Red alert: Singapore to suffer from more cybercriminal attacks

By Marc Bown

Earlier this year, National University of Singapore (NUS) confirmed that hackers had infiltrated the university’s backend systems and stolen a trove of information – including staff usernames, domain information and hashed passwords.

Even though the affected data was not deemed confidential by NUS, the university had to work carefully to inform the public and reset the passwords of all the affected accounts.

Then, in March 2012, Deputy Prime Minister and Singapore’s Coordinating Minister for National Security, Teo Chee Hean, cautioned all Singapore citizens that greater interconnectivity and access to technology will create a “new reality”, in which the country will suffer more cyberattacks and social extremists.

As an open society in a highly globalised world, Singapore encourages its citizens to access new technologies at the expense that the city-state becomes more prone to cybercriminal attacks.

Singapore is no different than any other nation in terms of the threats faced from perpetrators motivated to gather information about government-sensitive information. Similarly, Singapore organisations withvaluable information may also find themselves targeted by scheming attackers.

Different attackers have varying motives, choosing techniques and victims based on their specific objectives. There are three main goals behind all computer-based attacks – financial gain, ideology, and information gathering. By far, the most common motive for cybercrimes is financial gain.

Attackers seeking financial gain most often target credit-card data or other data-based commodities for which there are pre-established black markets interested in buying the information. These attackers do not care who their victim is, so long as that victim has access to data of interest.

In contrast, attackers who focus on a specific target tend to be driven by an ideology or the desire to learn more about that target.

In our experience, the cybercriminals behind these targeted attacks are presently favouring e-mail based attacks sent to individuals in the target organisation. Firstly, the attackers identify a relevant individual through profiling.

Next, an email is devised to pique the interest of the target, hoping to entice the victim to open a malicious attachment or click on a deceiving link. It is this human element that makes targeted attacks so much more difficult to defend against.

In general, attacks usually take advantage of known flaws in common software components – e.g. Microsoft Word, Adobe Acrobat or Adobe Flash – though other methods for targeted attacks do occur.

So, how can organisations better protect themselves from targeted attacks? The best protection against targeted attacks is a well-rounded information-security programme, designed to work across many levels.

Controls surrounding patch management – especially for desktop applications that are more difficult to patch, like Adobe Acrobat and Flash – and user awareness are especially effective against e-mail borne attack vectors. Gateway controls like e-mail and web-content malware detection, as well as filtering, are also key protection technologies.

Organisations should assume that they will eventually fall victim to a determined attacker, and should implement strong detective controls to facilitate a rapid response.

Unfortunately, attackers are often highly motivated to make a significant investment in compromising their target – so that even the best defended organisations can fall victim to targeted attacks.

However, organisations that have multiple layers of preventative and detective controls in place are most likely to prevent themselves against motivated attackers. 

Join Singapore Business Review community
Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

You're the reader we write for. You're also the person our partners want to reach.

If that sentence describes you — a founder, a C-suite, someone whose attention companies pay good money for — then you already understand why SBR works. We've spent twenty years earning the trust of readers exactly like you. Which is exactly what makes this an interesting place for your company to show up, too.

The ways it can show up are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. The right fit depends on what you're trying to do, which is why we'd rather start with a conversation than send a rate card.

If your company has something this audience should know about, we'd like to hear what you're working on.

No rate cards until we understand the brief. It's a better use of everyone's time.

Top News

30 One-Sentence Stories From People Who Have Built Better Habits
None of these stories are mine. They were sent to me by readers of Atomic Habits. My hope is that these examples will illustrate how real people are putting the book into practice. They will show you what people are actually doing to build good habits and break bad ones. And hopefully, they will spark some ideas for how you can do the same.
SBR 5 Lorem Ipsum News 2 [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 4 Lorem Ipsum [8 May Top Stories]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Exclusives

How Experts Figure What to Focus On
eliminate the distractions. Commit to one thing and become great at that thing.”
Exclusive three SBR 12 Lorem Ipsum [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 3 Lorem Ipsum [ Exclusive 2]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Event News

Video [Event News]
Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley