78% of Singaporeans use multi-factor authentication on personal accounts, and 60% of Singapore companies require MFA for all applications. Asia Pacific’s identity and access management (IAM) market is forecast to grow from US$5.29 billion in 2025 to US$9.55 billion by 2030. Yet stolen or compromised credentials were still the entry point for 22% of data breaches last year. The gap between where the region’s leading market sits and where its largest economies stand is the defining story of Southeast Asian identity security in 2026.
Southeast Asia’s six largest digital economies (Singapore, Malaysia, Indonesia, Thailand, Vietnam, and the Philippines) are in very different stages of IAM maturity. We compiled the latest vendor surveys, market forecasts, breach statistics, workforce studies, and each country’s data protection law to assess where the region stands. The picture that emerges is a two-tier region: one market is clearly ahead, a middle tier is being pulled forward by regulation, and the region’s biggest populations are still building the fundamentals that regulators increasingly require.
Summary
The short version: IAM maturity in Southeast Asia is mixed and rising. Singapore leads, with roughly 78% of survey respondents using MFA on personal accounts, ~60% of companies mandating MFA, and high PDPA compliance. Malaysia and Thailand sit in the middle, pushed by Malaysia’s PDPA amendments (effective June 2025) and Thailand’s PDPA full enforcement since June 2022. Indonesia, Vietnam, and the Philippines all have modern privacy laws on the books (Indonesia’s UU PDP, effective October 2024; Vietnam’s Law on Personal Data Protection, effective January 2026; and the Philippines’ Data Privacy Act 2012), but adoption and enforcement are earlier-stage.
Global adoption data confirms the direction of travel. Okta reports workforce MFA adoption reaching 70% by January 2025, with APAC the fastest-growing region at 68% (up 7 percentage points year-over-year). The markets are investing accordingly, and regulators are raising the stakes on identity controls.
Note on methodology: Metrics such as “MFA adoption” are survey-based (percentages of organizations or users) rather than measured deployment. Maturity scores (1–5) are inferred qualitatively from adoption and regulatory-compliance levels. Where no published country-level data exist, notably MFA, SSO, PAM, and Zero Trust rates for Malaysia, Thailand, Indonesia, Vietnam, and the Philippines, we flag this explicitly and label figures as author estimates.
Country-Level IAM Maturity: A Regional Divide
Assessed across MFA, SSO, Zero Trust adoption, and the regulatory environment, the six markets split into three bands:
| Country | MFA Deployment | SSO Deployment | Zero-Trust Adoption | Regulatory / Compliance | Maturity (1–5) |
|---|---|---|---|---|---|
| Singapore | – 78% of respondents use MFA on personal accounts; ~60% of companies require MFA on all apps (Yubico 2025) – National move toward phishing-resistant methods (passkeys, FIDO) | Widespread (driven by FinTech) | In pilot projects; Zero Trust reference architecture for government (CSA) | PDPA (2012, updated 2020; fines raised Oct 2022); Cybersecurity Act 2018 (amended 2024) | 4.0 (high) |
| Malaysia | Data scarce; presumed rising (author estimate) | Growing (cloud IAM uptake) | Interest rising | PDPA 2010, amended by the PDPA (Amendment) Act 2024 – DPO, breach notification and data portability effective 1 June 2025; fines raised to RM1,000,000 / 3 years | 3.0 (mid) |
| Indonesia | Many orgs begun MFA (e.g. banks); national digital ID programme underway | SSO in govt (e-ID); adoption uneven | Limited deployments | PDP Law (Law 27/2022, signed Oct 2022, effective Oct 2024) aligned with GDPR standards | 2.5 (low-mid) |
| Thailand | Moderate; BFSI adoption estimated ~70% regionally (author estimate) | Telecom/govt using SSO on major apps | Emerging; Thai government piloting ZT frameworks | PDPA enacted 2019, fully enforced June 2022; Cybersecurity Act 2019 | 3.0 (mid) |
| Vietnam | Limited public data; some MFA in tech sector | Increasing for e-government services | Low; zero-trust largely conceptual | Cybersecurity Law (2018, effective 2019); Law on Personal Data Protection (Law 91/2025, effective 1 Jan 2026, replacing Decree 13/2023) imposes strict data controls | 2.5 (low-mid) |
| Philippines | Noted MFA in BPO/finance; general awareness high | Some SSO in large enterprises | Low; Zero Trust mostly in tech multinationals | Data Privacy Act 2012 (implementing rules 2016); NIST-based National Cybersecurity Plan 2022-2028 | 3.0 (mid) |
Singapore’s lead is measurable, not just anecdotal: Yubico’s 2025 survey found Singaporeans “stand out” with 78% personal MFA usage and 60% corporate MFA mandates (versus a 48% global average). Large banks, telcos, and government agencies in Singapore run MFA and SSO as standard practice, and PDPA compliance is high.
Malaysia is catching up fastest. The PDPA (Amendment) Act 2024, phased in from January to June 2025, legally requires Data Protection Officers, mandatory breach notification, and data portability, a regulatory deadline that is now forcing real IAM investment. Indonesia’s PDP Law and Vietnam’s new PDPL imply momentum, but adoption in those markets remains uneven and enforcement bodies are still forming. Thailand’s PDPA only took full effect in 2022, so many Thai organizations remain on a transitional maturity curve. The Philippines has strong awareness in BPO and finance but broad adoption lags.
Our take: The two-tier divide is not a technology problem: it is a regulatory one. Singapore’s lead correlates directly with a decade of PDPA enforcement and sector guidance from MAS and CSA. Malaysia’s mid-pack position is climbing because the 2025 amendments gave companies a legal deadline, not a suggestion. Where enforcement is real, IAM maturity follows. Where it is still forming (Indonesia’s Lembaga PDP has yet to be formally established), budgets and behaviour lag. The fastest way to close the gap is not another security tool; it is a regulator that starts issuing decisions.
The Adoption Gap: MFA, SSO, PAM, and Zero Trust
MFA is the most quantifiable indicator. Okta reports ~70% workforce MFA adoption globally (January 2025), with APAC the fastest-growing region at 68% (up 7 percentage points year-over-year). Sector-level data from Okta show where the region’s own verticals are likely headed:
| Sector | MFA Adoption (Okta, Jan 2025) |
|---|---|
| Technology | 87% |
| Healthcare & Pharmaceuticals | ~74% |
| Public Sector / Government | ~69% |
| Retail | ~52% |
| Transport & Warehousing | ~42% |
We estimate Malaysia and Thailand at 50–60% MFA (large banks drive the higher end), with Indonesia and the Philippines lower: no published country-level statistics exist for these markets (author estimate). The payoff is well established: Microsoft research shows MFA blocks over 99.9% of account-compromise attacks and reduces compromise risk by 99.22% (98.56% even where credentials have already leaked). Credential-based breaches cost organizations an average of ~US$4.67M (IBM 2025).
SSO: Few public statistics exist, but SSO is common in enterprise apps across APAC: we infer high uptake in Singapore’s and Malaysia’s multinationals and government, moderate elsewhere. Many SEA banks and universities now run SAML-based SSO, and enterprises are shifting from legacy directories to cloud IAM suites (IDaaS).
PAM: Deployment remains partial. The GuidePoint Security–Ponemon Institute 2025 State of IAM Maturity Report found 42% of organizations run PAM on a dedicated platform, 27% have it integrated with other IAM systems (~69% have PAM in some form), and 31% still manage privileged access manually. In SEA, PAM is a growing focus in banking and telecom but remains among the least-deployed IAM controls.
Zero Trust: Formal adoption is nascent. Gartner found 63% of organizations worldwide have fully or partially implemented a zero-trust strategy (2023 survey) and predicts only ~10% of large enterprises will have a mature, measurable zero-trust program by 2026. Singapore (CSA reference architecture) and Malaysia have official guidance and pilots. We estimate only ~10–20% of SEA firms have any zero-trust components in place: author estimate, no regional data published.
Provisioning: Many SEA firms still onboard and offboard users manually. The trend is toward automation via cloud IDaaS: some Singapore and Malaysian banks now integrate HR systems with IAM for automatic provisioning. Automating provisioning reduces orphan accounts, a key risk factor in breaches.
Trends: Adoption is compounding quickly. Okta’s data show workforce MFA rising from ~35% in early 2020 to 70% by January 2025, with the COVID-19 shift to remote work driving a 15-percentage-point jump between February and March 2020 alone. Phishing-resistant and passwordless methods (passkeys, FIDO2, biometrics) are the fastest-growing category, up 63% in a year (8.6% to 14.0% of sign-ins). Cloud-based IAM (IDaaS) is increasingly preferred over on-premises, consistent with the APAC market’s 12.5% CAGR.
Regulatory Pressure Is Driving IAM Investment
Every major SEA economy now has a data protection law, and each one maps to identity controls:
- Singapore: PDPA (2012, updated 2020). Financial penalties were raised in October 2022 to S$1 million, or 10% of annual turnover in Singapore where turnover exceeds S$10 million. The PDPC’s Data Protection Trustmark programme signals strong DPO and access-control maturity among major firms, though SMEs lag.
- Malaysia: PDPA (Amendment) Act 2024, phased in from January to June 2025: mandatory Data Protection Officers, breach notification to the Commissioner within 72 hours (and to affected data subjects within seven days), data portability, and fines raised to RM1,000,000 / 3 years.
- Indonesia: UU PDP (Law 27/2022, signed October 2022, fully effective October 2024), aligned with GDPR: administrative fines up to 2% of annual revenue, breach notification within 3×24 hours (Article 46), and a mandatory DPO for large-scale processing. The dedicated supervisory authority (Lembaga PDP) had yet to be formally established; interim enforcement sits with Komdigi.
- Thailand: PDPA B.E. 2562 (gazetted May 2019, fully enforced June 2022): administrative fines up to 5 million baht and criminal penalties up to 1 year / 1 million baht.
- Vietnam: Law on Personal Data Protection (Law 91/2025), effective 1 January 2026, replacing Decree 13/2023 with implementing Decree 356/2025: a decisive regulatory shift for any company processing Vietnamese personal data.
- Philippines: Data Privacy Act 2012 (IRR 2016); the National Privacy Commission enforces compliance under the NIST-based National Cybersecurity Plan 2022–2028.
Beyond privacy law, sector regulators are tightening identity requirements: MAS technology-risk management guidelines in Singapore and Bank Negara Malaysia both mandate strong (multi-factor) authentication for banking. These drivers create divergent maturity: highly regulated BFSI and government lead, commercial sectors await enforcement. Analyst commentary confirms regulatory pressure is the #1 driver of IAM projects in SEA.
Compliance readiness: No standardized readiness index exists for the region. Consultancy assessments before Malaysia’s 2025 changes suggested a large share of Malaysian organizations were not fully compliant (third-party assessments commonly flag ~60% as not fully PDPA-compliant). Overall, we estimate <50% of organizations across SEA fully meet national privacy-law requirements (author estimate), with the rest in progress, often driven by international data-transfer demands.
Our take: If you manage identities in Southeast Asia, your regulator is your roadmap. The countries with enforceable, active laws (Singapore, now Malaysia, increasingly Vietnam) are the ones where IAM budgets get approved. The risk is that the markets with the largest user bases (Indonesia, Vietnam, Philippines) treat their new laws as a future problem. The Lembaga PDP and Vietnam’s new authority will eventually start issuing decisions, and the organizations that waited will be the ones paying retroactive compliance costs.
Incidents and Risk Indicators
Identity is the attack surface. Globally, the GuidePoint Security–Ponemon Institute 2025 report found 75% of cyberattacks leveraged identity-based threats. Verizon’s DBIR 2025 confirms stolen or compromised credentials were an initial access vector in 22% of breaches, the leading single vector, and 88% of web application attacks used stolen credentials.
In Southeast Asia, the pattern shows up in both headline incidents and quiet statistics:
- Singapore’s 2018 SingHealth breach exposed 1.5M patient records (including medication records of 160,000 patients) and remains the region’s cautionary tale.
- Malaysia’s online-fraud cases nearly doubled from 17,668 (2019) to 34,495 (2023), and ASEAN breach-related economic losses exceeded US$3 million by mid-2023 (up from US$2.87 million in 2022); Singapore lost over US$385.6 million to cyberscams in H1 2024 (Positive Technologies).
- UNODC (October 2024) estimated US$18–37 billion in losses from scams targeting East and Southeast Asia in 2023 alone.
The human gap is just as binding. Fortinet’s 2025 skills-gap report found 67% of organizations say the shortage creates additional cyber risk, and 54% cite lack of security skills as a leading cause of breaches. ISC2 puts the global cybersecurity workforce gap at 4.8 million (2024), with Asia-Pacific at 2.6 million (2023) against a workforce of ~960,000. IAM specialists (identity architects, provisioning engineers) are especially hard to find.
Budget reality: SEA security budgets average roughly 10–12% of IT spend (author estimate; no SEA-specific benchmark published). Globally, IANS Research/Artico Search put security budgets at 10.9% of IT budgets in 2025 (down from 11.9% in 2024), with budget growth slowing to 4% (versus 8%). Within cybersecurity budgets, IAM typically receives an estimated 5–15% (author estimate). Slower budget growth risks delaying IAM projects precisely when regulation is accelerating.
What You Should Do
Six priorities based on our assessment of the regional maturity gap:
1. Mandate MFA Everywhere
Given Microsoft research showing MFA blocks over 99.9% of account-compromise attacks, treat MFA as the baseline for every internal and external login. Prioritize phishing-resistant methods (FIDO keys, passkeys, biometrics) over SMS one-time passwords, which remain phishable.
2. Automate Identity Governance
Implement role-based access with regular entitlement reviews, and automate provisioning and deprovisioning so departing staff and contractors lose access immediately. Orphaned and over-privileged accounts are a leading breach factor.
3. Run Zero Trust Pilots
Mature organizations, especially in BFSI and government, should start with micro-segmentation and continuous authentication in critical domains rather than treating Zero Trust as an all-or-nothing programme.
4. Make Compliance Readiness a Project
Every SEA organization processing personal data should appoint a DPO, conduct Data Protection Impact Assessments, and build breach-notification workflows: the 72-hour clock in Malaysia and Indonesia’s 3×24-hour rule do not wait for you. If your company handles Vietnamese personal data, the new Law on Personal Data Protection (effective January 2026) is the immediate priority.
5. Invest in IAM Skills
With a global workforce gap of 4.8M (ISC2 2024), recruit and train identity specialists, and consider managed services for provisioning, access reviews, and PAM operations. Upskilling existing IT staff on IAM tooling is the fastest lever.
6. Benchmark Your Maturity Regularly
Conduct periodic IAM maturity assessments against a CMMI-style scale. Regional data is scarce: the more organizations publish adoption metrics, the better the baseline for everyone. Track MFA/SSO uptake, incident rates, and audit findings year over year.
Methodology & Sources
This assessment synthesizes the latest vendor surveys, market forecasts, breach statistics, workforce studies, analyst guidance, and each country’s data protection law. Key sources:
- Okta, Secure Sign-in Trends Report 2025: 70% global workforce MFA (Jan 2025); APAC 61%→68%; industry MFA rates; MFA growth 35% (2020)→70% (2025). https://www.okta.com/newsroom/articles/secure-sign-in-trends-report-2025/
- MarketsandMarkets, Asia Pacific IAM Market: Forecast to 2030: US$5.29B (2025) → US$9.55B (2030), 12.5% CAGR. https://www.marketsandmarkets.com/Market-Reports/asia-pacific-identity-access-management-market-35255491.html
- Yubico, 2025 Global State of Authentication Survey: 78% personal MFA (Singapore); 60% corporate MFA mandates vs 48% global average. https://www.yubico.com/resource/global-state-of-authentication-survey-2025-perception-vs-reality/
- Verizon, 2025 Data Breach Investigations Report (DBIR): credentials the leading initial access vector (22% of breaches); 88% of web-app attacks via stolen credentials. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf
- IBM, Cost of a Data Breach Report 2025: global average US$4.44M; compromised credentials US$4.67M. https://www.ibm.com/reports/data-breach
- Microsoft Security (2019) and Microsoft Research (2023): MFA blocks 99.9% of account-compromise attacks; 99.22% compromise-risk reduction (98.56% with leaked credentials).
- Gartner (Jan 2023; Q4 2023 survey): ~10% of large enterprises with mature zero-trust programs by 2026; 63% of organizations with fully or partially implemented zero-trust strategies.
- Malaysia PDPA (Amendment) Act 2024: phased commencement 1 Jan–1 Jun 2025; DPO, 72-hour breach notification, data portability, RM1,000,000/3-year fines. https://www.pdp.gov.my
- ISC2 Cybersecurity Workforce Study: global gap 3.4M (2022), 4.0M (2023), 4.8M (2024); APAC gap 2.6M (2023), workforce ~960,000.
- Fortinet, 2025 Global Cybersecurity Skills Gap Report: 67% say skills shortage creates additional risk; 54% cite lack of skills as a leading breach cause.
- GuidePoint Security / Ponemon Institute, State of IAM Maturity Report 2025: 75% of cyberattacks leveraged identity-based threats; PAM deployment (42% dedicated / 27% integrated / 31% manual).
- IANS Research / Artico Search, 2025 Security Budget Benchmark Report: security spend 10.9% of IT budget (down from 11.9%); budget growth 4% vs 8%.
- Positive Technologies, Cybersecurity threatscape in Southeast Asia (Mar 2025): Malaysia fraud 17,668→34,495; ASEAN breach losses >US$3M; Singapore US$385.6M cyberscam losses (H1 2024). https://global.ptsecurity.com/en/research/analytics/cybersecurity-threatscape-in-southeast-asia/
- UNODC (Oct 2024): US$18–37B scam losses across East/Southeast Asia in 2023.
- Vietnam Law No. 91/2025/QH15 (PDPL) and Decree No. 356/2025/NĐ-CP: effective 1 January 2026, replacing Decree 13/2023/NĐ-CP. https://congbao.chinhphu.vn; thuvienphapluat.vn
- Singapore CSA and Ministry of Health: Cyber Essentials/Cyber Trust marks (SS 712:2025); SingHealth 2018 breach disclosures.
Country-level MFA, SSO, PAM, and Zero Trust figures marked as estimates are inferences from vendor and market data; where no published data exist, we label them as author estimates rather than presenting them as measured statistics.
Referensi: The Southeast Asia IAM Maturity Index: 2026 Benchmark Report oleh Adaptist Consulting.
Analysis conducted by Adaptist Consulting, August 2026. For questions about methodology or how these findings apply to your organization’s identity infrastructure, contact us.
