::Trend Micro Threat Resource Center::

Showing posts with label Singapore. Show all posts
Showing posts with label Singapore. Show all posts

23 May 2016

Cross-sector collaboration aims to strengthen Singapore's cyber security capabilities

StarHub has announced plans to grow the local cyber security ecosystem at the launch of its Cyber Security Centre of Excellence (COE). It’s teamed with five industry partners, four IHLs.


StarHub and the COE partners will jointly invest S$200 million over the next five years to support a sustainable cyber security ecosystem.

According to the telco’s news release, StarHub today launched its new Cyber Security Center of Excellence (COE), and announced that StarHub and its partners will undertake initiatives to develop talent, innovation, and industry collaboration to bolster local cyber security.

Five industry partners, namely Blue Coat, Cyberbit, EY, Fortinet and Wedge Networks, and four institutes of higher learning (IHL), including Nanyang Polytechnic (NYP), Republic Polytechnic, Temasek Polytechnic and Singapore University of Technology and Design have thus far joined the COE.

StarHub shares that it plans to rope in more industry and IHL partners to the COE to drive value and results.

To help cyber security professionals enhance their knowledge and career development, StarHub plans to work with leading centres for professional development in cyber security to design and offer relevant training courses. StarHub is also committed to addressing the shortage of cyber security talent in Singapore by training at least 300 specialists on different cyber related capabilities and skill sets over the next five years. It is teaming up with the four IHLs and the Cyber Security Agency of Singapore (CSA) to enhance cyber security training curriculum and programmes, and to collaborate on research and development.

As a first step, StarHub and NYP have jointly established a lab on NYP campus to provide hands-on training for students of Cyber Security & Forensics. These students will subsequently have the opportunity to learn directly from experienced cyber security professionals during their internship placements at StarHub or its industry partners.

Meanwhile, Professor Yitzhak Ben-Israel has been appointed as the advisor to the COE. He is a member of Singapore’s Research, Innovation and Enterprise Council, as well as the International Advisory Panel for Singapore's National Cybersecurity Research and Development Programme. Ben-Israel is also Singapore’s Agency for Science, Technology & Research, and heads the Security Studies programme at Tel Aviv University.

03 December 2015

Symantec doubles APAC presence with new SOC in Singapore

Symantec Corp. has announced plans to beef up its Cyber Security Services business globally with an investment of more than US$50 million. A portion of this investment has been leveraged to build a new dedicated Security Operations Center (SOC) in Singapore, inaugurated yesterday, doubling Symantec’s Cyber Security Service expertise in the Asia-Pacific region.


Now more than ever, organizations require a deeper security understanding and strong proactive security measures to gain the upper hand on adversaries. Symantec’s SOCs analyze 30 billion logs worldwide each day to provide enterprise-wide protection to help organizations strengthen their defenses and respond to new threats as they emerge 24 hours a day, 7 days a week, 365 days a year.

With the launch of the SOC in Singapore, businesses will have access to intelligence, accurate threat detection and proactive notification of emerging threats to ensure their most sensitive data is protected. The new SOC will also enable businesses to shorten the time between detection and response, reduce operational costs and proactively counter emerging threats.

“Today, technology alone may not stop advanced threats. Organizations need security experts on hand to interpret and prioritize the critical events that need action. By investing in people and security IQ in Singapore and the Asia-Pacific, Symantec is expanding its visibility into the region, enabling us to bolster customers’ security operations capabilities, and protect their critical information and assets,” said Samir Kapuria, SVP and general manager of Cyber Security Services at Symantec.

“The Asia-Pacific region is incredibly diverse and multi-cultural. This allows us to attract highly educated multi lingual security professionals who bring expertise and experience from many vertical industries and global security organizations and are well-versed in the security landscape,” added Kapuria.

Last year Symantec’s team of cyber professionals protected organizations from more than half a million web attacks per day, according to the 2015 Internet Security Threat Report.

The investment will enable the company to expand its Chennai, India SOC as well as the Tokyo, Japan SOC. The next phase of the company’s SOC expansion will take place in Europe, with more facilities expected to open within the next 12 months. Once complete, Symantec will have eight SOCs worldwide, extending their current team of 500+ certified cybersecurity professionals to address every stage of the cyber-attack lifecycle.

Symantec has also invested significantly in its cyber services-enabling technology, including big data analytics and distributed computing. With an increasing demand to manage customers’ security environments with Security as a Service, Symantec Cyber Security Services offers a strong portfolio, including Managed Security Services, DeepSight Intelligence, Incident Response and Security Simulation training.

This announcement follows a US$20 million investment in existing SOCs across Australia, India and Japan in the past year.

24 November 2015

Singapore's infosec professionals rate cybersecurity readiness a 'C minus'


The world’s information security practitioners have given global cybersecurity readiness a “C” average with an overall score of 76 percent, according to the 2016 Global Cybersecurity Assurance Report Card released by Tenable Network Security, Inc.

Singapore, the only Asian country included in the report which focused on 6 countries, ranked 4th and received a C-.

According to survey data, global cybersecurity earned an overall score of 76 percent—an underwhelming “C” average. Nearly 40 percent of respondents said they feel “about the same” or “more pessimistic” about their organizations’ ability to defend against cyber attacks compared to last year.

When asked about the biggest challenges facing them today, the practitioners cited an overwhelming threat environment as the biggest challenge, while reporting relative confidence in the effectiveness of cybersecurity products.

“What this tells me is that while security innovations solve specific new challenges, practitioners are struggling to effectively deploy an overarching security strategy without gaps between defenses,” said Ron Gula, CEO, Tenable Network Security. “It’s no surprise that many in the profession feel overwhelmed by the increasingly complex threat environment. The recent, unprecedented cyberattacks have disrupted business for leading global companies, infiltrated governments and shaken confidence among security practitioners. With so much at stake, organizations need to know whether their security programs are effective or if they are falling short.”

Cloud days ahead
Respondents consistently cited cloud applications (graded D+) and cloud infrastructure (D-) as two of the three most challenging IT components for assessing cybersecurity risks.

Mobile devices (D) also were reported as particularly challenging when assessing cyber risks. The inability to even detect transient mobile devices in the first place (C) was another big challenge for the world’s security practitioners.

On the upside, respondents largely believe they have the tools in place to measure overall security effectiveness (B-) and to convey security risks to executives and board members. On the downside, respondents question whether their executives and board members fully understand those security risks (C+) and are investing enough to mitigate them (C).

Overall Cybersecurity Assurance Report Cards by Country

  •     Australia: D+ (69 percent)
  •     Canada: C+ (77 percent)
  •     Germany: C- (72 percent)
  •     Singapore: C- (72 percent)
  •     United Kingdom: C (74 percent)
  •     United States: B- (80 percent)

Overall Cybersecurity Assurance Report Cards by Industry

  •     Education: D (64 percent)
  •     Financial Services: B- (81 percent)
  •     Government: D (66 [percent)
  •     Health Care: C (73 percent)
  •     Manufacturing: C (76 percent)
  •     Retail: C+ (77 percent)
  •     Telecom & Technology: B- (81 percent)

“These index scores reflect a startling lack of ability to detect and assess cyber risk in both cloud infrastructure and applications as well as mobile devices,” said Gula. “Another concern is the uphill battle security professionals face in mobilizing their organizations’ leadership to prioritize security. There’s a disconnect between the CISO and the boardroom that must be bridged before real progress can be made.”

09 October 2015

Cyber Security Agency of Singapore forges partnerships to boost security capabilities

The Cyber Security Agency of Singapore (CSA) has forged new partnerships to boost cyber security capabilities as part of its ongoing efforts to strengthen Singapore’s cyber security posture and stay ahead of a rapidly evolving cyber security landscape.


The CSA signed a Memoranda of Understanding (MOU) with Singtel, Check Point Software Technologies and FireEye to signal the parties’ commitment to work together on key areas of interest.


CSA will be working with Singtel to build up local capabilities and deliver advanced cyber security services. The partnership will also see CSA and Singtel collaborate on developing manpower through training and certification to meet increasing demand and on research and development to develop new cyber security solutions.

Additionally, Singtel has launched an Advanced Security Operations Centre (ASOC) in Singapore through its strategic partnership with FireEye. The ASOC monitors advanced cyber threats globally and helps customers overcome sophisticated malicious software attacks.

“A resilient cyber security ecosystem will help reinforce Singapore’s position as a key business hub for innovation while building the foundation of a safe and smart nation,” said Bill Chang, Chief Executive Officer, Singtel Group Enterprise.

CSA’s collaboration with cyber security vendor, Check Point, taps on Check Point’s expertise in developing industry leading security solutions. Under the MOU, the parties will focus on bringing advanced solutions to Singapore while growing local capabilities to provide these solutions. The parties will also collaborate on workforce development initiatives and in-depth technical training.

CSA will work with cyber security company, FireEye, to strengthen information sharing on cyber trends and cybercrimes, threats and indicators of compromise as well as jointly devise measures to enhance incident response.

CSA also signed a Memorandum of Intent (MOI) with CREST International and the Association of Information Security Professionals (AISP) to introduce CREST certification for penetration testers in Singapore. The certifications will serve as a competency baseline for practicing professionals and service providers. Under this MOI, the partners will join hands to set up a CREST Singapore Chapter next year.

CSA and the Infocomm Development Authority of Singapore (IDA) have established the Cyber Security Associates and Technologists Programme (CSAT) to train and up-skill ICT professionals to acquire practical skills for specialised job roles for Cyber Security Operations.

The programme is aimed at helping fresh and mid-career ICT individuals attain the necessary practical skills to better equip them for cyber security roles and positions. CSA and IDA will collaborate with industry partners for the training and up-skilling of ICT professionals.

“We are excited to be taking these strides forward with our partners to enhance Singapore’s cyber security capabilities as well as raise the quality of the industry and workforce,” said David Koh, Chief Executive, CSA. “These partnerships pave the way for us to work closely together on innovative solutions to strengthen our cyber security core. We look forward to establishing more of such consequential partnerships to achieve the vision of a secure smart nation for Singapore.”

05 October 2015

Singapore is top country worldwide for attacks by banking Trojans


Singapore ranks as the top country globally for Kaspersky Lab users being attacked by banking
Trojans in the second quarter of 2015, according to a study done recently by Kaspersky Lab.

496 Kaspersky Lab users in the city-state had sustained such attacks. In the second quarter of 2015, Kaspersky Lab solutions had deflected attempts to launch malware capable of stealing money via online banking on the computers of 755,642 users. This is a decrease in 18.7% compared to 735,428 in the previous quarter.

Switzerland, Brazil and Australia were next in line in the list of top countries respectively. Hong Kong emerged as the fifth country in the list and also as the only other country in the Asia Pacific region. The bottom ten of the list constituted New Zealand, South Africa, Lebanon and the United Arab Emirates respectively.          

“An A.T. Kearney and EFMA global retail banking study concluded that Singapore is the second country worldwide with the highest inclination for digital banking,” says Jimmy Fong, Channel Sales Director, Southeast Asia, Kaspersky Lab.

“The nation was also placed among the top three for banking capabilities, which included innovative technological developments, a robust financial environment and digital infrastructure. Local banks also fare impeccably well in terms of online banking systems, providing cutting edge features to complement ordinary online banking services. This paves the way towards equipping banks in Singapore for the next level of digital banking.”    

With the large number of technologically savvy consumers, high smartphone penetration rates and strong digital service adoption levels, Singapore is one of the Southeast Asian countries with the highest digital banking penetration rate, pegged at 94%.

Online banking in Singapore was also the second most utilised service platform after ATMs, more than conventional branch visits and telephone banking, as a study conducted by Bain & Company found.      

Kaspersky Lab security solutions had registered a total of 5,903,377 notifications of malicious activity by programmes designed to steal money via online access to bank accounts in Q2 2015.

The percentage of Kaspersky Lab product users who encountered this threat during the reporting period in the country were calculated among all product users in the country. This is to evaluate and compare the degree of risk of being infected by banking Trojans which user computers are exposed to worldwide. Only countries with more than 10,000 Kaspersky Lab product users were included in this study.      

“Cybercriminals are always looking for ways to access vital information that can be monetised, especially when it comes to online banking. Securing critical data that can cause financial loss is essential for both individuals and businesses," said Vitaly Kamluk, Principal Security Researcher, Global Research & Analysis Team, Kaspersky Lab. “As the ease of banking becomes more convenient, it is vital that individuals follow best security practices when on the Internet, recognising that they represent a portal or doorway for numerous malicious agents to get into bigger networks and systems, to wreak havoc and cause significant damage for the business they are part of."

20 March 2015

PwC sets up Cyber Security Centre of Excellence in Singapore

PwC (PricewaterhouseCoopers) has launched a new Cyber Security Centre of Excellence in Singapore, which will be headed by Vincent Loy, Cyber Leader, PwC Singapore.


The Centre of Excellence aims to serve the business community both locally and in the region through the provision of research, training & skill development, information sharing, communication, awareness and policy, standards and international cooperation.

“As Singapore moves closer to becoming a Smart Nation, the need for the right talent to ensure that the nation and our systems are well guarded against threats will become a growing imperative,” said Loy. “PwC is working to build capabilities that will support businesses as they ‘go digital’.

“We are already in the process of heavily recruiting globally to bring different capabilities and skill sets to Singapore. In addition, we are training existing staff and new recruits on cyber related capabilities.”

PwC Singapore has been actively providing services in cyber security and related areas since 2012. In response to the growing demand for talent in the cyber and data risk areas, PwC Singapore aims to expand its practice from 40 staff to approximately 300 over the next three years.

PwC also plans to invest S$50 million over the next three years in capability and technological development in its continued commitment to be a thought leader in the area of cyber risk and security.

“Businesses and organizations need to move beyond focusing on tactical technology solutions,” said Yeoh Oon Jin, Executive Chairman, PwC Singapore. “The right culture and mindset to manage and mitigate digital risks need to seep through the entire organization.

Processes will need to become even more robust and standardized across all access channels. The end game is to prevent cyber threats and vulnerabilities for a safer, smarter and sustainable eco-system.”

16 February 2015

Microsoft opens 5th cybersecurity satellite center in Singapore

Microsoft has opened its fifth global Cybercrime Satellite Centre in Singapore to support its cybercrime efforts in Asia-Pacific, which is increasingly a hot target for hackers.


The facility is the third in the region where there are similar centers in Beijing and Tokyo, and will lend its services to Southeast Asian economies including India, South Korea, Australia, and New Zealand. The other two global sites are in Berlin and Washington, the latter of which was where the first was launched in November 2013.

The satellite centers run under Microsoft's digital crimes unit, which operates primarily as a support or cost center and not a for-profit business unit within the company, said Keshav Dhakad, Microsoft's Asia regional director of digital crimes unit, during a media briefing Monday at the launch. It supports the software vendor's business objectives and provides another layer of authentication to enhance its overall security environment, Dhakad said.

The global digital crime unit comprises more than 100 lawyers, investigators, engineers, forensic analysts, and data scientists located across the globe, including India, China, and EMEA. It works with industry partners, internet service providers as well as law enforcement and computer emergency response teams (CERTs) in the various local markets.

The Singapore center will leverage the resources of its U.S. counterpart, which coordinates global efforts to combat cybercrime and provides real-time cyberthreat intelligence and big data analytics. Microsoft has led various initiatives to deal with specific threats such as Operation Gameover Zeus in June 2014 aimed at combating the peer-to-peer botnet, which was based on the Zeus trojan and targeted banking and financial information.

The Microsoft digital crime unit also runs a Cyber Threat Intelligence Program that processes and analyzes more than 500 million transactions a day for malware infections, and provides training for third-party partners. CERTs have free access to the program, Dhakad said.

Richard Boscovich, Microsoft's US assistant general counsel for digital crimes unit added that the team works closely with the Interpol and will continue to do so when the Interpol Global Complex for Innovation officially opens in Singapore in April.

With three of its five global satellite centers located in Asia, Microsoft is putting resources in a region where IT consumption is growing exponentially and that is increasingly a target for hackers looking for financial gains.

Boscovich said: "We look at cybercriminals as business people and they follow [emerging markets] which are economically lucrative." A lot of computer usage in Asia also do not have safe practices, making these users prime targets for cybercriminals, he said, noting that the Singapore center will provide more visibility into malware developed specifically for the region.

S. Iswaran, Singapore's Second Minister for Home Affairs and Trade and Industry, noted that the city-state is "natural target for cybercriminals" because it is a trusted business hub with high presence of multinational corporations.

He noted that both government and commercial websites in the country had come under attack in recent years and could "inadvertently" become more vulnerable to cybersecurity threats as it drives its smart nation efforts.

"The sharing of expertise and information through cross-industry and public-private partnerships is a cornerstone of any effective cybersecurity ecosystem. It is critical that we create an environment of trust where networks can share intelligence expeditiously and partner organizations can discuss measures to tackle threats or prevent similar incidents from taking place," Iswaran said.

28 January 2015

Singapore to set up Cyber Security Agency

The Singapore government is setting up an agency, which will develop a national strategy to tackle cyber threats, create a national-level response and coordinate various agencies in managing threats.


Called the Cyber Security Agency (CSA), the agency will be operational from 01 April 2015. It will bring together existing agencies under the Ministry of Home Affairs (MHA) and the Infocomm Development Authority (IDA) to lead the cyber security master plan, the building and design of relevant systems, and to monitor and respond to cyber threats.

The CSA replaces the Singapore Infocomm Technology Security Authority (SITSA) which was set up on 1 Oct 2009 to safeguard Singapore against infocomm technology (IT) security threats.

SITSA has been monitoring 10 sectors: Government, infocomms energy (power), land transport, maritime, civil aviation, water, security and emergency, health, banking and finance; and will be subsumed into the CSA, together with the Singapore Computer Emergency Response Team, which deals with cyber security bodies outside Singapore.

These include strategy and policy development, cyber security operations, industry development and outreach. It will also work closely with the private sector to develop Singapore’s cyber security eco-system.

Dr Yaacob Ibrahim, Minister for Communications and Information, will be appointed as the Minister-in-charge of Cyber Security.

David Koh, Deputy Secretary (Technology) at the Ministry of Defence (MINDEF), has been appointed as the Chief Executive (Designate) of the CSA on 1 January 2015, and as Chief Executive, CSA from 1 April 2015.

Koh will assume his CSA and MINDEF appointments concurrently.

The efforts by the Singapore Government come in the wake of a spate of cyberattacks in the last couple of years that targeted government websites. About 1,560 SingPass accounts were illegally accessed in June last year and, in September, details of more than 300,000 customers of karaoke chain KBox were leaked by hackers. In 2013, a string of hacking incidents on Singapore government websites, including that of the Prime Minister’s Office (PMO).


16 December 2014

Four key areas of security solutions Singapore companies need to invest in


Singapore is one of the most well developed security markets in Asia/Pacific, and in the age of advanced attacks, organizations need to invest in four key areas of security solutions, according to Gartner, Inc. These four key areas of security solutions include: preventive, detective, retrospective and predictive.

“The key to achieving a strong security posture is to have these four types of security capabilities work well as an integrated, continuously monitored solution, something Gartner refers to as the adaptive security architecture,” said Sid Deshpande, principal research analyst at Gartner.

Organizations in Singapore display a heightened sense of urgency today towards improving their security posture, driven by the following factors:

  • Strong efforts by government and regulatory bodies to increase security awareness and drive investment in security innovation
  • The new types of risks associated with digital business models
  • Highly visible security incidents in 2013 and 2014
  • Overall IT spending growth
Gartner predicts that by 2018, 25 percent of corporate data traffic will flow directly from mobile devices to the cloud.


As the majority of consumer facing businesses in Singapore go digital, organizations are looking at investing in mobile and cloud security solutions that can help them mitigate risks associated with digital business.

The high interest areas around security from organizations in Singapore include security monitoring, identity and access management, advanced threat prevention, IoT security, application security, cloud security and GRC, among others.

“2013 and 2014 have seen a slew of merger and acquisition activity in the security space globally, and the increasingly complex nature of threats is driving security providers to fundamentally change the way they address their customers’ security challenges and communicate their message effectively. The renewed security opportunity presented to providers by Singapore enterprises brings with it sales and marketing challenges for security providers,” said Deshpande.