Cybersecurity as a strategic investment for businesses
Corporate leaders must safeguard public trust and confidence in the digital technologies that their companies will increasingly adopt in the age of Industry 4.0
THE 4th Industrial Revolution, or Industry 4.0, heralds the advent of smart and autonomous systems built upon data analytics and Artificial Intelligence.
With Industry 4.0, there will be more cyber-physical systems, greater use of the Internet of Things, and even an Internet of systems. And 5G - with its promise of significantly faster data transfer and lower latencies - will accelerate this trend.
As enterprises adopt these technologies and evolve new modus operandi, a cyber-attack can profoundly disrupt business operations.
We already see signs of this. Two months ago, Norsk Hydro, one of the world's top aluminium producers, was targeted by a destructive strain of ransomware which disrupted its production lines and forced the company to revert to manual systems and processes. This cost the company up to US$52 million in the first quarter alone.
In the age of Industry 4.0, cybersecurity is fundamental to fostering trust in the technologies that we adopt.
It is this trust that underpins our collective national digital ambitions; without it, those ambitions will be frustrated and remain unrealised.
If we believe that our future prosperity and security is contingent on digital technologies, we must be resolute in our commitment to prioritise cybersecurity as an existential issue that undergirds and enables our future.
Across the globe, this trust has increasingly come under siege. Cyber threats continue to grow in scale and sophistication, resulting in the exposure of millions of personal records.
Core component of doing business
Recognising cybersecurity as a key enabler for our collective digital future, the Singapore government established the Cyber Security Agency (CSA) four years ago to provide dedicated and centralised oversight of Singapore's national cybersecurity functions.
CSA's mandate includes the protection of 11 Critical Information Infrastructure (CII) sectors, which provide essential services such as transport, water, and energy.
The government also passed the Cybersecurity Act last year, which places legal obligations on CII owners to adopt mandatory cybersecurity measures in their systems and conduct regular risk assessments and audits on their CIIs.
However, cybersecurity is not, and cannot be, solely the government's responsibility. Private organisations must also treat cybersecurity as a core component of their business and view it as a strategic investment that underpins business continuity and competitive advantage.
Board chairmen, directors and CEOs have the responsibility to safeguard public trust and confidence in the digital technologies that their companies will increasingly adopt.
To be effective in cyber defence, an organisation's effort must focus on three areas - technology, processes, and people.
First, technology. Organisations can adopt a "defence-in-depth" approach. Today, the norm in many organisations is to monitor their perimeter to stop intruders from getting in.
As cyber-attacks become prevalent, we must assume that attackers may already be in our networks, lying dormant until an opportune moment to strike.
Hence, we have to change the way we design and monitor our networks. This entails assessing what needs to be safeguarded and setting up multiple layers of defence.
Organisations should implement the appropriate technology to not only prevent, but also detect, and respond to cyber-attacks. This includes stronger encryption for data; heightened monitoring of database activity; and an integrated system to rapidly isolate and contain the infected systems.
The measures adopted should be commensurate with the sensitivity of the information. Privileged access to an organisation's "crown jewels" should be accessible to only a tightly-controlled group of people.
The cyber equivalent of tripwires, surveillance cameras and alarms should be in place to monitor access and detect suspicious activity.
Second, on processes. Cybersecurity should be viewed as a risk management issue that requires balancing between security, usability, and cost. It is not just a technical issue, and, as with all high-level risks, it must be managed at the appropriate level of leadership.
Take, for example, the implementation of two-factor authentication (2FA). 2FA enhances security but causes inconvenience and diminishes the user experience.
This can have a real impact on organisations, especially if applied in time-critical operations such as the emergency departments in hospitals.
Decisions that entail a trade-off between security, usability and cost must be made at the right level of the organisation's decision hierarchy - by leaders who have the accountability and oversight of operational and business imperatives.
Organisations should therefore review their organisational and reporting structure to ensure that cybersecurity issues - from the escalation of security incidents, to the allocation of resources - are flagged to the appropriate level within the leadership team.
For example, cybersecurity teams should not be too far removed from key decision-makers such as the CEO or chief information security officer.
Additionally, organisations must develop contingency plans to ensure that appropriate procedures are in place in the event of a cyber-attack, such as incident response, crisis communication, and business continuity plans.
These plans must delineate clear roles, responsibilities and actions. Like fire drills, these plans must be exercised regularly.
Last, the people factor. Today, organisations rely extensively on technology for their day-to-day work. As a result, the responsibility for cybersecurity accrues far beyond the IT or security personnel.
Front-end users are often the weakest link, as sophisticated social engineering techniques, combined with human error, give threat actors the means to gain a foothold in the network.
Based on Symantec's 2018 Internet Security Threat Report, an average user received about 16 malicious e-mails every month. For an organisation of 500 employees, this would mean almost 100,000 threats a year, which underscores the scale of the problem.
The silver lining is that the vast majority of cyber-attacks, like malicious e-mails, are not highly sophisticated and can be averted by raising the basic level of cyber hygiene throughout the organisation.
This involves developing a positive cybersecurity culture within the organisation, and raising the level of cyber hygiene for all staff - such as using strong passwords, patching software regularly, and learning to spot signs of phishing. Board members and C-suite executives must lead by example.
Collective responsibility
Our increasingly digital and hyper-connected world presents us with vast opportunities. But we must address its attendant risks.
Cybersecurity is not a static, technical arena; it is a dynamic, contested space where skilled, cunning malicious actors are always trying to find ways to get past our defences.
Cybersecurity is also borderless; attacks can come from anywhere, at any time. In short, the threat is serious and evolving, and we need to stay abreast, if not ahead, of the curve.
Corporate leaders must carefully consider how they can enhance the cybersecurity posture of their organisations - and by extension, that of Singapore. If we all do our part and embrace this collective responsibility, together we can build a safe and trusted cyberspace for Singapore.
S Iswaran is the Minister for Communications and Information and the Minister-in-Charge of Cybersecurity. This is part of a keynote address that he delivered during a closed-door forum, targeted at C-suites, on May 21.
TRENDING NOW
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
Green fuels, autonomous ships: How Singapore is future-proofing its shipping industry
Singapore-based Ryde accused of pump-and-dump fraud in class action lawsuit
Jackspeed buys 2 Jalan Kilang Barat for S$39 million to house new car dealership