Rising cyber threats demand a new approach to cybersecurity
RUSSIA’S invasion of Ukraine has dominated news coverage since the first tanks rolled across the border in February 2022. What went much less publicised was the cyber conflict that preceded the invasion, with a wave of persistent cyber attacks in the months before the conflict disrupting Ukrainian critical infrastructure and, in some cases, taking them completely offline.
The Ukrainian networks had likely been infiltrated even earlier, to gather vital intelligence and prime them for disruption. This ongoing cyber conflict is but the latest in a series of episodes highlighting the growing threats emerging in cyberspace. Defending Singapore’s interests against cyber threats, whether from nation-states or other malicious actors, is increasingly vital, and yet getting ever more complex and challenging.
The number of potential avenues of attack that bad actors can exploit has grown with the rise of digitalisation in everyday life. There are expected to be over 75 billion connected devices globally by 2025, encompassing not just smartphones and computers, but also operational technology (OT) key to the functioning of industrial infrastructure including energy plants and water utilities.
Many of these systems are supported by, or interface with, a common set of underlying ‘linchpin’ or platform hardware and/or software solutions. A vulnerability in a single linchpin can thus open up a large number of devices and organisations to attack. For instance, 18,000 organisations globally—including Fortune 500 companies like Microsoft, Nvidia, Intel, and US government agencies such as the Department of Homeland Security and Treasury Department—were affected by the hack of a single US technology company, SolarWinds, because it provided network monitoring and IT administration tools widely used by hundreds of thousands of organisations. These ‘cyber supply chain’ risks are extremely difficult to secure, given the many underlying layers of hardware and software which bad actors can target.
Not only are the potential avenues of cyber attack growing, the potential consequences and costs of such attacks are also expanding significantly. Digital devices are increasingly key to the effective functioning of essential sectors such as finance, energy, aviation and others, and cyber-attacks on such critical infrastructure can fundamentally disrupt our lives. In 2021, hackers gained access to the networks of Colonial Pipeline, the operator of the largest fuel pipeline in the US. Colonial had to shut down its entire gasoline pipeline for the first time in its 57-year history, resulting in fuel shortages and higher fuel prices across the US East Coast for a week.
Preparing Singapore for its cyber future
As one of the most connected and digitised countries in the world, Singapore is highly exposed to cyber threats. Indeed, according to a Cisco survey of Asia Pacific businesses released in 2021, two in five SMEs in Singapore suffered a cyber incident over a period of 12 months from September 2020 to 2021. This rapidly changing cyberthreat landscape demands fundamental changes in how organisations in Singapore approach cybersecurity.
First, we need to move from manual, episodic security assessment of our nation’s digital inventory—both hardware and software—towards a more automated, continuous approach. Currently, many organisations conduct security reviews of their digital inventory only episodically, highlighting the need for fresh approaches to existing manual processes that may buckle under a constantly growing digital inventory. Automated tools are emerging that allow organisations to develop a continuous picture of changes in their digital inventory, and automatically alert them to risks—for example negative information about a vendor in public news feeds.
Second, we need to move from focusing only on the security of ‘Tier 1’ vendors that we have a direct contractual relationship with, towards a deeper view of risks within the fuller cyber supply chain, including sub-vendors in Tier 2, Tier 3, and so on. To do this effectively with limited resources, we need to utilise tools that automatically and continuously map out vendor and sub-vendor relationships based on various data sources, and adopt a risk-based approach that focuses on developing a more accurate, detailed supply chain picture for the most critical or widely used Tier 1 vendors.
Third, we need to move from a reactive approach of dealing with cyber threats or vulnerabilities as they arise, towards a more proactive and comprehensive approach of preventing, anticipating, and containing these threats. Such an approach could include strengthening security awareness training platforms for employees, and the use of cyberthreat intelligence and active network monitoring tools.
At a sectoral and national level, we also need to break down siloes between organisations, so that all parties supporting Singapore’s critical sectors can share information and collaborate in dealing with cyber threats. For instance, should a linchpin hardware or software supplier suffer a cyber-attack, it is vital to have mechanisms at the national and sectoral level to identify which organisations within each essential sector are using that supplier, so that they can be forewarned, and any disruption to essential services can be managed and contained.
Many organisations today are understandably cautious about disclosing information on their digital inventory, and particularly whether they have suffered any cyber breaches, but a lack of transparency and information-sharing leaves all organisations less prepared for incoming cyber attacks. This new approach to cybersecurity will require businesses and other organisations to adopt not only new tools and processes, but also a new mindset towards partnership with other organisations facing similar threats and challenges.
There are ongoing national efforts to educate businesses on how they can better prevent, anticipate, and contain cyber threats in a more complex threat landscape. These also look to equip them with the necessary toolkits and playbooks, and engender information-sharing and collaboration needed for an effective national response to cyber threats on critical sectors.
One key element in this effort is the newly released Critical Information Infrastructure Supply Chain Programme—a multi-faceted national programme to enhance visibility and management of risks, improve cybersecurity education, and create structures for local and international stakeholders to collaborate on improving cyber supply chain resilience. The programme includes, for instance, a standardised cyber supply chain risk assessment toolkit, certifications for vendors that meet baseline cyber supply chain requirements, and a learning hub for sharing of cyber supply chain risk management best practices.
The programme has been developed with the expertise of the private sector as well as best practices from the many different countries grappling with these cross-cutting and constantly evolving challenges. Ultimately, however, it is the willingness of businesses and organisations in Singapore to transform their individual approaches towards cybersecurity, and partner with each other, that will determine the extent to which the country’s cyberspace can be kept safe and secure.
Embracing this new approach towards cybersecurity offers three win-win-win benefits for businesses. Firstly, the approach reduces the risk of business disruption and loss of customer trust for their business. Secondly, the scale achieved through collaboration will result in cybersecurity cost savings in the long term. Ultimately, businesses will also enjoy a safer and more secure cyber ecosystem in Singapore in which to operate, with minimised disruptions to essential supporting services.
To achieve overall cyber supply chain resilience, it will be critical that all parties in the ecosystem—regulators, businesses, and organisations —work together to each do their part to enhance Singapore’s cybersecurity stance.
The writers are from Boston Consulting Group, where both are managing director and partner.