Skip to main content
Sercxi Index · Q2 2026 - Preliminary

Cybersecurity Displacement

APAC · Q2 2026 · Preliminary Assessment

Security Operations and GRC are both Displaced. AI Red Team leadership emerges as a new category. And AI-powered attacks have increased 300% in APAC H1 2026, making AI Security the most consequential hiring priority in the sector.

The attack surface is AI. The defence must be too.

Preliminary Notice

This is a preliminary edition based on data available through early Q2 2026. Final scores and additional role assessments will be published in the full Q2 edition.

8 Roles Assessed·🟢 3 Stable🟡 3 Transitioning🔴 2 Displaced
🟢
StableRole intact, demand holding
🟡
TransitioningScope shifting materially
🟠
ExposedMandate erosion underway
🔴
DisplacedRole being eliminated

Key Findings

Security Operations upgraded to Displaced - three major Singapore enterprises closed in-house SOCs in Q2, transitioning to AI-powered MDR services.

GRC Director upgraded to Displaced - standalone function being disaggregated as AI governance migrates to CISO and CRO roles.

Head of AI Red Team enters as a new Stable role - adversarial testing of AI systems creates a distinct security leadership category.

AI-powered attacks increased 300% in APAC H1 2026 - AI Security compensation premiums widened to 35-45% above CISO-track equivalents.

CISO creation signal upgraded to 5 - MAS guidance now requires AI security competence for licensed financial institution CISOs.

Cloud Security remains the strongest operational creation signal - Kubernetes security for AI workloads has emerged as a distinct specialisation.

Methodology

The Sercxi Displacement Index assesses senior leadership roles against three structural vectors. Each is scored 1–5. The combined profile produces a Displacement Rating.

Elimination Risk(1–5)

The probability that the role is structurally removed from organisational charts within 24 months - not through attrition, but through deliberate elimination driven by automation, managed services, or mandate consolidation.

Redefinition Pressure(1–5)

The degree to which the role's scope, accountability, and required competencies are shifting. A high score indicates the job description is being rewritten faster than most incumbents are adapting.

Creation Signal(1–5)

The strength of net-new demand for the role or its evolved successor. High creation signals indicate structural tailwinds - new regulatory mandates, emerging technology domains, or market gaps creating durable hiring pressure.

Scorecard Overview

RoleEliminationRedefinitionCreationRating
Chief Information Security Officer (CISO)
🟡Transitioning
VP / Director, Security Operations
🔴Displaced
Head of AI Security / ML Safety
🟢Stable
Data Protection Officer (DPO)
🟡Transitioning
Director, GRC / Risk & Compliance
🔴Displaced
Head of Cloud Security / DevSecOps
🟢Stable
VP Threat Intelligence / Incident Response
🟡Transitioning
Head of AI Red Team / Adversarial Testing
🟢Stable

Role-by-Role Analysis

01

Chief Information Security Officer (CISO)

Elimination: 1/5·Redefinition: 5/5·Creation: 5/5
🟡Transitioning

The CISO creation signal has strengthened to 5 - driven by the convergence of AI security requirements, board-level reporting mandates, and the expansion of the CISO's domain to include AI model governance. MAS has issued guidance requiring CISOs of licensed financial institutions to demonstrate competence in AI security threat vectors.

The CISO mandate in Singapore now spans six distinct domains: traditional perimeter security, cloud security, AI system security, data privacy governance, regulatory compliance across APAC jurisdictions, and board-level risk communication. The leaders who can operate credibly across all six are commanding the highest CISO compensation in the region's history.

The redefinition remains intense but the creation signal now matches it - the CISO who has evolved to govern AI security is in structural demand that outpaces every other security leadership role.

02

VP / Director, Security Operations

Elimination: 4/5·Redefinition: 5/5·Creation: 2/5
🔴Displaced

We are upgrading from Exposed to Displaced. The SOC consolidation into MDR contracts has accelerated materially in Q2. Three major Singapore enterprises closed their in-house SOC operations in Q2, transitioning to fully managed AI-powered detection and response services.

The Director-level mandate that justified this role - team management, incident response governance, and operational security oversight - has been compressed to a contract management function. The strategic judgment calls that automated systems cannot make remain valuable, but they do not justify a dedicated director-level role.

This is the security equivalent of the IT Infrastructure Director transition - the function persists as a managed service, not a leadership mandate.

03

Head of AI Security / ML Safety

Elimination: 1/5·Redefinition: 2/5·Creation: 5/5
🟢Stable

Demand has intensified beyond projections. AI-powered attacks - prompt injection at scale, model extraction attempts, and adversarial manipulation of production AI systems - have increased 300% in APAC in H1 2026. Every organisation deploying production AI now requires dedicated security leadership for its AI systems.

Compensation premiums have widened to 35-45% above equivalent CISO-track roles - up from 30-40% in Q1. The supply shortage remains severe: fewer than 200 professionals globally have production-scale AI security experience at senior leadership level.

This role remains the strongest creation signal in cybersecurity. The demand is structural, driven by the fundamental reality that every AI system is an attack surface - and most organisations have no dedicated leadership to defend it.

04

Data Protection Officer (DPO)

Elimination: 2/5·Redefinition: 5/5·Creation: 4/5
🟡Transitioning

The DPO creation signal has strengthened as AI governance responsibilities expand. Singapore's PDPC has issued updated guidelines specifically addressing the privacy implications of AI training data, synthetic data generation, and automated decision-making - creating a distinct AI privacy governance mandate.

The DPO who can govern AI data governance alongside traditional privacy compliance is in structural demand. The one who remains focused on consent management and data subject access requests is in a role where the operational content is being automated by the same AI tools their organisation deploys.

The bifurcation between AI-fluent DPOs and traditional DPOs has widened in Q2. Compensation for the former has risen 15% since Q1. Compensation for the latter has been flat.

05

Director, GRC / Risk & Compliance

Elimination: 4/5·Redefinition: 4/5·Creation: 2/5
🔴Displaced

We are upgrading from Exposed to Displaced. AI-driven compliance automation platforms have moved from augmenting to replacing the control testing, audit preparation, and compliance reporting functions that constituted the operational core of GRC leadership.

The strategic risk dimensions - AI governance, operational resilience, ESG compliance - have migrated to CISO, CRO, and dedicated AI governance functions. The traditional GRC Director who has not secured one of these adjacent mandates is in a role that is being disaggregated, not evolved.

Two organisations in Singapore eliminated the standalone GRC Director role in Q2, redistributing accountability to CISO and CRO functions with dedicated AI risk reporting lines.

06

Head of Cloud Security / DevSecOps

Elimination: 1/5·Redefinition: 3/5·Creation: 5/5
🟢Stable

The creation signal remains the strongest in operational security. As AI inference workloads expand across multi-cloud and hybrid environments, the security architecture challenge has intensified. The Head of Cloud Security now governs not only traditional cloud security posture but AI model serving security, GPU cluster access control, and inference pipeline integrity.

Singapore's hyperscaler concentration continues to drive demand. Compensation has risen 20% in 18 months, with the talent pipeline unable to keep pace with the expansion of AI workload security requirements.

The specific Q2 dynamic: Kubernetes security for AI workloads has emerged as a distinct specialisation. The leaders who understand container orchestration security in the context of GPU scheduling and model serving are in a creation role with no near-term displacement risk.

07

VP Threat Intelligence / Incident Response

Elimination: 2/5·Redefinition: 5/5·Creation: 4/5
🟡Transitioning

The redefinition has deepened as AI-powered threat actors deploy more sophisticated attacks. State-sponsored AI-generated phishing campaigns, automated vulnerability exploitation, and deepfake-enabled social engineering now constitute the majority of high-severity threats across APAC financial services.

The VP who has repositioned as a strategic threat advisor - translating AI-powered threat intelligence into board-level risk communication - is in structural demand. Those still primarily managing technical analysis teams are in a role where AI tools process threat data at scales no human team can match.

The creation opportunity is in AI threat intelligence: understanding how AI is being weaponised and building defensive strategies specifically designed for AI-powered attack vectors. This is a new competency that is being built in real time.

08

Head of AI Red Team / Adversarial Testing

Elimination: 1/5·Redefinition: 2/5·Creation: 5/5
🟢Stable

New to the Q2 assessment. As organisations deploy production AI systems at scale, the need for dedicated adversarial testing of AI models - prompt injection testing, jailbreak analysis, model robustness assessment, and bias auditing - has created an entirely new security leadership role.

This is the offensive security equivalent of the AI Security role - and it is emerging as a distinct function because the adversarial testing methodology for AI systems bears little resemblance to traditional penetration testing. The leaders who can build and manage AI red team programmes are being recruited from a talent pool that numbers in the dozens globally.

MAS has signalled that AI-specific adversarial testing will become a regulatory expectation for licensed financial institutions. When that guidance formalises, every major bank and FinTech in Singapore will require this capability - either internal or through advisory relationships.

The Sercxi Read

Q2 marks the point where APAC cybersecurity leadership splits cleanly into two categories: roles that defend against AI-powered threats and roles that are being replaced by AI-powered tools. Security Operations and GRC are on one side. AI Security, AI Red Team, and Cloud Security are on the other.

The speed of this divergence has exceeded our Q1 projections. The displacement of operational security roles is accelerating because AI-powered security tools are simultaneously better and cheaper than human-led alternatives. The creation of AI-focused security roles is accelerating because AI-powered threats are more sophisticated than anything traditional security leadership was trained to address.

The preliminary data describes a sector in structural bifurcation - and the leaders who recognise which side they need to be on are moving faster than those who believe their current positioning will sustain them.

AI is the threat. AI is the defence. The leaders who understand both sides of this equation are the only ones whose positions are structurally secure. Everyone else is in transition or decline.

Your Three Questions

Answer these honestly. No form. No follow-up unless you want one.

1.

Has your CISO demonstrated AI security competence to MAS standards - or is AI security still treated as a subset of traditional information security?

2.

Do you have dedicated AI adversarial testing capability - or is your AI red team still a theoretical item on next year's security roadmap?

3.

Has your SOC been formally restructured for AI-powered operations - or is MDR transition being discussed while human-led operations continue unchanged?

If these questions reveal gaps between your threat landscape and your security leadership architecture, the gaps are already being exploited.

Initiate Confidential Briefing →

Save this report

Print-optimized layout for executive distribution.

Full Edition · June 2026

Q2 2026 - Final Assessment

Complete methodology annotations, expanded role coverage, and cross-regional comparison data.