The battlefield for cybersecurity is changing and becoming even harder to detect. In this year, a growing surge in identity-based cyberattacks across APAC digital economies has led to significant operational disruption, financial losses, and reputational damage.
The use of AI to accelerate these attacks, including phishing, credential theft, impersonation, and social engineering techniques - along with the use of autonomous AI agents and deepfakes have exacerbated the threat further.
What are the common security gaps that continue to expose identity infrastructure, particularly as organisations manage employees, third-party vendors, privileged users, and machine identities across complex hybrid and multi-cloud environments?
Speaking with iTNews Asia, Sarah Cecchetti, Director of Product Management, Semperis discusses her view on the gaps, explains what organisations in APAC are doing wrong and recommends ways they can strengthen their identity resilience and reduce future risks.
iTNews Asia: Identity attacks have become the primary threat to business resilience across APAC organisations. What has been the real-world impact for enterprises?
Cecchetti: The impact of cyberattacks is playing out in boardrooms and operations centres across the region right now.
When identity infrastructure is compromised, the blast radius is enormous. We’re not talking about a single application going offline, we’re talking about the complete collapse of an organisation’s ability to authenticate users, authorise access, and run business-critical systems.
For example, Active Directory (AD) underpins the majority of enterprise environments in APAC, and when an attacker gets in there, they’ve got everything and its game over, because the system is designed to give authenticated users exactly what they need.
In practice, organisations hit by identity-based attacks, particularly ransomware groups that move laterally through identity infrastructure, are looking at recovery timelines measured in weeks.
When you look at ransom demands, forensic investigation, system rebuild costs, regulatory penalties, lost productivity, the financial toll is compounding. Many organisations haven’t figured out how they’d even communicate in a crisis once identity is down. In sectors like financial services, healthcare, and logistics, 48 hours of disruption can trigger contractual penalties and permanent customer attrition.

The reputational dimension is serious, and I think it’s underestimated. Customers and partners don’t distinguish between a ‘technical incident’ and a failure of trust. Once it becomes public that attackers were impersonating executives, accessing privileged systems, or sitting undetected inside the environment for months, the confidence damage is lasting. For publicly listed companies, or those in regulated industries, this goes all the way to the C-suite. Leadership accountability is very real.
- Sarah Cecchetti, Director of Product Management, Semperis
iTNews Asia: How serious (or even existential) can they become?
Cecchetti: Can it be existential? Yes, unfortunately. Smaller enterprises have simply been unable to recover, operationally or financially, after a severe identity compromise. For larger organisations, the more realistic risk is a sustained erosion of competitive position and partner trust that takes years to rebuild.
It’s the preparedness for that incident, the ability to respond in the moment, and the ability to recover, is super critical.
iTNews Asia: How are threat actors using AI to enhance identity attacks, what (method) has advanced the fastest and how are they evolving their tactics?
Cecchetti: AI has fundamentally changed the economics of identity attacks. Techniques that once required significant skill and resources to pull off are now automated, scalable, and frankly pretty accessible. And I’d caution against ‘shiny object syndrome’ here. There’s a lot of scary and innovative attack research that can whipsaw security teams into constantly chasing the latest headline. But the area that has genuinely advanced fastest (and most alarmingly) is social engineering - AI-generated phishing and voice impersonation.
Phishing was always a volume game. The more convincing and personalised the lure, the more expensive it was to produce. Generative AI has collapsed that constraint entirely. Attackers now produce highly personalised, grammatically flawless communications at scale, referencing your actual job title, your recent LinkedIn activity, and your internal business context. The ‘tells’ that trained users once relied on to spot phishing such as the awkward language, the generic salutations, the implausible urgency, are disappearing fast.
Voice cloning and deepfake video have taken this to another level. We’re now seeing real-world cases where attackers synthesise the voice of a CFO or IT administrator to authorise credential resets or wire transfers.
In APAC specifically, where cross-border operations mean many interactions happen remotely rather than face to face, this is a particularly dangerous vector. The attacker doesn’t even need to hack a system. They just convince a human to hand over the keys.
Beyond social engineering, AI is accelerating credential attacks across the board. Microsoft's data from its 2025 Digital Defense Report shows more than 7,000 password attacks being blocked per second, and intelligent automation now adapts attack patterns in real time to evade detection thresholds.
The trajectory is toward autonomous attacks with AI agents executing multi-stage identity campaigns with minimal human oversight. And here’s the thing: AI isn’t just an attacker’s tool. Defenders can harness it too. The organisations that are building genuine resilience are the ones recognising that AI-powered identity threat detection isn’t aspirational anymore. You need to be operating at the same speed and intelligence level as the attackers, right?
iTNews Asia: Despite increased awareness, many organisations still have structural weaknesses in how identity is managed and secured. Why do you think this is so?
Cecchetti: I think the awareness gap has genuinely narrowed. Most security leaders in APAC now understand that identity is a primary attack surface. The execution gap is where I still see a lot of pain. And the persistent structural weaknesses tend to fall into a few consistent categories, almost all the time.
iTNews Asia: What are the most common gaps that are currently leaving identity infrastructure exposed?
Cecchetti: 1. Firstly, excessive and unreviewed privilege. Organisations accumulate privileged access over time due to several IT projects, staff transitions, and operational shortcuts, without systematic clean-up. The result is a sprawl of accounts with domain admin rights, legacy service accounts with broad permissions, privileged access granted for a specific project years ago and never revoked.
Every one of those is a potential stepping stone for an attacker. And I’m not impugning any one organisation here. Everyone who hears this could say ‘well, I’m better than that’ and maybe they are. But many organisations simply haven’t done this work. Least privilege is well understood in theory; it’s consistently under-applied in practice.
2. Secondly, AD misconfigurations. AD remains the identity backbone for the overwhelming majority of enterprises in APAC, and it accumulates misconfigurations over its lifespan in the same way privilege sprawl accumulates.
Unconstrained delegation, weak Kerberos configurations, outdated password policies, and unprotected tier-zero assets are endemic. Many of these misconfigurations have existed for years without triggering alerts because organisations don’t have continuous visibility into their AD security posture.
3. Thirdly, multi-factor authentication gaps. MFA adoption has improved significantly, but coverage is rarely complete. Legacy applications, VPN endpoints, and operational technology systems often remain unprotected.
Attackers specifically target these gaps because they’re well aware that an organisation’s MFA policy applies to the corporate portal but not the legacy HR system running on premises.
4. Fourthly, weak identity threat monitoring. Many organisations rely on general-purpose SIEM tools to detect identity-specific threats, which is like using a general-purpose scanner to detect specialist malware. Identity-focused threat detection requires deep understanding of how AD and Entra ID behave under normal conditions, so that anomalous activity can be identified and acted upon in real time.
5. Finally, and this is the one that really gets me. Identity recovery is almost universally under-resourced. Many organisations have not yet figured out how to back up and restore their identity infrastructure in the case of a malware attack. They invest in prevention and detection but haven’t thought through what happens when the worst occurs.
When it does, and unfortunately it’s probably an inevitable moment for most organisations, the absence of a tested recovery plan dramatically extends downtime and increases the risk of reinfection.
iTNews Asia: Do you feel managing identities such as employees, third party vendors and machines across hybrid environments and cloud services is also adding complexity to security operations? What can enterprises do to manage the complexity and help neutralise the threats from them?
Cecchetti: Hybrid and multi-cloud environments have created an identity landscape that is genuinely complex, and I think it’s important to be honest about that rather than pretending there’s a simple fix. The complexity isn’t evenly distributed, though. The challenges tend to cluster around three distinct identity types.
Human identities (employees) are the most familiar challenge, but hybrid work has expanded the attack surface considerably. Users are authenticating from personal devices, across multiple cloud applications, and from networks IT doesn’t control. Perimeter-based security assumptions are simply no longer valid, right?
Zero Trust, where no identity is implicitly trusted and every access request is continuously validated against context and policy, is the right framework response here. But to be clear: Zero Trust is not a product. It’s an architectural principle that requires sustained commitment and real implementation discipline.
Third-party and vendor identities represent a disproportionate risk, and it’s one that’s easy to overlook. Contractors and technology partners often need privileged access but they operate outside the organisation’s normal onboarding, monitoring, and off-boarding processes.
Privileged Access Management (PAM) solutions with time-bound, just-in-time access for third parties are effective, but only if vendors are genuinely held to the same security standards as internal staff. Consistent enforcement is the thing that actually matters here.
Machine identities (service accounts, APIs, certificates, and now AI agents) are the fastest-growing identity category and the least well-governed. Many organisations have significantly more machine identities than human ones, and the governance frameworks simply haven’t kept pace. Treating machine identities with the same priority as human ones is essential for business resilience.
The unifying principle is visibility across the entire identity fabric. You need a consolidated view of all identities, human and machine, on-premises and cloud, with consistent policy enforcement and anomaly detection. Connected platforms outperform patchwork stacks every time. Fragmented tools that cover different segments create the blind spots attackers exploit.
iTNews Asia: What are organisations still getting wrong when it comes to managing and responding to identity threats? What advice can you give before they escalate? How can they strengthen identity resilience and reduce future risks?
Cecchetti: The most consequential mistake (and I see this repeatedly) is treating identity security as a technology problem rather than a continuous operational discipline. Organisations invest in tools, sometimes really excellent tools, and then assume the problem is addressed. It isn’t. Identity security requires the same operational rigour as any other critical infrastructure: regular assessment, ongoing remediation, tested response plans, and clear ownership.
A big part of what it means to be a force for good in this space is making that really easy to understand and execute for organisations at every level of maturity.
A specific pattern I keep coming back to is what I’d call the ‘detection without response’ problem. Organisations deploy monitoring that flags suspicious identity activity but have no defined playbook for what to do when an alert fires.
By the time a response is improvised, the attacker has moved laterally, escalated privileges, and established persistence that will survive any remediation that doesn’t include a full identity layer rebuild. Speed of containment is critical in identity incidents.
Another persistent error is failing to account for AD recovery in business continuity planning. If ransomware or a destructive attack takes down AD, you lose your ability to authenticate users across every system that depends on it. Without a clean, tested, and isolated AD backup, recovery could take weeks.
So, here’s the question every organisation running AD should be able to answer right now: ‘If our domain controllers were wiped today, how long would it take us to restore identity services, and are we confident our backup is also not compromised?’ In my experience, very few can answer that with confidence.
Before threats escalate, the practical priorities are: first, an identity risk assessment that covers AD misconfigurations, privileged access sprawl, and MFA coverage gaps with automated tooling that gives you continuous, not point-in-time, visibility.
Second, a Tier 0 asset protection programme: your domain controllers, privileged access workstations, and identity management systems under the strictest controls in your environment.
Third, and this is probably the most underinvested area, test your identity-specific incident response and recovery plan, including isolated AD backup infrastructure that an attacker who’s already in your production environment simply cannot reach.
Red team exercises targeting identity infrastructure, and regular purple team exercises that test detection and response against real attack techniques, are among the most effective investments you can make.




