience


Technology remains fundamental to cyber security, but resilience ultimately depends on how people behave when technology, processes and controls are put under pressure.

That makes the human layer one of the most consequential – and difficult to quantify – components of organisational resilience.

Beyond Box Ticking: Strengthening Cyber Resilience in Singapore – an Executive Roundtable in association with Moxie Insights and Immersive Labs

“The human layer remains one of the most critical components of cyber resilience,” Wei Kang continued.

“While organisations continue investing in advanced security technologies, many successful attacks still exploit human behaviour rather than technical vulnerabilities. Building awareness alone is not enough.

“Organisations should focus on creating a strong security culture where employees feel accountable, informed, and comfortable escalating suspicious activities without fear of blame. At the same time, leadership involvement is equally important.

“Cyber resilience becomes significantly stronger when management actively supports governance, prioritises investment, and reinforces that cyber security is a shared business responsibility rather than solely an IT function.”

Every employee now operates within the attack surface. They access applications, handle sensitive information, interact with customers and partners, make judgement calls and increasingly use AI tools as part of everyday work. One decision can strengthen an organisation’s defence or create an opening for an attacker.

Yet the objective cannot simply be to eliminate ‘human error’.

People should instead be viewed as an active layer of defence. That requires moving beyond awareness towards capability – giving employees the knowledge, judgement and practical experience required to recognise threats and respond appropriately when circumstances are ambiguous.

“Human risk management is very important to ensure strong cyber resilience,” Tan noted.

“Research has shown that an average of 80-90% of cyber attacks are due to human error. Hence, the ability to influence human behaviour is essential to transform humans from a ‘vulnerability’ to a ‘tool’. With AI in the picture, it amplifies the implication.

“Hence, if organisations can adopt a human risk management program as part of their cyber resiliency program, the organisational risks can be better mitigated. While executing a human risk management program is very difficult as there are ethical issues to deal with, organisations have to start somewhere.”

This becomes even more important as AI changes the threat environment. Phishing, impersonation and social engineering can become more convincing and scalable, making simple rules and annual training increasingly inadequate. Employees need experience making decisions in realistic situations, not simply remembering what they were told in a training module.

“The human layer is critical because AI risk now sits inside everyday work,” Goldenberg added.

“People are prompting AI tools, reviewing AI generated code, responding to AI assisted attacks, using AI agents in the SOC and making judgement calls in fast moving incidents. That makes the human layer one of the most dynamic parts of the organisation’s defence model.”

Dr. Jenny Tan (Institute of Risk Management)

For Goldenberg, the old idea that people are simply the ‘weakest link’ is too narrow.

With the right preparation, people become the organisation’s most adaptable detection, decision making and response capability. They can recognise context, verify intent, challenge suspicious behaviour and escalate quickly when something feels wrong.

“But that capability has to be proven, not assumed,” Goldenberg clarified.

“Training completion rates and policy acknowledgements do not show whether a person can make the right decision under pressure. Organisations need realistic, role based simulations that build confidence and produce measurable readiness data. That is how the human layer moves from perceived vulnerability to active resilience.”

Telling a better risk story with data


If boards are going to make better decisions about cyber risk, they need better evidence.

Traditional cyber reporting has often relied on static indicators – training completion rates, policy adherence, vulnerability counts and the outcomes of periodic tabletop exercises. These measures have value, but they can struggle to answer the question business leaders increasingly care about: how prepared are we to respond to the threats that could actually impact our organisation?

That requires a different risk story.

Rather than measuring activity, organisations can start measuring capability – continuously testing how individuals and teams perform against realistic scenarios, where weaknesses exist and whether resilience is improving over time.

“Immersive is helping organisations in Singapore move beyond static training records and compliance snapshots toward a clearer evidence layer for cyber resilience,” Goldenberg explained.

“Singapore is home to highly regulated financial services, regional headquarters and critical infrastructure, so the standard is not just awareness; it is demonstrable readiness.”

  • Workforce readiness: Immersive One puts employees into live fire scenarios based on the AI tools, data risks, policies and workflows they actually use. This gives leaders role level evidence of where people can adopt AI safely and where additional support is needed.
  • Technical and SOC readiness: Immersive helps security, engineering and incident response teams practise against high fidelity scenarios that reflect AI speed attacks, AI assisted development risk and the increasing use of autonomous agents in security operations.
  • Leadership and governance readiness: Immersive runs business focused crisis simulations that test escalation, decision making, communications and regulatory response. The output is an after action view of what held up, what failed, and what needs to be fixed before the next real incident.

“The aim is simple,” Goldenberg summarised.

“Give Singaporean CISOs, CIOs and business leaders proof that their people, processes and technology can hold up under pressure, not just proof that training was completed.”

SIGN UP FOR INSIGHTS VIA MOXIE MAIL

Inform your opinion with executive guidance, in-depth analysis and business commentary.