Cracking the Code: AI Cybersecurity Breakthroughs in Asia-Pacific and Japan
By Jeslyn Allison Rancap Jerota
Cracking the Code: AI Cybersecurity Breakthroughs in Asia-Pacific and Japan
Last week, a CFO in Singapore told me she wakes up at 3 a.m. most nights, checking her phone—not for market updates, but for breach alerts. Her company runs a forty-year-old ERP system duct-taped to a cloud analytics platform, and every security patch feels like defusing a bomb while the timer counts down. She's not alone. Across boardrooms in Tokyo, Mumbai, and Sydney, I've heard the same anxious refrain: our digital infrastructure is built on layers of legacy systems that were never designed for the AI era, and the attackers know it. When I sat down with Duncan Thomas, CEO of Innoculator and a veteran of AI-driven cybersecurity, I expected a technical deep dive. What I got instead was a wake-up call about how fundamentally we've misunderstood the nature of security in complex systems—and why the Asia-Pacific and Japan region is both the proving ground and the canary in the coal mine for what comes next.
Duncan's central argument is deceptively simple: cybersecurity isn't a technology problem anymore; it's an architecture problem compounded by a trust deficit. In the APJ market, organizations aren't dealing with clean-slate digital transformations. They're managing what he calls "Frankenstein infrastructures"—banking cores written in COBOL sitting alongside microservices architectures, manufacturing systems running decades-old SCADA protocols now exposed to internet-connected AI agents. The evidence is everywhere. Consider Japan's manufacturing sector, where operational technology systems designed in the 1980s now interface with supply chain AI that processes real-time data from thousands of endpoints. Each integration point is a potential vulnerability, and traditional perimeter-based security is about as effective as building a moat around a city that's already crisscrossed with subway tunnels. Duncan explained that in these environments, the attack surface isn't just large—it's incomprehensible to human security teams. That's why AI-driven security isn't optional; it's the only viable response to AI-enabled threats that can probe millions of configurations per second, learning from each failed attempt.
What makes this particularly urgent in our region is the velocity of change combined with governance fragmentation. While European organizations navigate GDPR and American companies wrangle with state-by-state regulations, APJ operates across a dizzying spectrum of data sovereignty laws, privacy frameworks, and cybersecurity mandates that rarely align. I've watched CISOs in multinational companies try to implement a single AI security solution across Singapore, Australia, India, and Japan, only to discover that what's permissible in one jurisdiction is legally toxic in another. Duncan emphasized that this regulatory patchwork creates security gaps that sophisticated adversaries exploit ruthlessly. The mechanism is straightforward: attackers identify the jurisdiction with the weakest enforcement, establish a foothold there, then pivot laterally across the organization's global network. The solution isn't trying to achieve perfect compliance everywhere—that's impossible—but rather designing AI security systems that can adapt their behavior contextually, operating more conservatively in high-regulation environments while maintaining aggressive threat hunting where regulations permit.
The human dimension Duncan illuminated cuts deeper than the usual "people are the weakest link" platitude. I've sat through enough security awareness training sessions to know that most treat employees as problems to be managed rather than assets to be mobilized. Duncan's approach flips this entirely. He argues that in the APJ context, where organizational cultures range from Japan's consensus-driven decision-making to Australia's flat hierarchies, effective cybersecurity requires AI systems that augment rather than replace human judgment. The evidence from Innoculator's deployments is striking: when security teams receive AI-generated threat assessments with clear explanations of the reasoning—not just red alerts and risk scores—response times improve by orders of magnitude. This isn't because the AI is faster at detection; it's because analysts trust recommendations they understand and can contextualize within their specific operational environment.
The ethical dimension emerged as perhaps the most underexplored territory in our conversation. Duncan raised questions that keep me awake now, too. When your AI security system identifies a vulnerability in a partner's network during routine monitoring, what's your obligation? When threat intelligence gathered by your AI reveals criminal activity by individuals who aren't directly threatening your systems, where does corporate responsibility end and law enforcement begin? In the APJ region, these aren't hypothetical scenarios. The interconnectedness of supply chains means your security perimeter effectively extends through dozens of organizations, many operating under different legal and ethical frameworks. Duncan's position is clear: we need industry-wide protocols for responsible AI security practices before a major incident forces governments to impose ham-fisted regulations that cripple legitimate defensive operations while barely inconveniencing determined attackers.
What strikes me most about this landscape is how rapidly the ground is shifting beneath our feet. The legacy systems that CFO in Singapore worries about aren't going away—her company's entire order management process depends on them. But the threat actors targeting those systems are upgrading their capabilities continuously, increasingly using AI not just for scale but for adaptive, contextual attacks that traditional signature-based defenses miss entirely. Duncan's point about the APJ market being a bellwether makes intuitive sense: we have the complexity, the economic incentives for attackers, and the diversity of technical environments that make us the perfect laboratory for next-generation security approaches. What works here will work anywhere.
For leaders navigating this terrain, Duncan's framework offers unexpected clarity. Stop trying to achieve perfect security—it's unattainable and paralyzing. Instead, focus on resilient architectures that assume breach and prioritize rapid detection and response. Invest in AI security tools that explain their reasoning and integrate with human decision-making rather than replacing it. And perhaps most importantly, recognize that cybersecurity is no longer a technical department's problem; it's a strategic imperative that requires board-level attention and cross-functional coordination.
The conversation left me with one conviction: the organizations that thrive won't be those with the most sophisticated defenses, but those that build security into their organizational DNA—where AI augments human expertise, where legacy and modern systems coexist within coherent security architectures, and where trust is engineered rather than assumed.# Cracking the Code: AI Cybersecurity Breakthroughs in Asia-Pacific and Japan
Last week, a CFO in Singapore told me she wakes up at 3 a.m. most nights, checking her phone—not for market updates, but for breach alerts. Her company runs a forty-year-old ERP system duct-taped to a cloud analytics platform, and every security patch feels like defusing a bomb while the timer counts down. She's not alone. Across boardrooms in Tokyo, Mumbai, and Sydney, I've heard the same anxious refrain: our digital infrastructure is built on layers of legacy systems that were never designed for the AI era, and the attackers know it. When I sat down with Duncan Thomas, CEO of Innoculator and a veteran of AI-driven cybersecurity, I expected a technical deep dive. What I got instead was a wake-up call about how fundamentally we've misunderstood the nature of security in complex systems—and why the Asia-Pacific and Japan region is both the proving ground and the canary in the coal mine for what comes next.
Duncan's central argument is deceptively simple: cybersecurity isn't a technology problem anymore; it's an architecture problem compounded by a trust deficit. In the APJ market, organizations aren't dealing with clean-slate digital transformations. They're managing what he calls "Frankenstein infrastructures"—banking cores written in COBOL sitting alongside microservices architectures, manufacturing systems running decades-old SCADA protocols now exposed to internet-connected AI agents. The evidence is everywhere. Consider Japan's manufacturing sector, where operational technology systems designed in the 1980s now interface with supply chain AI that processes real-time data from thousands of endpoints. Each integration point is a potential vulnerability, and traditional perimeter-based security is about as effective as building a moat around a city that's already crisscrossed with subway tunnels. Duncan explained that in these environments, the attack surface isn't just large—it's incomprehensible to human security teams. That's why AI-driven security isn't optional; it's the only viable response to AI-enabled threats that can probe millions of configurations per second, learning from each failed attempt.
What makes this particularly urgent in our region is the velocity of change combined with governance fragmentation. While European organizations navigate GDPR and American companies wrangle with state-by-state regulations, APJ operates across a dizzying spectrum of data sovereignty laws, privacy frameworks, and cybersecurity mandates that rarely align. I've watched CISOs in multinational companies try to implement a single AI security solution across Singapore, Australia, India, and Japan, only to discover that what's permissible in one jurisdiction is legally toxic in another. Duncan emphasized that this regulatory patchwork creates security gaps that sophisticated adversaries exploit ruthlessly. The mechanism is straightforward: attackers identify the jurisdiction with the weakest enforcement, establish a foothold there, then pivot laterally across the organization's global network. The solution isn't trying to achieve perfect compliance everywhere—that's impossible—but rather designing AI security systems that can adapt their behavior contextually, operating more conservatively in high-regulation environments while maintaining aggressive threat hunting where regulations permit.
The human dimension Duncan illuminated cuts deeper than the usual "people are the weakest link" platitude. I've sat through enough security awareness training sessions to know that most treat employees as problems to be managed rather than assets to be mobilized. Duncan's approach flips this entirely. He argues that in the APJ context, where organizational cultures range from Japan's consensus-driven decision-making to Australia's flat hierarchies, effective cybersecurity requires AI systems that augment rather than replace human judgment. The evidence from Innoculator's deployments is striking: when security teams receive AI-generated threat assessments with clear explanations of the reasoning—not just red alerts and risk scores—response times improve by orders of magnitude. This isn't because the AI is faster at detection; it's because analysts trust recommendations they understand and can contextualize within their specific operational environment.
The ethical dimension emerged as perhaps the most underexplored territory in our conversation. Duncan raised questions that keep me awake now, too. When your AI security system identifies a vulnerability in a partner's network during routine monitoring, what's your obligation? When threat intelligence gathered by your AI reveals criminal activity by individuals who aren't directly threatening your systems, where does corporate responsibility end and law enforcement begin? In the APJ region, these aren't hypothetical scenarios. The interconnectedness of supply chains means your security perimeter effectively extends through dozens of organizations, many operating under different legal and ethical frameworks. Duncan's position is clear: we need industry-wide protocols for responsible AI security practices before a major incident forces governments to impose ham-fisted regulations that cripple legitimate defensive operations while barely inconveniencing determined attackers.
What strikes me most about this landscape is how rapidly the ground is shifting beneath our feet. The legacy systems that CFO in Singapore worries about aren't going away—her company's entire order management process depends on them. But the threat actors targeting those systems are upgrading their capabilities continuously, increasingly using AI not just for scale but for adaptive, contextual attacks that traditional signature-based defenses miss entirely. Duncan's point about the APJ market being a bellwether makes intuitive sense: we have the complexity, the economic incentives for attackers, and the diversity of technical environments that make us the perfect laboratory for next-generation security approaches. What works here will work anywhere.
For leaders navigating this terrain, Duncan's framework offers unexpected clarity. Stop trying to achieve perfect security—it's unattainable and paralyzing. Instead, focus on resilient architectures that assume breach and prioritize rapid detection and response. Invest in AI security tools that explain their reasoning and integrate with human decision-making rather than replacing it. And perhaps most importantly, recognize that cybersecurity is no longer a technical department's problem; it's a strategic imperative that requires board-level attention and cross-functional coordination.
The conversation left me with one conviction: the organizations that thrive won't be those with the most sophisticated defenses, but those that build security into their organizational DNA—where AI augments human expertise, where legacy and modern systems coexist within coherent security architectures, and where trust is engineered rather than assumed.
Watch or Listen to the Full Episode
