IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
Asia Pacific leaders urge overhaul of scam defences

Asia Pacific leaders urge overhaul of scam defences

Fri, 21st Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Technology leaders across Asia Pacific are urging businesses to overhaul scam prevention during Scam Awareness Week, warning that current responses often lag behind fast-evolving cyber threats.

Scams and cyber-enabled fraud continue to rise across the region as attackers adopt artificial intelligence tools and exploit gaps in corporate governance. Security specialists say many organisations still rely on outdated playbooks and informal practices.

Harshvendra Soin, President - Asia Pacific and Japan Business at Tech Mahindra, said leaders he speaks with still question whether their organisations are truly prepared for sophisticated cybercrime.

"Speaking to leaders across APAC and Japan, there is always the question of whether a business could be better prepared in the face of cybercrime, and the answer is almost always yes. This Cyber Scam Awareness Week is a reminder that businesses and individuals need to build awareness and prepare for cyber risks well before an incident occurs."

Soin highlighted the importance of clear lines of authority during an incident and regular exercises involving senior decision-makers from across the business.

Organisations that treat incident playbooks as static documents risk slow or confused responses when an attack unfolds, he said.

Allan James Waddell, Founder and Co-Chief Executive Officer at cloud software firm Kablamo, said the speed of change in underlying technology has shifted the risk profile for many organisations.

"One of the biggest risks with scams today is the speed at which the technology is changing. AI is already embedded across many of the systems businesses use, and increasingly those systems can access data or take action on our behalf.

"That changes what businesses need to prepare for. You need to understand where AI has access across your environment and be very clear about who is accountable when something goes wrong. You also need to understand what your technology providers are responsible for if one of those systems is compromised.

"This is where smaller, nimble teams can be really useful. Give people exposure to realistic scam scenarios, see how they respond, and learn from where they get caught out. You can then take those lessons into the wider business.

"The technology will keep moving quickly. Businesses need to make sure their ability to respond quickly can move with it too."

Soin said a credible response also depends on honest post-incident assessment and organisational culture.

"Readiness looks less like a document and more like instinct. That starts with knowing who has the authority to contain an incident and communicate externally before it escalates. It also means testing that instinct through regular exercises involving decision-makers from across the business.

"Being honest about recovery and learning from it is just as important. Restoration needs to be proven, because a backup you have never recovered from is a hope, not a control. Organisations also need a culture where reporting a mistake is rewarded. Your people notice incidents before your systems do."

Regulators are also sharpening their focus on scams, particularly in Australia, where a new Scams Prevention Framework will place obligations on banks, telecommunications providers and digital platforms.

Heng Mok, CISO-in-Residence, Asia Pacific-Japan at Zscaler, said the regulatory changes underline that scams have become a core risk management and governance issue.

"This Scam Awareness Week, organisations should recognise that scam prevention can no longer rely on individual caution or basic security controls alone. With Australia's Scams Prevention Framework (https://www.accc.gov.au/about-us/scams-prevention-framework) set to require regulated banks, telcos and digital platforms to prevent, detect, disrupt, report and respond to scams, scam prevention is, and should be, a business resilience and governance priority.

"Zscaler research shows why this shift matters: Australia is among the top 10 most targeted countries globally for phishing activity. This comes as attackers continue to abuse legitimate AI platform features, such as shareable chats, to make malicious content appear more credible.

"MFA can no longer be treated as the final line of defence. Organisations need stronger visibility, identity-based controls and Zero Trust principles to reduce the risk of scams becoming a broader compromise."