HOST
HOST
APAC
LOCATION
3
EVENTS
IT and Security
INDUSTRY
APAC, December 2025 —Recorded Future, in partnership with The Ortus Club, brought together senior security, IT, and risk leaders across Jakarta, Singapore, and Bangkok for three consecutive roundtable dinners. The series was designed to surface the texture of cyber risk across three of APAC’s most consequential financial and digital economies.
A Threat Landscape That Has Outpaced Traditional Defence
Recorded Future partnered with The Ortus Club to convene a series of senior security events across Southeast Asia around a single, urgent question: how do you move from reacting to threats that have already landed, to anticipating them before they do?
The brief called for three separate events, a luncheon in Jakarta, a dinner in Singapore, and a dinner in Bangkok, each tailored to the local market while united by a single thematic thread: the shift from reactive defence to intelligence-led anticipation. Recorded Future wanted to surface the real anxieties and genuine strategies of the region’s top security minds, and to position their platform within that conversation credibly and without noise.
Three Venues, One Standard of Execution
The series opened in Jakarta with a roundtable luncheon at The Langham Jakarta, tucked inside the gleaming SCBD district. The Langham’s private dining room carried the quiet authority that the occasion demanded: natural light, and the kind of service that stays invisible until you need it. For a group of executives navigating year-end pressures and boardroom scrutiny, the setting gave the conversation room to breathe.
Singapore followed at the Artemis Grill & Sky Bar, forty floors above Market Street in the CapitaGreen tower. Floor-to-ceiling glass, the city laid out below like a circuit board. It was a venue that made the topic feel appropriately urgent. The sky bar’s private dining configuration kept intimacy despite the panoramic views.
Bangkok closed the series at The Peninsula Bangkok, one of the city’s most storied luxury properties on the banks of the Chao Phraya.The Peninsula’s private dining rooms carry a distinct Siamese warmth, with dark wood, orchids, and the river light. The team had arranged the evening to begin with cocktail arrivals before moving into dinner and discussions. For a city where personal relationships underpin professional ones, the setting did more than impress: it signalled respect.
Interested to find out how the event was shaped and the work that went behind it?
The Region’s Cyber and Risk Leadership, in One Room
Across the three evenings, attendees included Heads of Cyber Risk and Security Intelligence from major regional banks, Chief Security Officers from financial technology and cryptocurrency platforms, senior directors from central banks and regulators, and IT and digital transformation leads from insurance groups, energy infrastructure operators, shipping companies, and multinational manufacturers.
The seniority of the room mattered. These were leaders with budget authority, board-level reporting lines, and direct relationships with national cybersecurity agencies. The mix was also important. Each city brought its own regulatory pressures, its own threat surface, and its own institutional appetite for risk. The result was a conversation pitched at the level of strategy and decision-making, not implementation detail.
When Having More Threat Intelligence Feels Like Having Less Control
The central question across the three events was deceptively simple: how do you move from defending against known threats to anticipating ones that don’t exist yet?
Each city brought its own points to the theme. Jakarta took the framing that acknowledged the immediate nature of threat exposure in Indonesia’s rapidly digitising financial sector. Singapore and Bangkok ran a slightly more strategic register, reflecting the more mature institutional frameworks in those markets.
The discussion questions that anchored each session were:
And in Jakarta specifically:
The moderators were briefed to push beyond the theoretical. The threat landscape was the entry point. The exit point was always: what does this organisation actually do on Monday morning?
What Emerged Across the Region
The vocabulary of resilience has shifted, but the operating model often hasn’t.
Across all three cities, leaders described a widening gap between how they talked about cyber strategy in board presentations, intelligence-led, anticipatory, adaptive, and how their teams actually operated when an incident occurred. Organisations know what good looks like, but are still largely running incident response playbooks built for a simpler threat environment.
Scams are no longer just a consumer problem. They are becoming an enterprise liability.
In Jakarta and Bangkok especially, the conversation around scams went beyond phishing awareness training and into structural risk. With fraud growing more sophisticated across every channel, several participants noted that the perimeter has effectively dissolved. The question is no longer whether an attempt will be made, but whether the organisation will detect it before it succeeds.
Collaboration is widely endorsed and quietly avoided.
Every room agreed that shared threat intelligence makes everyone safer. Every room also revealed, in practice, that information sharing between competitors, even within the same regulated sector, remains constrained by legal caution, competitive instinct, and the absence of trusted neutral infrastructure.
AI in cybersecurity has moved from roadmap to reality, but so has adversarial AI.
Organisations are using machine learning for anomaly detection, behavioural analysis, and automated response. Threat actors are using generative AI for more convincing phishing, more targeted social engineering, and more adaptive malware. The consensus was that advantage in this race is temporary, and that the organisations who treat AI as a product feature rather than a security architecture principle will find themselves permanently one cycle behind.
Lessons in Intelligence, Collaboration, and the Cost of Staying Reactive
1. Intelligence without action is just data.
The recurring challenge across all three roundtables was the operationalisation gap: leaders have access to more threat intelligence than ever before, but the organisational workflows to translate that intelligence into real-time decisions remain underdeveloped. Closing this gap requires investment in people and process, not just tools.
2. The threat perimeter no longer exists.
From deepfake-enabled executive fraud in Bangkok to ransomware targeting legacy infrastructure in Jakarta, every room confirmed what many already suspected: the idea of securing a defined boundary has become a dangerous fiction. Resilience architecture needs to assume breach, not prevent it.
3. Sector-specific regulation is both an accelerant and a drag
Banking regulators in Indonesia, Singapore, and Thailand have all sharpened their cybersecurity expectations in recent years. Several participants noted this as a genuine forcing function for improvement, but also flagged the risk of compliance-oriented security posture, where organisations optimise for the audit rather than the threat.
4. Cross-border threat actors require cross-border responses
State-sponsored attacks and criminal networks operating across Southeast Asia do not respect national boundaries. The consensus was that the region needs deeper multilateral mechanisms for cyber coordination, and that private sector actors, including financial institutions, have a role to play in making the case to regulators.
5. Trust is the prerequisite for intelligence sharing
The Bangkok and Singapore tables both arrived at the same conclusion: the reason threat intelligence sharing remains limited is not legal or technical. It is relational. Organisations share with people they trust. Building those relationships is the work that conferences and formal frameworks cannot fully substitute for. Events like this one are, in that sense, part of the infrastructure.
6. Talent is the longest-running crisis in the room
Across all three cities, unprompted, leaders flagged the difficulty of recruiting, developing, and retaining security professionals. Automation and AI can address some of the scale problem, but the interpretive judgment required for complex threat analysis cannot yet be automated, and the pipeline of people who possess it is chronically short.
Three Cities, Three Days, One Regional Conversation
The December APAC series demonstrated something that Recorded Future’s team understood going in and had confirmed by the end: the most valuable intelligence in cybersecurity is still human. It lives in the heads of the practitioners who are fighting these battles every day, in organisations that rarely get the chance to compare notes with their peers without a vendor agenda in the room.
The series also reinforced the value of the multi-city format when client objectives require regional reach without sacrificing the intimacy that produces genuine conversation. Running Jakarta, Singapore, and Bangkok in a 72-hour window is not the easiest way to execute three events. It is the right way to tell a regional story.
Our Feasibility Studies show exactly who we can reach and how we can engage them. Using your brief, we analyse roles, regions, industries, and company size to deliver a clear, data-driven report that highlights your audience potential.