AI cyberattacks mean we can’t defend ourselves the same way as before: Singapore’s founding cybersecurity chief


AI makes it less costly to attack rarer systems, said Mr Koh, citing the operational technology systems running essential services such as power plants, electrical grids and train systems, as examples.

“You typically find that these kinds of attacks are only done by very sophisticated, targeted, well-resourced agencies who have a specific reason they want to target this power plant. So typically, it’s a state attack.

“With the age of AI, these kinds of attacks become easier to do,” he said.

AI capabilities mean that the current industry standard of two to three weeks to develop a security patch for a newly discovered vulnerability may no longer be reasonable.

To respond more quickly, defenders may also need continual monitoring of computer systems, instead of relying on annual security audits.

“We need to be aware that the world is changing. How we used to organise, how we used to operate, how we used to defend ourselves cannot remain the same,” said Mr Koh.

This requires board-level attention, and is why CSA has tasked senior leaders of critical information infrastructure to review their cybersecurity set-ups, he added.

A few days after CNA’s interview, OpenAI disclosed that some of its most advanced AI models managed to break out of a controlled testing environment and hack into an AI start-up to achieve a testing goal.

CRISIS COMMUNICATIONS

Before he was Singapore’s founding cybersecurity chief, Mr Koh served in the Singapore Armed Forces and the Ministry of Defence.

He took on various appointments as defence cyber chief, deputy secretary for technology, director of military security and chief signals officer.

It is harder to galvanise people around cybersecurity, compared with traditional security, said Mr Koh, because the consequences of a cyberattack are not as visible as a physical attack that destroys buildings and injures people.

Another key difference is the porous nature of borders in the digital domain.

“It’s not clear where your national borders extend to. It’s not clear where your infrastructure is sitting. It’s not clear whether things that are happening are coming from within your borders or coming from outside.”

Cybersecurity stakeholders are not only governments or government-linked, but can be private companies, and attacks can more directly impact individual civilians.

This was what happened with the SingHealth breach in 2018 – a major test of the fledgling CSA three years after its founding.

Hackers infiltrated the healthcare provider’s systems and obtained the medical data of 1.5 million patients, while repeatedly targeting then-Prime Minister Lee Hsien Loong’s records.

Mr Koh recalled a “very compressed” period in which CSA had to establish more information before it could go public and notify affected patients.



Source link