Case study: Pioneering cybersecurity solutions for mobile
Startup V-Key explains why its offerings and digital capabilities are increasingly relevant.
V-KEY stands out among startups in Singapore. It's among the small, pioneer batch of companies accredited by the government's infocomm arm. It's partnered by several banks and government agencies in the region, and it's backed by Ant Financial, the payments affiliate of none other than Alibaba.
Founded in 2011, V-Key develops cybersecurity solutions for mobile applications. Asked what inspired it, the startup says it was the struggles faced by co-founder Benjamin Mah's father when he was making online transactions on his mobile device.
Mr Mah's father had to juggle between several devices, screens and codes - including fumbling with a hardware token, entering a code into an app, reading from an SMS in another app, and then reverting to the first app.
The younger Mr Mah, already then with over 16 years of cybersecurity experience behind him, thus wanted to ease this frustration and inconvenience that his father and many others faced while making transactions on their mobile devices.
He tells The Business Times: "My driving concern was that the element of trust while making a material transaction with any third party - be it a bank, government or e-commerce company - should be utterly secure."
This motivation became a personal ambition: to ensure that everyone doing a mobile transaction, even involving as little as a dollar, has it safe and secure. Mr Mah later found business partners in Eddie Chau and Joseph Gan, and V-Key was born.
V-OS, V-Key's core offering, is said to be a virtual secure element. It is patented, and designed to enable and secure a digital world where mobile is the primary mode for interaction and communication. V-OS works by having it integrated into an iOS or Android app using a software development kit. This adds a secure element (comprising a virtual processor and secure data repository) that can be used for any "trusted app".
Uniquely, with V-OS, the app can operate even if the mobile phone has been comprised. V-OS is fully threat-aware and self-defending with in-depth multi-layered protections against advanced threats targeting mobile apps. Mr Mah notes: "Call it what you will: military-, government- or banking-grade. V-Key aspires to the highest grade of security for all its customers using V-OS as the core security element."
V-Key says its cybersecurity solutions and digital capabilities are increasingly relevant for three reasons. First, with the exponential increase in the use of smartphones and mobile apps comes the corresponding increase in threats, malware and security risks to devices. "Consider, for example, the use of mobile devices on Single's Day on Nov 11, 2016, in China. Some 82 per cent of the almost US$18 billion in transactions in 24 hours were made using mobile devices, although the devices are fundamentally insecure."
Secondly, hardware tokens are problematic. They are inconvenient to use, can be lost and will need to be replaced. Once stolen, there is no security around the token. All that a malicious user needs is a username and password, after which they can pretend to be the user, and steal his money. Similarly, there is no additional security on top of a credit card. If one loses a physical credit card such as a Visa PayWave or Mastercard PayPass, anyone who picks it up can start using it. To boot, SMS delivery is not entirely secure, as the SMS itself can be intercepted.
Thirdly, more industries globally - following in the footsteps of governments and banks - are pursuing full digitisation, swiftly converging on building new ecosystems that require a secure digital identity that is conveniently authenticated across platforms.
V-Key explains: "This is where our solutions, built into the app on the smartphone, become more and more relevant in conveniently securing apps on the phone."
The startup's focus for the next decade is globalisation - expanding its presence to global financial institutions, payment platforms and governments. It is currently rolling out its solutions across South-east Asia, and says that in fact, any connected device that transmits secure data or requires identification or verification is a candidate for V-OS.
In Singapore, V-Key is preparing to grow its team to 80-strong by the end of 2017. Its current team of 50 comprises more than 30 engineers who work on software security, as well as solution architects, deployment engineers, support officers and management.
V-Key is also enhancing its support capabilities with a new location in Vietnam. It will move its Singapore headquarters to Changi Business Park around the second quarter of 2017, to be closer to some of its regional and global banking customers.
As one of the pioneer batch of companies accredited under the Accreditation@IMDA programme, V-Key says that it has enjoyed a reputation of being a recognised and trusted national brand, and found it easier to make global connections and engagements.
Mr Mah adds: "It has opened up opportunities for us to build relations and win work from both the government and enterprise sectors, locally and globally. This is important as startups need to set their sights to go global from the start."