Deterring cyberthreats through digital identities and advanced technologies
David Chan
SCAM cases have become all the rage in Singapore in recent years. In 2021, over 23,000 scam cases were reported -- more than half of all reported crime in the year. The most devastating incident, which came to light towards the end of the year, saw scammers walk away with close to S$14 million – with some victims giving up their entire life savings.
If there is (even) a silver lining to be found here, it is that the prominence of these incidents has surfaced more conversations around the importance of cybersecurity and cyber hygiene, raising greater awareness on how we can better protect ourselves.
But while Singapore has gone to great lengths to push out anti-scam and phishing prevention campaigns to educate its citizens, human error remains inevitable, which threat actors can take advantage of. The onus lies with corporations whom we entrust our data with, to ensure a strong security posture that deters cyberthreats.
Protecting digital data with a national digital ID system
Cyberthreats will only grow in prominence, and threat actors will become more emboldened. While we can revert to the pen-and-paper era to avoid the risks of cyberthreats, that would only stifle our progress as a society. Besides, after enjoying the convenience of having all our important documents at our fingertips, there is no going back to the old ways.
What organisations need is a trusted digital ecosystem where data and services transcend the boundaries of an entity, equipped with the highest level of security to mitigate cyberthreats.
A tall order, but thankfully, organisations in Singapore don’t have to reinvent the wheel. They can instead just leverage the nation’s digital ID system, Singapore Personal Access (Singpass), to authenticate users accessing its services. Businesses and consumers can be assured that government-issued digital IDs are verified and authenticated to a high degree of assurance.
Most recently, Singapore also announced that users with valid Corppass accounts would be able to view their business entity information on their Singpass app. This integration not only enhances convenience and accessibility for citizens, but improves authentication processes and security for business owners. Organisations with Myinfo Business Integration stand to benefit from having more seamless, secured data management and digital transactions for its users.
Trust in the machine – a safety net if all else fails
As with any technology, overreliance on any single solution can be a weakness. Organisations will need secondary security measures to prevent unauthorised access to the few sophisticated hackers that slip through. This is where advanced technologies like artificial intelligence and machine learning (AI/ML) come in as a safety net.
Acting as a fraud detection system, AI/ML serves as an additional layer of security, identifying malicious patterns of behaviour using big data sets of security events. AI/ML systems can also capture the more dynamic aspects of a user’s digital identity and behavioural ‘signatures’ – typing rhythm, mouse movement, geolocation, the usual pages and links that we access – which are significantly harder to fake. Suspicious activities can be detected, which would alert the organisation to restrict access to the account or prompt the real user to investigate. Compared to adaptive security methods that constantly interrupt the user’s activity to verify their identity, behavioural analytics solutions work unobtrusively to continuously authenticate users.
Malware-like bots, fraudsters with stolen credentials, and even those wielding remote access tools, all stick out like a sore thumb when viewed through the lens of behavioural biometrics as emulating behavioural characteristics is close-to-impossible.
The tactics and tools of cybercriminals change constantly. With thousands of new threat variants emerging daily, it is challenging to keep up. AI/ML helps cybersecurity systems predict threats and empower greater proactivity instead of simply responding to attacks.
Takes two to tango
At the end of the day, the responsibility to protect oneself from becoming a victim of cyberattacks falls on both consumers and organisations.
For a start, we need to be up-to-date with the latest cyberthreats and take a cautionary approach when it comes to sharing personal information. Organisations will also need to step up as custodians of information and data that customers trust them with, keep up with the latest cybersecurity trends and threats, and adopt advanced cybersecurity solutions.
Threat actors can and will continue to poke at the weaknesses of organisations and consumers to achieve their goals. But taking a proactive stance can put us ‘one step, two steps’, ahead of them.
The writer is managing director of Adnovum Singapore
TRENDING NOW
‘We don’t want to stay as we are’: CEO Patrick Ng builds a more resilient Huationg
URA to review guidelines on floor space to give developers more design flexibility: Chee Hong Tat
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
32 companies, 6 individuals bag accolades at Singapore Corporate Awards 2026