Geopolitics adding to cyber risks; Singapore companies are attractive targets: cybersecurity practitioners

Yong Jun Yuan
Published Mon, Jan 22, 2024 · 05:00 AM
    • Small companies are attractive to hackers as they often have inadequate cybersecurity, making them easier targets.
    • Small companies are attractive to hackers as they often have inadequate cybersecurity, making them easier targets. PHOTO: BT FILE

    WITHIN the first two weeks of this year, three Singapore-listed companies announced that they had fallen victim to ransomware attacks.

    Security solutions provider IPS Securex , shipbuilder ES Group and restaurant operator RE&S all announced that their servers had been compromised.

    They join a growing list of relatively small companies that are attractive targets for hackers.

    Cybersecurity professionals said that as the cost of mounting such attacks falls and geopolitical tensions rise, more companies could be targeted.

    Foo Siang-Tse, senior partner of cyber at IT-services provider NCS Group, said: “The modus operandi of attackers is to target as many companies as possible as the marginal cost of doing so is very low.”

    Malware toolkits and other software tools to engineer an attack are so widely available and so cheap that it takes very little to achieve economies of scale.

    “Attackers do not discriminate based on size,” he added.

    In fact, small companies are particularly attractive to hackers. They often have inadequate cybersecurity, making them easier targets, said Ensign Infosecurity’s vice-president of advisory, Teo Xiang Zheng.

    Smaller companies are also a great entry point into a larger company, as these small companies tend to be vendors and sit within a larger company’s supply chain.

    Horangi Cybersecurity chief executive and co-founder Paul Hadjy said the company has observed more attacks on core infrastructure and supply chains. “By compromising a vendor within the supply chain, attackers can gain access to numerous clients; and the damage can be far-reaching.”

    IPS Securex, for instance, is a provider of homeland-security products to checkpoints and law-enforcement agencies, as well as government bodies in the Asia-Pacific.

    On Jan 2, the company said its business operations were not significantly impacted, and that there was no evidence of data having been stolen in the attack.

    The Singapore factor

    Ensign’s Teo said there has been a recent rise in global cyberattacks, with so-called “hacktivists” being motivated by the Russia-Ukraine and Israel-Hamas conflicts. The term is derived from the words “hack” and “activist”, and refers to those who compromise computer systems in the name of a political or social cause.

    Teo noted that Singapore experienced targeted cyberattacks from Malaysian and Indonesian hacktivist groups in the pro-Palestinian #OpSingapore campaign, which resulted in Distributed Denial of Service attacks, data breaches and website defacements.

    Palo Alto Networks regional vice-president for Asean, Steven Scheurmann, said Singapore has “added allure” for hackers because it is a major business hub; many organisations have located their global or regional headquarters in the city-state.

    Best practices

    Investors seeking to stress-test companies should ask management how they are managing their cybersecurity risks.

    “Companies often do not spend enough time and resources to analyse the outcomes of their tabletop exercises. Analysing the results can provide key insights on the cybersecurity vulnerabilities of each organisation,” said Ensign’s Teo.

    He added that companies should document asset inventories, map out dependencies and quickly respond to vulnerabilities.

    Palo Alto’s Scheurmann said a robust and holistic security system should include multiple layers of defence that include firewalls, intrusion-detection systems and secure configurations.

    “It must be noted that responding to a cybersecurity incident is not just a reactive approach, but also about detection and prevention,” he said, adding that organisations should consider implementing artificial intelligence and machine-learning solutions to detect anomalous patterns and stop threats in real time.

    Horangi’s Hadjy recommends that companies have backups of their data – backups that must be regularly tested to ensure they are not corrupt. Periodic restoration exercises are needed, so everyone understands what they must do when data restoration has to be carried out.

    He advised against paying ransomware attackers for ethical and legal considerations.

    One concern is that this could motivate malicious actors to organise further attacks. From a corporate-governance perspective, such costs could be difficult to account for and be a loophole for fraud, he said.

    “Some countries can prosecute companies for paying these gangs, because it’s legally prohibited. Also, banks can flag such transactions and stop doing business with companies.”

    Ensign’s Teo said there is also no guarantee hackers will honour their promises, as there are many stakeholders in the ransomware business. Some stakeholders may sell the data even as a ransom payment is being negotiated.

    “If (companies are) contemplating payment, negotiation could adjust the amount. However, smaller organisations risk exacerbating the situation and escalating problems due to a lack of expertise and understanding of the consequences,” he said.

    Zscaler chief security officer Deepen Desai, however, said payment may sometimes be unavoidable.

    “If the stolen data or information can result in physical security risks, then you may choose to negotiate and take steps to prevent a public leak,” he said. “Regardless, your organisation should always work with law-enforcement agencies and security experts when responding to cyberattacks.”