Building on Asean’s cyber-cooperation momentum
THE theme for Indonesia’s Asean chairmanship this year is “Asean Matters: Epicentrum of Growth”. This would certainly involve the expansion of our digital economies.
However, cyberthreats and risks pose formidable challenges to our digitalisation journey. To reap the full benefits of digital developments, Asean must work together to improve our collective cybersecurity.
There are at least two areas of priorities. The first is to strengthen cybersecurity cooperation and resilience regionally. The second is to support the establishment of a rules-based multilateral order in cyberspace internationally.
In fact, regional cooperation on cybersecurity is going well. In 2017, we developed the Asean Cybersecurity Cooperation Strategy to set out the roadmap for achieving a safe and secure Asean cyberspace. To keep pace with the changing landscape, the strategy was updated in 2021, and is planned for a mid-term review in 2024.
These efforts build on even earlier foundations and complementary initiatives. Since 2006, the Asean Computer Emergency Response Team (Cert) Incident Drill led by the Cyber Security Agency of Singapore (CSA) has taken place every year, even during the Covid pandemic.
Following the 2020 SolarWinds hacking incident, we also established the Asean Cert Information Exchange Mechanism to facilitate timely information-sharing.
We should build on the momentum to advance our cooperation even further. There are three ways to do so.
First, we should strengthen cyber-incident response in Asean. Cyberthreats do not respect borders. It is therefore important for all our Certs to work together to quickly share information and warn each other as early as possible. An Asean Regional Cert is in the works.
Second, we should strive to develop standards. Adopting baseline technology standards is vital to building confidence among businesses and users.
One rapidly growing area is the Internet of Things (IoT).
It has been estimated there could be some 50 billion IoT devices in use worldwide by 2030. Yet, many of these devices are developed without proper cybersecurity features because developers tend to prioritise speed to market and cost.
Imagine if smart home security systems are hacked by burglars or medical IoT devices are exploited to give incorrect readings. This is why Singapore introduced the Cybersecurity Labelling Scheme for IoT devices, to encourage greater awareness and the development of more secure products.
CSA is actively working to establish mutual recognition arrangements with international partners, and developing an international standard, ISO 27404, to define a Cybersecurity Labelling Framework. The ISO standard will facilitate take-up in more countries.
Third, we should enhance capacity-building. Singapore is keen to contribute to regional capacity-building efforts. We will take a practical, multidisciplinary and multistakeholder approach and organise our programmes through the Asean-Singapore Cybersecurity Centre of Excellence (ASCCE). Our funding commitment of S$30 million has been extended by another three years.
We are also expanding the ASCCE programme. With the launch of the SG Cyber Leadership and Alumni Programme, participants from countries beyond Asean can soon participate.
This will better equip our officials against emergent threats and enhance relationships, which will in turn facilitate regional and international cooperation.
Asean has long recognised that it is in our interest to cooperate internationally to establish a rules-based multilateral order in cyberspace.
In 2018, during the Asean Ministerial Conference on Cybersecurity (AMCC), Asean ministers subscribed in-principle to the 11 voluntary, non-binding norms for responsible behaviour in cyberspace, which were recommended by the 2015 UN Group of Governmental Experts. Asean was the first regional grouping, and remains the only regional grouping, to make this commitment to the norms.
Presently, Singapore and Malaysia, together with other Asean member states, are putting together a norms implementation checklist as a non-binding reference.
This serves to move us towards taking practical and concrete steps in implementation.
These discussions will also take place at the United Nations Open-ended Working Group (OEWG) on the security and use of infocomm technologies, which Singapore is honoured to chair.
The UN is an inclusive platform where all countries have a voice. We therefore welcome the adoption of the OEWG’s second annual progress report.
The discussions leading up to it were not easy, which makes the adoption even more remarkable.
Important initiatives such as the Global Points of Contact directory will also be essential in facilitating coordination and communication between member states, especially in times of crisis.
The AMCC’s accomplishments are the result of our shared commitment towards maintaining progress and advancing cooperation for a secure and resilient cyberspace.
There are immense opportunities presented by digital technologies and innovation. Getting cybersecurity right is as challenging as it is essential.
But with the right level of ambition and commitment, progress is well within reach.
The writer is Singapore’s Minister for Communications and Information. This is an abridged version of her opening address at the Singapore International Cyber Week (SICW) Asean Ministerial Conference on Cybersecurity held on Oct 18, 2023