CFOtech India - Technology news for CFOs & financial decision-makers
India
More budget, more breaches: The ROI problem Asia Pacific can no longer ignore

More budget, more breaches: The ROI problem Asia Pacific can no longer ignore

Tue, 22nd Sep 2026 (Today)
Andrew Kay
ANDREW KAY Senior Director, Systems Engineering, APJ Illumio

When the Qilin ransomware group hit Asahi in late September 2025, the stolen data of nearly two million people was almost a footnote. The real damage was played out on the production line. Ordering, shipping, and logistics systems went dark, forcing Asahi to shut most of its 30 factories across Japan. Staff reverted back to fax machines and handwritten forms. While brewing restarted within a week, distribution was down for close to two months, as shelves emptied nationwide.

Sit with that for a second. The intrusion was the incident. The downtime was the catastrophe.

That gap, between "we were breached" and "we couldn't operate," sits at the heart of a problem businesses have spent a decade avoiding. Cybersecurity spending increases year after year. More tools, bigger budgets. Yet the only figures climbing faster than the investment are the number of breaches, their scale, and the cost of the fallout. That pattern should be triggering hard questions in every boardroom across the region. The conversation is happening, but not nearly fast enough.

The data the industry would rather not discuss

The numbers tell an uncomfortable story. IDC puts Asia-Pacific security spending at US$39.5 billion in 2026, climbing toward US$52 billion by 2029. And IBM's research showed ASEAN data breach costs rose to US$3.67 million, extending a climb that hit an all-time high the year before. The bill keeps going up in this region.

That doesn't mean everything we do is wrong. Plenty of controls work and quietly prevent worse incidents. But if a director asks why a decade of accelerating spend hasn't bent the breach curve, 'it would be worse without it' won't hold. With regulators, insurers, and investors across APAC scrutinising outcomes, that answer has run its course.

Three reasons the old model is broken

First, we measure activity, not outcomes. Tools deployed, alerts raised, vulnerabilities patched, training completed. All of it shows what the team is busy doing. None of it shows whether the organisation is safer. Proving a breach didn't happen because of your program is close to impossible, so we counted what we could. Fund a team on activity and you get more activity, not better results.

Second, the model is built around prevention. For fifty years the promise behind nearly every product has been 'deploy this and the bad thing won't happen.' That made sense when a breach was cheaper and serious attacks were rarer. Today the cost of one getting through has exploded, and Asahi shows why. A model designed to stop everything has no plan for the moment something slips past.

Third, more tools have added complexity without coverage. A large enterprise now runs 50 to 100 security products, each bought to close a gap, yet the gaps keep widening. Tools that don't talk to each other, signals nobody can correlate, and teams with no time to chase every alert don't create protection. They create the illusion of it. Attackers exploit the seams while defenders drown in sprawl.

From preventing breaches to pricing resilience

The hardest question I get from CISOs is how to quantify something that didn't happen. You can't, so stop trying. Quantify resilience instead.

Measure the cost of incidents rather than their absence. When something does occur, and it usually does, the numbers are right there. How long systems were down, what recovery cost, what the downtime did to the business, what the regulatory exposure looked like. Those figures are real and can be used to model future impact.

For example, if segmentation shrinks an incident's blast radius by 60 percent, that's a measurable cut in expected loss. If response drops containment from 48 hours to four, so is that.

Then anchor the conversation in examples boards recognise. Asahi has put a number on it, roughly five billion yen, about US$31 million in lost revenue, plus a delayed earnings report and market share handed to rivals. That is a benchmark boards understand. Show how your architecture would have turned weeks of paralysis into hours of disruption instead of weeks, and you have a case no board can dismiss. Keep a library of these, because directors trust concrete precedent over abstract risk frameworks.

Finally, reframe the discussion around expected loss reduction. Boards already speak the language of insurance. Every organisation carries an expected annual loss from cyber, drawn from breach probability, frequency, and cost. Judge each investment by how much it lowers that number relative to its price. It beats proving a negative, and it usually exposes which big line items aren't earning their keep.

The clock is running

A decade of rising spend has produced a difficult reality: spending more has not translated into fewer breaches or lower losses. That doesn't mean security investments have failed. It does mean organisations need a better way to demonstrate value.

The future discussion isn't about how many tools you bought or how many alerts you closed. It's about whether you can limit disruption, reduce loss, and keep the business operating when an incident occurs.

Every organisation in this region should expect its own Asahi moment. The question is whether it becomes a temporary disruption or a business crisis.