IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Proofpoint expands APJ data security amid AI risks

Proofpoint expands APJ data security amid AI risks

Tue, 1st Sep 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Proofpoint has expanded its data security operations across Asia Pacific and Japan, adding local infrastructure and compliance support in several APJ markets.

The expansion is intended to address rising data sovereignty demands as businesses in the region deploy more artificial intelligence tools and autonomous agents. It includes local data centre support in Singapore and broader local service delivery in India and Japan, while maintaining existing locally delivered services in Australia.

At the centre of the rollout is Proofpoint's data security platform, which combines data loss prevention, insider threat management, and data security posture management. The regional build-out is designed to help customers keep sensitive information within local jurisdictions while linking data risk findings to controls aligned with national privacy laws.

Proofpoint already provides locally delivered Email DLP, Endpoint DLP, Insider Threat Management software-as-a-service, and Cloud DLP in Australia. In India, the same services are already delivered locally, with Data Security Posture Management to be added. In Japan, local support is expanding to include Cloud DLP and Data Security Posture Management, while Singapore is being added as a new local hosting location for several services.

AI pressure

Proofpoint positioned the expansion around the effect of AI adoption on corporate data governance. According to its 2026 AI and Human Risk Landscape report, 86% of organisations in APJ have moved AI assistants beyond pilot programmes and 74% are progressing with autonomous agents, while 51% said their security posture remains inconsistent, reactive, or still catching up.

That mismatch has become a central concern for security teams because AI systems often need broad access to internal information to function. When existing permission structures are weak or excessive, those problems can spread more quickly as machine-led tools are introduced into everyday workflows.

George Lee, Senior Vice President, Asia Pacific and Japan, at Proofpoint, said the company is seeing a convergence of AI-related data risk and tightening regulation across the region.

"Data loss has always primarily been a people problem; however, as AI adoption accelerates, that problem is compounding within the APJ region. In this new agentic workspace, enterprises are increasingly facing new challenges like shadow AI and AI over-permissioning, which lead to data loss issues that are already challenging to manage," Lee said.

He added that compliance and protection can no longer be treated as separate tracks.

"That governance gap is arriving at the same time as compliance requirements across the region are getting stronger, which means organisations can no longer treat data protection and regulatory compliance as separate problems. Closing both requires intent-based protection that understands how data is actually being used, paired with local capability to keep that data hosted where regulations require it," Lee said.

Regional rules

The APJ expansion reflects a wider shift among security suppliers towards local hosting and country-specific compliance mapping. Regulators across Asia have tightened rules around how personal and corporate data is stored, transferred, and monitored, particularly where cross-border data flows are involved.

Proofpoint said its controls are aligned with regional frameworks including Singapore's Personal Data Protection Act, India's Digital Personal Data Protection Act, Japan's Act on the Protection of Personal Information, and Australia's Privacy Act. Its system also maps data risk findings to recommended controls across more than 25 compliance and regulatory frameworks.

Those requirements matter because many organisations now face a mix of local legal obligations and global internal security standards. For multinationals operating across APJ, a fragmented set of tools can make it harder to understand where sensitive data sits, who has access to it, and whether controls match local rules.

Loss rates

Proofpoint's survey data points to a high level of concern in the region. In its latest Voice of the CISO report, 99% of Chief Information Security Officers in India and 91% in Singapore said they had experienced material data loss in the past year, compared with a global average of 66%.

Those figures suggest that broad use of data loss prevention tools has not eliminated the problem. Security specialists have increasingly focused on whether existing systems are too narrow, operating in silos across email, endpoint devices, and cloud environments without connecting user behaviour to the underlying sensitivity of the data involved.

Proofpoint said its approach brings together Data Security Posture Management, Enterprise DLP, Adaptive Email DLP, and Insider Threat Management in one system. That allows security teams to identify sensitive data, monitor how it is being accessed by people and AI agents, and act on excessive access before it contributes to a breach or loss event.

More than 80 of the Fortune 100 and more than 14,000 large enterprises use Proofpoint's services. In APJ, the latest infrastructure expansion is aimed at organisations trying to balance AI deployment with national compliance requirements and a persistent rate of data loss.