MAS スピーチ · 2026-07-14

「警戒、レジリエンス、信頼:アジア太平洋の金融セクターを守る」— シンガポール金融管理局(MAS)副局長(金融監督)Ho Hern Shin 氏による FS-ISAC APAC サミット基調講演、2026年7月14日

Ho Hern Shin · シンガポール金融管理局副局長(金融監督) · FS-ISAC APAC サミット(7月14日)

要点

  • FS-ISAC APAC Intelligence Centreは、2017年にMASとの協業を通じて設立され、当初の3つの会員企業から、アジア太平洋地域の20カ国にわたる130社以上の会員へと成長しました。
  • 2025年にシンガポール拠点の第三者ベンダーに対するランサムウェア攻撃により、重大なデータ流出が発生しました。4月のToppan Next Tech事件ではDBS及びBank of Chinaの顧客11,000人以上が被害を受け、5月のDataPost事件ではIncome Insurance加入者146人以上が被害を受けました。
  • ディープフェイク技術は、シニアレベルの金融機関幹部、政府関係者、政治家になりすまして、従業員に詐欺師のアカウントへの送金を誘引するために、ますます使用されるようになっています。
  • Frontier AIは、脅威アクターが脆弱性を特定し、連鎖させ、大規模かつ迅速に悪用することを可能にすることで、既存のサイバー脅威を増幅させる力の乗数として特定されています。
  • 中核的なサイバー衛生慣行(適切なテストおよび変更管理を伴うタイムリーなパッチ適用、多要素認証による管理者アカウントの保護、正確なソフトウェア資産インベントリの維持、サポート終了前のシステム廃止)は、現在および新興のサイバー攻撃に対する基本的な防衛手段として機能し続けています。
  • FS-ISACなどの地域的脅威インテリジェンスプラットフォーム(Americas、APAC、EMEA地域にわたるサイバー脅威レベルを定期的に更新)を通じたタイムリーな情報共有は、集団的な状況認識と協調したセクター回復力にとって不可欠です。

全文翻訳

MAS 英語原文の翻訳 · 翻訳日: 2026-09-14

議長のテライさん、ご来賓の皆様、ご列席の皆様、本当におはようございます。まず第一に、本サミットを主催していただいたFS-ISACにお礼申し上げるとともに、シンガポールでのFS-ISACの10周年を迎える皆様をお祝い申し上げます。2017年、MASとFS-ISACは協力して、Asia Pacific Regional Intelligence and Analysis Centre(アジア太平洋地域インテリジェンス・分析センター)を設立し、地域のサイバーセキュリティ脅威インテリジェンスの共有と分析を促進することになりました。これはAPAC全域の金融機関(FIs)のサイバーレジリエンスを強化する上で、重要な一歩を示しました。この設立以前は、金融セクターコミュニティ内のインテリジェンス共有は、機会的で、断片的で、かつ無組織的でした。FIsは主に各々がサイバー脅威インテリジェンスを収集していて、外部のサイバー脅威状況に対する集団的な状況把握は限定的でした。FS-ISAC APACインテリジェンスセンターの設立は、良好に結合されたインテリジェンス共有コミュニティが、単独で行動する防御者よりもはるかにレジリエントであるという確固たる信念に支えられていました。過去10年間で、このビジョンは根を張りました。地域内でわずか3つの会員企業からスタートしたものは、APAC内の20カ国にわたる130社を超える会員を持つコミュニティに成長しました。会員数の増加を超えて、FS-ISACは今日、APAC内のFIs間の意味のあるインテリジェンス共有のための主要な「行き先」プラットフォームです。FS-ISACはまた、インテリジェンスレポート、脅威コール(FS-ISACのAPACインテリジェンスチームが主催する隔週ウェビナーで、最新のサイバー脅威トレンドと、FI会員コミュニティによってまとめられた地域のサイバー脅威レベルの更新をカバーしています)、およびこのサミットなどのイベント開催を通じて、機関が結束を育むことを支援してきました。過去を振り返ると、FS-ISACはAPAC内での効果的なサイバー防御のための重要な基礎を築いてきました。サイバー脅威が速度、スケール、複雑性において進化し続けているため、これはさらに重要性を増しています。サイバー脅威状況の進化

過去10年間で、私たちは金融セクターに対するサイバー脅威の4つの大きな変化を観察してきました。

(a)第一に、攻撃はより高度化しています。今日の攻撃は、電子メールフィッシング、受信箱の侵害、またはDDoS攻撃を超えています。ランサムウェア感染、および防御の手薄い第三者ベンダーや仕入先を通じた攻撃、ならびにAI対応のなりすまし行為がますます一般的になっています。(b)第二に、攻撃者はますます高度に相互接続された金融セクターエコシステムの弱点を標的にしており、第三者のサービスプロバイダー、さらには顧客さえも含まれています。これにより、これらの企業に対する攻撃面が効果的に拡大され、侵害の可能な入口が拡大されます。(c)第三に、脅威行為者のプロフィールもまた、より多様になっており、金銭的動機を持つサイバー犯罪者、活動家グループ、からスクリプトキディなどの組織化されていない、機会主義的な脅威行為者まで、幅広い範囲に及んでいます。(d)第四に、世界中の地政学的緊張がサイバー活動を高めています。例えば、ロシアの国家支援を受けたサイバー脅威行為者は、ウクライナとNATO同盟国の重要インフラを紛争の開始時に標的にし、進行中のロシア・ウクライナ紛争の期間中も標的にし続けています[ Link ]。日本などの国も、制裁を課している他の国々とともに、ロシアと関係があると思われるグループからのランサムウェアおよびDDoS攻撃の増加を観察しています[ Link ]。これは、影響力を投影しようとするハクティビストからであれ、不確実性を金銭的利益のために悪用するサイバー犯罪グループからであれ、より広い戦略目標を追求する国家関連の行為者からであれ、のいずれかです。

本日、シンガポールのサイバー脅威状況は、より広いAPAC地域の縮図のままです。ランサムウェア攻撃とデータ流出は、この部分の世界のFIsに対する深刻な脅威であり続けています。これらのインシデントは、しばしば不十分なアクセス制御やエッジデバイスに関する未適用の脆弱性などの馴染みのある弱点から発生し、攻撃者はFIシステムのデータを盗み、身代金のために暗号化することを可能にします。第三者のブリーチは、懸念のもう一つの領域を表しています。シンガポール当局のコンテキストでは、私たちは昨年の企業印刷サービスプロバイダーToppan Next Tech(2025年4月、印刷ベンダーのToppan Next Tech(TNT)へのランサムウェア攻撃により、DBSバンクおよびBank of Chinaの11,000人を超える顧客の名前と住所が流出され、その後、侵害されたTraffic Policeのデータがオンラインで公開されることになりました[ Link ])およびDatapostへのランサムウェア攻撃(2025年5月、シンガポール系のデータ処理業者DataPostへのランサムウェア攻撃により、少なくとも146人のIncome Insuranceの保険契約者に属する名前、住所、および年間ボーナス記録を含む個人データが流出しました[ Link ])を記憶するでしょう。これにより、運用上の混乱と顧客データの流出がもたらされました。同時に、デジタル詐欺の脅威は急速に進化しています。ディープフェイクの使用の増加により、脅威行為者は信頼できる個人を高度な精密さでなりすます能力を得ています。MASは、シニアFI幹部、政府関係者、および政治家がFI従業員に詐欺師の銀行口座への資金移動を促すためになりすまされたディープフェイクケースについて知らされています。これらのディープフェイクインシデントは、重要な現実を強調しています。ますます、脅威行為者はシステムの脆弱性だけを標的にしています。彼らはまた、信頼そのものを標的にしています。彼らの目的は、混乱を生み出し、信頼を損なわせ、私たちの機関が大切にしている信頼できる関係を破壊することです。Frontier AIリスク

ごく最近、Frontier AIがセクターが直面する必要のあるより幅広く深い課題を提示しています。グローバルなサイバーセキュリティ機関とセキュリティ研究者の両方が、Frontier AIが脆弱性をスケールと速度の両面で特定、連鎖、悪用する可能性を強調しています。Frontier AIは、サイバーリスクがどのように発生し、スケールするかを根本的に変えています。AIは独立したリスクカテゴリではなく、サイバー状況全体の既存の脅威を増幅する力の倍増装置です。このコンテキストにおいて、サイバーハイジーンはかつてないほど重要です。タイムリーなパッチ適用、MFAなどの強力な認証によるアドミニストレータアカウントの保護、ソフトウェア資産の正確なインベントリの維持、およびサポート終了に達する前のシステムの廃止という基本的なセキュリティ原則は、現在および将来のサイバー攻撃から機関を保護するための中核の信条のままです。しかし、サイバーハイジーンを実行する方法は変更が必要です。パッチを適用するのに要する時間は減らす必要があります。意図しないレジリエンスまたはセキュリティの問題が生じるのを避けるため、適切なテストと変更管理は維持されます。Frontier AIsが表面化させている脆弱性の膨大な数を考えると、FIsはパッチ適用の進捗に追いつくことは困難になります。強化されたアプローチが検討される必要があります。これには、パッチ適用の考え方から脆弱性管理の考え方(悪意のあるトラフィックをブロックするためにバーチャルパッチを使用するなど)への移行が含まれます。Frontier AI対応の攻撃者の速度に対抗するために、FIsはまた、コードセキュリティ、パッチの優先順位付け、および侵入検知などの領域で改善するために、AI対応のディフェンスを採用する必要があります。この点で、すべてのFIsが高度なAI搭載のディフェンスに投資する立場にあり、専用の脅威インテリジェンスチームを持っているわけではありません。一部のFIsはリソースと専門知識ははるかに少ないですが、同じリスクに直面しています。AI対応の脅威に対する防御で遅れている人は、より広いエコシステム内の弱いリンクになる可能性があり、私たちの集団的防御を損なわせます。したがって、私たちはすべての人を連れていくという共有された関心を持っています。これを行うための一つの手段は、セクター全体での共有を改善することにより、すべての防御者が新たな脅威に関する最新情報を保つことを支援することです。FIsが新たな脅威と対抗策の両方をより明確に把握しているとき、彼らは効果的な先制措置を講じるために限定されたリソースをより良く優先順位付けすることができるようになります。私たちはFS-ISACがFrontier AIリスクに関するタイムリーな勧告を発行し、新たな懸念を実践的なガイダンスに変える思想的リーダーシップを引き継ぐことを期待しています。

助言は、しかし、最初に新たな脅威を特定する最前線にいるFIsによるタイムリーな情報共有に大きく依存しています。これはFS-ISACなどの信頼できるサイバー情報共有プラットフォームが非常に貴重になる場所です。私はFS-ISACワークグループの議論を通じて、Americas、APAC、およびEMEA地域のサイバー脅威レベルが定期的に更新され、単一の機関のツールとフレームワークが提供できるものを超える状況把握が提供されていると言われています。したがって、業界は情報共有を改善するために協力する必要があり、新たなAI対応の脅威などの洞察が迅速に配信され、実行されることができます。サイバー労働力の向上。AI ツールで労働力がスキルアップするにつれて、FIs はコア サイバーセキュリティ能力の訓練を無視してはいけません。チームは依然としてAI生成の出力を精査し、本物の脅威を誤検知から区別し、優先順位を付けるべき内容を判断し、ケースをエスカレートする時期を決定する必要があります。自動化されたソリューションは反復的なセキュリティ関連タスクの負荷を軽減するかもしれませんが、インシデント調整、利害関係者コミュニケーション、および説明責任は依然として本来的に人間の責任のままです。この部屋にいるセキュリティアナリスト、マネージャー、および情報専門家は、私たちの集団的サイバー防御に不可欠です。ツールが豊富であり、セキュリティ業務の自動化が増加しているにもかかわらず、私たちの防御者はまだ防御の最後の砦を形成しています。脅威はより洗練されるかもしれませんが、あなたのスキル、判断、および警戒が最終的に業界がどのように対応するかを決定するのはあなたのスキル、判断、および警戒です。APACでは、私たちの防御者の役割はこれまでになく重要です。この地域は、タイムリーで協調的な対応を要求する急速に変動する高度なサイバー脅威にますます晒されています。したがって、地域インテリジェンス共有とコラボレーションは、もはや少数の機関による任意の貢献と見なすことはできません。APACコミュニティ内の各メンバー全体で一般的な慣行となる必要があります。これがこのサミットなどのイベントが非常に重要な理由です。サイバー防御はチームスポーツです。フットボールとよく似ており、単一のプレイヤーが単独でマッチに勝つことはありません。チームメイト間の協調と信頼は、良い結果をもたらすのに不可欠です。最後に、その指導力に対してFS-ISACに改めてお礼申し上げ、過去10年間シンガポールでこのコミュニティを集めていただいたことに感謝いたします。このサミットでの討議が、我々のセクターが今後数年間レジリエントを保つために必要とする信頼、洞察、実践的協力を深めることを願っています。ありがとうございました。

英語原文

MAS 公式サイト原文 · 取得日: 2026-09-14

Summit Chair, Terai-san, Distinguished Guests, Ladies and gentlemen, a very good morning to all of you. 2 First, allow me to thank FS-ISAC for organising this Summit, and to congratulate you as we mark FS-ISAC’s 10th anniversary here in Singapore. 3 In 2017, MAS and FS-ISAC collaborated to establish the Asia Pacific Regional Intelligence and Analysis Centre, to encourage regional sharing and analysis of cybersecurity threat intelligence. This represented a significant step in strengthening cyber resilience of financial institutions (FIs) across APAC. Prior to this, intelligence sharing within the financial sector community had been opportunistic, patchy, and unorganised. FIs largely went about their own way to gather cyber threat intelligence, and collective situational awareness of the external cyber threat landscape was limited. The establishment of the FS-ISAC APAC Intelligence Centre was anchored upon the firm belief that a well-connected, intelligence-sharing community would be far more resilient than any single defender acting in isolation. 4 Over the past decade, this vision has taken root. What began with just three member firms in the region has grown into a community of more than 130 members spanning 20 countries in APAC. Beyond the growth in membership numbers, FS-ISAC is today a key “go to” platform for meaningful intelligence sharing amongst FIs in APAC. FS-ISAC also has helped institutions foster cohesion and strengthen awareness of emerging threats through its intelligence reports, threat calls Threat calls are bi-weekly webinars hosted by FS-ISAC’s APAC intelligence team which cover the latest cyber threat trends and updates on the regional cyber threat level (collated by its FI member community). , and hosting events like this Summit. 5 Looking back, the FS-ISAC has laid an important foundation for effective cyber defence in APAC. This has become even more significant as cyber threats continue to evolve in speed, scale and complexity. Evolving Cyber Threat Landscape

6 Over the past 10 years, we have observed four broad shifts in cyber threats against the financial sector.

(a) First, attacks are getting more sophisticated. Attacks today go beyond email phishing, inbox compromise, or DDoS attacks. Ransomware infections, and attacks through less well defended third-party vendors and suppliers, as well as AI-enabled impersonations are increasingly commonplace. (b) Second, attackers are increasingly targeting the weak links in our highly interconnected financial sector ecosystem, such as third party service providers, and even customers. This effectively extends the attack surface to these entities, expanding the potential entry points for compromise. (c) Third, the profile of threat actors has also become more diverse, ranging from financially motivated cybercriminals, activist groups, to less organised, opportunistic threat actors such as script kiddies. (d) Fourth, geopolitical tensions around the globe have heightened cyber activity For example: Russian state-sponsored cyber threat actors targeted Ukrainian and NATO-aligned critical infrastructure at the onset, and ongoing Russia-Ukraine conflict [ Link ]. Countries such as Japan also observed increased ransomware and DDoS attacks from suspected Russia-aligned groups due to imposing sanctions along with other countries. [ Link ] , whether from hacktivists seeking to project influence, cybercriminal groups exploiting uncertainty for financial gain, or state-linked actors pursuing broader strategic objectives.

7 Today, Singapore’s cyber threat landscape remains a microcosm of the broader APAC region. Ransomware attacks and data exfiltration continue to post a serious threat to FIs in this part of the world. These incidents often stem from familiar weaknesses such as inadequate access controls and unpatched vulnerabilities on edge devices, which allow attackers to steal data and encrypt FI systems for ransom. 8 Third-party breaches represent another area of concern. In the Singapore context, we will remember last year's ransomware attacks on corporate printing service providers Toppan Next Tech In Apr 2025, a ransomware attack on printing vendor Toppan Next Tech (TNT) in April 2025 resulted in the extraction of names and addresses belonging to over 11,000 customers of DBS Bank and the Bank of China, later leading to a subsequent publication of compromised Traffic Police data online [ Link ] . and Datapost In May 2025, a ransomware attack on Singapore-based data handling vendor DataPost exfiltrated personal data, including names, addresses, and annual bonus records belonging to at least 146 Income Insurance policyholders. [ Link ] , which caused operational disruptions and exposure of customer data. 9 At the same time, the threat of digital fraud is evolving rapidly. The increasing use of deepfakes has enabled threat actors to impersonate trusted individuals with a growing degree of sophistication. MAS has been made aware of deepfake cases in which senior FI executives, government officials and politicians were impersonated to induce FI employees to transfer funds into fraudsters’ bank accounts. 10 These deepfake incidents highlight an important reality. Increasingly, threat actors are not only targeting vulnerabilities in our systems. They are also targeting trust itself. Their objective is to create confusion, undermine confidence, and disrupt the trusted relationships that our institutions so dearly rely upon. Frontier AI Risks

11 Most recently, frontier AI is posing broader and deeper challenges that the sector must now confront. Both global cybersecurity agencies and security researchers highlight the potential for frontier AI to identify, chain and exploit vulnerabilities at both scale and speed. Frontier AI is fundamentally reshaping how cyber risks can arise and scale. AI is not a separate risk category, but a force multiplier that amplifies existing threats across the cyber landscape. 12 In this context, cyber hygiene has never been more important. The fundamental security principles of timely patching, securing administrator accounts with strong authentication such as MFA, maintaining an accurate inventory of software assets, and retiring systems before they reach end-of-support remain core tenets of protecting institutions against both current and future cyber-attacks. 13 However, the manner in which we execute cyber hygiene will require changes. The time taken to patch must reduce, with proper testing and change management maintained, to avoid introducing unintended resilience or security issues. FIs will be hard pressed to keep up with the patching cadence, given the significant number of vulnerabilities frontier AIs is and will continue to surface. Enhanced approaches must be considered. This includes moving from a patching mindset to a vulnerability management mindset such as using virtual patching to block malicious traffic. 14 To match the speed of the frontier AI enabled attackers, FIs will also need to up their ante to adopt AI-enabled defences - to improve in areas such as code security, patch prioritisation, and intrusion detection. 15 In this regard, not all FIs are equally positioned to invest in advanced AI-powered defences and have dedicated threat intelligence teams. Some FIs face the same risks with far less resources and expertise. Those who lag behind in defending against AI-enabled threats could become weak links in the wider ecosystem, eroding our collective defence. We thus have a shared interest to bring everyone along. 16 One avenue to so is to help every defender stay abreast emerging threats by improving sharing across the sector. When FIs have a clearer view of both emerging threats and countermeasures, they will be better placed to prioritise their limited resources to take effective pre-emptive measures. We see FS-ISAC taking up the thought leadership to issue timely advisories on frontier AI risks and translate emerging concerns into practical guidance for FIs.

17 Advisories, however, are heavily reliant on timely information-sharing by FIs who are at the frontline that first identify emerging threats. This is where trusted cyber information-sharing platforms such as FS-ISAC become invaluable. I am told that cyber threat levels across the Americas, APAC, and EMEA regions are regularly updated through FS-ISAC workgroup discussions, providing situational awareness that extends far beyond what any single institution's tools and frameworks can offer. Therefore, the industry must work together to improve information sharing so that insights such as emerging AI-enabled threats can be quickly disseminated and acted upon. Uplifting the Cyber Workforce 18 As our workforce upskills in AI tools, FIs must not neglect training in core cybersecurity competencies. Teams are still needed to scrutinise AI-generated outputs, distinguish genuine threats from false positives, what leads to prioritise, and decide when to escalate cases. While automated solutions may reduce the load of repetitive security-related tasks, incident coordination, stakeholder communication and accountability remain innately human responsibilities. 19 The security analysts, managers and intelligence professionals in this room are indispensable in our collective cyber defense. Notwithstanding the plethora of tools, and increasing automation of our security operations, our defenders still form the last line of defence. Threats may grow more sophisticated, but it is your skill, judgement and vigilance that will ultimately determine how our industry responds. 20 For APAC, the role of our defenders is more important now than ever. The region is increasingly exposed to fast-moving and sophisticated cyber threats that warrant timely and coordinated responses. Regional intelligence sharing and collaboration can therefore no longer be viewed as a voluntary contribution by a few institutions; it must become common practice across each and every member within the APAC community. 21 This is why events such as this Summit are so essential. Cyber defence is a team sport. Much like football, no single player wins the match alone; the coordination and trust between teammates is essential in delivering a good outcome. 22 Let me close by thanking FS-ISAC once again for its leadership, and for convening this community over the past decade in Singapore. I hope the discussions at this Summit will deepen the trust, insights and practical cooperation that our sector will need to stay resilient in the years ahead. Thank you.