TL;DR: Cyber risk across Southeast Asia is rising as average breach costs climbed from $3.23 million to $3.67 million in 2025, while attackers increasingly exploit cloud, supply chain, insider, and third-party exposure, according to Seclore. Data-centric controls matter because trust now has to follow the data, not just the perimeter.
NHIMG editorial — based on content published by Seclore: Cyber Threats Are Rising Across Southeast Asia - Is Your Data Ready?
By the numbers:
- In 2025, ASEAN recorded an increase in average data breach costs from $3.23 million to $3.67 million.
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should security teams govern shared data across vendors and cloud collaboration tools?
A: Treat shared data as a lifecycle object, not a static asset.
Q: Why do third-party access paths increase identity risk across enterprise programmes?
A: Third-party access paths increase identity risk because they often rely on tokens, OAuth grants, API keys, and service accounts that sit outside the normal employee lifecycle.
Q: What breaks when insider risk is managed only with perimeter security?
A: Perimeter security fails when the threat originates inside trusted workflows.
Practitioner guidance
- Map data-sharing workflows end to end Inventory where sensitive files move across collaboration platforms, vendors, and internal teams, then document which identities can read, copy, forward, or sync each dataset.
- Enforce expiry on externally shared content Set time-bound access for partner and contractor workflows so permissions automatically lapse when the business need ends, rather than relying on manual follow-up.
- Require revocation and audit hooks Make revocation, access logs, and user-level traceability mandatory for protected content so responders can remove access and reconstruct usage after an incident.
What's in the full article
Seclore's full blog post covers the operational detail this post intentionally leaves for the source:
- Regional breach-cost context and how the article maps those costs to Southeast Asia-specific threat exposure
- Practical examples of file-level protections, including time-bound access, dynamic watermarking, and instant revocation
- Compliance mapping across ASEAN privacy regimes and how organisations can evidence accountability to auditors
- Implementation framing for teams evaluating data-centric security alongside existing DLP, IAM, and collaboration controls
Data-centric security in Southeast Asia: what IAM teams should notice?
Explore further
Data-centric security is now an identity governance problem, not just a file protection problem. Once sensitive content moves into collaboration tools, vendor systems, and cloud storage, the organisation has to govern access after the file leaves the originating boundary. That means lifecycle controls, revocation, and auditability matter as much as encryption. For IAM and NHI teams, this is a reminder that policy must travel with the data, not sit only in the directory.
A question worth separating out:
Q: Who is accountable when sensitive data leaves through a vendor, API, or misconfigured system?
A: Accountability usually sits with the business owner of the data, the identity or platform team that granted access, and the vendor manager if external trust was involved. Frameworks such as Zero Trust and least privilege make that shared responsibility harder to ignore because they require continuous verification of access, not one-time approval.
👉 Read our full editorial: Cyber threats in Southeast Asia expose the limits of perimeter security