SAPPORO, Japan – August 4, 2026 — As frontier Artificial Intelligence (AI) accelerates the sophistication and scale of cyberattacks, cybersecurity experts are warning that ASEAN must urgently address several structural weaknesses in its cybersecurity policies to protect the region's critical infrastructure.
Speaking at the Critical Information Infrastructure Protection (CIIP) Meeting in Sapporo, Lito Averia, President of PH-CERT and a leading member of the ASEAN-Japan Cybersecurity Community Alliance (AJCCA), identified four critical policy gaps that ASEAN governments should prioritize to prevent potentially devastating cyber incidents affecting essential services and regional digital connectivity.
"Cyber threats are no longer confined within national borders," Averia said. "As ASEAN becomes increasingly interconnected through digital infrastructure, our weakest links can quickly become regional risks. Policymakers need to act now before these gaps are exploited by increasingly sophisticated threat actors empowered by frontier AI."
Averia highlighted Operational Technology (OT) and Industrial Control Systems (ICS) as one of the region's most pressing cybersecurity concerns. These systems operate essential services such as power grids, water treatment facilities, manufacturing plants, transportation networks, and energy infrastructure.
Despite their critical role, no ASEAN country currently has legislation that provides dedicated legal treatment or comprehensive technical cybersecurity standards specifically for OT and ICS environments.
"While many cybersecurity regulations focus on traditional IT systems, OT environments remain largely under-protected," Averia explained. "Yet these are the systems that directly control physical infrastructure. A successful attack could have real-world consequences affecting public safety, national security, and economic stability."
A second critical concern is the security of submarine communication cables and their landing stations, which carry more than 99% of ASEAN's intercontinental internet traffic.
According to Averia, existing regulations largely concentrate on restoring connectivity after physical cable damage, but insufficient attention has been given to protecting these strategic assets from cyber threats.
"The cybersecurity gap is significant," he noted. "In many ASEAN countries, submarine cables and their landing stations have not yet been formally designated as Critical Information Infrastructure (CII). Without that classification, they may not receive the level of cybersecurity protection and regulatory oversight they deserve."
As geopolitical tensions and cyber sabotage risks continue to increase globally, securing these digital lifelines has become an urgent regional priority.
The third challenge lies in the absence of mandatory cross-border cyber incident reporting mechanisms across ASEAN.
With regional economies increasingly relying on interconnected payment systems, cloud platforms, digital government services, and cross-border digital trade, a cyber incident originating in one country can rapidly affect neighboring nations.
However, Averia observed that there is currently no legal obligation requiring countries to promptly notify neighboring states when significant cyber incidents occur.
"This creates systemic risk," he explained. "Without timely information sharing, neighboring countries may lose valuable time to prepare defensive measures, allowing attacks to spread more easily across borders."
He encouraged ASEAN policymakers to establish formal regional notification frameworks that would strengthen collective cyber resilience and enable faster coordinated responses.
Finally, Averia warned that the explosive growth of Internet of Things (IoT) devices is dramatically expanding ASEAN's cyber attack surface.
Driven in part by the ASEAN Smart Cities Network, which comprises 38 cities as of January 2026, connected devices are becoming deeply integrated into transportation, utilities, healthcare, public safety, and urban management systems.
Yet many of these devices continue to be deployed without minimum cybersecurity requirements.
"The number of connected devices is growing much faster than our ability to secure them," Averia said. "Without baseline security standards for IoT manufacturers and operators, these devices could become entry points for attacks against larger critical infrastructure ecosystems."
He called for region-wide security certification requirements and minimum cybersecurity standards for IoT devices before deployment.
Also attending the meeting, Rudi Lumanto, Chairman of the ASEAN-Japan Cybersecurity Community Alliance (AJCCA), emphasized that collaboration has become the defining factor in successfully addressing today's increasingly complex cyber threats.
"Cybersecurity is no longer a challenge that any organization or country can solve independently," Lumanto said. "Collaboration has become one of the most critical factors for success and sustainable growth. As cyber threats continue to evolve—particularly with the emergence of frontier AI—we must strengthen cooperation among governments, critical infrastructure operators, academia, industry, and international partners."
He added that trusted information sharing, joint capacity-building initiatives, coordinated incident response, and public-private partnerships are essential to building a resilient digital ecosystem across ASEAN and Japan.
The discussions at the CIIP Meeting reinforced a shared understanding among participants that while frontier AI offers transformative opportunities, it also introduces unprecedented cybersecurity challenges. Addressing the four policy gaps identified by Averia—OT/ICS protection, submarine cable security, cross-border incident reporting, and IoT security standards—will be critical to safeguarding ASEAN's digital future.
As ASEAN accelerates its digital transformation, experts agreed that proactive policymaking, regional cooperation, and collective preparedness will determine whether the region can stay ahead of increasingly intelligent and borderless cyber threats