Factor
About
Who we help
Compare Vendors
Advisory
Platforms
Events
eLearning
InsightsPlansSign in
All insights

Research Report

September 2024

CISO - Wave of Change™ Singapore

The CISO Wave of Change report is based on a pulse survey conducted in April and June 2024 by Factor

Singapore technology leaders are not asking for more control. They are asking for control that can be operated, evidenced and scaled at business speed. That is the central finding of Factor's Wave of Change survey, a quarterly Tech Decision Maker survey extract built on 102 responses from senior CIO, CTO and security leaders in Singapore, published in June 2026.

The research catches a market being asked to protect, simplify and accelerate at the same time: maintain assurance, resilience and confidence as environments become more distributed, reduce the drag created by platform overlap, manual workflows and fragmented evidence, and embed controls into delivery so business change moves faster without creating unmanaged risk. Across the survey, teams have invested in capability, but the operating model has not caught up. The opportunity now is to make control easier to operate, evidence and scale.

102

Senior CIO, CTO and security leaders surveyed in Singapore

50%

Name Governance, Risk & Leadership as the single challenge that would unlock serious momentum

25%

Say GenAI launch activity is forcing a strategy rethink

30%

Report controls integrated into delivery pipelines

30%

Describe their IAM maturity as mostly unmanaged

24%

Cite manual steps, the leading blocker to faster, safer response

Executive attention is concentrating on control and momentum

When Factor asked which areas are demanding the most focus right now, leaders ranked Security Strategy & Leadership highest at 27%, followed by Risk Management & Governance at 24%. Data Security & Privacy sits at 17% and Threat Detection & Response at 14%, with Identity & Access Management and Cloud & SaaS Security at 13% each. Security Culture & Capability (12%), Application & DevSecOps (11%), Security Architecture & Operations (11%) and Third-Party & Supply Chain Risk (10%) complete the picture (valid n = 107).

A companion question sharpens the signal. Asked what single challenge, if solved, would unlock serious momentum, 50% of valid responses in Factor's survey named Governance, Risk & Leadership. Data, Privacy & Identity Control followed at 29%, Threat Detection & Operations at 24% and Secure Technology & Cloud Enablement at 23%, with People, Culture & Capability at 12% and Third-Party & Supply Chain Assurance at 10% (valid n = 107).

The responses show a clear tension: governance dominates attention, but progress depends on operating speed. Viewed together, the results show that leaders are not treating control as a narrow technical function. They are trying to align accountability, decision rights and operating discipline across a broader technology environment.

Areas demanding the most focus now, alongside the single challenge leaders say would unlock serious momentum. Factor survey, valid n = 107 for both questions.

Areas demanding the most focus now, alongside the single challenge leaders say would unlock serious momentum. Factor survey, valid n = 107 for both questions.

The 2026 technology agenda is being reset

Asked which recent shifts are forcing a rethink of strategy, leaders pointed to forces beyond the traditional technology function. GenAI launches top the list, cited by 25% of valid responses in Factor's survey. Board pressure follows at 19%, with leadership change at 17% and regulatory reform at 16%. Cloud expansion (14%), M&A activity (12%), SaaS adoption (11%) and audit findings (10%) round out the reprioritisation picture (valid n = 183).

This signals that control priorities are now being shaped by business change, AI experimentation and governance scrutiny, not only by the threat landscape. The 2026 agenda is being reset from outside the security function as much as from within it.

Recent shifts forcing a strategic rethink, led by GenAI launches at 25%. Factor survey, valid n = 183.

Recent shifts forcing a strategic rethink, led by GenAI launches at 25%. Factor survey, valid n = 183.

Why this matters

GenAI is the strongest signal because it turns control from a defensive discipline into an enablement requirement. Leaders need confidence, assurance and accountability without slowing experimentation.

Where leaders would deploy 10% more capability

Asked where they would deploy 10% more capability tomorrow, leaders pointed to the operating layers that make control repeatable. Access governance, DevSecOps enablement and security automation each sit at 20% in Factor's survey, followed by SOC uplift and Zero Trust uplift at 16%. Cloud controls (12%) and threat detection tuning (10%) rank lower but remain meaningful (valid n = 183).

The distribution shows that leaders see the greatest value in capabilities that reduce manual governance, embed control earlier and improve response scalability. The strongest investment signals sit where identity, automation, DevSecOps and response capability intersect. This is not a pure tooling agenda; it is an operating-capability agenda, less about buying another platform and more about reducing manual governance, embedding controls earlier and scaling response.

Capability deployment priorities: access governance, DevSecOps enablement and security automation each at 20%. Factor survey, valid n = 183.

Capability deployment priorities: access governance, DevSecOps enablement and security automation each at 20%. Factor survey, valid n = 183.

Faster response still breaks at the workflow layer

Asked by Factor about the biggest blockers to faster, safer response, leaders pointed squarely at the workflow layer. Manual steps lead at 24%, followed by staffing limits at 19%, disconnected tools at 17% and delayed handoffs at 16%. False positives and inconsistent telemetry each sit at 13%, with limited context at 11% (valid n = 138). The issue is not lack of signal; it is the difficulty of turning signal into coordinated action.

Blockers to faster, safer response: manual steps, staffing limits, disconnected tools and delayed handoffs lead. Factor survey, valid n = 138.

Blockers to faster, safer response: manual steps, staffing limits, disconnected tools and delayed handoffs lead. Factor survey, valid n = 138.

The maturity picture in Factor's research reinforces the problem. Defined runbooks with some coordination lead the threat detection and response approaches at 24%, but tested, automated and continuously improved approaches sit at 21%, exactly equal to ad hoc and reactive approaches. Manual workflows with gaps account for 19% and integrated live correlation for 17% (valid n = 159). Workflow orchestration is just as mixed: 29% say some alerts flow into action, while fully orchestrated and mostly manual, siloed environments both sit at 25%, and partially orchestrated response accounts for 23% (valid n = 159).

This is a market caught between formalisation and automation. Teams may have alerts, runbooks and tools, but response remains fragile when orchestration depends on people stitching systems together. Many teams have the components of maturity; few have consistent end-to-end flow.

Why this matters

Faster response comes from reducing the distance between detection, context, decision and action. Manual steps and handoffs are where speed and confidence leak away.

Partial visibility is limiting response confidence

Asked how unified visibility is across environments, most of Factor's respondents described a middle ground: visibility has improved, but traceability remains inconsistent. The largest share, 29%, report some unification across cloud and SaaS, while 26% remain fragmented tool-by-tool. Mostly unified for key risk zones and fully unified real-time telemetry each sit at 24% (valid n = 159).

Investigation readiness shows the same shape in Factor's data. Centralised evidence gathering leads at 30%, followed by some tool-level correlation at 26%, while integrated forensics and traceability and manual log pulls per system both sit at 23% (valid n = 158). Many teams have moved beyond fully manual investigation, but few have achieved consistent, cross-environment traceability. Without unified telemetry and traceability, every incident carries additional time cost, confidence cost and evidence burden.

Visibility unification across environments and incident investigation readiness. Factor survey, valid n = 159 and n = 158.

Visibility unification across environments and incident investigation readiness. Factor survey, valid n = 159 and n = 158.

Platform duplication is draining momentum

Asked in Factor's Wave of Change survey where platform sprawl or duplication creates drag, leaders spread the load widely. Awareness tooling, policy controls and reporting tools each sit at 20%, with the identity stack close behind at 19%. The endpoint stack accounts for 13%, and the threat detection stack and cloud tooling for 10% each (valid n = 171). The tools intended to improve awareness, evidence and decision-making are increasingly creating complexity of their own.

Consolidation intentions follow the drag. Orchestration platforms top the list of areas leaders told Factor they are most likely to consolidate or simplify this year at 22%, followed by email at 18%, detection and response at 17% and reporting tools at 16%. Endpoint (14%), IAM (11%) and cloud security (9%) complete the picture (valid n = 159). Consolidation is becoming a control strategy, not just a cost strategy.

Where platform sprawl creates drag, and where leaders are most likely to consolidate this year. Factor survey, valid n = 171 and n = 159.

Where platform sprawl creates drag, and where leaders are most likely to consolidate this year. Factor survey, valid n = 171 and n = 159.

Cloud, SaaS and identity are the control bottleneck

Factor's research shows confidence in cloud and SaaS posture remains constrained by fragmentation. Basic controls in place leads at 24%, followed closely by mostly reactive at 23% and mostly covered but fragmented at 22%. The more mature postures, policy enforcement with automation and a unified posture view, sit at 17% and 16% respectively (valid n = 159).

IAM maturity shows a similar challenge, and a starker headline: mostly unmanaged is the highest response in Factor's survey at 30%, with basic federation and MFA at 28%. Policy-based automated lifecycle sits at 24%, while centralised governance accounts for 19% (valid n = 159).

Cloud and SaaS posture confidence alongside IAM maturity, where mostly unmanaged is the highest response at 30%. Factor survey, valid n = 159.

Cloud and SaaS posture confidence alongside IAM maturity, where mostly unmanaged is the highest response at 30%. Factor survey, valid n = 159.

These findings suggest that many organisations have partial coverage, but automation, lifecycle governance and unified posture management are not yet consistently embedded. The foundations are still developing even as they become central to modern technology operations.

Assurance work is consuming delivery capacity

Audit and compliance cycles are now a recurring operating workload rather than a periodic event. Asked where those cycles put the most pressure on teams, leaders surveyed by Factor named evidence collection first at 21%, with access reviews, framework alignment and vendor risk each at 19%. Regulatory change tracking follows at 17% and reporting at 13% (valid n = 159).

Why this matters

Assurance becomes a capacity drain when evidence, access reviews and control mapping have to be recreated manually across fragmented systems.

The opportunity the research points to is a shift from compliance as a periodic scramble to compliance as an operational by-product: reusable evidence, mapped controls and automated access workflows.

Embedded controls are changing delivery workflows

Asked how far teams have progressed embedding control earlier in delivery workflows, Factor's results show meaningful progress but uneven maturity. Integration into pipelines leads at 30%, followed by shift-left with developer self-service at 26%. Static scans and checklists account for 25%, while 22% report no structured DevSecOps yet (valid n = 158).

Embedding controls earlier in delivery: 30% report controls integrated into pipelines, while 22% have no structured DevSecOps yet. Factor survey, valid n = 158.

Embedding controls earlier in delivery: 30% report controls integrated into pipelines, while 22% have no structured DevSecOps yet. Factor survey, valid n = 158.

For CTOs, the implication is direct: delivery speed depends on controls being easy to understand, easy to use and embedded into existing developer workflows. The next maturity step is not more late-stage checks, but developer-friendly control that reduces friction while maintaining assurance.

Control must move into the flow of work

Control is still seen as a blocker rather than an enabler in the places closest to innovation, delivery and adoption, respondents told Factor. Developer velocity leads at 19%, with cloud adoption and AI experimentation each at 18%. Automation initiatives follow at 15%, vendor onboarding at 14%, and SaaS usage and business change at 13% each (valid n = 157). Leaders are not rejecting control; they are identifying where control pathways feel too slow, fragmented or difficult to navigate.

Enablement mandate

When control blocks the work it is meant to protect, it becomes an adoption risk. The goal is assurance that feels like enablement, not resistance.

Across priorities, blockers, maturity and consolidation signals, the same logic repeats: organisations are not short of controls; they are short of control models that scale cleanly across work. Factor's survey traces a four-step pattern.

  • Pressure rises: GenAI, board scrutiny, regulatory reform and cloud/SaaS expansion reset the agenda.
  • Friction appears: manual steps, disconnected tools and delayed handoffs slow action and evidence.
  • Maturity gaps surface: IAM, cloud posture, visibility and orchestration remain uneven.
  • Enablement becomes the goal: control must be embedded, reusable and easier to operate at speed.

For Singapore technology leaders, the next step is to move from owning control to making control easier to operate at scale. Factor's research points to five moves.

  • Unify telemetry: reduce tool-by-tool visibility and improve cross-environment confidence.
  • Automate evidence and access: turn assurance into a reusable operating capability.
  • Consolidate where drag is highest: simplify orchestration, reporting, identity and response layers.
  • Embed controls earlier: make developer-friendly controls part of delivery workflows.
  • Orchestrate response: close the gap between signal, context, decision and action.

The winning model

The winning model is not more control for its own sake. It is control that enables faster, safer execution. The strategic task for CIOs, CTOs and security leaders is to turn control from a set of review points into a set of operating capabilities that make change safer and faster.

About the data: responses to Factor's Wave of Change survey were collected from senior CIO, CTO and security leaders in Singapore. N/A responses were excluded from chart-level analysis, so valid n varies by question and is shown on each chart. Percentages are rounded up, and where questions allowed multiple selections some charts may not sum to 100%.

Talk to Factor about the Wave of Change research

Related insights

Research Report

CMO - Wave of Change™ August 2026

ANZ marketing leaders are under growing pressure to prove commercial impact.

Research Report

CIO - Wave of Change™ ANZ 2026

After two years of rapid AI acceleration, ANZ technology leaders enter 2026 with confidence - but the data reveals a widening set of gaps between ambition and value.

Research Report

CIO - Wave of Change™ Singapore 2025

Shedding light on how technology leaders are adapting to rising complexity