MAS 연설문 · 2026-07-14

「경계, 회복력, 신뢰: 아시아태평양 금융 부문 지키기」– 싱가포르 통화청(MAS) 부총재(금융감독) Ho Hern Shin의 FS-ISAC APAC 서밋 기조연설, 2026년 7월 14일

Ho Hern Shin · 싱가포르 통화청 부총재(금융감독) · FS-ISAC APAC 서밋 (7월 14일)

요점

  • FS-ISAC 아태 인텔리전스 센터는 2017년 MAS 협력을 통해 설립되었으며, 3개의 회원 기업에서 시작하여 이 지역의 20개국에 걸친 130개 이상의 회원으로 성장했습니다.
  • 2025년 싱가포르 기반 제3자 공급업체에 대한 랜섬웨어 공격으로 인해 상당한 데이터 유출이 발생했습니다: 4월 Toppan Next Tech는 11,000명 이상의 DBS 및 Bank of China 고객에게 영향을 미쳤으며, 5월 DataPost는 최소 146명의 Income Insurance 가입자에게 영향을 미쳤습니다.
  • 딥페이크가 고위 금융 기관 임원, 정부 관계자, 정치인을 사칭하여 직원들이 사기범의 계좌로 자금을 이체하도록 유도하는 데 점점 더 많이 사용되고 있습니다.
  • 프런티어 AI는 위협 행위자가 대규모로 신속하게 취약점을 식별, 연결, 악용할 수 있도록 함으로써 기존 사이버 위협을 증폭하는 배수로 식별되었습니다.
  • 핵심 사이버 위생 관행 — 적절한 테스트와 변경 관리를 포함한 시기적절한 패칭, 다중 인증을 통한 관리자 계정 보안, 정확한 소프트웨어 자산 인벤토리 유지, 지원 종료 전 시스템 폐기 — 은 현재 및 신흥 사이버 공격에 대한 근본적인 방어책으로 남아있습니다.
  • Americas, APAC, EMEA 지역 전반의 사이버 위협 수준을 정기적으로 업데이트하는 FS-ISAC과 같은 지역 위협 인텔리전스 플랫폼을 통한 적시의 정보 공유는 집단적 상황 인식과 조정된 부문 회복력을 위해 필수적입니다.

전체 번역

MAS 영어 원문의 번역 · 번역일: 2026-09-14

의장님, 테라이 상, 귀빈 여러분, 숙녀 여러분, 신사 여러분 여러분께 매우 좋은 아침을 인사드립니다. 2 먼저 이 정상회담을 주최해주신 FS-ISAC에 감사드리며, 싱가포르에서 FS-ISAC의 10주년을 맞이한 것을 축하드립니다. 3 2017년에 MAS와 FS-ISAC은 아시아 태평양 지역 정보 분석 센터(Asia Pacific Regional Intelligence and Analysis Centre)를 설립하기 위해 협력했으며, 이는 사이버 위협 정보의 지역 간 공유 및 분석을 장려하기 위한 것입니다. 이는 APAC 전역의 금융기관(FIs)들의 사이버 복원력을 강화하는 데 있어 중요한 발걸음이었습니다. 이전까지 금융 부문 커뮤니티 내에서의 정보 공유는 기회주의적이고 산발적이며 체계적이지 않았습니다. FIs는 대체로 독자적으로 사이버 위협 정보를 수집했으며, 외부 사이버 위협 환경에 대한 집단적 상황 인식은 제한적이었습니다. FS-ISAC APAC 정보 센터의 설립은 잘 연결된 정보 공유 커뮤니티가 고립된 단일 방어자보다 훨씬 더 복원력이 있을 것이라는 확고한 믿음에 근거했습니다. 4 지난 10년간 이 비전이 현실화되었습니다. 지역의 3개 회원사로 시작했던 것이 APAC 20개 국가에 걸친 130개 이상의 회원으로 성장했습니다. 회원 수 증가를 넘어서, FS-ISAC은 오늘날 APAC의 FIs 간의 의미 있는 정보 공유를 위한 「주요한」플랫폼입니다. FS-ISAC은 또한 기관들이 정보 보고서, 위협 콜(위협 콜은 FS-ISAC의 APAC 정보팀이 개최하는 격주 웨비나로 최신 사이버 위협 추세와 지역 사이버 위협 수준의 업데이트를 다룸(FI 회원 커뮤니티에 의해 수집됨)), 그리고 이 정상회담과 같은 행사 개최를 통해 결속을 강화하고 신흥 위협에 대한 인식을 높이도록 도움을 주고 있습니다. 5 돌이켜 보면, FS-ISAC은 APAC의 효과적인 사이버 방어를 위한 중요한 토대를 마련했습니다. 사이버 위협이 속도, 규모, 복잡성에서 계속 진화함에 따라 이는 더욱 중요해졌습니다. 진화하는 사이버 위협 환경

지난 10년간 우리는 금융 부문에 대한 사이버 위협에서 4가지 광범위한 변화를 관찰했습니다.

(a) 첫째, 공격이 점점 더 정교해지고 있습니다. 오늘날의 공격은 이메일 피싱, 받은편지함 침해, 또는 DDoS 공격을 넘어섭니다. 랜섬웨어 감염, 보안이 취약한 제3자 공급자를 통한 공격, AI 기반 사칭이 흔해지고 있습니다. (b) 둘째, 공격자들은 제3자 서비스 제공자, 심지어 고객들과 같은 상호 연결된 금융 부문 생태계의 취약한 고리를 점점 더 많이 목표로 하고 있습니다. 이는 효과적으로 이러한 엔터티로 공격 표면을 확대하여 침해의 잠재적 진입 포인트를 늘립니다. (c) 셋째, 위협 행위자의 프로필도 금전적 동기가 있는 사이버 범죄자, 활동가 그룹, 스크립트 키디와 같은 덜 조직화된 기회주의적 위협 행위자에 이르기까지 더욱 다양해졌습니다. (d) 넷째, 전 지구적 지정학적 긴장은 사이버 활동을 고조시켰습니다. 예를 들어, 러시아 국가 후원 사이버 위협 행위자들은 러시아-우크라이나 분쟁의 시작과 지속 과정에서 우크라이나 및 NATO 연계 중요 인프라를 목표로 삼았습니다[링크]. 일본과 같은 국가들도 다른 국가들과 함께 제재를 부과한 결과로, 러시아 연계로 추정되는 집단의 랜섬웨어 및 DDoS 공격 증가를 관찰했습니다[링크]. 이는 영향력을 투사하려는 해커 활동가, 불확실성을 이용해 금전적 이득을 추구하는 사이버 범죄 집단, 또는 더 광범위한 전략적 목표를 추구하는 국가 연계 행위자들로부터 비롯된 것입니다.

7 오늘날 싱가포르의 사이버 위협 환경은 보다 광범위한 APAC 지역의 축소판으로 남아 있습니다. 랜섬웨어 공격과 데이터 유출은 이 지역의 FI들에 계속해서 심각한 위협을 가하고 있습니다. 이러한 사건들은 부족한 접근 제어 및 엣지 디바이스의 패치되지 않은 취약점 같은 익숙한 약점에서 비롯되는 경우가 많으며, 이는 공격자들이 데이터를 도용하고 FI 시스템을 암호화하여 몸값을 요구할 수 있게 합니다. 8 제3자 침해는 또 다른 우려 영역을 나타냅니다. 싱가포르의 맥락에서, 우리는 지난해 기업 인쇄 서비스 제공자 Toppan Next Tech에 대한 랜섬웨어 공격을 기억할 것입니다. 2025년 4월에 인쇄 공급업체 Toppan Next Tech (TNT)에 대한 랜섬웨어 공격은 DBS Bank와 Bank of China의 11,000명 이상의 고객에 속한 이름과 주소를 추출하는 결과를 낳았으며, 나중에 손상된 Traffic Police 데이터가 온라인에 공개되었습니다 [ Link ]. 그리고 Datapost. 2025년 5월에 싱가포르 기반 데이터 처리 업체 DataPost에 대한 랜섬웨어 공격은 최소 146명의 Income Insurance 가입자에 속한 이름, 주소, 연간 보너스 기록을 포함한 개인 데이터를 유출했습니다 [ Link ], 이는 운영 중단과 고객 데이터 노출을 야기했습니다. 9 동시에 디지털 사기의 위협은 빠르게 진화하고 있습니다. 딥페이크 사용의 증가는 위협 행위자들이 신뢰할 수 있는 개인을 점점 더 정교하게 사칭할 수 있게 해주었습니다. MAS는 선임 FI 임원, 정부 관리, 정치인들이 사칭되어 FI 직원들이 사기꾼의 은행 계좌로 자금을 이체하도록 유도한 딥페이크 사건들을 인식하게 되었습니다. 10 이러한 딥페이크 사건들은 중요한 현실을 부각시킵니다. 위협 행위자들은 우리 시스템의 취약점만을 겨냥하는 것이 아닙니다. 그들은 신뢰 자체를 겨냥하고 있습니다. 그들의 목표는 혼란을 야기하고, 신뢰를 훼손하며, 우리 기관들이 매우 소중히 여기는 신뢰 관계를 방해하는 것입니다. 선도 AI 위험

11 최근 들어 선도 AI는 이 부문이 이제 직면해야 하는 보다 광범위하고 깊은 도전들을 제시하고 있습니다. 전 세계 사이버보안 기관과 보안 연구자들은 선도 AI가 규모와 속도 모두에서 취약점을 식별하고 연결하며 악용할 수 있는 잠재력을 강조합니다. 선도 AI는 사이버 위험이 어떻게 발생하고 확대될 수 있는지를 근본적으로 재구성하고 있습니다. AI는 별개의 위험 범주가 아니라 사이버 환경 전반에서 기존 위협을 증폭시키는 힘의 배수입니다. 12 이러한 맥락에서 사이버 위생은 그 어느 때보다 중요합니다. 적절한 시간에 패치하기, MFA와 같은 강력한 인증으로 관리자 계정 보호하기, 소프트웨어 자산의 정확한 인벤토리 유지하기, 그리고 지원 중단 이전에 시스템 폐기하기라는 기본적인 보안 원칙들은 현재와 미래의 사이버 공격으로부터 기관들을 보호하는 핵심 원칙으로 남아 있습니다. 13 그러나 우리가 사이버 위생을 실행하는 방식은 변화가 필요할 것입니다. 패치에 소요되는 시간은 의도하지 않은 회복력이나 보안 문제를 도입하는 것을 피하기 위해 적절한 테스트와 변경 관리를 유지하면서 감소해야 합니다. FI들은 선도 AI가 노출시키고 계속 노출할 것으로 예상되는 상당한 수의 취약점으로 인해 패칭 속도를 따라가기 어려울 것입니다. 강화된 접근 방식을 고려해야 합니다. 여기에는 악의적인 트래픽을 차단하기 위해 가상 패칭을 사용하는 등 패칭 사고방식에서 취약점 관리 사고방식으로의 전환이 포함됩니다. 14 선도 AI 기반 공격자들의 속도에 맞추기 위해, FI들은 AI 기반 방어를 도입하기 위해 노력을 강화해야 합니다 - 코드 보안, 패치 우선순위 결정, 침입 탐지 같은 분야들을 개선하기 위해서 말입니다. 15 이와 관련하여, 모든 FI가 고급 AI 기반 방어를 투자할 입장이 같지 않으며 전담 위협 정보 팀을 갖추고 있지 않습니다. 일부 FI는 훨씬 적은 자원과 전문성으로 동일한 위험에 직면하고 있습니다. AI 기반 위협 방어에 뒤처진 기관들은 더 넓은 생태계에서 약한 고리가 되어 우리 집단 방어를 훼손할 수 있습니다. 따라서 우리는 모두를 함께 참여시켜야 할 공동의 이익이 있습니다. 16 이를 위한 한 가지 방법은 이 부문 전체에서 공유를 개선함으로써 모든 방어자들이 새로운 위협에 발맞춰 나갈 수 있도록 도와주는 것입니다. FI들이 새로운 위협과 대응 방안에 대해 더 명확한 관점을 가질 때, 그들은 효과적인 사전 예방 조치를 취하기 위해 제한된 자원을 우선순위지을 수 있는 더 나은 위치에 있을 것입니다. 우리는 FS-ISAC이 선도 AI 위험에 관한 시의적절한 권고를 발행하고 새로운 우려 사항을 FI들을 위한 실용적인 지침으로 전환하는 리더십을 발휘하는 것을 봅니다.

17 그러나 권고는 새로운 위협을 최초로 식별하는 최전선에 있는 FI들의 적절한 시간의 정보 공유에 크게 의존합니다. 이것이 FS-ISAC과 같은 신뢰할 수 있는 사이버 정보 공유 플랫폼이 매우 중요해지는 지점입니다. 저는 아메리카, APAC, EMEA 지역 전역의 사이버 위협 수준이 FS-ISAC 작업 그룹 논의를 통해 정기적으로 업데이트되고 있으며, 이는 단일 기관의 도구와 프레임워크가 제공할 수 있는 것을 훨씬 뛰어넘는 상황 인식을 제공한다는 것을 들었습니다. 따라서 업계는 새로운 AI 기반 위협과 같은 통찰력을 빠르게 공유하고 이에 대응할 수 있도록 정보 공유를 개선하기 위해 함께 일해야 합니다. 사이버 인력 강화 18 우리의 인력이 AI 도구에 관한 기술을 향상시킴에 따라, FI들은 핵심 사이버보안 역량 훈련을 소홀히 해서는 안 됩니다. 팀들은 여전히 AI 생성 산출물을 검토하고, 진정한 위협을 거짓 양성에서 구별하며, 우선순위를 정할 사항을 파악하고, 사건을 상향 보고할 시기를 결정하기 위해 필요합니다. 자동화된 솔루션이 반복적인 보안 관련 작업의 부담을 줄일 수 있지만, 사건 조율, 이해관계자 소통, 책임은 본질적으로 인간의 책임으로 남아 있습니다. 19 이 자리에 있는 보안 분석가, 관리자, 정보 전문가들은 우리의 집단 사이버 방어에 불가결합니다. 수많은 도구와 우리 보안 운영의 점증하는 자동화에도 불구하고, 우리의 방어자들은 여전히 방어의 마지막 선을 형성합니다. 위협이 더 정교해질 수 있지만, 우리 업계가 어떻게 대응할지를 궁극적으로 결정하는 것은 당신의 기술, 판단력, 그리고 주의력입니다. 20 APAC의 경우, 우리의 방어자들의 역할은 지금 어느 때보다 더 중요합니다. 이 지역은 적절한 시간에 조율된 대응을 필요로 하는 빠르게 움직이고 정교한 사이버 위협에 점점 더 노출되고 있습니다. 따라서 지역 정보 공유와 협력은 더 이상 소수 기관들의 자발적 기여로 볼 수 없습니다; 그것은 APAC 커뮤니티 내의 각 모든 회원 전체에 걸쳐 일반적인 관행이 되어야 합니다. 21 이것이 이 정상회담과 같은 행사들이 매우 필수적인 이유입니다. 사이버 방어는 팀 스포츠입니다. 축구처럼, 단일 선수가 경기를 혼자 이기는 일은 없습니다; 팀원 간의 조율과 신뢰가 좋은 결과를 제공하는 데 필수적입니다. 22 FS-ISAC의 리더십과 지난 10년간 싱가포르에서 이 커뮤니티를 소집한 것에 대해 다시 한 번 감사를 드리며 마무리하겠습니다. 저는 이 정상회담에서의 논의가 앞으로의 년도들에서 회복탄력성을 유지하기 위해 우리 부문이 필요로 할 신뢰, 통찰력, 그리고 실용적 협력을 심화시키기를 바랍니다. 감사합니다.

영어 원문

MAS 공식 웹사이트 원문 · 수집일: 2026-09-14

Summit Chair, Terai-san, Distinguished Guests, Ladies and gentlemen, a very good morning to all of you. 2 First, allow me to thank FS-ISAC for organising this Summit, and to congratulate you as we mark FS-ISAC’s 10th anniversary here in Singapore. 3 In 2017, MAS and FS-ISAC collaborated to establish the Asia Pacific Regional Intelligence and Analysis Centre, to encourage regional sharing and analysis of cybersecurity threat intelligence. This represented a significant step in strengthening cyber resilience of financial institutions (FIs) across APAC. Prior to this, intelligence sharing within the financial sector community had been opportunistic, patchy, and unorganised. FIs largely went about their own way to gather cyber threat intelligence, and collective situational awareness of the external cyber threat landscape was limited. The establishment of the FS-ISAC APAC Intelligence Centre was anchored upon the firm belief that a well-connected, intelligence-sharing community would be far more resilient than any single defender acting in isolation. 4 Over the past decade, this vision has taken root. What began with just three member firms in the region has grown into a community of more than 130 members spanning 20 countries in APAC. Beyond the growth in membership numbers, FS-ISAC is today a key “go to” platform for meaningful intelligence sharing amongst FIs in APAC. FS-ISAC also has helped institutions foster cohesion and strengthen awareness of emerging threats through its intelligence reports, threat calls Threat calls are bi-weekly webinars hosted by FS-ISAC’s APAC intelligence team which cover the latest cyber threat trends and updates on the regional cyber threat level (collated by its FI member community). , and hosting events like this Summit. 5 Looking back, the FS-ISAC has laid an important foundation for effective cyber defence in APAC. This has become even more significant as cyber threats continue to evolve in speed, scale and complexity. Evolving Cyber Threat Landscape

6 Over the past 10 years, we have observed four broad shifts in cyber threats against the financial sector.

(a) First, attacks are getting more sophisticated. Attacks today go beyond email phishing, inbox compromise, or DDoS attacks. Ransomware infections, and attacks through less well defended third-party vendors and suppliers, as well as AI-enabled impersonations are increasingly commonplace. (b) Second, attackers are increasingly targeting the weak links in our highly interconnected financial sector ecosystem, such as third party service providers, and even customers. This effectively extends the attack surface to these entities, expanding the potential entry points for compromise. (c) Third, the profile of threat actors has also become more diverse, ranging from financially motivated cybercriminals, activist groups, to less organised, opportunistic threat actors such as script kiddies. (d) Fourth, geopolitical tensions around the globe have heightened cyber activity For example: Russian state-sponsored cyber threat actors targeted Ukrainian and NATO-aligned critical infrastructure at the onset, and ongoing Russia-Ukraine conflict [ Link ]. Countries such as Japan also observed increased ransomware and DDoS attacks from suspected Russia-aligned groups due to imposing sanctions along with other countries. [ Link ] , whether from hacktivists seeking to project influence, cybercriminal groups exploiting uncertainty for financial gain, or state-linked actors pursuing broader strategic objectives.

7 Today, Singapore’s cyber threat landscape remains a microcosm of the broader APAC region. Ransomware attacks and data exfiltration continue to post a serious threat to FIs in this part of the world. These incidents often stem from familiar weaknesses such as inadequate access controls and unpatched vulnerabilities on edge devices, which allow attackers to steal data and encrypt FI systems for ransom. 8 Third-party breaches represent another area of concern. In the Singapore context, we will remember last year's ransomware attacks on corporate printing service providers Toppan Next Tech In Apr 2025, a ransomware attack on printing vendor Toppan Next Tech (TNT) in April 2025 resulted in the extraction of names and addresses belonging to over 11,000 customers of DBS Bank and the Bank of China, later leading to a subsequent publication of compromised Traffic Police data online [ Link ] . and Datapost In May 2025, a ransomware attack on Singapore-based data handling vendor DataPost exfiltrated personal data, including names, addresses, and annual bonus records belonging to at least 146 Income Insurance policyholders. [ Link ] , which caused operational disruptions and exposure of customer data. 9 At the same time, the threat of digital fraud is evolving rapidly. The increasing use of deepfakes has enabled threat actors to impersonate trusted individuals with a growing degree of sophistication. MAS has been made aware of deepfake cases in which senior FI executives, government officials and politicians were impersonated to induce FI employees to transfer funds into fraudsters’ bank accounts. 10 These deepfake incidents highlight an important reality. Increasingly, threat actors are not only targeting vulnerabilities in our systems. They are also targeting trust itself. Their objective is to create confusion, undermine confidence, and disrupt the trusted relationships that our institutions so dearly rely upon. Frontier AI Risks

11 Most recently, frontier AI is posing broader and deeper challenges that the sector must now confront. Both global cybersecurity agencies and security researchers highlight the potential for frontier AI to identify, chain and exploit vulnerabilities at both scale and speed. Frontier AI is fundamentally reshaping how cyber risks can arise and scale. AI is not a separate risk category, but a force multiplier that amplifies existing threats across the cyber landscape. 12 In this context, cyber hygiene has never been more important. The fundamental security principles of timely patching, securing administrator accounts with strong authentication such as MFA, maintaining an accurate inventory of software assets, and retiring systems before they reach end-of-support remain core tenets of protecting institutions against both current and future cyber-attacks. 13 However, the manner in which we execute cyber hygiene will require changes. The time taken to patch must reduce, with proper testing and change management maintained, to avoid introducing unintended resilience or security issues. FIs will be hard pressed to keep up with the patching cadence, given the significant number of vulnerabilities frontier AIs is and will continue to surface. Enhanced approaches must be considered. This includes moving from a patching mindset to a vulnerability management mindset such as using virtual patching to block malicious traffic. 14 To match the speed of the frontier AI enabled attackers, FIs will also need to up their ante to adopt AI-enabled defences - to improve in areas such as code security, patch prioritisation, and intrusion detection. 15 In this regard, not all FIs are equally positioned to invest in advanced AI-powered defences and have dedicated threat intelligence teams. Some FIs face the same risks with far less resources and expertise. Those who lag behind in defending against AI-enabled threats could become weak links in the wider ecosystem, eroding our collective defence. We thus have a shared interest to bring everyone along. 16 One avenue to so is to help every defender stay abreast emerging threats by improving sharing across the sector. When FIs have a clearer view of both emerging threats and countermeasures, they will be better placed to prioritise their limited resources to take effective pre-emptive measures. We see FS-ISAC taking up the thought leadership to issue timely advisories on frontier AI risks and translate emerging concerns into practical guidance for FIs.

17 Advisories, however, are heavily reliant on timely information-sharing by FIs who are at the frontline that first identify emerging threats. This is where trusted cyber information-sharing platforms such as FS-ISAC become invaluable. I am told that cyber threat levels across the Americas, APAC, and EMEA regions are regularly updated through FS-ISAC workgroup discussions, providing situational awareness that extends far beyond what any single institution's tools and frameworks can offer. Therefore, the industry must work together to improve information sharing so that insights such as emerging AI-enabled threats can be quickly disseminated and acted upon. Uplifting the Cyber Workforce 18 As our workforce upskills in AI tools, FIs must not neglect training in core cybersecurity competencies. Teams are still needed to scrutinise AI-generated outputs, distinguish genuine threats from false positives, what leads to prioritise, and decide when to escalate cases. While automated solutions may reduce the load of repetitive security-related tasks, incident coordination, stakeholder communication and accountability remain innately human responsibilities. 19 The security analysts, managers and intelligence professionals in this room are indispensable in our collective cyber defense. Notwithstanding the plethora of tools, and increasing automation of our security operations, our defenders still form the last line of defence. Threats may grow more sophisticated, but it is your skill, judgement and vigilance that will ultimately determine how our industry responds. 20 For APAC, the role of our defenders is more important now than ever. The region is increasingly exposed to fast-moving and sophisticated cyber threats that warrant timely and coordinated responses. Regional intelligence sharing and collaboration can therefore no longer be viewed as a voluntary contribution by a few institutions; it must become common practice across each and every member within the APAC community. 21 This is why events such as this Summit are so essential. Cyber defence is a team sport. Much like football, no single player wins the match alone; the coordination and trust between teammates is essential in delivering a good outcome. 22 Let me close by thanking FS-ISAC once again for its leadership, and for convening this community over the past decade in Singapore. I hope the discussions at this Summit will deepen the trust, insights and practical cooperation that our sector will need to stay resilient in the years ahead. Thank you.