New era of cybersecurity
According to Mr. Adrian Hia - CEO of Kaspersky Asia-Pacific (APAC), recent cyberattacks in the region show that the boundary between the digital world and the real world is almost non-existent.
Not long ago, Nichirei Corporation of Japan faced an attack that disrupted its logistics network. Meanwhile, India's manufacturing industry has become one of the hotspots suffering from ransomware attacks targeting industrial systems in the APAC region. Attack groups continuously paralyze production lines and information technology systems serving industrial production activities.
Mr. Hia also emphasized that AI agents (AI Agents) are creating a new link in the software supply chain. In 2026 alone, Kaspersky's security experts discovered more than 15,000 malware samples disguised as AI Agent software. This significantly expands the scope of attacks for sabotage and cyber espionage activities.
As AI increasingly becomes a core part of cyber security threats, and also becomes a driving force to strengthen defense capabilities, APAC organizations should not just stop at preventing attacks. More importantly, organizations need to ask themselves if they are really capable of monitoring and detecting what is happening inside their systems," Mr. Hia emphasized.
SOC applies AI to restore the ability to monitor and detect threats
According to a new report from Kaspersky's system intrusion assessment department, data from 31% of analyzed incidents shows that malicious activities have been silently taking place in the organization's system for more than three months before being detected.
Notably, 52% of serious incidents are only detected after more than 90 days from the time the attacker successfully infiltrated. Even Kaspersky recorded an intrusion that had silently existed in the system for 4 years before being detected. In those 4 years, the harmful agent was hidden in the system without being detected.
These findings reflect major challenges in network security operations. Although many organizations have invested in security technologies, the technology still cannot compensate for the limitations in monitoring, detection and response readiness.
From in-depth research, Kaspersky experts emphasize that the modern and unified Network Security Operations Center (SOC) is becoming a key factor in business operations.
When organizations still apply coping security methods or lack continuous monitoring capabilities, bad actors will have more time to expand the scope of intrusion in the system, gain access at a higher level and access important systems and data.
Conversely, a well-built and well-operated SOC will shorten this time period by providing comprehensive monitoring capabilities, a team of professionals and the necessary operating procedures to detect threats before they break out into serious incidents.
