Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

14 February 2025

Cornerstone unveils cyber insurance for Singapore SMBs with QBE and ESET

Cornerstone, a Singapore-based independent financial advisory, has launched CyberFender, a cyber insurance solution tailored to small-to-medium businesses (SMBs) in Singapore. 

CyberFender offers insurance coverage that will help to safeguard critical business assets against malicious actors in areas like data security, business interruption, and cyber extortion. It also covers related incident response and recovery costs, providing both financial and operational protection against cyber incidents—empowering businesses to better build and maintain customer trust, Cornerstone said. 

Underwritten by QBE, a global insurer with a presence in Singapore for more than 130 years, CyberFender policyholders will also receive 24x7 cybersecurity protection through ESET Small Business Security, which is a set-and-protect solution against online threats, frauds, data theft and unwanted tracking. 

Cornerstone can guide and support SMEs throughout the process, serving as trusted advisors who simplify, facilitate, and ensure a seamless download and understanding of key information. 

SMBs make up 99% of all enterprises in Singapore and are responsible for nearly half of the nation’s GDP. As they embrace digital transformation, robust cybersecurity measures are essential to maintain customer trust and ensure a resilient business environment. Cyber insurance has emerged as a vital safety net, helping SMBs to mitigate the financial risks of cyber incidents while reinforcing confidence in data security.

ESET’s APAC SMB Cybersecurity Report 2024 found that 73% of Asia Pacific (APAC) SMBs experienced cybersecurity incidents last year—with one out of four incidents related to ransomware, while Cyber Security Agency of Singapore (CSA) findings from 2024 estimated that eight in 10 organisations in Singapore encountered a cybersecurity incident in a year, with half encountering it several times a year. 

QBE Singapore’s small- and medium-sized enterprise (SME) survey further showed that the percentage of businesses that do not have any processes or protection against cyber risks rose to 19% in 2024, from 9% in 2023.

“At Cornerstone, we recognise that recovery from cyberattacks can be costly and challenging for SMBs. This is why we partnered with QBE and ESET to deliver robust, easy-to-use cyberdefence solutions to our policyholders through CyberFender,” said Leonard Tan, MD, Cornerstone.

“No industry is insulated from cyberthreats, regardless of company size. As technology evolves, it’s creating both new opportunities and new risks, further expanding the digital attack surface. Together with Cornerstone and ESET, we are delighted to be a part of the CyberFender offering, which is well suited to address SMBs’ needs when it comes to the current cyber risk landscape,” said Ronak Shah, CEO, QBE Singapore.

“ESET is committed to empowering SMBs with the right tools to proactively protect their businesses from cyber threats, including ransomware. By adopting a prevention-first approach, business owners can effectively safeguard their organisations from the risk of cyberattacks and disruption. We are honoured that Cornerstone and QBE have chosen to work with ESET; it is a testament to our commitment to ensure businesses of all sizes are safeguarded in an ever-evolving threat landscape,” said Parvinder Walia, ESET President for Asia Pacific and Japan.

CyberFender is available in Singapore through Cornerstone's financial advisors.

9 February 2017

Media Literacy Council of Singapore launches Better Internet Campaign

Source: Media Literacy Council. From left: Chong Ee Jay, Manager of TOUCH Family Services and a member of the Media Literacy Council, a former victim of cyberbullying who subsequently bullied back in retaliation; Tan Chee Wee, Executive Director, Media Literacy Council, and Lock Wai Han, Chairman, Media Literacy Council.
Source: Media Literacy Council. From left: Chong Ee Jay, Manager of TOUCH Family Services and a member of the Media Literacy Council, a former victim of cyberbullying who subsequently cyberbullied in retaliation; Tan Chee Wee, Executive Director, Media Literacy Council, and Lock Wai Han, Chairman, Media Literacy Council.

Singapore's Media Literacy Council (MLC) recently celebrated Safer Internet Day (SID) on February 7 with the launch of the Better Internet CampaignThe campaign will run till 31 May 2017, focusing on current cyber wellness issues of cyberbullying, discernment and excessive screen time. 

The MLC partners industry, community and government to champion and develop public education and awareness programmes relating to media literacy and cyber wellness. The council has spearheaded the campaign for the fourth time since Singapore’s participation in the global initiative in 2013. This year ,campaign activities include a series of on-ground engagements and broadcasts on mainstream and social media to bring more awareness and discussions about various issues around the areas of focus.

MLC has adopted the campaign tagline Do What’s Right Online, Be the Change for a Better Internet. A showcase of real-life stories profiling a diverse range of individuals who have personally experienced cyber-wellness issues (including students, educators, counsellors, perpetrators and victims will also be available at the campaign website. A series of social experiments covering these issues will further be conducted to generate awareness, conversations and reflections on the issues.

Lock Wai Han, Chairman of the Media Literacy Council, said: “The Internet and mobile devices have become an integral part of our lives, especially among our young people. It is therefore critical to encourage our youths to be positive online, while giving them the resilience, knowledge and support they need to navigate online risks. With the proliferation of news sources online, we need to be discerning to distinguish between falsehood and the truth, to avoid falling prey to scams and fake news.” 

Chong Ee Jay – Manager, TOUCH Family Services, and Member, Media Literacy Council, a former victim of cyberbullying who subsequently bullied back in retaliation, said that online interactions should be governed by sensitivity to others. "Basically, it is a question about good manners, and what is acceptable between family and close friends. Some remarks can be hurtful and we must be mindful about this, especially when it is a sensitive subject of say, how a person looks, his/her size, etc. This applies whether online or offline," he commented.

That said, cyberbullying is even more of a problem compared to face-to-face bullying for several reasons, noted Chong. "The cloak of anonymity online often creates an enhanced false sense of security or empowerment which results in users often becoming seemingly bolder or adventurous online to do things which they often may not dare or be willing to try out in real life.," he explained. "Cyberbullying is one clear example where bullies resort to hiding behind their keyboards to make hurtful comments rather than resolving the matter in person. That's why often in cyber bullying cases, anyone can be the bully."

If someone is being cyberbullied, creating a supportive environment is essential. "Often many are hurt by the comments. However not all victimised cases end up depressed or in a despondent state. Some whose personalities are more resilient, or those who have better management of their emotions and have healthy social support from friends and family, tend to cope much better in the face of cyber bullying," said Chong.

Chong also advises against running away from it all through deleting social media accounts, for example. "Running away would not solve the problem. In fact more often than not, it sends the message to the bully (or bullies) that he/she/they have 'succeeded'. An alternative proposition would be to block or delete the bullies from your social media friends' list. Minimise possible social contact with the bully until you are better able to manage your emotions," he said.

Getting a respected third party to offer a balanced perspective can also help, as it did in Chong's case. "Our teacher/counsellor stepped in and reasoned with the both of us who were involved in the matter. I realised that by retaliating (against) the cyberbully, I became a bully myself. Both of us then realised the value of our friendship and how silly the whole matter had become as our ‘battle’ was in full view of our other friends, too. We stopped hitting out at each other via the Internet after that. We remain friends till today," he shared.

"As adults, resolve it face to face and talk it out, or seek help from professional Counsellors or even Family Centres like TOUCH Family Services. As some of the bullying incidents may happen in school, it would be important for parents to teach their young to inform and seek advice from school leaders such as teachers and counsellors who would provide emotional support as well as keep a look out for the students in school. It would also be important for students to share the incident with parents and allow them to better understand what the students are facing as well as provide advice, and if required, to make reports to the school together with the student."

Chong also said that the law can be called in for more serious cases. "In severe harassment cases which involves offensive messages are defamatory or criminal intimidation*, a police report can be lodged," he added.

SID is a public awareness initiative started in 2004 by the Insafe Network, a network of Awareness Centres funded under the Safer Internet Programme of the European Commission. The SID takes place on the second Tuesday of February every year and seeks to promote safe and positive use of digital technology, especially amongst children and young people. This year’s global theme is Be the Change: Unite for a Better Internet which emphasises the importance of collaboration and unity.

Interested?

Find out more about Chong's cyberbullying experience, and those of others

Read the WorkSmart Asia blog post about Microsoft's commemoration of Safer Internet Day with the Digital Civility Index

*A definition provided by Chong for criminal intimidation runs: "Whoever threatens another with any injury to his or her person, reputation or property, or to the person or reputation of any one in whom that person is interested, with intent to cause alarm to that person, or to cause that person to do any act which he or she is not legally bound to do, or to omit to do any act which that person is legally entitled to do, as the means of avoiding the execution of such threat, commits criminal intimidation." More on the law

26 April 2016

Singtel Cyber Security Institute to upskill individuals and companies in cyber security

Singapore Telecommunications has set up the Singtel Cyber Security Institute (CSI) to enhance the cyber security skills and preparedness of businesses and governments in the Asia Pacific region. A hybrid between an advanced cyber range and an educational institute, the CSI is a first-of–its-kind organisation in the region to test and train companies in dealing with sophisticated cyber threats.

Bill Chang, Chief Executive Officer, Group Enterprise at Singtel said, “Based on our engagements with companies in Singapore, more than 85% do not have robust cyber response plans nor the opportunity to conduct realistic drills to test and sharpen such plans. This lack of cyber preparedness is worsened by the severe global shortfall of trained cyber security experts, which Forbes puts at some 1 million in 2016. This is why we’ve stepped up to the plate. We know we have to help companies secure themselves against a potential slew of increasingly sophisticated cyber attacks.”

Dr Yaacob Ibrahim, Singapore's Minister-in-Charge of Cybersecurity, noted in his opening remarks at the official opening of the Singtel Cyber Security Institute that cyber experts who can address both present and future cyber threats will be in demand, and that a vibrant cybersecurity ecosystem must be cultivated to ensure that manpower with the right skills will be available.

"Our vision of a dynamic cybersecurity ecosystem is one that comprises strong local cybersecurity firms co-existing with established global companies, fed by a talented workforce. Across the economy, businesses must also be sensitive to cyber threats and adopt the right level of cybersecurity measures. Within this ecosystem, cybersecurity talents can circulate, providing the spark for greater innovation," he said.

Housed in a permanent space of over 10,000 sq ft, the institute provides cyber skills development and education programmes tailored to the varying needs of company boards, C-suite management, technology and operational staff. Boards and C-suite level participants will be trained in the areas of cyber threat awareness, risk management, business continuity planning and crisis communications preparation. The cyber operations team will be trained in defence and response capabilities to sharpen their skills.

“Cyber security is no longer just a technical issue to be tackled only at the operational level. It needs to involve all levels within an organisation including boards and C-suite management, and even external stakeholders such as regulators. We hope to arm enterprises and public agencies with the necessary knowhow to counter cyber threats in a holistic manner. This will help them mitigate the risks and costs associated with cyber disruptions,” Chang said.

The CSI can emulate the environments and operations of enterprises using state-of-the-art technologies. Like other cyber ranges the facility can simulate cyber attacks in order to test a company’s inherent vulnerabilities, defence and response capabilities. Unlike other ranges however, the new facility can easily replicate any company’s operating environment and use the latest range of cyber threats, including an extensive library of viruses and malware, to simulate attacks.

Singtel has brought together over 30 ICT and cybersecurity companies as partners for the CSI, Dr Yaacob said. "At the Institute’s cyber range, I understand that cyber professionals can also pit their skills against adversaries in realistic simulation environments. Exercises like these can help heighten cyber professionals’ knowledge of their roles and their responsiveness during cyber incidents," he commented.

An incubation lab at the CSI will focus on scanning for emerging and disruptive cybersecurity solutions. The lab will also enable the testing of proofs-of-concept, and the validation, adaptation, integration and eventual commercialisation of new solutions.

In conjunction with the launch of the CSI, Singtel announced that it is the first company in Singapore to work with the Infocomm Development Authority of Singapore (IDA) and the Cyber Security Agency of Singapore (CSA) on the Cyber Security Associates and Technologists (CSAT) Programme to train infocomm professionals in cyber security. 

Dr Yaacob shared that the dual-track programme nurtures fresh ICT and engineering professionals under the Associate track, while the Technologist track is for experienced professionals seeking to switch careers to focus on cybersecurity. 

"Under CSAT, both these groups can be upskilled through on-the-job training programmes led by companies which are CSAT training partners. These professionals can be trained for roles encompassing security assessment, security operations and the technology development of cybersecurity solutions. They will have the chance to take courses, and participate in local and overseas attachments identified by the CSAT training partners," he elaborated. 

"Trainees can apply their newfound skills to projects, and learn from the best through mentorships with experienced industry practitioners. The comprehensive training available through CSAT will help raise the standards of cyber experts, as well as strengthen the professionalism of the sector."

Under the CSAT programme, Singtel will train fresh infocomm technology professionals and equip them with basic cyber security skills. At the same time, Singtel will also provide experienced cyber security professionals with the opportunity to enhance their skills by training with leading cyber security experts. Through this two-pronged approach, Singtel aims to build a cyber security talent pipeline to drive its cyber security initiatives.

David Koh, Chief Executive of the CSA said, “A strong pool of cyber security talent is necessary to build a dynamic cyber security ecosystem that can support Singapore’s Smart Nation journey. With the introduction of the Cyber Security Associates and Technologists Programme and the setup of the Institute, we hope to encourage more to join the profession as well as enable cyber security professionals to hone their skills and stay a step ahead in the ever-evolving cyber security landscape.”
According to Dr Yaacob, Ernst & Young, NEC, Quann, Palo Alto Networks, and ST Electronics (Info-Security) are some of the companies which have indicated interest in being CSAT partners.

Hashtag: #YaacobIbrahim

10 October 2015

The escalating economic impact of cyber crime

Source: HP infographic.
HP has unveiled the results from its sixth annual study in partnership with the Ponemon Institute detailing the economic impact of cyber attacks across both the private and public sectors. 

The findings reveal a dramatic increase in the overall cost of cyber crime, and reveal that small organisations incur a significantly higher per capita cost than larger organisations3.

Conducted by the Ponemon Institute and sponsored by HP Enterprise Security, the 2015 Cost of Cyber Crime Study quantifies the annual cost of cyber crime for companies across seven countries: the US, UK, Japan, Germany, Australia, Brazil and the Russian Federation.

In the study, researchers found the average annualised cost of cyber crime incurred by a benchmark sample of Australian and Japanese organisations had increased by 13% and 14% respectively since last year. The results also revealed that it took an average of 31 days to resolve a cyber attack in Australia as compared to 26 days in Japan1, 2.

“As organisations increasingly invest in new technologies like mobile, cloud, and the Internet of Things, the attack surface for more sophisticated adversaries continues to expand,” said Matthew Shriner, Director, Enterprise Security Products, Asia Pacific and Japan, and Europe, Middle East and Africa, HP. “To address this challenging dynamic, we must first understand the threats that pose the most risk and then prioritise the security strategies that can make a difference in minimising the impact.”

Key findings from the 2015 Australia and Japan Cost of Cyber Crime Studies:

· Cyber crimes continue to be very costly: The average annualised cost of cyber crime incurred in Japan was US$6.81 million, compared to US$3.47 million in Australia1, 2.

· Cyber crimes require more time to resolve: The average time to resolve a cyber attack was 31 days in Australia, compared to 26 days in Japan. This represents an increase of eight days in Australia and one day in Japan over the last year. Results also showed that malicious insider attacks can take an average of 50 days to contain in Australia, compared to 37 days in Japan1, 2.

Understanding the cyber threats that pose the biggest risk and have the most economic impact to organizations can help enterprises better plan their security approach and investments.

· In both Japan and Australia, the most costly cyber crimes continued to be caused by denial of service and malicious insiders1, 2.

· In Australia, business disruption continued to represent the highest external cost, followed by the costs associated with information loss. On an annual basis, business disruption accounted for 38% of total external costs1.

· In Japan, information theft represented the highest external cost, followed by the costs associated with business disruption. On an annual basis, information theft accounted for 48% of total external costs2.

· Recovery and detection were the most costly internal activities in both countries. Australia reported that it accounted for 48% while Japan reported it accounted for 53% of the total annual internal activity cost. In both countries, productivity, cash outlays and direct labour represented the majority of these costs1, 2.

Organisations investing in and using security intelligence technologies and governance practices to address the crimes that proved most costly were more efficient in detecting and containing cyber attacks, thereby reducing costs otherwise incurred1.

· Deploying a security information and event management (SIEM) solution led to an average cost savings of US$1.9 million per year3, compared to companies not deploying similar security solutions.

· Employment of certified/expert security personnel trigger savings of US$1.5 million3.

· The appointment of a high-level security leader can reduce costs by US$1.3 million3.

“With cyber attacks growing in both frequency and severity, understanding of the financial impact can help organisations determine the appropriate amount of investment and resources needed to prevent or mitigate the consequences of an attack,” said Dr Larry Ponemon, chairman and founder, Ponemon Institute. “As seen in this year’s study, the return on investment for organisations deploying security intelligence systems, such as SIEM, realised an average annual cost savings of nearly US$4 million – showcasing the ability to minimise impact by more efficiently detecting and containing cyber attacks.”

Across all seven countries studied, the US sample reported the highest total average cost of cyber crime at US$15 million per company. The Japan sample ranked third globally at US$6.81 million while the Australia sample ranked second lowest out of seven countries, reporting an average cost of cyber crime at US$3.47 million3.

Interested?

Hear more detail on the Cost of Cyber Crime Study’s findings and how actionable security intelligence can help to minimise the impact of cyber crime through a webcast being held Wednesday, October 14 at 12 pm EDT (12am October 15 Singapore time). 



1 2015 Cost of Cyber Crime Study: Australia, Ponemon Institute, September 2015.
2 2015 Cost of Cyber Crime Study: Japan, Ponemon Institute, October 2015.
3 2015 Cost of Cyber Crime Study: Global, Ponemon Institute, October 2015.
4 2014 Cost of Cyber Crime Study: Australia, Ponemon Institute, October 2014.
5 2014 Cost of Cyber Crime Study: Japan, Ponemon Institute, October 2014.

30 September 2015

Cybercriminals love Donnie Yen and Jackie Chan

Hong Kong actor and martial arts expert Donnie Yen has been revealed as Intel Security’s most dangerous celebrity to search for online from Singapore. For the fifth year in a row in Singapore, Intel Security researched* celebrities to reveal which of them generates the most dangerous search results. 

Cybercriminals are always looking for ways to take advantage of consumer interest around popular culture. They capitalise on this interest by enticing unsuspecting consumers to sites laden with malware, enabling them to steal passwords and personal information. For Singapore, the Intel Security Most Dangerous Celebrities study revealed that searches for certain martial art legends, established female actresses and musicians tend to expose Internet searchers to more viruses and malware.

“The pervasiveness of electronic goods and gadgets, as well as a desire for real time information, has resulted in consumers often clicking on sites that will quickly provide them with news and entertainment. Often, safety and security implications are not considered,” said David Freer, Vice President, Consumer APAC at Intel Security. “Cybercriminals leverage this need for immediacy by encouraging people to visit unsafe sites that can steal private data.”

People in Singapore looking to download free music or free movies may be especially at risk, the company notes. “Celebrity names combined with the terms ‘free MP4, ‘HD downloads,’ or ‘torrent’ are some of the most searched terms on the Web,” Freer warned. "When consumers search for music that is not made available through legitimate channels, they put both their digital lives and devices at risk.”

Kungfu heroes top the list: Yen and fellow action hero Jackie Chan claimed the top two spots in the top 10 list, a testament to the longevity of the popularity of martial arts as a form of entertainment in popular culture.

Multi-tasking entertainers generate more risk. Industry veteran Andy Lau (No. 7) is a singer-songwriter, actor, presenter, and film producer. Daniel Henney (No. 6) is a “mactor” (model and actor) while Angelababy (No. 8) is a singer, actress and model.

Female actresses in their 30s and 40s: Gong Li is at No. 5, Maggie Q at No. 9 and Jun Ji-Hyun rounding is No. 10.

Music acts are popular: Singer-songwriter Jay Chou hit No. 4 and K-pop group Girls Generation reached No. 3.

Intel Security advises users to:

Beware of clicking on third-party links. Access content directly from official websites of content providers.

Use web protection that will alert users of risky sites or links. Stick to official news sites for breaking news.

Download videos from well-known, legitimate sites. Most news clips can easily be found on official video sites and do not require any downloading.

Use caution when searching for “HD downloads.” This term is by far the highest virus-prone search term. Consumers searching for videos or files to download should be careful as not to unleash unsafe content such as malware onto their computers.

Always use password protection on mobile devices. If a phone is lost or stolen, those without passwords will yield the owner's personal information to anyone who uses the device.

Don’t 'log in' or provide other information. If you receive a message, text or email or visit a third-party website that asks for your information — including your credit card, email, home address, or Facebook login — to grant access to information, don’t do it. Such requests are a common tactic for phishing that could lead to identity theft.

Interested?

Tools such as McAfee WebAdvisor software protect users from malicious websites and browser exploits. Download a complimentary version

Hashtag: #RiskyCeleb

*The study was conducted using McAfee WebAdvisor, using SiteAdvisor site ratings to determine the number of risky sites that would be generated in search results including a celebrity name and commonly searched terms (noted below) and calculates an overall risk percentage for that celebrity. McAfee SiteAdvisor technology helps protect users from malicious websites and browser exploits. SiteAdvisor technology tests and rates nearly every Internet website it finds, and uses red, yellow and green icons to indicate the website’s risk level. Ratings are created by using patented advanced technology to conduct automated website tests and works with Internet Explorer, Chrome, Safari and Firefox.

The terms “Donnie Yen” “Donnie Yen HD downloads,” “Donnie Yen free MP4,” and “Donnie Yen torrent” were used to search for Donnie Yen, and similar terms were used for each celebrity on the list. The results indicated the percentage of risk of running into online threats — if a user clicked all the results generated by the terms. Fans clicking on sites deemed risky and downloading files including photos and videos from those sites may also be prone to downloading viruses and malware.