Protecting data as the new gold
Companies must do more to protect themselves against cyberattack, but why are their defences often not up to scratch?
GOH, a former MyRepublic mobile subscriber, was one of nearly 79,400 other customers who had their personal data potentially accessed by hackers when the telco's third-party servers were compromised on Aug 29 this year. He had ported his mobile number to MyRepublic to take advantage of its cheaper rates, but has since ported back to his previous telco after the breach.
Data, including scanned copies of both sides of National Registration Identity Cards (NRICs) were potentially exposed in the MyRepublic breach. The information had been used to verify the identity of customers applying for their mobile services.
"As a service provider, I would have expected them to have higher (levels of) security," Goh says. Since the incident, he has received quite a number of scam calls, although the company says there was no evidence that the personal data had been misused when it publicly disclosed the hack on Sep 10.
"I asked them if they would take responsibility for any outcome that would happen in relation to the breach but... they just gave template answers," Goh says.
The company's offer of half-a-year of credit monitoring through Credit Bureau Singapore (CBS) was cold comfort as bad actors could still use his details to take out loans from unlicensed moneylenders.
It appears that companies have been falling victim to cyber attacks on their data at a faster clip. Statistics from the Cyber Security Agency of Singapore (CSA) show that there were 89 cases of ransomware attacks reported to the agency last year, up from 35 in 2019. In the first half of this year, 68 cases were reported, more than double the 31 cases reported in the same period last year.
Experts The Business Times spoke to pointed to the increased adoption of digital tools during the pandemic as well as increasingly sophisticated hacker gangs for the increase in cases. They also agreed that companies need to do more to protect themselves against attacks on the data that they have collected.
Veritas Technologies vice-president and managing director for Asia South and Pacific region Andy Ng says that when the Covid-19 pandemic hit, many companies accelerated their plans to go digital so that employees could work from home. This resulted in a large increase in devices that needed to be secured, he says. He also notes that the average Singaporean company uses 14 cloud providers, widening the area over which data is shared between employees.
Ang Yuit, Association of Small & Medium Enterprises (ASME) vice-president for strategies, development and digitalisation, says 80 to 90 per cent of ASME members adopted digitalisation initiatives during the pandemic. These initiatives range from leveraging online marketing tools to improving processes with digital alternatives, he says.
Ang likens the adoption of these new tools to moving a company into a new building. While companies may consider having security cameras and security guards in place to protect the building, many of them are not thinking about cybersecurity in the same way.
He has also observed that many companies never progress beyond the "trying" phase of adopting new digital tools. "They may try, find that (the initiatives) work quite well and they hope that they don't have to invest further, so that may be an issue," he says.
"If the initiative works and then you start to make it a more permanent thing, then you need to change your posture," he adds.
Assume a hostile environment
Adding fuel to fire is the emergence of cyber cartels that are getting more sophisticated in the work that they do.
VMware principal cybersecurity strategist Rick McElroy notes that cyber cartels have been acting like businesses in the way they market their services with "100 per cent payouts" and how they provide customer service to their clients.
According to a Wall Street Journal report in October, it was found that so-called "ransomware-as-a-service" provider Fin7 has even been recruiting by posing as legitimate businesses online with job listings. The Russian hacker group is behind BlackMatter, a threat actor that stole 500,000 pieces of contact information for sales leads from Temasek-backed payments platform Pine Labs in August this year. The same hacker group's software was also linked to the Colonial Pipeline hack in May this year, which led to fuel shortages in the East Coast of the United States.
"For the most part, companies operate on the premise that the Internet is a safe neighbourhood and it's really not. It's a very hostile environment," McElroy says.
Are fines sufficiently deterrent?
In November last year, amendments to the Singapore Personal Data Protection Act (PDPA) were also passed. Among changes made to the law was an increase in the maximum amount a company can be fined for a data breach to 10 per cent of its annual turnover in Singapore or S$1 million, whichever is higher.
Yet, fines doled out to companies have regularly fallen short of the S$1 million limit that the Act previously had.
SingHealth and the Integrated Health Information Systems, Singapore's public healthcare sector's IT provider, were fined S$250,000 and S$750,000 respectively for a cyber attack that saw the theft of 1.5 million patients' names, NRIC numbers, addresses and other information.
Since then, fines have generally been of much smaller quantums. Hotel booking site RedDoorz was fined S$74,000 for leaking 5.9 million customers' details, including their contact numbers, email addresses, dates of birth and hashed passwords.
The Personal Data Protection Commission (PDPC) says that it had arrived at the fine quantum after considering the pandemic's impact on the hospitality industry. Other mitigating factors included the fact that they had cooperated in investigations and had conducted periodic security reviews, even if they did not check the affected systems.
The Safra National Service Association was previously fined S$10,000 for sending out two separate batches of e-mails with spreadsheets containing the data of 780 members of its shooting club. Data in the spreadsheets included NRIC numbers, dates of birth, phone numbers and addresses.
Tech company Creative Technology was fined S$15,000 for failing to protect the data of 484,000 of its users on its online support forum too, resulting in the theft of usernames, passwords and, in some cases, names and e-mail addresses as well.
In comparison, British Airways was fined £20 million (S$36.7 million) by the UK's Information Commissioner's Office (ICO) for a data breach in 2018 that affected personal and credit card data under the General Data Protection Regulation (GDPR), which governs the personal data of all individuals located in the European Union. It allows companies to be fined up to 20 million euros (S$30.79 million) or 4 per cent of their worldwide turnover for breaches, whichever is higher.
InCorp Global director of business advisory Dorriz Tay says that penalties under the PDPA should be higher for companies that hold more customer data, or those who leak more sensitive information such as credit card numbers.
"There are a few cases recently for which we are still waiting for the outcome of investigations and the actions that PDPC could take," she added.
Hoi Wai Khin, director of business consulting at RSM Singapore also says that larger companies should be penalised to a larger extent, although some leniency could be applied when judging SMEs as they face challenges on multiple fronts.
"For big organisations, we should (expect harsher fines) because they have the processes in place, the governance and the resources that they should put in. If there's a breach, it should not be excused," he says.
"Nevertheless, SMEs should also not use this as an excuse to say 'I've got no resources'. They still need to do their part as it's the law, and definitely there will be penalties," he says.
Lim Kian Kim, partner at Clayton Law, says that a framework or a set of guidelines could help companies and the public better understand how the PDPC arrives at its fine quantums. (see amendment note)
More than just penalties
Still, deputy commissioner of the PDPC Yeong Zee Kin says that the fines should not be seen in isolation as companies lose productive man hours to investigations into the breach and pay legal costs when breaches occur. He adds that companies should be wary of the reputational impact of such breaches, which could cost them future business opportunities.
"Don't look at this as an investment in security, right? Look at it as an investment in your reputation and trust of your consumers. You have one bad case, a newspaper article up, the loss of commercial reputation... definitely it will have an impact," he says, adding that companies that only consider the financial penalties are too short-sighted.
Aside from Pine Labs, other companies have also seen data leaks this year, with a range of different types of data being leaked.
In the same month, Eye & Retina Surgeons also fell victim to a ransomware attack affecting 73,500 patients' personal data and clinical information. Insurer Tokio Marine Insurance Singapore was also hit, although it said then that customer information and confidential information were not compromised.
Throughout 2021, telcos MyRepublic, StarHub and Singtel announced that customer data in their possession had been leaked.
In MyRepublic's case, scanned copies of both sides of customers' NRICs were leaked, while Singtel lost personal data from customers during a breach of its secure file sharing service provider Accellion's services. StarHub too says that IC numbers, mobile numbers and e-mail addresses belonging to some of its customers had been leaked.
Notably, StarHub is certified under the PDPC's Data Protection Trust Mark (DPTM), which was introduced in 2019 to recognise companies that have put in place data protection regimes to comply with their PDPA obligations.
Still, the PDPC's Yeong says that the DPTM does not give companies a free pass and the facts of the breach will be taken into account.
"The DPTM only gives you the assurance that the (right) practices are in place, you are exercising those practices, and that you have an external auditor to keep an eye to make sure that you're doing those things. It means that you're more ready, but it doesn't mean that you're immune (to breaches)," he says, adding that the commission may consider accepting an undertaking from an affected company if it meets their enforcement objectives.
Such an undertaking - in the form of a plan to address the immediate breach and address any systemic shortcomings - could be accepted in place of the full investigation process, which may lead to other financial penalties, directions to improve their processes to comply with the PDPA or both.
Managing the costs of protection
While cost remains an issue for smaller companies adopting new technologies, experts say that these costs can be managed.
The Infocomm Media Development Authority (IMDA) has a programme called the Data Protection-as-a-Service for SMEs (DPaaS@SMEs), which helps companies set up protections. These include appointing a data protection officer (DPO) responsible for ensuring the company's compliance to the PDPA as well as creating a data inventory map to understand the type of sensitive information that they collect so that they can protect such data with the necessary measures.
Rachel Ler, vice-president and general manager of Commvault Asia Pacific and Japan, points out that different forms of data warrant different levels of security protection. For example, NRIC numbers, which are personally identifying and cannot be changed, deserve an extra layer of protection.
"We all have smartphones, we generate data, but not all data on our phones are equal right? Organisations really need to take a holistic view around data categorisation," she says.
BT understands that the cost of the DPaaS@SMEs package can range from S$10,000 to S$30,000, depending on the number of employees a company has as well as the amount of data that they collect.
Lionel Tan, partner at law firm Rajah & Tann, noted that companies that engage in business-to-consumer sales such as e-commerce tend to collect more customer information and face higher fees in the process. Tan suggests that one way companies could guard against employee complacency could be through fake phishing e-mails sent through the company's email network to test ability to respond.
Companies can also take inexpensive steps to protect themselves from data breaches.
VMware's McElroy notes that managed detection and response service costs come down to as low as US$5 per device. Such services can detect security threats to a company's networks and analyse cybersecurity incidents that may happen.
Deputy head of National University of Singapore's (NUS) department of computer science and principal investigator at NUS Centre for Research in Privacy Technologies (N-CRiPT) professor Anthony Tung also notes that companies should set up virtual private networks to ensure that their internal resources are not directly connected to the wider internet.
Aside from adopting these paid solutions, Veritas' Ng also recommends that companies delete data that they no longer need, even if storage costs are getting cheaper.
"We've actually had a few very large customers literally deleting terabytes and terabytes of data... that means they know exactly what those data are, they can go in and just say 'I'm deleting this forever'," he says.
Associate professor at the School of Computing at NUS Chang Ee-Chien, who is also a principal investigator at N-CRiPT, believes that companies need to restructure their IT security teams to ensure that they do not put all their eggs in one basket, aside from adopting technologies like firewalls and virtual private networks to protect their internal resources.
For instance, a single person should not have the administrator passwords for all the services in a company because this creates a single point of failure. If the person's laptop is compromised, then a hacker could potentially log the person's activity and access all the company's systems, creating havoc.
In order for these measures to truly work, Hoi believes that companies need to see data as a profit centre, noting that this would take a mindset shift for companies.
With such a mindset, companies would see the importance of investing resources into protecting their data to increase their competitiveness and provide customers with more assurance that their data is safe.
Agreeing, Rajeev Peshawaria, chief executive officer of Stewardship Asia Centre, says that if data is the new gold, then business continuity planning (BCP) takes on a whole meaning.
Strategies and processes on how to manage data need to come from the top, with chief executive officers leading the charge.
"If your data is hacked, what are you going to do the next morning? It's not something you wait for your CTO (chief technology officer - to call you at 4am and say, 'boss, data is hacked and I need your attention'. That should not be the first time you should be talking about it," he says.
Amendment note: An earlier version of this article incorrectly spelled Lim's name. The article above has been revised to reflect this.
TRENDING NOW
32 companies, 6 individuals bag accolades at Singapore Corporate Awards 2026
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
URA to review guidelines on floor space to give developers more design flexibility: Chee Hong Tat
Chagee, Mixue and Luckin won the market. Sustaining their edge is the harder part