MDDI スピーチ · 2026-04-17

STACKx Cybersecurity Conference 2026 における SMS Tan Kiat How による開会挨拶

陳傑豪 · MDDI 上級政務部長 · STACKx Cybersecurity ConferenceにおけるHow

要点

  • GovTechの創設10周年を迎え、市民と政府間の取引の99%がデジタルで完了するようになりました。Singpassは月間4,100万件以上の取引を処理しており、LifeSGは130以上の政府サービスを単一のアプリに統合しています。
  • CSAとGovTechは、フロンティアAIリスクについてCritical Information Infrastructure(CII)の所有者および政府機関に対して警告を発しました。その中では、Anthropicの「Claude Mythos」がゼロデイ脆弱性を自律的に特定し、実際に機能するエクスプロイトへと連鎖させることが可能であると報告されていることが言及されています。
  • シンガポールは、CII所有者との関係において、規制者・被規制者モデルからパートナーシップモデルへと移行しつつあります。その好例がOperation Cyber Guardianであり、通信インフラを標的としたUNC3886 APT攻撃に対して複数の政府機関にわたるサイバー防衛担当者を動員したものです。政府は現在、機密の脅威インテリジェンスや独自の脅威検知システムを選択的に共有するようになっています。
  • GovTechのGovernment Bug Bounty Programmeは2018年から継続して実施されており、世界各地のホワイトハットハッカーを参加させ、60以上の政府機関と連携するとともに、1,000件を超えるセキュリティ上の問題を発見してきました。
  • 政府はAIとサイバーセキュリティを三つの側面から捉えています。すなわち、AIを脅威として——大規模かつより迅速で高度な攻撃を可能にするもの——、AIをツールとして——より早期の検知と迅速な対応を実現するもの——、そしてAIをターゲットとして——安全な導入のための標準が求められるもの——というかたちです。
  • シンガポールのサイバーセキュリティ人材の育成パイプラインは、CSAのSG Cyber Talentイニシアティブを通じて、若者から経験豊富な専門家まで幅広くカバーしています。一方、GovTechは自らのサイバーセキュリティチームにAI特化型トレーニングを提供するとともに、政府全体への展開を予定した専門的なキャリアパスを開発しています。
  • シンガポールのサイバーセキュリティガバナンスは最高レベルで確立されており、Prime Minister's Officeが直接的な監督権限を担い、国家安全保障担当調整大臣およびサイバーセキュリティ担当大臣がそれぞれ任命されることで、リーダーシップの説明責任が強調されています。

全文翻訳

MDDI 英語原文の翻訳 · 翻訳日: 2026-06-21

おはようございます。本日はSTACKx サイバーセキュリティ会議にご参加の皆様とともに出席できることを光栄に思います。

今年は、GovTechの創設10周年という節目でもあります。GovTechは、市民が政府と関わる方法を根本的に変革しました。

現在、市民と政府のやり取りの99%はデジタルで完結しており、市民と公共部門の双方に利益をもたらす、より効率的で利便性の高いサービスの提供が実現しています。

Singpassは、日常サービスへのより安全かつ迅速なアクセスを可能にする国家デジタルアイデンティティへと進化し、月間4,100万件を超えるトランザクションを支えており、ほとんどの住民にとって紙の書類の記入を事実上不要としています。

LifeSGもその一例であり、130以上の政府サービスを一元化したワンストップアプリとして、家族や個人が政府サービスをより簡単に利用できるよう支援しています。

GovTechのチーム全員の努力を称えるとともに、過去10年間にわたり緊密に連携してくださったパートナーの皆様に心より感謝申し上げます。今後もさらなる節目の達成を楽しみにしています。

これらの成果を祝う一方で、ますます複雑化するサイバー空間を航行していく中で、私たちのデジタルシステムの攻撃対象領域(アタックサーフェス)が大幅に拡大していることを認識しています。

第一に、サイバー犯罪者から傭兵グループ、国家支援を受けたアクターに至るまで、これまで以上に多くの敵対者の脅威に直面しています。

例えば最近、シンガポールの通信インフラを高度な手法で標的にした持続的標的型脅威(APT)であるUNC3886への対処を余儀なくされました。

第二に、AIは急速に進歩しています。AIとサイバーセキュリティは深く絡み合っています。AIはサイバー防衛者にとって大きな機会となる一方、ますます高速化・高度化する大規模サイバー攻撃への悪用も懸念されます。

Anthropicが最近発表したClaude Mythosに関するレポートは、サイバーコミュニティに大きな波紋を呼んでいます。同モデルはゼロデイ脆弱性を自律的に特定し、それらを連鎖させて実際に機能するエクスプロイトへと組み上げる能力があると報告されています。専門家の間では、こうした開発動向が脅威の状況における飛躍的な変化を意味するという見解が広く共有されています。悪意ある者の手に渡れば、技術力の低い脅威アクターでさえ大規模かつ高速な高度攻撃を実施できるようになります。AIによって能力を増強された熟練のオペレーターの手に渡った場合にもたらされる被害は、想像に難くありません。

Claude Mythosは、根本的に新しい種類の攻撃を生み出すものではありません。しかし、このようなAIツールがサイバー攻撃の実施に必要な時間とリソースを削減することは認識されています。組織は、フロンティアAIモデルを利用した攻撃リスクに対し、サイバー防衛態勢全体を強化するための積極的な措置を講じる必要があります。

組織はデジタルシステムをいかに保護するかについて、根本的な見直しを迫られるでしょう。例えば、組織が脆弱性にパッチを適用するために与えられる時間は、日単位から分単位へと縮小するかもしれません。

これまで、難解なソースコードを持つレガシーシステムや運用技術(OT)システムを抱える組織は、これらのシステムを侵害するには専門的なスキルセットが必要であることを安心の根拠としていました。しかし今やAIは、脆弱性の特定と悪用を加速させることができます。

パンドラの箱はすでに開かれました。

そのため、シンガポールサイバーセキュリティ庁(CSA)とGovTechは、重要情報インフラ(CII)の所有者および政府機関に対してアラートを発出しました。CSAはまた、フロンティアAIリスクに関する勧告を公表しました。同勧告では、高度に重大な脆弱性へのパッチ適用などの即時緩和措置のほか、AIを活用して脆弱性を積極的に特定・対処するといった防衛戦略が示されています。

私たちはこれらの脅威を真剣に受け止めなければなりません。

本日は、サイバー空間を安全に保つために必要な三つの重要な要素についてお話ししたいと思います。

サイバー空間の安全確保における政府の役割の再定義

第一に、政府の役割についてです。

シンガポールがサイバーセキュリティの取り組みを正式に組織化したのは、約10年余り前のことです。

2015年にはCSAを設立してシンガポールのサイバーセキュリティを一元的に統括する体制を整え、サイバーセキュリティ戦略を打ち出しました。

2016年にはGovTechを立ち上げてスマートネーション構想を推進するとともに、政府システムのサイバーセキュリティ監督の責任を担わせました。

また、サイバーセキュリティ法(Cybersecurity Act)を成立させ、必須サービスを保護するための法的枠組みを確立しました。

これらの取り組みにより、CII所有者に求められるサイバーセキュリティ基準の明確化や、監査・コンプライアンスの枠組みといった基盤を整えることができました。

変化した運営環境におけるサイバーセキュリティの脅威に対処するためには、組織はサイバーセキュリティを単なる要件充足のためのチェックボックス作業としてではなく、真剣に向き合うべき課題として捉える必要があります。また、個々の組織のサイバーセキュリティ態勢を向上させるだけでは不十分です。

次の例えを考えてみてください。自宅を安全に保つには、強固な鍵を取り付け、運任せにしないことが必要です。それは最低限の対策であり、各家屋所有者の利益にもかないます。しかし同時に、いかに強力な鍵を持っていても、近隣地域全体が安全でなければ、侵入されるリスクは依然として高いままです。すべての人にとって安全な環境を作るためには、集団的な取り組みが必要です。

そのため、政府はCII所有者との従来の規制者・被規制者という関係を超え、サイバー脅威に共同で立ち向かうべく、組織とより緊密なパートナーシップを築いています。

UNC3886攻撃に対する私たちの集団的対応は、この変化を体現するものです。通信事業者が攻撃を受けた際、政府はOperation Cyber Guardianのもとで複数の機関にまたがるサイバー防衛者を動員し、事業者と緊密に連携して脅威に対処しました。

先月の予算委員会審議(Committee of Supply Debate)では、APTに対するCII所有者との取り組みを強化していることをお伝えしました。政府はCII所有者を積極的に支援するため、機密の脅威インテリジェンスを選択的に共有するとともに、十分なリソースを持つ敵対者から身を守るための独自の脅威検知システムを提供していきます。

この共同責任の概念は、政府・企業・個人がそれぞれ役割を担うシンガポールのTotal Defenceのアプローチと共通しています。

同様に、サイバーセキュリティにおいてもこの集団的精神を育む必要があります。

能力向上に向けた官民連携の強化

政府はサイバー空間の保護に全力を尽くしますが、すべての答えを持ち合わせているわけではありません。民間部門には豊富な専門知識と能力が蓄積されています。これが、官民連携の重要性という第二のポイントにつながります。

本日は民間部門から多くの方々にご参加いただき、大変嬉しく思います。この機会が、皆様とともに学び合い、新たな関係を築く場となることを願っています。

協力し合い、経験を共有することで、私たちの防衛を強化するネットワークを構築することができます。

GovTechのGovernment Bug Bounty Programmeはその一例です。2018年以来、世界中のエシカルハッカーをクラウドソーシングし、60以上の機関と連携して1,000件を超えるセキュリティ上の問題を発見してきました。

AIの普及が進むにつれ、こうしたパートナーシップはさらに重要性を増します。私たちは共に、AIとサイバーセキュリティの三つの側面に取り組まなければなりません。

脅威としてのAIについてです。脅威アクターはAIを活用し、攻撃の速度・規模・巧妙さを高めています。これに対抗するため、脅威をリアルタイムで検知・軽減するための継続的なモニタリングと保証モデルへの移行が必要です。

ツールとしてのAIについてです。高度化したAI自動化攻撃チェーンに対抗するため、AIを活用する必要があります。AIは脅威の早期検知と迅速な対応を可能にし、攻撃者と防御者の間の非対称性を縮小することができます。

最後に、標的としてのAIについてです。企業がAIを安全に導入し、脆弱性とならないよう確保しなければなりません。そのためには、テストに関する能力の構築と、安全かつセキュアなAI利用のための標準の策定が求められます。

AI分野は急速に進化しており、先手を維持するには政府・産業界・学術界の緊密な連携が不可欠です。私たちに危害を加えようとする者より一歩先んじるため、AIの能力を最大限に活用して防衛に当たる必要があります。

政府はこうした課題において、民間部門と連携して主導的役割を担う準備ができています。本日のセッションでは、革新的なAI・サイバーセキュリティプロジェクトにおいてどのように協力できるかを探っていきます。

サイバーセキュリティ人材とリーダーの育成

第三に、サイバーセキュリティ人材とリーダーの育成についてです。AIと自動化について語る中でも、サイバー空間を守るうえで最も重要な要素は人であると確信しています。この点において、サイバーセキュリティの人材とリーダーシップは極めて重要です。

若者から経験豊富な専門家まで、あらゆる段階の人材を惹きつけ育成するための多様な経路を整備しています。需要は旺盛であり、良質な雇用とキャリアの展望が開けています。

CSAのSG Cyber Talentイニシアティブなどのプログラムを通じて、実践的スキルと即戦力の育成に重点を置いた総合的なトレーニングを提供しています。

AIがサイバーセキュリティに与える変革的な影響を踏まえ、AIを活用するとともにAIの脅威から守るための能力・コンピテンシーの構築が求められます。政府は率先して模範を示していきます。

GovTechはサイバーセキュリティチームに対し、サイバーセキュリティにおけるAI活用およびAIシステムのセキュリティに関するトレーニングを実施しています。専門的なトレーニング経路の開発と、これらのプログラムを政府全体に拡大する取り組みが進行中です。

産業界・学校・コミュニティと緊密に連携しながら人材の育成に取り組んでいます。政府と民間部門の間で人材が行き来することで知識の移転が促進され、エコシステム全体の能力が強化されます。政府が主導的役割を担い、私たちも貢献していますので、民間部門および学術界のすべてのパートナーの皆様にも、ぜひ共に取り組んでいただくよう呼びかけます。

しかし、人材は方程式の一部に過ぎません。優れたサイバーセキュリティには優れたリーダーシップも必要です。リーダーは、順調な時だけでなく、困難な時にこそより一層、責任ある判断を下せなければなりません。

サイバーセキュリティのリーダーシップは重要であり、デジタル変革やAI変革と同様に不可欠です。優れたブレーキを備えずに速い車が欲しいとは言えません。サイバーセキュリティはCISOやIT部門だけの技術的課題ではなく、CEOや取締役会が担うべきリーダーシップの責任です。

これはシンガポール政府内におけるサイバーセキュリティのガバナンスにも反映されています。

政府はサイバーレジリエンスが最高レベルの監督を必要とすることを認識しています。それゆえ、Prime Minister's Officeが国家のサイバーセキュリティ機能を直接統括しています。

Coordinating Minister for National SecurityおよびMinister for Cybersecurityの双方の任命は、リーダーシップの重要性をさらに強調するものです。

このリーダーシップのマインドセットは、すべての組織に根付かなければなりません。

結びに、シンガポールはますますグローバル化・AI駆動化が進む世界において、信頼できるパートナーであり続けることを固く誓います。

現状維持という選択肢はありません。脅威アクターは急速に動いており、AIが敵対的な能力を再定義しています。私たちはこれらの課題に立ち向かうとともに、これらの技術を活用して優位性を高めるイノベーションを推進しなければなりません。

私たちのサイバー空間の未来は、今日築くパートナーシップにかかっています。

皆様にとって実りあるセッションと会議となることを願うとともに、新たな友人をつくり、新たな関係を築き、このコミュニティ・オブ・プラクティスを育み続けることで、私たちのサイバー空間のさらなる安全確保に貢献されることを期待しています。ありがとうございました。

英語原文

MDDI 公式サイト原文 · 取得日: 2026-06-21

Good morning. I am pleased to join you at the STACKx Cybersecurity conference today.

This year, we are also marking the 10th anniversary of GovTech. GovTech has fundamentally shifted how citizens interact with the government.

Today, 99% of citizens' transactions with the government are completed digitally, enabling more efficient and convenient services that benefit citizens and the public sector alike.

Singpass has evolved into our national digital identity for safer and faster access to everyday services, supporting over 41 million transactions monthly, and effectively eliminating physical forms for most residents.

LifeSG is another example, serving as a one-stop app consolidating over 130 government services, helping families and individuals interact with government services with greater ease.

Well done to the entire GovTech team, and a big thank you to partners that have worked closely with them over the past 10 years! We look forward to many more milestones.

As we celebrate our achievements, we recognise that the attack surface of our digital system has increased significantly, even as we need to navigate an increasingly complex cyber landscape.

Firstly, we face many more adversaries, from cybercriminals to mercenary groups to state-backed actors.

For example, recently, we have had to deal with an advanced persistent threat (APT), UNC3886 which targeted Singapore’s telecommunications infrastructure with sophisticated techniques.

Secondly, AI is advancing rapidly. AI and cybersecurity are deeply intertwined. AI is a significant opportunity for cyber defenders but can also be misused for increasingly fast and sophisticated cyberattacks at scale.

Anthropic’s recent report on Claude Mythos has created a stir within the cyber community. It is reportedly capable of autonomously identifying zero-day vulnerabilities and chaining these into working exploits. There is consensus among experts that these developments represent a step jump in the threat landscape. In the wrong hands, it will enable even the less skilled threat actors to conduct sophisticated attacks at scale and speed. You can imagine the harm that can be done in the hands of skilled operatives who are augmented by AI.

Claude Mythos does not yet create fundamentally new classes of attacks. However, it is recognised that such AI tools reduce the time and resources required to conduct cyber-attacks. Organisations need to take proactive steps to strengthen their overall cyber defence posture against the risk of attacks from frontier AI models.

Organisations will need a fundamental rethink on how they secure their digital systems. For example, the time that organisations have to patch vulnerabilities may shrink from days to minutes.

In the past, organisations that have legacy systems with obscure source codes and Operational Technology systems could take comfort that specialised skillsets were required to compromise these systems. AI can now accelerate the identification and exploitation of vulnerabilities.

Pandora’s box has been opened.

As such, the Cyber Security Agency of Singapore (CSA) and GovTech have issued an alert to our Critical Information Infrastructure (CII) owners and government agencies. CSA has also published an advisory on frontier AI risks. This outlines immediate mitigation measures such as patching high-critical vulnerabilities, as well as other defence strategies like leveraging AI to proactively identify and address vulnerabilities.

We have to take these threats seriously.

Today, I would like to speak about three important elements needed to secure our cyberspace.

Reframing the role of the Government in securing cyberspace

First, the role of the Government.

Singapore formally organised its cybersecurity effort a little over a decade ago.

We established CSA in 2015 to provide centralised oversight of Singapore’s cybersecurity, and launched the Cybersecurity Strategy.

In 2016, we launched GovTech to drive our Smart Nation initiatives and gave it the responsibility of overseeing the cybersecurity of government systems.

We also passed the Cybersecurity Act and established the legislative framework to secure essential services.

These moves enabled us to put in place the foundations such as articulating the cybersecurity standards expected of our CII owners and the framework for audits and compliance.

To deal with the cybersecurity threats in a different operating environment, organisations need to see cybersecurity as not just another box-checking exercise to meet requirements; it is also not enough to just uplift the cybersecurity posture of individual organisations.

Consider this analogy: to keep your house safe, you must install strong locks on your house and not leave it to chance. That is the minimum and in the interest of each homeowner. At the same time, even if you have the strongest lock, if the rest of the neighbourhood remains unsafe, your risk of intrusion stays high. There needs to be a collective effort to create a secure environment for all.

Hence, the Government is moving beyond the traditional regulator-regulatee relationship with CII owners, and is partnering more closely with organisations to combat cyber threats together.

Our collective response to the UNC3886 attacks exemplifies this shift. When the telcos came under attack, the Government mobilised cyber defenders across different agencies under Operation Cyber Guardian and worked closely with the operators to tackle the threat.

At the Committee of Supply Debate last month, I shared how we are stepping up efforts with CII owners against APTs. The Government will lean in to help CII owners, selectively sharing classified threat intelligence and equipping them with proprietary threat detection systems to defend against well-resourced adversaries.

This shared responsibility concept is similar with the approach Singapore takes for Total Defence where the Government, firms and individuals all play a role.

Similarly, we need to foster this collective spirit for cybersecurity.

Strengthening public-private collaboration to uplift capabilities

While the Government will do our best to protect cyberspace, we will not have all the answers. There is a wealth of expertise and capabilities in the private sector. This brings me to my second point on the importance of public-private collaboration.

I am glad to see many attendees from the private sector today. I hope that this will be an occasion for all of us to learn together and build new relationships.

Through collaboration and sharing experiences, we build a network that strengthens our defence.

GovTech's Government Bug Bounty Programme is one such example. Since 2018, it has crowdsourced ethical hackers worldwide, working with over 60 agencies and uncovering more than 1000 security issues.

These partnerships will become even more critical as AI adoption grows. Together, we must address three aspects of AI and cybersecurity:

AI as a threat. Threat actors are using AI to increase the speed, scale and sophistication of their attacks. To counter this, we must shift toward a continuous monitoring and assurance model to detect and mitigate threats in real-time.

AI as a tool. We will need to harness AI to counter sophisticated, AI-automated attack chains. AI can enable earlier threat detection and faster response times and reduce the asymmetry between attackers and defenders.

Lastly, AI as a target. We must ensure enterprises adopt AI securely so it does not become a vulnerability. This means building capabilities in testing and establishing standards for safe and secure AI use.

The AI space is evolving rapidly, and staying ahead requires close collaboration between government, industry and academia. We need to make full use of AI capabilities to defend and be a step ahead of those who wish us harm.

The Government is prepared to take the lead in working with the private sector on these challenges. The sessions today will explore how we can collaborate on innovative AI and cybersecurity projects.

Developing cybersecurity talents and leaders

Third, developing cybersecurity talents and leaders. While we talk about AI and automation, I firmly believe that the most important ingredient to secure our cyberspace is our people. Cybersecurity talent and leadership are critical in this aspect.

We are developing multiple pathways to attract and nurture talent at all stages, from youths to experienced professionals. The demand is strong, with good jobs and career prospects ahead.

Through programmes like CSA's SG Cyber Talent initiative, we provide comprehensive training focusing on real-world skills and practical readiness.

AI’s transformative impact on cybersecurity demands building capabilities and competencies to use and guard against it. The Government is stepping up to lead by example.

GovTech has provided its cybersecurity teams with training on AI applications in cybersecurity and the security of AI systems. Work is underway to develop specialised training pathways and expand these programmes across the rest of government.

We work closely with industry, schools and the community to build up our workforce. Talent flows between government and the private sector, enabling knowledge transfer and strengthening capabilities across the ecosystem. Government is taking the lead and we are doing our part so I encourage all our partners in the private sector, as well as academia, to work together with us.

But talent is only part of the equation. Good cybersecurity also requires good leadership. Leaders must be able to make responsible decisions that hold up not only on good days, but even more so on bad days.

Cybersecurity leadership matters, and is as important as digital or AI transformation. You cannot say you want a fast car without putting in good brakes. Cybersecurity is not simply a technical issue for the CISO or IT department, but a leadership responsibility that the CEO and board must own.

This is reflected in the governance of cybersecurity within the Singapore Government.

The Government recognises that cyber resilience demands oversight at the highest levels. This is why the Prime Minister’s Office maintains direct stewardship over our national cybersecurity functions.

The appointment of both a Coordinating Minister for National Security and a Minister for Cybersecurity further underscores the importance of leadership.

This leadership mindset must take root in every organisation.

In closing, Singapore remains committed to being a trusted partner in an increasingly globalised, AI-driven world.

Standing still is not an option. Threat actors are moving fast, with AI redefining adversarial capabilities. We must rise to meet these challenges while driving innovation to harness these technologies to our advantage.

The future of our cyberspace depends on the partnerships we forge today.

I wish all of you a productive session and conference, and hope that you make new friends, build new relationships and continue to foster this community of practice to further secure our cyberspace. Thank you.