Ensign sees big potential in Asia cybersecurity

Interim chief looking for permanent CEO who understands Asia market as the new venture set up by Temasek unit, StarHub and Accel focuses on the continent

Ng Ren Jye

Published Sun, Dec 23, 2018 · 09:50 PM

    Singapore

    THE official inquiry into June's SingHealth cyber attack has yet to submit its report, but a clear message has emerged from the extensive sessions - cybersecurity needs to be taken more seriously in Singapore.

    In a wide-ranging interview with The Business Times, Yeoh Keat Chuan, the interim chief executive officer of Ensign InfoSecurity, discussed various issues and opportunities in the cybersecurity landscape.

    Created as a joint venture between Temasek and StarHub in October, Ensign is made up of Quann, the cybersecurity arm of Temasek-owned Certis, StarHub's Cyber Security Centre of Excellence, and Accel Systems & Technologies, a security infrastructure company majority-owned by StarHub.

    As the interim chief, Mr Yeoh is looking to stay at the helm for one to two years, with plans to bring in a permanent CEO by then.

    His current priorities are to ensure the post-merger integration goes smoothly.

    He said: "There's Quann, StarHub, and Accel - these are the three that I want to make sure that collectively, we pull onboard all the different capabilities and we function effectively as a team as well."

    According to a report by cybersecurity firm FireEye, the "mean time to detection" - a measure of the average number of days before a cyber criminal's successful breach is detected in a company's IT system - was 99 days in the US in 2016, and 76 days in 2017.

    Comparatively, during 2016 it was 172 days in Asia-Pacific, and a staggering 498 days in 2017.

    Mr Yeoh said: "In Asia in 2016, most countries were not worried about cyber breaches. They never really took a look at their own networks. Only in 2017, with the increasing profile, they started inviting cyber professionals in to secure their system. That's when they discovered that their system had already been compromised."

    He also mentioned an oft-quoted phrase: "There are only two types of companies in the world - those that have been breached and know it, and those that have been breached and don't know it."

    It is particularly pertinent now as Mr Yeoh said the cybersecurity landscape continues to evolve in favour of the attackers, and there is an expanding number of internet-connected smart devices that hackers can attack.

    When there are problems, there are opportunities to address them. Cybersecurity is a US$111 billion industry globally, and is expected to grow to US$240 billion in 10 years time.

    Mr Yeoh said the cybersecurity market today is split 48 per cent in the US, 24 per cent Europe and 17 per cent Asia-Pacific. America and Europe's compound annual growth rate (CAGR) is 8 per cent , while Asia is at 11 per cent.

    This meant that Asia is growing faster from a smaller base. It comes as no surprise then that, for its next CEO, Ensign wants someone who understands the trends in Asia as the continent is their focus.

    Mr Yeoh said: "We want someone who obviously shares the vision that we have for Ensign as a pure-play cybersecurity services company, and who understands the landscape in Asia."

    When companies think about cybersecurity, Mr Yeoh said recognition needs to come from the top, particularly the need to understand and quantify what exactly is the exposure and risk.

    "If the board doesn't appreciate and recognise it, then obviously at the enterprise level, they might not give it the necessary focus required."

    This echoes what Richard Magnus, chairman of the SingHealth Committee of Inquiry (COI) and David Koh, the CEO of Singapore's Cyber Security Agency, said during the SingHealth hearings.

    Both emphasised the need for senior management to be more involved in policy and decisions pertaining to cybersecurity risks.

    Mr Yeoh noted the direct cost of a breach is only the tip of the iceberg.

    Beyond that, he said: "The second level would be, for ransomware, the remediation cost. The third level is the reputational hit. Many regulations now, GDPR (General Data Protection Regulation) for example, within 72 hours of a breach, companies must disclose it. The fourth level is if its a publicly traded company, the shareholder price will be affected."

    A key area Ensign is focusing on is incidence response, as it looks to cut down the aforementioned 498 days mean time to detection for Asia-Pacific.

    The company is working with incidence response specialists Sygnia, which was acquired in October 2018 by Temasek for US$250 million.

    Mr Yeoh said that as an industry, incidence response is valued at about US$11 billion, and is expected to grow to US$34 billion in 5 years time, representing a CAGR of more than 20 per cent.

    Mr Yeoh - who was previously managing director at Singapore's Economic Development Board and currently wears a second hat as managing director of Enterprise Development Group at Temasek - will also look at how Ensign can tap global capabilities of the platform, partnering with companies such as Israel's Sygnia and Claroty, as well IronNet in the US.

    "Temasek is a lead investor in Claroty. It is very advanced in multi-networks - industrial control systems, manufacturing systems," he said.

    Mr Yeoh added that Claroty is working with Ensign to offer solutions that can secure transport systems, utility generation and manufacturing assets in Singapore.

    As for IronNet, Ensign is in the process of setting up a joint venture with the US company in Singapore.

    Founded by former US National Security Agency Director Keith Alexander, it will work with Ensign to develop solutions that protect whole sectors.

    "They can help companies to exchange intelligence at network speed. Sophisticated attacks will probably look at the opportunity to attack not only one company, but a sector."

    "To be able to see in real-time that these attacks are all the same and to be able to address them is the premise for IronNet. In Singapore, we have strong industry clusters, whether its financial services, healthcare, petrochemical or semi-conductor."

    Amendment note: The story above has been updated to reflect that the "mean time to detection" stat was derived from a FireEye study, and not Booz Allen Hamilton as previously reported.