Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

APAC regulatory landscape

File security and audit obligations across APAC

What each APAC territory requires of organisations handling untrusted files, the instruments, the regulators and the dated developments.

Covering 13 territories across Southeast Asia, Oceania, East Asia and South Asia.

Coverage

13

territories covered

29

instruments mapped

18

dated developments

28

regulators cited

Latest across the region

What changed recently

The most recent developments across the region.

  1. ConsultationHigh impactSingapore

    CCoP for CII to be updated to address APT and AI-enabled threats

    CSA announced that the Cybersecurity Code of Practice for CII will be updated to address advanced persistent threats and AI-enabled threats, with changes expected to take effect in the later part of 2026. The update covers board accountability with annually reviewed cyber resilience frameworks, Cyber Trust Mark Level 5 certification, oversight of interconnected systems, threat detection deployment, cybersecurity exercise planning, and network monitoring and detection management. A separate Code of Practice for Cloud Services is planned on the same timetable.

    Why it matters for file security. AI-enabled threats raise the ceiling on file-borne attacks specifically: polymorphic document payloads and machine-generated lures degrade signature and heuristic detection faster than they degrade deterministic rebuild. CII owners reviewing their control set against the updated Code should expect content-inspection and known-good reconstruction to be scrutinised more closely than detection tuning.

    How Glasswall addresses it

    This is the development most worth acting on ahead of the Code landing. AI-generated document payloads and machine-tailored lures degrade signature and heuristic detection considerably faster than they degrade deterministic rebuild, because rebuild does not need to recognise the threat, it removes the active content regardless. CII owners revisiting their control set before the updated Code takes effect should expect content inspection and known-good reconstruction to attract more scrutiny than detection tuning. Macro intelligence covers the Office macro surface specifically, and Large Archive reaches the container formats inline scanning cannot open.

    Content Disarm and ReconstructionMacro intelligenceLarge ArchiveGlasswall Halo / Glasswall Meteor

    • cii
    • government
    • banking
    • healthcare
    • telco
    • energy
    • transport

    Source: CSA

  2. In forceContextNew Zealand

    IPP 3A indirect collection transparency obligation comes into force

    IPP 3A took effect, requiring agencies to take reasonable steps to notify individuals when their personal information is collected indirectly from a third party. It applies only to personal information collected on or after this date.

    Why it matters for file security. Organisations receiving bulk personal data from third parties, frequently as documents and spreadsheets, now have a transparency obligation attached to that intake.

    • banking
    • telco
    • healthcare
    • education

    Source: Bell Gully

  3. AmendmentMedium impactJapan

    Cabinet approves APPI amendment introducing administrative fines

    The Cabinet approved an APPI amendment bill introducing administrative fines, strengthened protections for children's personal data, and new provisions addressing the use of personal data in AI training.

    Why it matters for file security. Administrative fines change the calculus on file-borne personal data loss. Controls that reduce personal data sitting in loose documents move from good practice to risk reduction with a quantifiable value.

    How Glasswall addresses it

    Reducing the personal data carried in documents lowers the exposure that an administrative fine would be calculated against. Find & Redact addresses documents in flight; Storage Monitor addresses the existing estate at rest.

    Find & RedactStorage Monitor + SM AuditGlasswall Halo

    • banking
    • healthcare
    • telco
    • education

    Source: PPC

  4. ConsultationMedium impactAustralia

    Consultation opens on SOCI Act Ministerial Directions and risk management reforms

    Following the first independent review of the SOCI Act delivered on 31 January 2026, the Government opened consultation on amendments to the Ministerial Directions powers under Part 3 and to the Critical Infrastructure Risk Management Program Rules.

    Why it matters for file security. Changes to the risk management program rules are the part to watch: they determine what an entity must document about how material risks, including file-borne compromise of data storage systems, are actually mitigated.

    How Glasswall addresses it

    Entities revisiting their risk management program during this consultation should expect to describe file-handling mitigations more explicitly than before. A deterministic rebuild control plus a per-file verdict record is materially easier to write into a program document than a detection-tuning posture.

    Content Disarm and ReconstructionPer-file verdict recordGlasswall Halo / Glasswall Meteor

    • cii
    • energy
    • telco
    • transport
    • banking
    • healthcare

    Source: Minister for Home Affairs

  5. AmendmentHigh impactSouth Korea

    Amended PIPA promulgated with revenue-based fines and mandatory ISMS-P

    The PIPA amendment was promulgated as Act No. 21445, authorising administrative fines of up to 10% of total revenue in high-severity breach cases. Most provisions take effect 11 September 2026; mandatory ISMS-P certification provisions take effect 1 July 2027.

    Why it matters for file security. Revenue-based penalties materially change the business case for reducing personal data held in documents, and the ISMS-P mandate creates a dated deadline for evidencing technical safeguards.

    How Glasswall addresses it

    Two dated deadlines to plan against: September 2026 for the penalty regime and July 2027 for ISMS-P certification. Reducing personal data in documents addresses the first; documented deterministic file handling with a per-file verdict record addresses the second.

    Find & RedactContent Disarm and ReconstructionPer-file verdict recordGlasswall Halo

    • banking
    • healthcare
    • telco
    • education

    Source: Hunton Andrews Kurth

  6. In forceContextAustralia

    Mandatory smart device security standards take effect

    Security standards for smart devices supplied to critical infrastructure operators commenced under the Cyber Security Act 2024.

    Why it matters for file security. Indirect for file security, but relevant to supply-chain assurance: device firmware and configuration bundles are files, and their provenance is increasingly expected to be verifiable.

    How Glasswall addresses it

    Signature Verify checks file signatures against a managed site list on a any-deny-wins basis, which is the relevant control where firmware or configuration bundles arrive from a supplier and provenance has to be established before use.

    Signature VerifyGlasswall Halo

    • cii
    • manufacturing
    • energy

    Source: ACSC

  7. GuidanceMedium impactAustralia

    First independent review of the SOCI Act delivered

    The first independent review of the Security of Critical Infrastructure Act was delivered to Government, forming the basis for the reform consultation opened in March 2026.

    Why it matters for file security. Sets the direction for the next round of obligations on critical infrastructure entities, including how prescriptively risk management programs must describe technical controls.

    • cii

    Source: CISC

  8. In forceHigh impactIndia

    DPDP Rules 2025 notified with phased compliance rollout

    The Digital Personal Data Protection Rules 2025 were notified, setting a phased 12- to 18-month compliance rollout including a 72-hour detailed breach report and at least one year of traffic and processing log retention.

    Why it matters for file security. Establishes dated compliance milestones and, importantly, an explicit log retention period tied to breach investigation, a requirement that structured per-file processing records satisfy more cleanly than application logs alone.

    How Glasswall addresses it

    Organisations mapping their DPDP log-retention obligation should account for file-processing evidence, not just application and network logs. The per-file verdict record is exportable to whatever retention tier the Rules require.

    Per-file verdict recordFind & RedactGlasswall Halo

    • banking
    • telco
    • healthcare
    • education

    Source: MeitY

Scope

About these pages

These pages are a working reference, not legal advice, obligations depend on designation, sector and architecture, so take local advice before relying on them for a compliance decision. Where a page describes how Glasswall relates to an obligation, it describes a control, not a certification.

Need this mapped to your environment?