By Resham Ganglani, CEO of Halodata Group
Something interesting happens when you sit between the boardroom and the businesses that deliver security. You hear conversations on largely the same topics, but they play out in different ways.
At the board level, the message is clear. Cybersecurity is a strategic priority; AI is likely to increase threats; and Zero Trust is the architecture of choice. Leaders across Asia are saying the right things, and they largely mean them.
When I talk to the MSPs and IT service providers doing the work at the sharp end of the cyber defense industry, the picture often looks quite different. Board intent and execution are not always aligned.
The Implementation Gap
The gap between declaring Zero Trust a priority and rolling it out is significant for many organisations. MSPs face a range of challenges, including skills shortages, vendor complexity, clients who want enterprise-grade security on SME budgets, and compliance requirements that shift faster than teams can keep up.
When a board says, “we need to implement zero trust,” they rarely appreciate what that asks of the people who will need to deliver it. Zero Trust is not a switch that you can simply flick on. It involves rearchitecting how access, identity, and trust work across an organisation, often in hybrid environments that mix legacy systems with modern cloud infrastructure.
Halodata’s vendors have the components needed to build a zero-trust model. However, the burden of assembling them into a coherent whole still falls to Internal IT teams, MSPs, and other IT companies in the channel.
AI Could Widen the Gap Further
There’s no escaping the dialogue around AI and how it’ll impact cybersecurity. And it’s pointless to try. Suffice it to say, for this article, that AI could drive an increase in threats and activity on both the adversary and defender sides of the equation. What often goes unsaid, however, is how that plays out on the ground.
Threat actors across the region use AI to generate highly convincing phishing campaigns at scale, including deepfake audio and video used to impersonate executives in what people now commonly call “CEO fraud” attacks. Attackers also use AI to scan for vulnerabilities faster than most security teams can patch. The speed advantage has shifted.
Defenders in the middle between attackers and users are dealing with the same resource constraints, training deficits, and fragmented advice they faced two years ago.
The security conversation has matured at the top of organisations. However, it has not always matured at the same pace on the ground where security is delivered.
Claude Mythos, Project Glasswing, and What It Means on the Ground
I’d be surprised if you missed all the furore around the unreleased Anthropic AI model called Mythos, and their claims about what it means for cybersecurity. They say Mythos is a frontier model capable of surpassing all but the most skilled humans in finding and exploiting software vulnerabilities.
In response to this Mythos model and the vulnerabilities they claim it discovered across all OSes, browsers, and many cloud SaaS products, Anthropic announced Project Glasswing. The intent behind Glasswing is defensive: a coalition of major technology companies using Mythos to find and fix critical vulnerabilities before attackers do.
I’ve seen responses to Mythos and Project Glasswing announcements fall into two camps. In one, there are people who think that Mythos changes everything. They posit that if an AI model can now autonomously find and chain together vulnerabilities at a scale and speed that no human team can match, then the attack surface for every organisation has just grown dramatically.
In the second camp are people who point out that finding vulnerabilities to exploit has not been a bottleneck for attackers. We already have a large catalogue of known flaws in OSes and software that remain unpatched. Having an AI model like Mythos surface more vulnerabilities doesn’t change the underlying issue that most successful attacks already exploit human weakness or a known vulnerability that a supplier hasn’t provided a patch for. Project Glasswing will put pressure on software suppliers to patch newly identified vulnerabilities. But suppliers have faced that pressure for years, and the patching cycle has remained, if you’ll pardon the pun, patchy!
I think the implications of Mythos (and other rumoured models with similar capabilities from OpenAI and Google, not to mention models from Chinese AI companies) will fall somewhere between these two camps. Mythos-class models do represent a genuine step change in what attackers could eventually find and exploit autonomously. That matters, and organisations should take it seriously.
But for MSPs and IT teams doing the real work of security delivery, the answer is not to wait for the threat landscape to stabilise before acting. Patch what you know, reduce your attack surface, verify access continuously, and train your people. No AI model, however capable, changes these security fundamentals.
The Compliance Layer Nobody Talks About
There is a third pressure point that boards often overlook when declaring cybersecurity a strategic priority: the regulatory environment.
Across Southeast Asia, the regulatory picture is fragmented. Singapore’s Personal Data Protection Act and the Cyber Security Agency’s frameworks sit alongside Malaysia’s Cyber Security Act 2024 and Bank Negara’s Risk Management in Technology guidelines, while Indonesia operates under its own evolving data protection legislation. Each market has different obligations, timelines, and consequences for non-compliance. Organisations operating across borders need to be compliant with all of them simultaneously.
For the MSPs and IT service providers working to help clients meet these requirements, this fragmentation is a practical challenge, not a theoretical one. A five-person team supporting clients in two or three countries cannot be compliance experts across every framework while also managing security architecture, incident response, and day-to-day support. Something has to give.
Boards that see compliance as a tick-box exercise, rather than a workload placed on their IT team (whether internal or outsourced to an MSP), underestimate how much that friction slows down the very transformation they are trying to drive.
What Helps Bridge This Gap
After decades of working with security vendors and channel partners across Southeast Asia, the clearest differentiator I see is not the sophistication of the tools. It is whether the people deploying them understand the business context in which they operate.
That means MSPs need more than product training. They need to connect technical capability to commercial and operational reality. It also means vendors need to consider how their solutions perform in the hands of a five-person IT team, not just in a 500-person enterprise security operation in Singapore.
It also means that trusted security partners like Halodata have a responsibility that goes beyond selling products. We sit at the intersection of vendor intent and partner capability. If we do not actively work to close the implementation gap, then who will?
In practice, that looks like helping an MSP understand not just how to deploy an identity governance solution, but how to position it commercially to a mid-market client and how to scope an implementation that fits a realistic budget and timeline. It’s about helping another organisation understand how an advanced browser security solution fits into a broader phishing defence strategy, and explaining the value to a procurement officer rather than a security architect. Good distribution is not just logistics. It is also the translation of a technology solution into business language and outcomes.
Final Thoughts
The conversation around security has moved in the right direction. Cybersecurity belongs in the boardroom, and it is increasingly finding its place there. Most boards are now asking the right questions. But strategic intent only creates value when it translates into effective action on the ground. That translation is the work.
It’s the job of professionals at the intersection of business and technology to make sure board-level leaders get the right answers. In Asia right now, there is still work to be done to make this happen.
Talk to one of our experts and discover the benefits of Halodata for your company.
It’s Time to Get Started with Halodata
Request Demo
Contact Us
Please complete this form to be contacted by one of our experts.

