VI · EN
Get a consultation098.169.1103
Back to News
— PERSPECTIVE / ENTERPRISE INFORMATION SECURITY

Why Information Security Is No Longer Optional for Business

Cyberattacks in Vietnam fell nearly 20% in 2025, yet the share of organisations that suffered actual damage went up. That paradox says something important: attackers are not doing more, they are aiming better. And they increasingly aim at companies that believe they are too small to be a target.

PERSPECTIVE·18.08.2026·12 min read·The TechShield Team

In most budget meetings, information security occupies the same slot: a cost line, sitting next to electricity and server rental. It generates no revenue, appears in no growth report, and is the first item cut when savings are needed. That view survives right up until the first incident — at which point the company discovers that what it lost was not data, but the ability to keep operating.

This article is not about technology. It is about numbers: the real cost of an incident, the real path attackers take inside, the real legal obligations businesses in Vietnam carry from 2026 onward, and the first steps that are worth taking even on a constrained budget.

01Vietnam's threat landscape: fewer attacks, heavier losses

According to the annual cybersecurity report published by Vietnam's National Cyber Security Association (NCA) in January 2026, based on a survey of more than 5,300 organisations, information systems in Vietnam faced roughly 552,000 cyberattacks during 2025 — a 19.38% decrease from 2024. Read on its own, that number suggests things are getting better.

The same report, however, found that 52.30% of organisations recorded actual damage from cyberattacks during the year, up substantially from 46.15% in 2024. Fewer attacks, more real victims. That reflects a strategic shift: threat actors are moving away from broad automated campaigns toward selective, targeted operations — studying each target carefully, preparing longer, and digging deeper once inside.

Figures from Vietnam's Ministry of Science and Technology for Q3 2025 fill in the picture: over 6.5 million accounts stolen, roughly 4,000 phishing domains recorded, and 550,000 denial-of-service attacks. Ransomware alone caused more than 250 billion VND in damage in Vietnam during the first half of 2025, including one company that lost an estimated 800 billion VND to a single extortion campaign.

Selective targeting replaces mass campaigns

Attackers now spend weeks or months on reconnaissance against a specific organisation rather than spraying malware indiscriminately.

The real victim rate is higher than reported

Fear of blame keeps many IT teams from disclosing incidents, so 52.30% is very likely an undercount.

The five most common attack types

Denial of service, injected gambling backlinks, targeted APT intrusions, data theft, and ransomware encryption.

A drop in attack volume does not mean a drop in risk. It means attackers have stopped guessing and started choosing.

02What a data breach actually costs

IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at a record US$4.99 million, up 12% year over year. For ASEAN — a cost base far closer to Vietnam's than the global figure — the average rose from US$3.67 million in 2025 to US$4.12 million in 2026, ranking ninth among the 16 countries and regions studied.

Costs are not evenly distributed across sectors. In ASEAN, financial services carried the highest average breach cost at US$6.53 million, followed by industrial organisations at US$5.99 million and communications firms at US$4.28 million. These are the sectors with sensitive data, expensive downtime, and strict reporting duties.

The more instructive number sits on the defensive side. ASEAN organisations that deployed AI and security automation extensively averaged US$3.66 million per breach, against US$4.86 million for those that did not — a gap of US$1.2 million. Those same organisations identified and contained incidents 123 days faster. Investment in early detection is not a sunk cost; it is insurance with a measurable return.

Direct costs

Incident investigation, system recovery, external specialists, legal fees, and regulatory fines.

Disruption costs

Revenue lost while systems are down — ransomware alone can halt business operations for roughly 21 days.

Trust costs

Customer churn, contracts reopened by partners, and higher acquisition costs — these persist for quarters after the incident closes.

03How attackers get in — evidence from 22,000 breaches

Verizon's 2026 Data Breach Investigations Report (DBIR) analysed more than 22,000 breaches and reached a conclusion that reset industry assumptions: exploitation of technical vulnerabilities now accounts for 31% of all initial access, up from 20% the year before — a 55% jump in twelve months — making it, for the first time, the single most common way breaches begin.

The most uncomfortable detail is where those vulnerabilities live. Edge devices and VPNs rose from 3% to 22% of exploitation-driven breaches, a sevenfold increase in a single year. These are precisely the assets that sit at the perimeter, face the internet directly, are typically installed once and forgotten, and rarely appear on a regular patching schedule.

At the same time, the report found that 62% of breaches still involved a human element — clicking a phishing link, reusing a password, misconfiguring access rights. The two trends are not mutually exclusive: attackers commonly use a technical flaw to get in, then human error to go deeper.

The most exploitable device in a company is usually the one nobody remembers owning.

04The 2026 regulatory picture: security became a legal duty

On 1 January 2026, Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15) came into force, moving personal data protection from decree-level guidance to statutory obligation. Decree 13/2023/ND-CP continues to serve as the implementing instrument during the transition until replaced.

The penalties changed in kind, not just in size. Administrative fines for personal data violations reach up to 3 billion VND. Illegal buying and selling of personal data can be penalised at up to ten times the revenue gained from the violation. Organisations breaching cross-border personal data transfer rules face a maximum penalty of 5% of the prior year's revenue. These are revenue-linked figures rather than fixed ceilings — meaning the larger the business, the larger the exposure.

In parallel, Decree 85/2016/ND-CP and Circular 12/2022/TT-BTTTT set out the duty to secure information systems by assurance level: determining the level, preparing and obtaining approval of the level proposal dossier, implementing the corresponding protection plan, and conducting security inspection and assessment against each approved criterion. For many companies the question is no longer whether to do this, but whether the dossier has been approved yet.

Law No. 91/2025/QH15

Effective 1 January 2026, elevating personal data protection to statutory level with revenue-linked penalties.

Decree 13/2023/ND-CP

Still the implementing instrument during the transition — obligations such as data processing impact assessment dossiers remain in force.

Decree 85/2016 and Circular 12/2022

Govern the information system assurance level dossier and the duty to run periodic security inspection and assessment.

ISO/IEC 27001

Not legally mandatory, but increasingly a precondition in tender submissions and contracts with international partners.

05Why small and mid-sized businesses are the preferred target

A belief runs deep among smaller companies: we have nothing worth stealing. It is wrong in two ways. First, customer data — names, phone numbers, ID numbers, transaction history — has market value regardless of the size of the company that collected it. Second, and more importantly, small companies are the on-ramp to large ones.

In a modern digital supply chain, an accounting service provider, a logistics partner, or a marketing agency all hold direct connections into a large client's environment: VPN accounts, API credentials, shared mailboxes. Attackers understand perfectly well that breaking into a twenty-person firm is far easier than breaking into a conglomerate — while both routes end in the same place.

What makes the risk asymmetric is resilience. A large group can absorb a few million dollars and keep trading. A fifty-person company whose entire accounting system is encrypted during closing season may never recover. Same attack, entirely different outcome.

No company is too small to be attacked. Some companies are only too small to survive being attacked.

06Security creates business value, not just risk reduction

Treating information security purely as a cost misses the value it produces on the revenue side. In most tenders issued by financial, telecom, healthcare, and multinational organisations operating in Vietnam, vendor security assessment is now a mandatory section. A supplier holding ISO/IEC 27001 certification, an independent penetration test report, and a documented incident response process clears due diligence in days; one without them is filtered out at the submission stage.

Second, security capability shortens the sales cycle. When an enterprise client sends a vendor assessment questionnaire running to hundreds of items, having policy documents, data flow diagrams, and a recent assessment report on hand turns a quarter-long exercise into a week. In many deals, that speed is the deciding factor.

Third, it is the entry ticket to international markets. A Vietnamese software company serving European clients must demonstrate GDPR compliance; serving US financial institutions requires a SOC 2 assessment. Both assume a security programme that has been running steadily — not one assembled in the weeks before signing.

07Where to start: a six-step path for companies beginning from zero

No organisation builds a complete security capability in one quarter, and none needs to. What matters is sequencing: the first moves should be the ones that block the most risk per unit of spend.

The path below is what TechShield applies with companies starting from nothing. Each step stands on its own and delivers value even when the later steps have not been taken.

01 — Inventory your digital assets

List every server, domain, cloud service, edge device, and privileged account. You cannot protect what you do not know you own.

02 — Multi-factor authentication everywhere

Enable MFA on email, VPN, system administration, and every cloud service. Pound for pound, it blocks more attacks than any other control.

03 — Backups on the 3-2-1 rule

Three copies, two media types, one fully isolated from the network. This is the line between losing a day of work and losing the company to ransomware.

04 — Patch management for edge devices

Prioritise firewalls, VPN gateways, and load balancers — the asset class whose share of breaches grew sevenfold according to the 2026 DBIR.

05 — Independent penetration testing

One test a year on critical systems, plus one after every major architectural change, to learn how far your defences actually hold.

06 — Incident response playbook and drills

Who calls whom at 2 a.m., which systems are isolated first, how long you have to notify regulators. An untested playbook is no playbook.

Security is not a state you reach once and keep. It is an operational habit, verified on a schedule.

Key takeaways

  • 01Vietnam recorded roughly 552,000 cyberattacks in 2025 — down 19.38% — yet the share of organisations suffering real damage rose from 46.15% to 52.30%.
  • 02The average breach in ASEAN cost US$4.12 million in 2026; organisations using AI and security automation saved around US$1.2 million per incident and contained breaches 123 days faster.
  • 03Vulnerability exploitation is now the leading initial access vector at 31% of breaches, with edge devices and VPNs jumping from 3% to 22% in a single year.
  • 04From 1 January 2026, Vietnam's Personal Data Protection Law carries penalties up to 3 billion VND, ten times illicit gains, or 5% of prior-year revenue depending on the violation.
  • 05Start with six moves: asset inventory, MFA, 3-2-1 backups, edge device patching, independent penetration testing, and incident response drills.
// READY TO ACT

Assess your organisation's security posture

The TechShield team can help you review your risks and build a security strategy fit for the age of AI. Book a free consultation today.

Accent color

Density