It is not easy to imagine that our online activities carry intensifying and proliferating risks. Scam networks in mainland Southeast Asia that have preyed on many thousands of hapless citizens worldwide and thereby plagued the Asean region are just one of these risks. More potent are the cyber operations perpetrated by government and non-government actors against each other and against individual societies. For Southeast Asia, preempting, mitigating and managing cybersecurity challenges ultimately have to rely on state-society relations and intergovernmental cooperation and collaboration across the Asean region.
This message came through loud and clear at the recent Fourth Digital Defence Symposium organised by the ADMM Cybersecurity and Information Centre of Excellence (ACICE) in Singapore. Future conflicts will not simply be fought over sovereignty and territory but will increasingly be waged over data and information. This may sound obvious in the age of artificial intelligence (AI), but the implications are profound.
Data has become the lifeblood of national security. Cyberattacks no longer target only military networks. They can cripple hospitals, banks, ports, airports, power grids, telecommunications systems, and financial markets. Undersea communication cables, cloud servers and data centres have become strategic assets as critical as naval bases and airfields. The distinction between physical and digital security is fast disappearing.
Data transcends borders. Unlike conventional military threats, cyber threats ignore geography, sovereignty, and jurisdiction. They also blur boundaries between civilian and military sectors and between governments and private industry. An attack on a commercial cloud provider or telecommunications company may ultimately compromise national security. Conversely, protecting critical infrastructure has become a shared responsibility among governments, businesses and technology companies.
AI is accelerating this transformation. Military commanders used to make operational decisions over days or weeks. AI is compressing decision cycles into minutes or even seconds. It's scary, but it's happening. The war in Ukraine demonstrates this new reality. Drones are intercepted, their memory chips immediately analysed, operating frequencies identified, and countermeasures deployed almost in real time. The big advantage belongs not to whoever possesses the most advanced technology, but to whoever can collect, analyse and act on information the fastest.
Equally striking is the shift in thinking about cybersecurity itself. Traditionally, the objective was to build impenetrable digital defences. That assumption is now giving way to a more sobering reality because every network will eventually be penetrated and compromised. The challenge is therefore no longer preventing every breach but ensuring resilience, detecting attacks quickly, limiting damage, restoring operations rapidly, and adapting all the time.
Yet the symposium's most important lesson had little to do with technology. Speakers kept returning to the same conclusion that no country can defend cyberspace alone. Cybersecurity depends fundamentally on trust. Governments must trust one another enough to share intelligence, while militaries must become interoperable. State agencies must be able to work with private industry because much of the critical infrastructure they seek to defend is privately owned. Universities and think tanks must contribute research and policy ideas, while professional exchanges and trusted networks become as important as firewalls and encryption. Even protecting undersea cables that carry 95% of internet traffic requires close cooperation across jurisdictions because ownership, maintenance, and operational responsibility are widely dispersed.
Thailand and Asean more broadly thus face a more difficult strategic environment. Internal divisions over Myanmar remain unresolved, while the recent Thai-Cambodian border dispute has exposed new political fault lines and the South China Sea continues to divide member states according to their respective national interests. Meanwhile, strategic competition between the United States and China is intensifying across the Indo-Pacific.
Precisely because cyber threats disregard national borders, no Asean member state can protect itself acting alone. Malware and ransomware are borderless, and disinformation campaigns spread instantly across borders and social media platforms. Attacks on financial systems, telecommunications networks or energy infrastructure in one country can rapidly affect Asean neighbours. Digital vulnerability has thus become a regional vulnerability.
This is Asean's emerging cybersecurity paradox. The 11-member grouping appears more divided but also indispensable. The digital age makes regional cooperation not just a good idea but an essential one. No Southeast Asian state wants to be forced into choosing permanently between Washington and Beijing. At the same time, none possesses sufficient cyber capabilities to confront increasingly sophisticated digital threats independently. Asean therefore becomes more valuable not despite its imperfections but because it remains the region's only inclusive platform capable of forging and fostering habits of cooperation across political differences.
Technology will continue evolving at warp speed while geopolitical rivalry is likely to worsen. Together, these two trends create a growing need for Asean institutions and mechanisms that can sustain cooperation even when political relations become strained. AI itself can also become part of the solution rather than part of the risks.
One opportunity lies in overcoming Asean's linguistic diversity. Much valuable research produced by regional institutions reaches only English-speaking audiences. AI-powered translation now makes it possible to disseminate policy papers, technical studies, and best practices rapidly into Thai, Bahasa, Vietnamese, Khmer, Lao, Burmese, and Tagalog, among other dialects in the region. Instead of limiting cybersecurity knowledge to a relatively small community of specialists, Asean could dramatically broaden participation among policymakers, academics, journalists and civil society throughout the region.
This may sound like a modest initiative, but stronger regional awareness often begins with better regional communication. In addition, promoting trust is paramount. Trust cannot be programmed into algorithms or purchased through sophisticated software. It must be cultivated patiently through dialogue, transparency, goodwill, reciprocity, and sustained cooperation.
As geopolitics becomes more competitive and technology more disruptive, Asean's cybersecurity challenge will not simply be acquiring better technology. It will be building stronger ways of cooperation among member states that increasingly need one another even as they disagree on many issues.
That is Asean's paradox today. The Southeast Asian bloc looks more politically troubled, but in an era when cyber threats ignore borders, and AI is transforming the nature of security itself, Asean also appears ever more necessary.