Getting serious about digital identities
Ajay Biyani
IN HIS book ‘21 Lessons for the 21st Century’, noted historian Yuval Noah Harari highlighted how national identities were forged across centuries, “because humans faced problems and opportunities that were far beyond the scope of local tribes and which only countrywide cooperation could hope to handle”.
These national identities slowly evolved from the analogue era into digital identities in recent years, enabling people to easily access digital services and transact with both government and private service providers. But this period also led to an increase in cybercrime and digital identity fraud.
The technological milieu of the evolution of cybercrime goes all the way back to the 1950s -- to the era of ‘phone phreaking’. ‘Phreaks’ - people who had a peculiar interest in the workings of the telephone -- exploited the vulnerabilities in a telephone network to make free calls.
Since then, from phone phreaking to the Morris Worm, from phishing to ransomware to crypto-jacking, cybercrime has grown in size, scale, impact, innovation and sophistication. This progression coincided with the rapid rise in people adopting the Internet.
Today, social media, e-commerce and other online services have made us reckless with the amount of personally identifiable information (PII) that we share online, leading to an exponential increase in digital identity theft. This is largely due to people prioritising convenience over privacy; an Achilles heel we cannot ignore.
Cyber Darwinian contest
Cybersecurity and digital identity theft have become hot topics in recent years. Singapore has been the target of cybercrime in recent years, from the 2018 SingHealth data breach to the OCBC phishing scam more recently. The impact of such breaches can be massive – the cost of discovering and mitigating the breach, damage to the brand, subsequent lost business, and fines levied by regulatory bodies can all be significant.
According to the 2021 ForgeRock Consumer Breach Report, phishing scams, ransomware attacks, misconfigured servers that allow unintended access, and passwords reused for multiple accounts are some of the key contributors that led to unwanted access to sensitive information in Singapore.
Cyberattacks continue to become more sophisticated. Typically, digital attack attempts that are close to the boundaries of vulnerability and uncertainty, such as claiming issues with one’s bank accounts, are more successful with victims ending up clicking a URL and inadvertently sharing log-in credentials.
Over the years, usernames and passwords helped secure access to people’s digital lives. But an ongoing surge in breaches of those very tenets (usernames and passwords) emphasises how going passwordless can help prevent these types of attacks while offering a more secure way of keeping us all safe in today’s increasingly online world.
Robust digital identity practices -- the canary in digital coal mine
The proliferation of digital identity data today has spurred people’s concerns over consent, control, transparency and the ethical use of data. To assuage these fears, organisations need to build privacy and transparency from their technology infrastructure right through to the user experience across different segmented requirements -- people as consumers, people as workers, and people as citizens.
At the same time, the importance of investing in consumer education cannot be understated. I was recently listening to an episode of the Stops Scams podcast, a new series by The Straits Times, about how scammers are reaching out to youths to buy their digital identity credentials. Yes, that’s right -- to buy their digital identity credentials and even bank accounts. To end this, the government machinery and private institutions need to continue with mass awareness programmes because consumers can no longer be absolved of poor digital hygiene.
With the Monetary Authority of Singapore (MAS) introducing new measures recently and the announcement of a framework for equitable sharing of losses, the onus lies on both businesses and consumers to practise good cyber hygiene and safeguard data.
Building tangible trust
Technology plays a key role in combating the rise in cybercrime. Businesses need to ensure updated planning for emergency scenarios, leverage artificial intelligence (AI) and machine learning (ML) technologies to identify anomalies that lie outside normal tolerance at pace and enable contextual and adaptive multi-factor authentication to ensure accurate identification and access.
A strong identity and access management approach uses real-time data and situational context to personalise and protect experiences, as well as solutions that design different authentication journeys for varying security and risk profiles. This helps achieve zero trust for people across their different segmented requirements and, combined with strong user digital hygiene, will help reduce occurrences of digital identity theft.
But the end goal isn’t just to reduce the risk of identity theft but rather to build trust and inclusive growth. Trust is the most important currency in the digital world. A robust identity approach will help build trust across the value chain and accelerate the digital transformation journey - for businesses and for consumers.
The next few years can be the coming-of-age of the region’s digital identity scene and it need not be a Sisyphean task.
The writer is regional vice president, Asean, at ForgeRock
Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.
Share with us your feedback on BT's products and services
TRENDING NOW
‘My grandfather’s legacy’: Sherman Kwek lays out three-year plan for CDL to drive returns
‘How many will survive?’: Bubble fears arise as China’s humanoid robotics face reality check
CDL to hire dedicated CEO for fund management as it steps up push into private funds
Stock to watch: Mapletree Industrial Trust