Research Report
September 2024
The CISO Wave of Change report is based on a pulse survey conducted in April and June 2024 by Factor

Singapore technology leaders are not asking for more control. They are asking for control that can be operated, evidenced and scaled at business speed. That is the central finding of Factor's Wave of Change survey, a quarterly Tech Decision Maker survey extract built on 102 responses from senior CIO, CTO and security leaders in Singapore, published in June 2026.
The research catches a market being asked to protect, simplify and accelerate at the same time: maintain assurance, resilience and confidence as environments become more distributed, reduce the drag created by platform overlap, manual workflows and fragmented evidence, and embed controls into delivery so business change moves faster without creating unmanaged risk. Across the survey, teams have invested in capability, but the operating model has not caught up. The opportunity now is to make control easier to operate, evidence and scale.
102
Senior CIO, CTO and security leaders surveyed in Singapore
50%
Name Governance, Risk & Leadership as the single challenge that would unlock serious momentum
25%
Say GenAI launch activity is forcing a strategy rethink
30%
Report controls integrated into delivery pipelines
30%
Describe their IAM maturity as mostly unmanaged
24%
Cite manual steps, the leading blocker to faster, safer response
When Factor asked which areas are demanding the most focus right now, leaders ranked Security Strategy & Leadership highest at 27%, followed by Risk Management & Governance at 24%. Data Security & Privacy sits at 17% and Threat Detection & Response at 14%, with Identity & Access Management and Cloud & SaaS Security at 13% each. Security Culture & Capability (12%), Application & DevSecOps (11%), Security Architecture & Operations (11%) and Third-Party & Supply Chain Risk (10%) complete the picture (valid n = 107).
A companion question sharpens the signal. Asked what single challenge, if solved, would unlock serious momentum, 50% of valid responses in Factor's survey named Governance, Risk & Leadership. Data, Privacy & Identity Control followed at 29%, Threat Detection & Operations at 24% and Secure Technology & Cloud Enablement at 23%, with People, Culture & Capability at 12% and Third-Party & Supply Chain Assurance at 10% (valid n = 107).
The responses show a clear tension: governance dominates attention, but progress depends on operating speed. Viewed together, the results show that leaders are not treating control as a narrow technical function. They are trying to align accountability, decision rights and operating discipline across a broader technology environment.

Areas demanding the most focus now, alongside the single challenge leaders say would unlock serious momentum. Factor survey, valid n = 107 for both questions.
Asked which recent shifts are forcing a rethink of strategy, leaders pointed to forces beyond the traditional technology function. GenAI launches top the list, cited by 25% of valid responses in Factor's survey. Board pressure follows at 19%, with leadership change at 17% and regulatory reform at 16%. Cloud expansion (14%), M&A activity (12%), SaaS adoption (11%) and audit findings (10%) round out the reprioritisation picture (valid n = 183).
This signals that control priorities are now being shaped by business change, AI experimentation and governance scrutiny, not only by the threat landscape. The 2026 agenda is being reset from outside the security function as much as from within it.

Recent shifts forcing a strategic rethink, led by GenAI launches at 25%. Factor survey, valid n = 183.
Why this matters
GenAI is the strongest signal because it turns control from a defensive discipline into an enablement requirement. Leaders need confidence, assurance and accountability without slowing experimentation.
Asked where they would deploy 10% more capability tomorrow, leaders pointed to the operating layers that make control repeatable. Access governance, DevSecOps enablement and security automation each sit at 20% in Factor's survey, followed by SOC uplift and Zero Trust uplift at 16%. Cloud controls (12%) and threat detection tuning (10%) rank lower but remain meaningful (valid n = 183).
The distribution shows that leaders see the greatest value in capabilities that reduce manual governance, embed control earlier and improve response scalability. The strongest investment signals sit where identity, automation, DevSecOps and response capability intersect. This is not a pure tooling agenda; it is an operating-capability agenda, less about buying another platform and more about reducing manual governance, embedding controls earlier and scaling response.

Capability deployment priorities: access governance, DevSecOps enablement and security automation each at 20%. Factor survey, valid n = 183.
Asked by Factor about the biggest blockers to faster, safer response, leaders pointed squarely at the workflow layer. Manual steps lead at 24%, followed by staffing limits at 19%, disconnected tools at 17% and delayed handoffs at 16%. False positives and inconsistent telemetry each sit at 13%, with limited context at 11% (valid n = 138). The issue is not lack of signal; it is the difficulty of turning signal into coordinated action.

Blockers to faster, safer response: manual steps, staffing limits, disconnected tools and delayed handoffs lead. Factor survey, valid n = 138.
The maturity picture in Factor's research reinforces the problem. Defined runbooks with some coordination lead the threat detection and response approaches at 24%, but tested, automated and continuously improved approaches sit at 21%, exactly equal to ad hoc and reactive approaches. Manual workflows with gaps account for 19% and integrated live correlation for 17% (valid n = 159). Workflow orchestration is just as mixed: 29% say some alerts flow into action, while fully orchestrated and mostly manual, siloed environments both sit at 25%, and partially orchestrated response accounts for 23% (valid n = 159).
This is a market caught between formalisation and automation. Teams may have alerts, runbooks and tools, but response remains fragile when orchestration depends on people stitching systems together. Many teams have the components of maturity; few have consistent end-to-end flow.
Why this matters
Faster response comes from reducing the distance between detection, context, decision and action. Manual steps and handoffs are where speed and confidence leak away.
Asked how unified visibility is across environments, most of Factor's respondents described a middle ground: visibility has improved, but traceability remains inconsistent. The largest share, 29%, report some unification across cloud and SaaS, while 26% remain fragmented tool-by-tool. Mostly unified for key risk zones and fully unified real-time telemetry each sit at 24% (valid n = 159).
Investigation readiness shows the same shape in Factor's data. Centralised evidence gathering leads at 30%, followed by some tool-level correlation at 26%, while integrated forensics and traceability and manual log pulls per system both sit at 23% (valid n = 158). Many teams have moved beyond fully manual investigation, but few have achieved consistent, cross-environment traceability. Without unified telemetry and traceability, every incident carries additional time cost, confidence cost and evidence burden.

Visibility unification across environments and incident investigation readiness. Factor survey, valid n = 159 and n = 158.
Asked in Factor's Wave of Change survey where platform sprawl or duplication creates drag, leaders spread the load widely. Awareness tooling, policy controls and reporting tools each sit at 20%, with the identity stack close behind at 19%. The endpoint stack accounts for 13%, and the threat detection stack and cloud tooling for 10% each (valid n = 171). The tools intended to improve awareness, evidence and decision-making are increasingly creating complexity of their own.
Consolidation intentions follow the drag. Orchestration platforms top the list of areas leaders told Factor they are most likely to consolidate or simplify this year at 22%, followed by email at 18%, detection and response at 17% and reporting tools at 16%. Endpoint (14%), IAM (11%) and cloud security (9%) complete the picture (valid n = 159). Consolidation is becoming a control strategy, not just a cost strategy.

Where platform sprawl creates drag, and where leaders are most likely to consolidate this year. Factor survey, valid n = 171 and n = 159.
Factor's research shows confidence in cloud and SaaS posture remains constrained by fragmentation. Basic controls in place leads at 24%, followed closely by mostly reactive at 23% and mostly covered but fragmented at 22%. The more mature postures, policy enforcement with automation and a unified posture view, sit at 17% and 16% respectively (valid n = 159).
IAM maturity shows a similar challenge, and a starker headline: mostly unmanaged is the highest response in Factor's survey at 30%, with basic federation and MFA at 28%. Policy-based automated lifecycle sits at 24%, while centralised governance accounts for 19% (valid n = 159).

Cloud and SaaS posture confidence alongside IAM maturity, where mostly unmanaged is the highest response at 30%. Factor survey, valid n = 159.
These findings suggest that many organisations have partial coverage, but automation, lifecycle governance and unified posture management are not yet consistently embedded. The foundations are still developing even as they become central to modern technology operations.
Audit and compliance cycles are now a recurring operating workload rather than a periodic event. Asked where those cycles put the most pressure on teams, leaders surveyed by Factor named evidence collection first at 21%, with access reviews, framework alignment and vendor risk each at 19%. Regulatory change tracking follows at 17% and reporting at 13% (valid n = 159).
Why this matters
Assurance becomes a capacity drain when evidence, access reviews and control mapping have to be recreated manually across fragmented systems.
The opportunity the research points to is a shift from compliance as a periodic scramble to compliance as an operational by-product: reusable evidence, mapped controls and automated access workflows.
Asked how far teams have progressed embedding control earlier in delivery workflows, Factor's results show meaningful progress but uneven maturity. Integration into pipelines leads at 30%, followed by shift-left with developer self-service at 26%. Static scans and checklists account for 25%, while 22% report no structured DevSecOps yet (valid n = 158).

Embedding controls earlier in delivery: 30% report controls integrated into pipelines, while 22% have no structured DevSecOps yet. Factor survey, valid n = 158.
For CTOs, the implication is direct: delivery speed depends on controls being easy to understand, easy to use and embedded into existing developer workflows. The next maturity step is not more late-stage checks, but developer-friendly control that reduces friction while maintaining assurance.
Control is still seen as a blocker rather than an enabler in the places closest to innovation, delivery and adoption, respondents told Factor. Developer velocity leads at 19%, with cloud adoption and AI experimentation each at 18%. Automation initiatives follow at 15%, vendor onboarding at 14%, and SaaS usage and business change at 13% each (valid n = 157). Leaders are not rejecting control; they are identifying where control pathways feel too slow, fragmented or difficult to navigate.
Enablement mandate
When control blocks the work it is meant to protect, it becomes an adoption risk. The goal is assurance that feels like enablement, not resistance.
Across priorities, blockers, maturity and consolidation signals, the same logic repeats: organisations are not short of controls; they are short of control models that scale cleanly across work. Factor's survey traces a four-step pattern.
For Singapore technology leaders, the next step is to move from owning control to making control easier to operate at scale. Factor's research points to five moves.
The winning model
The winning model is not more control for its own sake. It is control that enables faster, safer execution. The strategic task for CIOs, CTOs and security leaders is to turn control from a set of review points into a set of operating capabilities that make change safer and faster.
About the data: responses to Factor's Wave of Change survey were collected from senior CIO, CTO and security leaders in Singapore. N/A responses were excluded from chart-level analysis, so valid n varies by question and is shown on each chart. Percentages are rounded up, and where questions allowed multiple selections some charts may not sum to 100%.
Related insights
CMO - Wave of Change™ August 2026
ANZ marketing leaders are under growing pressure to prove commercial impact.
CIO - Wave of Change™ ANZ 2026
After two years of rapid AI acceleration, ANZ technology leaders enter 2026 with confidence - but the data reveals a widening set of gaps between ambition and value.
CIO - Wave of Change™ Singapore 2025
Shedding light on how technology leaders are adapting to rising complexity