The battle for sovereignty is now fought online
JONATHAN TAN
The ongoing war between Russia and Ukraine has captured the unwavering attention of the globe. While the news media was initially focused on Russia’s superior firepower, the narrative soon incorporated a new dimension — cyber attacks.
This war is symbolic of the zeitgeist we live in. While the phrase “nation-state attacks” once conjured images of physical warfare with bombs, guns, and fire, conflicts are now increasingly being waged on the cyber front as well.
Today, nation-state attacks can also refer to an onslaught on a country’s critical information infrastructure, which would weaken its government, military, and businesses.
Our Advanced Threat Research Report found that in Q3 2021, the government was the fourth most targeted sector by ransomware attacks. As the pandemic forced us to move various aspects of our lives online -- education, healthcare, shopping, and more -- governments and their operations were not spared either. Government agencies everywhere played a key role in accelerating their nations’ digital transformation, and in doing so, had to transform their operations first.
Digital transformation and serious vulnerabilities
One of the most notable shifts in government operations was the move to the cloud. For late adopters, this entailed implementing cloud infrastructure and technology. For others, this meant integrating deeper into the cloud to improve their processes and services.
Singapore was an early adopter of cloud. In October 2018, long before the pandemic struck, Prime Minister Lee Hsien Loong announced that the government would move part of its IT systems onto commercial clouds. The republic has been well-prepared for potential attacks on this off-site technology, having established its very own Cybersecurity Agency since 2015.
But this foresight was not always replicated elsewhere. Take the US for example -- we found that as many as 76 per cent of US government agency respondents agree that currently there is no real consistency as to how organisations respond to a cyber incident. Closer to home in Southeast Asia, Indonesia experienced a data breach in May 2021 where information on 279 million people was stolen from the social health security administration.
To keep pace with increasingly sophisticated and impactful cyber-attacks, nation states must recognise that their digital transformations not only boost economies but also increase the vulnerabilities they are exposed to.
The more technologies government agencies adopt, the larger the surface area for potential attackers to strike at. Territories that need to be guarded are no longer limited to land, air and sea. Digital territories may be invisible, but the ramifications of risking any breaches are extremely real.
It’s become clear that even private software companies struggle to keep up with cyberattacks -- the SolarWinds Sunburst hack is testament to this. We can thus assume that governments, whose main job is to govern, would grapple even more with defending critical information infrastructure (CII).
To that end, the Singapore Armed Forces (SAF) will establish a new Digital and Intelligence Service (DIS) by the fourth quarter of 2022, the fourth military service alongside the existing Army, Navy, and Air Force. The DIS will be responsible for addressing emerging threats in the digital domain by providing accurate, relevant and timely early warning and operational intelligence. But this isn’t enough.
Government leaders are also stressing the need to secure and protect digital infrastructure beyond CII and stay updated with the latest developments in cybersecurity. But chances are, if governments are still using static and siloed security solutions, hackers and malicious parties will still be one step ahead.
Enhance cybersecurity governance to address emerging cyber threats
Nation states, even technologically developed ones like Singapore, need to monitor and protect an ever-expanding threat surface without overburdening already stretched IT teams. What this calls for is a more holistic and integrated approach to cybersecurity.
To meet this growing demand, Extended Detection and Response (XDR) has emerged as a new security paradigm. Combining data from the whole landscape of IT assets, including mobile devices, emails and cloud infrastructure, XDR aims to simplify security management, enabling organisations to identify and stop threats with higher efficacy.
Governments will also have to keep pace with the latest cyber-attack campaigns and vulnerabilities. This is where public-private partnerships to facilitate data sharing must come into play. Information sharing has historically been impeded by privacy concerns or contractual obligations, but such initiatives are key to gaining the visibility needed to catalyse the shift from a reactive to proactive cybersecurity stance.
As threats on nation states become increasingly sophisticated and unwieldy, governments need to find ways to hit these moving targets effectively.
Nation states will only be able to keep up if they adopt cybersecurity defences that move as quickly as the threats they face. Only then can they effectively navigate the digital terrain, and build a safer and more resilient digital environment that will benefit and protect their people.
The writer is managing director, Asia, at Trellix
TRENDING NOW
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
What role can Japan play in Asean’s future?
From folding clothes to factory work: Why China is sending humanoid robots to school