EDITORIAL

International cooperation best bet against new cyberthreats

Published Tue, Oct 26, 2021 · 09:50 PM

ONE of the important cybersecurity threats highlighted during this year's Singapore International Cyber Week (SICW) and GovWare conference, held earlier in October, is supply chain attacks.

These are cyberattacks where hackers, instead of targeting a specific company, zero in on the software or IT services vendors whose products the company uses. They insert malicious code into these IT companies such that when the next batch of (usually automated) software updates happen, the virus moves into the networks of all the customers of these vendors.

Like all other forms of cyberattacks (for example, ransomware), supply chain hacks are not new. What is new is that with increased connectivity and digitalisation, the devastating effects of these attacks have increased manifold. The danger came into the limelight when Solar Winds, a US-based IT services company that provides IT system management tools to thousands of organisations around the world, reported last December that its network had been breached by what it claimed was a hacking group backed by a nation-state. The Solar Winds raid affected close to 18,000 customers. The breach was discovered nearly 14 months after it happened, during which time the hackers had access to some of the world's most high-profile companies, including Intel, Nvidia, Cisco and a host of other non-technology firms.

While Solar Winds, and presumably other IT services companies, have taken remedial safeguard measures, their customers also need to figure out how to ensure their systems are protected and any damage, in the event of a breach, can be minimised. This is a challenge for many companies, especially small and medium enterprises.

There are two aspects to defending against cyberattacks - one that's technical and the other, policy. In the technical realm, it is a never-ending "arms race" between hackers and cybersecurity professionals. This "race" will go on for the foreseeable future because digitalisation has democratised access to technology. Cybersecurity personnel employ the latest technologies such as artificial intelligence (AI), machine learning (ML) and automation but so do hackers - to create increasingly sophisticated malicious code.

While it is a stalemate as far as technology is concerned, the policy perspective is where progress can be made given sufficient will. As government leaders and policymakers have noted, the need of the hour is for international cooperation to build consensus on the rules, norms, principles and standards of governing cyberspace since it is essentially borderless. The United Nations has been trying to craft such rules for close to 20 years. Progress has been made but there is still a lot that needs to be done.

The good news is that regional and bilateral cooperation in cybersecurity has been thriving. Singapore has signed a number of bilateral agreements on cybersecurity. At the same time, the Asean region has led the way in developing a regional cybersecurity framework that is not just a policy document but has teeth built into it with institutions such as the Asean-Singapore Cybersecurity Centre for Excellence (ASCCE) as well as the Asean Digital Masterplan 2025.

A combination of good technical skills and an international or regional cooperative framework may not quite stop all cyberattacks but it can help minimise the damage caused. Resources and efforts must continue to be poured towards that end.