Banks, Shopee welcome CSA’s new safe app standard

Yong Jun Yuan
Published Fri, Jan 12, 2024 · 04:54 PM
    • Security controls within the CSA's standard include measures that prevent bad actors from tampering with or reverse-engineering apps.
    • Security controls within the CSA's standard include measures that prevent bad actors from tampering with or reverse-engineering apps. PHOTO: BT FILE

    BANKS and e-commerce app Shopee said that they welcome the Cyber Security Agency of Singapore’s (CSA) safe app standard, which was published on Wednesday (Jan 10).

    OCBC group head of information security and digital risk management Thomas Kok emphasised the importance of having safe and reliable digital products, including apps.

    “Having a common benchmark and sharing of best practices to achieve this desired outcome, via CSA’s safe app standard, is a positive move and will serve to enhance digital trust with the public,” he said.

    Meanwhile, a UOB spokesperson said that the bank welcomes the sharing of best practices under the standard, and that the bank “constantly monitors the evolving threat landscape to enhance our security controls to protect customers”.

    It also highlighted the security controls that it has put in place, such as SMS notifications when new payees are added.

    Furthermore, it said that it will continue to work closely with the regulator, law enforcement agencies and the industry to fight against scams.

    A Shopee spokesperson said on Friday that the company welcomes CSA’s standard, and that it has proactively adopted industry-standard measures to protect buyers and sellers as part of its app development process.

    “For example, control measures such as two-factor verification for high-risk transactions are already implemented in our app as an added layer of security to protect our users from unauthorised actions,” the spokesperson said, adding that the company will continue to improve its capabilities to remain a trusted marketplace.

    Cybersecurity experts have warned that there could be additional costs incurred as companies try to meet the CSA’s standard.

    Security controls within the standard include measures that prevent bad actors from tampering with or reverse-engineering apps.

    The standard targets apps that perform high-risk transactions, such as banking and e-commerce apps. Developers are encouraged to adopt the new standard to protect their apps from common malware and phishing attacks.

    Malware scams became more prevalent in 2023, with over 1,400 victims losing at least S$20.6 million between January and August, according to police data.

    In August 2023, OCBC was the first among the trio of local banks to introduce measures to prevent its mobile app from working when it detects malicious apps on the same device. Other banks have since introduced similar features with their mobile apps.