B BROCENT

The Rising Cost of Cybersecurity Incidents: What It Means for IT Service Providers and the Companies That Hire Them

A research report on the economics of cybersecurity incident cost: why the headline breach-cost figure and the average insurance claim differ by two orders of magnitude and both are correct, what Hong Kong and Singapore's own published data does and does not contain, why cyber premiums are falling while breach costs rise, and how to budget security into an IT decision without quoting the wrong population's number.

Two analysts working side by side at monitored workstations, representing the continuous detection capability that determines what a cybersecurity incident ultimately costs
In short: There is no single "cost of a cyber incident." IBM's 2026 report puts the global average breach at a record USD 4.99 million; Coalition's 2026 claims data puts the average insurance claim at USD 116,000 — down 19%. Both are correct. They measure different populations. Getting the population right is the whole exercise, and neither Hong Kong nor Singapore publishes a local cost figure at all.

Every security budget conversation eventually reaches for a number, usually the headline one: the average data breach now costs about five million dollars. It is a real figure from a credible source, and quoting it to a board is almost always misleading — not because the figure is wrong, but because "the cost of a cybersecurity incident" is not one quantity but at least three — what a large surveyed enterprise self-reports as total breach cost, what an insurer actually pays on a claim, and what a national incident-response body counts without ever costing it. All three were published in 2026, all three are defensible, and they differ by more than two orders of magnitude.

This report works through what each is measuring, what the published Hong Kong and Singapore data does and does not contain, and what that changes for both parties to a managed IT contract. Its subject is the economics of incident cost — who pays, how much, and how that reshapes budgets and service expectations — not third-party and supply-chain risk allocation, which is a different question with a different answer.

Key Findings

  • The headline global average is USD 4.99 million — from a survey of 602 organisations. IBM's 2026 Cost of a Data Breach Report, with the Ponemon Institute, covers 602 organisations breached between March 2025 and February 2026 across 16 countries and regions and 17 industries. That is the population the number describes, not a forecast for any individual company.
  • The average insurance claim is USD 116,000, and it fell 19%. Coalition's 2026 Cyber Claims Report, covering full-year 2025 across more than 100,000 policyholders, reports claims severity down 19%. Ransomware remained the most expensive claim type at USD 269,000.
  • Both are true because they are not the same measurement. One is a self-reported, activity-costed total across mostly large organisations; the other is what an insurer actually paid across a book weighted toward smaller businesses. Quoting one as if it were the other is the most common error in security budgeting.
  • Hong Kong and Singapore publish incident counts, not incident costs. HKCERT recorded 15,877 incidents in 2025, up 27% to a record; CSA recorded 165 ransomware cases and roughly 4,800 phishing attempts. Neither publishes a cost figure, and that gap is itself a finding.
  • Cyber insurance is getting cheaper while breach costs rise. Marsh's Q2 2026 Global Insurance Market Index reports cyber rates down 4% globally — the twelfth consecutive quarterly decline.
  • Detection time, not attack sophistication, is where the money is. IBM puts mean time to identify and contain a breach at 247 days — 183 to identify, 64 to contain. Detection and escalation plus lost business account for 63% of the global average cost.
  • Roughly 30% of Hong Kong enterprises have no dedicated cybersecurity personnel. HKCERT found 26% of SMEs have fully dedicated security staff against 59% of large enterprises. Detection capacity does not scale down gracefully with headcount.

Why There Is No Single "Cost of a Cyber Incident"

Three bodies publish credible incident data every year, and none is measuring the same thing.

  • IBM asks: if a large organisation is breached and reconstructs every cost the event caused, what is the total? For 2026: USD 4.99 million globally, a record and up 12%.
  • Coalition asks: when a smaller insured business suffers a cyber loss and files a claim, what does the insurer actually pay? For 2025: USD 116,000 on average, down 19%.
  • HKCERT and CSA ask: how much is happening, and what kind? For 2025: a record 15,877 incidents in Hong Kong, up 27%; 165 ransomware cases and 284,300 infected systems in Singapore. Neither body costs any of it.

A company with sixty staff in Kowloon Bay or Tanjong Pagar is closer to Coalition's population than IBM's. That does not make the IBM number irrelevant — its cost *structure* is instructive even where its *level* is not — but budgeting to a five-million-dollar expectation means budgeting against another company's balance sheet.

What Incident Cost Actually Includes

The headline figure obscures where the money goes. IBM's 2026 breakdown of the global average is clarifying, because the largest component is not the one most people expect.

  • Detection and escalation — USD 1.64 million. Forensic investigation, assessment and audit, crisis management, internal communication. The single largest category.
  • Lost business — USD 1.54 million. Disruption, revenue lost to downtime, customer attrition, the cost of replacing those customers, reputational damage.
  • Post-breach response — USD 1.36 million. Help-desk and inbound communication, credit monitoring, regulatory fines, legal expenditure, product discounts.
  • Notification — USD 0.45 million. Communication to regulators and data subjects, determining regulatory requirements, engaging outside experts.

Detection and escalation plus lost business together make up 63% of the global average — roughly USD 3.18 million. There is no ransom in that list, and no malware. The money is in *finding out what happened* and in *the business that stopped while you found out* — which inverts the intuition driving most security spending. The instinct is to buy prevention; the cost data says the dominant expense is the investigation-and-disruption window, a function of how quickly an incident is detected and contained rather than of how many preventive products are installed.

What the Global Numbers Say — and What Sample They Come From

The headline, and the sample behind it

IBM's 2026 report — the 21st annual edition, conducted with the Ponemon Institute and released in late July 2026 — puts the global average at USD 4.99 million and the United States average at USD 11.5 million, more than twice the global figure. It also found one in four malicious breaches were AI-enabled, up 56% year on year, costing about USD 6 million on average; deepfakes drove 45% of them.

The study covers 602 organisations breached between March 2025 and February 2026, across 16 countries and regions and 17 industries. That is a respectable sample, but not a census, and it is weighted toward organisations large enough to have the internal function such a study requires — a twelve-person logistics firm has nobody who can reconstruct the activity-based cost of a breach.

The correct reading, then, is: *among 602 mostly substantial organisations breached in a twelve-month window, the reconstructed average total cost was USD 4.99 million.* Useful — but not what a breach will cost your company.

The regional breakouts, and why ASEAN's is thinner than it looks

IBM's ASEAN release reports an average breach cost of USD 4.12 million, described as the highest level recorded, drawn from 26 organisations studied over the same window. As reported in coverage of that release, this was up 12% from USD 3.67 million the prior year and placed ASEAN ninth among the 16 country and regional samples, against Japan at USD 4.01 million, South Korea at USD 3.03 million, Australia at USD 2.96 million and India at USD 2.79 million. Within ASEAN, financial services recorded the highest average at USD 6.53 million, industrial organisations USD 5.99 million and communications USD 4.28 million.

Twenty-six organisations spread across six countries and multiple industries is a small sample, and the industry breakouts within it are smaller still — "financial services in ASEAN: USD 6.53 million" may rest on a single-digit number of firms. IBM is transparent about this; the reporting chain usually is not. Hong Kong does not appear as its own regional sample at all, so anyone quoting a Hong Kong breach-cost figure is either using the global average as a proxy or has invented it.

The honest use of this data is directional. The dishonest use is to hand a fifty-person Singapore company a USD 4.12 million planning figure derived from 26 organisations, most of them larger than it will ever be.

The Number the Insurers See Is Two Orders of Magnitude Smaller

Coalition's 2026 claims data

Coalition's 2026 Cyber Claims Report, published in March 2026 and covering full-year 2025, draws on more than 100,000 policyholders across the United States, Canada, the United Kingdom, Australia and Germany.

  • Overall claims severity fell 19% year on year, to an average loss of USD 116,000.
  • Ransomware remained the most expensive claim type, averaging USD 269,000.
  • Business email compromise severity fell 28%, to USD 27,000; funds transfer fraud fell 14%, to USD 141,000.
  • Initial ransom demands surged 47% — while a record 86% of targeted businesses refused to pay.
  • Businesses above USD 100 million in revenue filed claims five times more frequently, at an average loss of USD 268,000.

That fourth finding deserves attention: ransom *demands* rose sharply, but payments did not follow, because the overwhelming majority of victims declined. A demand is an opening position, not a cost.

Why both numbers are true

The gap between USD 4.99 million and USD 116,000 is not a contradiction. Here is what actually differs:

  • What is being counted, and for whom. IBM reconstructs *total organisational cost* — including lost business and reputational effects — at respondents large enough to participate in a costing study. Coalition reports *insured loss paid*, excluding uninsured consequences and anything inside the retention or outside policy terms, across a book weighted toward small and mid-sized businesses. That weighting is why Coalition's large-business subset, at USD 268,000, is more than twice its overall average.
  • What kind of event, and how the number is produced. IBM studies *data breaches* specifically, via survey estimates; Coalition pays audited claims across the full cyber loss spectrum, including funds transfer fraud and business email compromise — far more frequent than large data breaches, and much cheaper. Reconstructed estimates run systematically higher than settled payments.
  • Direction of travel. IBM's total is rising 12%; Coalition's severity is falling 19%. Both hold if large breaches are getting more expensive while the typical insured loss gets cheaper — consistent with better backup practices, higher ransom refusal rates, and faster containment among insured businesses with mandated controls.

The practical implication: plan against the distribution you are actually in, and plan for the tail rather than the average. A mid-sized firm in Hong Kong or Singapore should expect its realistic exposure to resemble Coalition's book far more than IBM's survey — while recognising that the tail of Coalition's own distribution reaches the hundreds of thousands, and that the uninsured portion of an incident is not in those numbers at all.

What Hong Kong and Singapore's Own Published Data Shows

Both jurisdictions have credible national incident data; neither publishes cost data. That combination shapes what can honestly be said.

Hong Kong: HKCERT's incident counts

HKCERT — the Hong Kong Computer Emergency Response Team Coordination Centre, operated by HKPC — released its "Hong Kong Cybersecurity Outlook 2026" in January 2026. The headline: 15,877 security incidents handled in 2025, a 27% year-on-year increase and a record high. The composition is as informative as the total:

  • Phishing accounted for 57% of cases — by a wide margin the dominant category.
  • Botnet-related incidents made up 18%.
  • Vulnerable systems accounted for 2,328 incidents, or 15% — more than a 3.5-fold increase on the prior year, the fastest-growing category by a distance.
  • Attack delivery has moved beyond email, with 34% of cases arriving via social media or instant messaging and 18% via cryptocurrency platforms.

HKCERT's accompanying enterprise survey is the most useful thing in the report for our purposes. Nearly 70% of Hong Kong enterprises have personnel responsible for cybersecurity — meaning approximately 30% have none at all. Broken down: 67% of SMEs have someone responsible but only 26% have fully dedicated staff, against 95% and 59% for large enterprises. Around 35% of businesses using AI tools said they would enter corporate data into them.

Singapore: CSA's incident counts

The Cyber Security Agency of Singapore published Singapore Cyber Landscape 2025/2026 on 30 June 2026, covering 2025 and the first half of 2026. Its figures:

  • Ransomware cases rose slightly, from 159 in 2024 to 165 in 2025.
  • Phishing attempts fell to approximately 4,800 in 2025, a 21% decrease from about 6,100 in 2024.
  • Infected infrastructure detected in Singapore rose to 284,300 in 2025, a 142% increase on 2024.

The divergence on phishing is worth noting rather than explaining away: HKCERT's caseload grew while CSA's fell by a fifth. The two bodies count different things through different channels, and neither figure measures underlying attack volume — both measure *reported* incidents, and a single year's movement cannot distinguish a change in attacks from a change in reporting behaviour. The infected-infrastructure figure is the one that should give a Singapore operations lead pause: a 142% increase in detected infected systems, in a year when phishing reports fell, points to compromise persisting quietly rather than arriving loudly.

The gap worth naming: counts without costs

Neither HKCERT nor CSA publishes a monetary cost figure for cybersecurity incidents. We checked both bodies' own publications directly. They count incidents, categorise them and describe trends — they do not cost them.

This is where most content on the subject does something indefensible: it multiplies a local incident count by a global average cost and presents the product as a local finding. "15,877 incidents at USD 4.99 million each" is arithmetic, not research, and the result is meaningless — HKCERT's incident definition includes phishing reports that cost nobody anything, while IBM's figure describes a completed breach at a large surveyed enterprise.

What can honestly be said is narrower: incident volume in Hong Kong hit a record in 2025, compromise persistence in Singapore rose sharply, and neither jurisdiction publishes what any of it cost. That absence is a real limitation of the evidence base here, and it is worth more to a buyer than a fabricated number with two decimal places.

Why the Cost Curve Is Rising Faster Than Company Size

If incident costs are rising while the typical insured loss falls, what is getting more expensive? Three things, and they compound.

Detection is slow and has not improved. IBM puts mean time to identify and contain a breach at 247 days — 183 to identify and 64 to contain. That is not a technology problem in the sense most people mean; it is a *monitoring* problem. And because detection and escalation is the largest cost category, time-to-detect is close to a direct multiplier on total cost. IBM's ASEAN release makes the point from the other side: organisations using AI and automation extensively contained breaches 123 days faster.

The attacker's cost of sophistication has collapsed. IBM found one in four malicious breaches were AI-enabled, up 56% year on year, with deepfakes driving 45% of them. Verizon's 2026 Data Breach Investigations Report — its 19th edition — found 31% of breaches now begin with vulnerability exploitation, which has overtaken stolen credentials as the leading initial access vector, that mobile social engineering succeeds 40% more often than email phishing, and that employee use of shadow AI tripled to 45%.

That first finding is the most operationally significant. Credential theft is defended by identity controls; vulnerability exploitation is defended by patching cadence — an operational discipline, not a product purchase. HKCERT's independent finding that vulnerable-system incidents grew more than 3.5-fold in a year is the same signal from a different vantage point.

Defensive capacity does not scale down. An attacker's cost to target a sixty-person firm is nearly identical to targeting a six-thousand-person firm, and the defender's is not proportional either — patch management, monitoring, backup verification and incident response are required whether there are sixty endpoints or six thousand. HKCERT's 26%-versus-59% staffing split is what that asymmetry looks like in practice.

Verizon's finding that 48% of breaches now involve a third party is frequently cited here, and it is real — but it is a question about risk allocation between a company and its vendors, a distinct subject from incident economics that deserves its own treatment.

The Insurance Market Is Pricing This Down, Not Up

The finding most likely to surprise anyone who has read only security-vendor material: cyber insurance is getting cheaper, and has been for three years.

Marsh's Global Insurance Market Index for Q2 2026 reports global cyber insurance rates down 4% — the twelfth consecutive quarter of declines. The global composite commercial rate fell 6%, its eighth consecutive quarterly decrease, with composite declines of 2% in the US, 6% in Europe and 5% in Asia. On cyber specifically, Marsh reported declines of 14% across India, the Middle East and Africa and 2% in the US. In Q1 2026, global cyber rates fell 5%, after a 7% decline in Q4 2025.

Marsh attributes this to stable capacity and continued insurer competition; read it as broker market commentary rather than neutral statistics, but the direction is unambiguous.

That is not a contradiction either. It reflects a market that finished repricing after the 2020–2022 ransomware shock, attracted enough capacity to compete, and — crucially — succeeded in forcing controls onto the businesses it insures. Multi-factor authentication, endpoint detection, tested backups and patch discipline moved from recommended to mandatory in underwriting, and loss experience improved; Coalition's 19% drop in claims severity is what that looks like from the claims side.

The consequence for a buyer is the opposite of what the price signal implies. Premiums fell because the questions got harder. A questionnaire asking whether multi-factor authentication is enforced on all remote access, whether backups are tested and segregated, whether endpoint detection covers every device, and how quickly critical patches are applied is not a formality — the answers determine the price and whether cover is offered at all. Companies that cannot answer cleanly do not get the falling rate.

This is where the managed-services relationship has become load-bearing, and we have written about the operational side in detail: vulnerability scanning ahead of a cyber insurance renewal is now routine work rather than exceptional.

What This Changes for IT Service Providers

Rising incident cost and hardening underwriting have rewritten what a managed IT contract must contain. Three changes stand out.

Evidence has become a deliverable. Patching systems is no longer sufficient; a provider has to demonstrate *that* they were patched, when, and which were not. Insurance renewals, customer security reviews and regulatory examinations now ask for evidence rather than assurance, and a provider without exportable patch, backup and endpoint-coverage reporting cannot support a client through any of them.

Response time has moved from a marketing number to a contractual one. When detection and escalation is the largest component of breach cost and mean time to identify runs to 183 days, the value of a monitored environment is concrete rather than theoretical.

Continuous monitoring has become table stakes, not an upsell. If the dominant cost driver is undetected dwell time, monitoring is the base product and everything else is elaboration — the reasoning behind bundling endpoint visibility into standard support rather than pricing it separately, as we do with continuous endpoint support and monitoring.

Brocent's own operational observation, offered as exactly that. Across our client base in Hong Kong, Singapore and mainland China, what clients ask for has shifted noticeably in two years. Requests once occasional are now routine: exportable evidence trails; response-time commitments written into the agreement rather than described in a brochure; scanning cadence aligned to insurance renewal dates rather than an internal calendar. The trigger is usually external — a questionnaire, a vendor assessment, an examination — rather than an incident. Qualitative, from our own book of business, unquantified.

What This Changes for the Companies That Hire Them

On the buyer's side of the contract, four things have changed.

Insurance underwriting has become a de facto security standard. For most mid-sized companies in Hong Kong and Singapore, the cyber insurance questionnaire is now the most specific security requirement they face — more specific than any regulation that applies to them. A company that can answer it honestly and cleanly has, almost by accident, implemented a reasonable baseline.

The "if" has become "when," and the budget should reflect it. With Hong Kong incidents up 27% to a record and Singapore's infected infrastructure up 142%, planning on the assumption that nothing will happen is no longer defensible. The implication is not "spend more" but to move money from prevention toward detection, response and recovery, where the cost data says it actually goes.

Compliance burden is rising independently of incident risk. Hong Kong's critical-infrastructure legislation, financial-sector supervisory expectations and customer-imposed contractual requirements all add obligations that exist whether or not anything goes wrong — and for many firms, what large customers demand now bites sooner than what regulators do.

Security is no longer separable from IT operations. Patch cadence, backup verification, endpoint coverage and access control are security controls and operational tasks at once. Splitting them across a security vendor and an IT vendor creates a gap neither owns — the structural argument for treating them as one function, whether delivered internally or through managed IT security services.

Brocent's own operational observation, again labelled as such. The pattern we see most often is not a company that decided against security spending, but one where nobody owns it: patching is "mostly" current, backups are configured but never restored from, multi-factor authentication covers some systems, and there is no monitoring because nobody chose not to have it.

Reactive Security vs Continuous Managed Security

The two operating models differ far more in cost profile than in the security products deployed.

  • Cost. Reactive: invisible until it is enormous — forensics, recovery and downtime arrive together in one unbudgeted quarter. Continuous: a predictable monthly line.
  • Detection. Reactive: depends on a user noticing a slow machine or a file that will not open; IBM's 183-day mean time to identify is what that looks like at scale. Continuous: alerts fire against a baseline whether or not anyone is looking.
  • Evidence. Reactive: reconstructed after the fact from memory and partial logs when an insurer asks. Continuous: a standing report.
  • Patch cadence. Reactive: applied when someone has time — which is why vulnerability exploitation is now the leading initial access vector at 31% of breaches. Continuous: scheduled, measured, reported.
  • Recovery. Reactive: backups exist, and whether they restore is discovered during the incident. Continuous: restoration is tested on a schedule, and the test result is the deliverable.

The distinction is not that one model buys better tools. It is that one converts a volatile, tail-heavy cost into a predictable one — the same argument that applies to managed IT support generally, at higher stakes.

A Practical Framework for Budgeting Security Into an IT Decision

A workable approach for a company of thirty to three hundred people.

1. Establish which distribution you are in. Under roughly USD 100 million in revenue, your realistic exposure resembles Coalition's claims data — around USD 116,000 average insured loss, USD 269,000 for ransomware — far more than IBM's USD 4.99 million survey average. Budget against the former; use the latter only for the *shape* of where cost accumulates.

2. Budget for the tail, not the average. The question is not "what does a typical incident cost" but "what is the largest loss we could absorb, and what closes the gap between that and our realistic worst case" — a framing that leads to insurance and recovery capability rather than more preventive products.

3. Spend where the cost data says the cost is. Sixty-three percent of IBM's global average sits in detection, escalation and lost business. Weight the budget toward reducing time-to-detect and time-to-recover: monitoring, tested backups, a rehearsed response process, support that answers out of hours.

4. Use the insurance questionnaire as the specification. It is free, specific, externally maintained and updated annually against real loss experience. Answer it honestly, treat every "no" as a backlog item, and re-answer after remediation — for most mid-sized firms this beats any framework as a starting point, because failing it has an immediate, quantified consequence.

5. Make the evidence a contractual deliverable, not a favour. Require patch status, backup verification and endpoint coverage to be reported on a schedule; evidence that exists only when requested tends not to exist. When comparing providers, ask for an actual sample report rather than a description of one, and check it against what is included at each service tier.

For companies subject to financial-sector supervisory expectations or handling regulated data, the same framework applies with an extra evidentiary layer — only the audience for the evidence changes. Our cybersecurity practice covers that ground in more detail.

Frequently Asked Questions

What does a cybersecurity incident actually cost a small or mid-sized company?

There is no reliable published figure for Hong Kong or Singapore, because neither HKCERT nor CSA publishes cost data. The closest defensible proxy is insurance claims: Coalition's 2026 report puts average claims severity at USD 116,000 for full-year 2025, ransomware at USD 269,000, across a policyholder base weighted toward smaller businesses. Treat that as an order of magnitude for insured loss, not a prediction.

Why is the "average data breach costs USD 4.99 million" figure misleading for my company?

It is not misleading — it is precise about something other than your company: the reconstructed total cost among 602 organisations breached between March 2025 and February 2026 that were large enough to participate in a costing study. Its cost *structure* transfers usefully, since detection, escalation and lost business dominate. Its cost *level* does not.

Is there any Hong Kong-specific breach cost data?

No. HKCERT publishes incident counts but not costs, and Hong Kong is not broken out as its own regional sample in IBM's study. Any Hong Kong breach-cost figure is either an extrapolation from a global or ASEAN average — which should be stated plainly — or fabricated.

If breach costs are rising, why is cyber insurance getting cheaper?

Because the market repriced after the 2020–2022 ransomware period, attracted enough capacity to compete, and made controls a condition of cover. Marsh reports cyber rates down 4% globally in Q2 2026, the twelfth consecutive quarterly decline; Coalition reports claims severity down 19%. The price fell because the requirements rose.

What should we do before our next cyber insurance renewal?

Answer the questionnaire from evidence rather than assumption, at least six weeks out. The common failure is discovering mid-renewal that multi-factor authentication is not enforced everywhere, that backups have never been restore-tested, or that endpoint coverage has gaps — each fixable in weeks, and expensive to explain at renewal. A vulnerability scan with a written remediation record before the questionnaire falls due is usually the single highest-value piece of preparation.

Our provider handles security. Isn't that enough?

It depends what "handles" means contractually. Ask what is monitored and who reviews the alerts, how quickly a security incident is responded to outside business hours, and what evidence can be produced on demand for an insurer or enterprise customer. If the answers are not written into the agreement with a defined cadence, security is being described rather than delivered.

The Conclusion Worth Keeping

The most useful thing in this year's data is not a number, but the distance between two numbers that are both correct.

IBM says USD 4.99 million and Coalition says USD 116,000, and the gap is not measurement error — it is the difference between a self-reported total at a large surveyed enterprise and an audited payment on a smaller company's claim. A security budget built on the first number, for a company that lives in the second, is not conservative but simply aimed at the wrong target, and it usually buys prevention where the cost data points at detection and recovery. Meanwhile the two things a Hong Kong or Singapore buyer would most like to know — what an incident costs here, and how likely one is at their size — are published by nobody.

What the evidence does support: incident volume in Hong Kong is at a record, compromise persistence in Singapore has more than doubled, detection remains slow enough to dominate the cost of an incident, and the insurance market has spent three years converting security controls from a recommendation into a precondition of cover. None of that argues for spending more on security. It argues for spending it where the losses actually accumulate — on knowing sooner and recovering faster — and for being able to prove, on demand, that you do.

How This Report Was Sourced

Every figure above traces to one of the following, all consulted directly.

  • IBM Cost of a Data Breach Report 2026, with the Ponemon Institute — global and US averages, cost categories, mean time to identify and contain, AI-enabled breach findings, sample description. IBM's ASEAN newsroom release supplied the ASEAN average, its 26-organisation sample and the industry breakouts; ASEAN's prior-year figure and regional ranking come from reporting on that release rather than a document we opened ourselves, and are attributed as such above.
  • Coalition 2026 Cyber Claims Report — claims severity overall and by type, ransom figures, organisation-size split, policyholder base. Insurer claims data, not neutral statistics.
  • Marsh Global Insurance Market Index, Q2 2026 — cyber and composite rate changes. Broker market commentary.
  • Verizon 2026 Data Breach Investigations Report (19th edition) — initial access vectors, third-party involvement, mobile social engineering, shadow AI.
  • HKCERT, "Hong Kong Cybersecurity Outlook 2026" (January 2026) and CSA, Singapore Cyber Landscape 2025/2026 (30 June 2026) — local incident counts, composition and the staffing survey.
  • Brocent's own operational observations, labelled wherever they appear and kept strictly qualitative. No percentages are attached to them, because we have not measured them.

Brocent has provided managed IT services since 2007, when the company was founded in Beijing. We opened our Hong Kong office in 2016 and have been headquartered in Singapore since 2021 — which is why this report weights Hong Kong and Singapore evidence heavily, and says plainly where it does not exist.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →