MDDI 연설문 · 2025-04-15

Tan Kiat How SMS의 확대된 Cyber Essentials 및 Cyber Trust Marks 출범식 개막 연설

Tan Kiat How · MDDI 선임정무선임국무장관 · 확대된 Cyber Essentials 및 Cyber Trust Marks 출범에서의 발언

요점

  • 싱가포르 사이버보안청이 Cyber Essentials 및 Cyber Trust 인증 마크를 클라우드 보안, AI 보안, 운영기술 보안을 포함하도록 확대했습니다.
  • 클라우드 보안은 기업이 「클라우드 공유 책임 모델」 하에서 보안 조치를 구현하도록 요구하며, 이 모델에서는 클라우드 서비스 제공자와 기업이 각자의 책임 범위에서 보안을 담당합니다.
  • 확대된 Cyber Trust 및 Cyber Essentials 마크는 이제 「섀도우 AI」(IT 부서의 승인이나 감시 없이 직원들이 AI 도구를 무단으로 사용하는 것)를 포함한 AI 보안 위험에 대응합니다.
  • 운영기술(OT) 보안은 Industry 4.0과 제조업 등의 산업에서 IT와 OT 환경의 융합에 대응하기 위해 Cyber Essentials 및 Cyber Trust에 통합되었습니다.
  • 싱가포르 정부는 민감한 정부 데이터에 접근할 수 있는 사이버보안 공급업체(침투 테스트 회사 및 감사 회사 등)가 정부 계약에 입찰하기 전에 Cyber Essentials 및/또는 Cyber Trust 인증을 취득하도록 요구할지 여부를 평가 중입니다.
  • 500개 이상의 조직이 Cyber Essentials 인증을 획득했으며, 적격 중소기업과 사이버보안청 계약 컨설턴트가 제공하는 CISO-as-a-Service에 정부 자금이 지원됩니다.

전체 번역

MDDI 영어 원문의 번역 · 번역일: 2026-07-04

싱가포르 디지털개발정보부 선임국무장관 탄끼엣하우의 확장 Cyber Essentials 및 Cyber Trust 마크 런칭 행사 개회사 (2025년 4월 15일)

존경하는 내빈 여러분

신사 숙녀 여러분

좋은 오후입니다. 오늘 이렇게 많은 분들이 참석해주셔서 매우 기쁩니다. 우리의 사이버 공간을 보호하고 함께 취할 수 있는 방안에 관한 매우 중요한 주제에 대해서입니다.

알려진 바와 같이 디지털화가 가속화되고 있습니다. 싱가포르의 기업들, 대기업부터 많은 중소기업들까지 디지털 전환을 추진하고 있습니다. 대기업에서 클라우드 컴퓨팅이 주류가 되었으며, 중소기업(SME)의 약 3분의 1이 클라우드를 사용하고 있습니다.

인공지능(AI)은 흥미로운 기술 영역입니다. 기업들이 생산성을 개선하고, 새로운 비즈니스 모델을 창출하거나 제품의 새로운 시장을 개발하기 위해 AI를 도입하고 있습니다. 정부는 IMDA의 GenAI 샌드박스와 기업용 GenAI 플레이북을 포함한 다양한 이니셔티브를 통해 기업의 AI 도입을 지원하고 있습니다.

새로운 기술들이 기업의 생산성을 높여주지만, 동시에 사이버 공격 면적도 확대됩니다. 특히 싱가포르의 중소기업과 관련된 사이버 침해 사례와 개인 데이터 손실 사례가 증가하고 있습니다.

따라서 CSA가 클라우드 보안, AI 보안, 운영기술(OT) 보안을 포함하도록 Cyber Essentials 및 Cyber Trust 인증 마크를 업데이트하는 것은 시기적절합니다.

Cyber Essentials는 중소기업을 대상으로 합니다. 규모가 작거나 디지털화 수준이 낮은 기업을 위해 설계되었으며, 일반적인 사이버보안 공격으로부터의 보호 조치를 제시합니다. Cyber Trust는 규모가 크거나 디지털화 수준이 높은 기업이 위험 기반의 사이버보안 구현 접근 방식을 채택하도록 돕습니다.

이번 업데이트를 통해 Cyber Essentials와 Cyber Trust는 클라우드 컴퓨팅, AI, OT를 도입하는 기업들에 대한 커버리지와 보호를 제공할 것입니다. 주요 업데이트 사항을 간략히 설명하겠습니다.

먼저 클라우드 컴퓨팅에 대해서입니다. 기업이 클라우드 컴퓨팅을 채택할 때, 사이버보안에 대한 책임은 클라우드 서비스 제공자와 기업 간에 공유됩니다. 이를 「클라우드 공동 책임 모델」이라고 합니다.

한편, 클라우드 서비스 제공자는 디지털 기반 시설의 핵심 제공자이며, 우리는 이들이 견고한 디지털 회복력을 갖추도록 할 것입니다. 그러나 다른 한편, 기업도 자신의 역할을 해야 합니다. 클라우드 서비스 제공자에게 「맡겨버리는」것이 아니라, 기업도 자신의 클라우드 사용을 보호해야 하며, Cyber Essentials나 Cyber Trust의 클라우드 보안 내용을 참고할 수 있습니다.

두 번째 영역은 AI입니다. 기업이 AI로 실험하고 혁신할 때, AI 사용에 따른 위험으로부터 자신을 보호해야 합니다. 예시로는 「섀도우 AI」가 있으며, 이는 IT 부서의 승인이나 감시 없이 직원들이 무단으로 AI 도구를 사용하는 경우, 또는 정보의 우발적 유출, 부적절한 정보의 생성 등을 지칭합니다.

World Economic Forum(WEF) 조사에 따르면, 조사 대상 조직의 66%가 AI가 사이버보안에 가장 큰 영향을 미칠 것으로 예상하고 있습니다. AI 사용자를 보유한 기업은 이제 Cyber Essentials와 Cyber Trust의 AI 보안 내용을 참고할 수 있습니다.

세 번째 영역은 운영기술(OT)입니다. 인더스트리 4.0의 부상으로 OT 환경과 IT 환경의 융합이 진행 중입니다. 이는 싱가포르의 제조업과 같은 핵심 산업에 영향을 미치고 있습니다. IT가 정보의 기밀성, 무결성, 가용성에 중점을 두고 데이터 관리를 우선시하는 반면, OT는 산업 환경에서 물리적 프로세스와 장비의 실시간 제어 및 안전을 우선시합니다.

IT 환경을 보호하기 위한 관행이 투자 사이클이 길고 레거시 프로토콜과 장비가 여전히 사용 중인 OT 환경에서는 반드시 실행 가능하지 않을 수 있습니다. OT 기업은 이제 Cyber Essentials와 Cyber Trust의 OT 보안 내용을 참고하여 자신의 OT 환경을 보호할 수 있습니다. 우리는 단순히 IT 환경과 OT 환경을 보호하는 것뿐만 아니라, 점점 더 IT와 OT의 경계 지점에 주목하고 있습니다. 더 많은 글로벌 시스템이 IT화되고, 더 많은 시스템이 자동화를 포함하며, 더 많은 OT 프로세스와 프로토콜을 초래하기 때문입니다. CSA가 클라우드 컴퓨팅, AI, OT를 포함하도록 이러한 Essentials 및 Trust 마크를 업데이트하는 조치를 취하고 있어 매우 기쁩니다. 이들은 모두 디지털 기업에 있어 매우 중요한 영역입니다.

이제 중국어로 몇 가지 간단한 의견을 말씀드리겠습니다.

이제 중국어로 핵심 내용을 요약하겠습니다:

새로운 디지털 기술을 사용하면 효율성을 향상시킬 수 있지만, 동시에 공격 면적을 확대할 수 있습니다. 우리는 많은 사이버보안 취약점과 개인 데이터 유출 사건을 목격했으며, 특히 싱가포르의 중소기업과 관련된 사건들이 그러합니다.

싱가포르 사이버보안청(CSA)이 「네트워크보안 기본 능력 마크」(Cyber Essentials)와 「네트워크보안 신용 마크」(Cyber Trust)의 인증 범위를 확대하는 것은 현재 매우 시기적절하며, 새로운 세 가지 영역을 추가합니다:

(1) 클라우드 보안

(2) 인공지능 보안

(3) 운영기술 보안。

정부는 또한 국가 사이버보안 표준을 전면적으로 향상시킬 계획 중이며, 특히 높은 위험도의 산업 기관을 대상으로 합니다. 사이버보안청은 민감한 데이터에 접근하는 기관이 정부 계약 입찰에 참여하기 위해 관련 사이버보안 인증을 취득해야 한다는 요구 사항을 평가 중입니다. 구체적인 실행 방안은 준비 완료 후 별도로 공시될 것입니다.

사이버보안 구현이 중소기업에게 도전적일 수 있다는 업계 피드백을 받았습니다. 중소기업의 사이버보안을 단순화하기 위해 CSA는 Chief Information Security Officer(CISO) as-a-Service 역할을 수행하는 사이버보안 컨설턴트들을 활용합니다. 이 컨설턴트들은 중소기업이 Cyber Essentials 마크에 부합하는 사이버 위생 조치를 구현하도록 돕습니다.

정부 자금 지원이 적격 중소기업을 위해 제공됩니다. 500개 이상의 조직이 최소한 Cyber Essentials 인증을 취득하여 사이버보안의 중요성에 대해 조치를 취하는 것을 보니 기쁩니다.

최근 몇 년간 사이버 위협이 더욱 심각해졌으며, 범죄 집단들이 점점 더 온라인에서 부정한 이득을 추구하고 있습니다. 국가적 차원에서 기본 사이버보안 표준을 높이고 더 많은 조직, 특히 높은 위험도의 조직들을 보호하기 위한 더욱 체계적인 접근이 필요합니다.

올해 우리 부처의 공급 위원회 논쟁에서 공유한 대로, CSA는 특히 정부 내 민감한 데이터 또는 시스템에 접근할 수 있는 벤더에 대해 더 많은 조치가 필요한지 평가하고 있습니다.

이러한 벤더에는 사이버보안 침투 테스트 회사 및 사이버보안 감사자들이 포함됩니다. 가능한 조치에는 이러한 벤더 및 그들의 하청업체가 정부에서 제공되는 계약의 라이선스를 받거나 입찰하기 전에 Cyber Essentials 및/또는 Cyber Trust 마크를 취득하도록 요구하는 것이 포함될 수 있습니다. CSA는 향후 방향에 대해 업계와 협력할 것입니다.

Cyber Essentials와 Cyber Trust는 싱가포르의 기업들의 사이버보안 태세를 향상시키기 위해 원래 개발된 국내 마크입니다.

우리는 이 지역 국가들로부터의 관심에 기쁩니다. 말레이시아, 태국, 필리핀 및 중동의 기업들이 인증을 받았으며, 브루나이의 또 다른 회사도 절차를 진행 중일 가능성이 있음을 알고 있습니다.

우리 기업의 사이버보안 태세를 높이고 디지털 경제를 보호하는 것 이외에도, 싱가포르가 알려진 신뢰와 신뢰도의 브랜드를 바탕으로 우리 회사들을 위한 시장 기회가 있습니다.

모든 이해관계자들의 집단적 노력을 기대하며, 모든 기업과 근로자들에게 기회를 제공하는 활기찬 디지털 경제를 구축해 나가길 기대합니다.

「감사합니다.」

영어 원문

MDDI 공식 웹사이트 원문 · 수집일: 2026-07-04

Opening Remarks by Senior Minister of State for Digital Development and Information Tan Kiat How at the Launch Event for the Expanded Cyber Essentials and Cyber Trust Marks on 15 April 2025

Distinguished guests

Ladies and Gentlemen

Good afternoon. I am very glad to see many of you here today, for a very important topic about securing our cyberspace, and what steps we can take together.

As we all know, digitalisation is picking up pace. Enterprises in Singapore are pushing ahead with their digital transformation - large enterprises, and many SMEs as well. We see cloud computing become mainstream with large enterprises. About one-third of Small and Medium Enterprises (SMEs) are using cloud.

Artificial Intelligence (AI) is an exciting area of technology, where companies are adopting AI to improve productivity, create new business models or new markets for their products. The Government is supporting enterprise AI adoption through various initiatives, including the IMDA’s GenAI sandbox and the GenAI playbook for enterprises.

While such new technologies enable firms to be more productive, they also enlarge the cyber attack surface. We are seeing more cases of cyber breaches and loss of personal data, especially those involving SMEs in Singapore.

It is therefore timely for CSA to update the Cyber Essentials and Cyber Trust certification marks to include coverage of cloud security, AI security and Operational Technology, or OT.

Cyber Essentials is targeted towards SMEs. It is designed for smaller or less digital enterprises, proposing protection measures from common cybersecurity attacks. Cyber Trust helps larger or more digital enterprises to adopt a risk-based approach to implementing cybersecurity.

With the update, Cyber Essentials and Cyber Trust will provide coverage and protection for enterprises that are implementing cloud computing, AI and OT. Let me briefly outline the key updates.

First on cloud computing - when enterprises embrace cloud computing, the responsibility for cybersecurity is shared between the cloud service provider and the enterprise – this is referred to as the “cloud shared responsibility model”.

On one hand, cloud service providers are key providers of digital infrastructure, and we will ensure that they have robust digital resilience. But, on the other hand, enterprises also need to do their part. It is not a case of “leaving it” to the cloud service provider; the enterprise also needs to secure their cloud usage, and they can take reference from the cloud security content in Cyber Essentials or Cyber Trust.

The second area, AI - as enterprises experiment with and innovate with AI, we need to protect ourselves from the risks associated with the use of AI. Examples include “shadow AI”, which refers to the unsanctioned use of AI tools by employees without approval or oversight of the IT department, or accidental leakage of information, and the output of inappropriate information.

In a World Economic Forum (WEF) survey, 66% of organisations polled expect AI to have the most significant impact on cybersecurity. Enterprises that have AI users can now refer to the AI security content in Cyber Essentials and Cyber Trust.

The third area, OT - with the rise of Industry 4.0, we are seeing a convergence of the OT environment and the IT environment. This has an impact on key sectors in Singapore, such as manufacturing. While IT prioritises data management, focusing on the confidentiality, integrity and availability of information, OT prioritises real-time control and safety of physical processes and equipment in industrial settings.

The practices to secure an IT environment are not necessarily feasible in an OT environment, where the investment cycle is long, and legacy protocols and equipment may still be in use. OT enterprises can now refer to the OT security content in Cyber Essentials and Cyber Trust to secure their OT environment. We are not just looking at securing your IT environment and OT environment, but increasingly, at the nexus of the IT and OT boundaries, as more global systems become more IT-like, and more systems invite automation and more OT processes and protocols. I am very glad that CSA is taking these steps to update these Essential and Trust marks, to include computing, AI and OT – all very important areas for digital enterprises.

Let me make a few brief remarks in Mandarin.

现在,请允许我用华语总结关键内容:

虽然使用新兴数字技术可以提升效率,却也可扩大攻击面。我们看到了很多网安漏洞及个人数据泄露事件的发生,尤其涉及到新加坡的中小企业。

新加坡网安局(CSA)此时扩展 "网络安全 基本能力 标志"(Cyber Essentials)和 "网络安全 信誉 标志"(Cyber Trust)的认证范围 非常及时,新增三大领域:

(一)云 安全

(二)人工智能 安全

(三)运营技术 安全。

政府还在计划全面提升国家网络安全标准,特别是针对高风险的行业机构。网安局正在评估,要求接触敏感数据的机构必须取得相关网络安全认证才可以参与政府合同竞标。具体实施方案将在筹备完成后另外公报。

We have received industry feedback that implementing cybersecurity can be challenging for SMEs. To simplify cybersecurity for SMEs, CSA taps on cybersecurity consultants that play the role of their Chief Information Security Officer [(CISO) as-a-Service]. These consultants help SMEs to implement cyber hygiene measures aligned to the Cyber Essentials mark.

Government funding support is available for eligible SMEs. We are heartened to see more than 500 organisations acting on the importance of cybersecurity by attaining at least Cyber Essentials certification.

In recent years, cyber threats have become more severe, and criminal groups are increasingly going online to look for illicit gains. We need a more systematic approach to raise baseline cybersecurity standards nationally and protect more organisations, especially those of higher risk.

As shared at our Ministry’s Committee of Supply Debate this year, CSA is assessing if more measures are needed, particularly for vendors that may be given access to sensitive data or systems within Government.

Such vendors include cybersecurity penetration testing firms, and cybersecurity auditors. Possible measures include requiring these vendors and their subcontractors to obtain their Cyber Essentials and/or Cyber Trust marks before they can be licensed or bid for contracts offered by Government. CSA will be engaging the industry on the way ahead.

Cyber Essentials and Cyber Trust are domestic marks, originally developed to uplift the cybersecurity posture of enterprises in Singapore.

We are glad that there has been interest from countries in the region. We understand that there are enterprises in Malaysia, Thailand, Philippines and the Middle East, who have been certified, with possibly another firm in Brunei going through the process.

Beyond raising the cybersecurity posture of our enterprises and securing our digital economy, there are market opportunities for our firms, building on the brand of trust and reliability that Singapore is known for.

I look forward to the collective effort of all stakeholders in this effort as we build a vibrant digital economy that provides opportunities for all enterprises and our workers.

Thank you.