A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Minor Hotels
AI: A Double-Edged Sword for Cybersecurity Professionals


Artificial intelligence, or AI, has, by 2025, become a transformative force in redefining cybersecurity operations in Southeast Asia. What was recently considered an emerging threat, AI is now a core component of enterprise security approaches as well as attacker toolkits. It represents both a strong asset and a pressing challenge to cybersecurity professionals.
AI solutions on the defense side are greatly strengthening detection and response capabilities. The power lies in the capacity to consume and analyze huge datasets in realtime far greater than human capacity, creating possibilities to detect anomalies, zero-day exploits, and lateral movement in networks ahead of time. Machine learning algorithms are able to identify slight behavioral deviations within user behavior, which makes detection of attacked accounts or insider threats possible sooner.
AI’s predictive capabilities are also being harnessed to build models that anticipate attacks based on historical data and threat intelligence feeds. This allows security teams to move from reactive to proactive postures, implementing controls before incidents occur. In many cases, these systems outperform legacy rule-based solutions and manual processes, which are still in use across many organizations in the region.
However, the offensive use of AI is advancing just as quickly. Threat actors are leveraging AI for automated reconnaissance, crafting hyper-personalized phishing campaigns, and deploying polymorphic malware that continuously evolves to evade detection. Deepfake technologies are being used in social engineering attacks, including impersonating executives in voice or video to authorize fraudulent transactions. For cybersecurity professionals, distinguishing real from synthetic content is becoming increasingly difficult.
Complicating matters further, AI systems are data-dependent and often operate with limited transparency. Once personal or sensitive data is fed into a large model, especially one trained on scraped public datasets, control over that data is effectively lost. This poses new privacy and compliance risks, particularly under regulations such as the PDPA, GDPR, and other regional frameworks. Generative AI can also infer sensitive relationships and behavioral profiles from non-identifiable data points, leading to re-identification risks. For cybersecurity teams, this means that even anonymized datasets may no longer be sufficient to mitigate privacy threats.
Key action points for cybersecurity leaders in this new landscape include:
• Deploying AI responsibly: Ensure model transparency, data minimization, and alignment with privacy-by-design principles.
• Securing the training pipeline: Protect datasets used in AI model development from tampering or leakage.
• Hardening infrastructure against AI-enabled attacks: Update phishing detection, anomaly monitoring, and endpoint protection with AI-aware capabilities.
• Enhancing workforce readiness: Provide targeted training for employees to recognize AI-driven threats, including deepfakes and synthetic phishing.
”As AI continues to evolve and data fuels both innovation and exploitation, cybersecurity professionals must lead the conversation on ethical, secure, and resilient deployment.”
• Strengthening governance: Define cross-functional accountability for AI-related risks across cybersecurity, legal, compliance, and data teams.
As AI continues to evolve, the cybersecurity function must do more than just keep pace. It must lead the conversation on ethical, secure, and resilient deployment. In a world where data fuels both innovation and exploitation, cybersecurity professionals must act as both engineers and guardians of trust.