
Kenneth Lai, Vice President, Asean, Cloudflare. Image: Cloudflare
At the 11th National Congress of the Vietnam Fatherland Front (VFF), delegates highlighted how the application of Artificial Intelligence (AI) and digital transformation has become an inevitable step for the market’s development in the coming years. This has shifted the national conversation from access and adoption to value creation.
Now, it’s all about how digital technologies can drive productivity, improve customer engagement, and open new engines of growth for national development. This will be an important transition for the country, but it also raises a deeper question: as Vietnamese organizations scale digital systems, are they building on resilient foundations, or onto systems that are already under strain?
The response to this will matter because digital progress and digital resilience do not automatically move hand in hand. Often, many organizations may appear to be modernizing well with digital transformation. But beneath that progress, they are still operating on legacy architecture, tightly connected systems, and fragmented technology environments that were not designed for the speed, complexity, and interdependence of today’s digital economy. In fact, our latest Signals Report found that today’s most catastrophic failures don’t come from obvious doors left open, but from hidden structural fault lines that stay invisible—right up until the moment of impact.
With AI projects moving from pilot to implementation quickly in Vietnam, the need for resilient foundations that can withstand these workloads securely, reliably, and at scale, is becoming increasingly urgent.
Hidden risks in plain sight
As operations in Vietnam seek to become faster and more autonomous, infrastructure gaps are becoming harder to detect and faster to exploit. What defines this moment is not simply the volume of vulnerabilities that could potentially occur; it is also the pace at which they are exploited.
Agentic AI will further compress this window between disclosure and exploitation. Systems today either have or will soon enter an era in which they can execute thousands of actions in milliseconds, from reconfiguring infrastructure to adjusting supply chains, leaving little room for human intervention when something goes wrong. This is enabling adversaries to identify and operationalize exploits within hours.
Often, the challenge is compounded by the fact that every SaaS integration, API call, open-source library, and AI service adds another layer of inherited risk. Failures anywhere in this extended web – whether a breach, outage, or compliance lapse – can quickly cascade into customer harm, regulatory exposure, and systemic disruption. React2Shell is one such example. It was one of 2025’s most notorious vulnerabilities, recording over 1 billion exploitation attempts in just 11 days.
This convergence of speed and fragility creates what can be described as a “velocity paradox” – where the very technologies that drive value also collapse the margin for error.
Adding to this fragility is a growing web of AI dependencies. Employees are increasingly relying on generative AI tools and embedded services that expose sensitive data to external models, expanding risk beyond a company’s direct control. For many organizations, this introduces blind spots in data governance, intellectual property protection, and regulatory compliance – and is the ultimate reason why security can no longer sit outside of the IT system; it must be woven into every layer of the digital environment.
When new ambitions meet old foundations
Taken together, these pressures point to a much bigger issue – what many organizations view as a compounding technical debt is becoming a strategic business risk. Legacy systems built previously assumed that manual intervention, static configurations, and perimeter-based protection would be sufficient.
Today, that’s no longer the case. Modern digital environments depend on automation, integration, and real-time control. As a result, these older systems are creating cyber and operational risks, leaving organizations exposed in ways that machine-speed threats can easily exploit.
The cost of this is significant. The average global enterprise loses more than $370 million a year because it cannot modernize legacy systems efficiently, with around 31% of tech resources dedicated to resolving tech debt, while true innovation through new products, AI initiatives, and automation receives as little as 7%.
This is not stagnation; it is regression. And the impact on Vietnamese organizations can be cyclical: when infrastructure becomes more fragile, security incidents become more frequent; when incidents increase, more time, budget, and talent are diverted to maintenance, leaving less capacity for innovation. Meanwhile, organizations with modernized architectures allow AI initiatives to pull modernization forward — using real workloads to justify and accelerate architectural renewal. For instance, 62% of organizations leading in application innovation find it “very easy” to track their current level of security compliance, compared to 35% of those behind schedule.
This makes the fragility of older systems harder to sustain.
Resilience must be engineered, not assumed
For Vietnam’s growth ambitions to truly translate into lasting value, resilience needs to be seen not as a defensive measure, but as a competitive edge – and security will need to be built at the center of the entire system.
Underlying systems need to be secure by design to be resilient enough to support the organization’s growth as conditions change, including the ability to contain failures before they spread. For leaders in Vietnam, this means designing and building systems strong enough to adapt, contain, and absorb pressure while continuing to operate with confidence. In practice, this will require separating critical dependencies, adding guardrails and policy-as-code to reduce error impact, and regularly testing failure scenarios. It will also be important to have a clearer view of shared control planes, identity dependencies, and pipelines, as well as evidence of failure-mode testing, not just uptime.
In a world shaped by AI and machine-speed risk, the strongest competitive advantage any Vietnamese business can have will be an architecture built to endure. That is why resilience should no longer be treated as a downstream consideration; it must be architected from the very beginning.
By Kenneth Lai, Vice President, Asean, Cloudflare
The article is also featured on: https://cafef.vn/tham-vong-so-cua-viet-nam-can-duoc-xay-dung-tren-nen-tang-vung-chac-khong-chi-don-thuan-thuc-day-toc-do-ung-dung-cong-nghe-188260824160839086.chn



