MAS Speech · 2026-07-14

“Vigilance, Resilience and Trust: Securing APAC’s Financial Sector” – Keynote Address by Ms Ho Hern Shin, Deputy Managing Director (Financial Supervision), Monetary Authority of Singapore, at the FS-ISAC APAC Summit on 14 July 2026

Ho Hern Shin · Deputy Managing Director (Financial Supervision), Monetary Authority of Singapore · FS-ISAC APAC Summit on 14 July

Key takeaways

  • The FS-ISAC APAC Intelligence Centre, established in 2017 through MAS collaboration, grew from three member firms to over 130 members across 20 countries in the region.
  • Ransomware attacks on Singapore-based third-party vendors in 2025 resulted in significant data exfiltration: Toppan Next Tech in April affected over 11,000 DBS and Bank of China customers, while DataPost in May affected at least 146 Income Insurance policyholders.
  • Deepfakes have increasingly been used to impersonate senior financial institution executives, government officials, and politicians to induce employees to transfer funds to fraudsters' accounts.
  • Frontier AI is identified as a force multiplier that amplifies existing cyber threats by enabling threat actors to identify, chain, and exploit vulnerabilities at scale and speed.
  • Core cyber hygiene practices—timely patching with proper testing and change management, securing administrator accounts with multi-factor authentication, maintaining accurate software asset inventories, and retiring systems before end-of-support—remain fundamental defenses against current and emerging cyber attacks.
  • Timely information sharing through regional threat intelligence platforms such as FS-ISAC, which regularly updates cyber threat levels across the Americas, APAC, and EMEA regions, is essential for collective situational awareness and coordinated sector resilience.

Full speech

Archived from mas.gov.sg · Fetched 2026-09-14

Summit Chair, Terai-san, Distinguished Guests, Ladies and gentlemen, a very good morning to all of you. 2 First, allow me to thank FS-ISAC for organising this Summit, and to congratulate you as we mark FS-ISAC’s 10th anniversary here in Singapore. 3 In 2017, MAS and FS-ISAC collaborated to establish the Asia Pacific Regional Intelligence and Analysis Centre, to encourage regional sharing and analysis of cybersecurity threat intelligence. This represented a significant step in strengthening cyber resilience of financial institutions (FIs) across APAC. Prior to this, intelligence sharing within the financial sector community had been opportunistic, patchy, and unorganised. FIs largely went about their own way to gather cyber threat intelligence, and collective situational awareness of the external cyber threat landscape was limited. The establishment of the FS-ISAC APAC Intelligence Centre was anchored upon the firm belief that a well-connected, intelligence-sharing community would be far more resilient than any single defender acting in isolation. 4 Over the past decade, this vision has taken root. What began with just three member firms in the region has grown into a community of more than 130 members spanning 20 countries in APAC. Beyond the growth in membership numbers, FS-ISAC is today a key “go to” platform for meaningful intelligence sharing amongst FIs in APAC. FS-ISAC also has helped institutions foster cohesion and strengthen awareness of emerging threats through its intelligence reports, threat calls Threat calls are bi-weekly webinars hosted by FS-ISAC’s APAC intelligence team which cover the latest cyber threat trends and updates on the regional cyber threat level (collated by its FI member community). , and hosting events like this Summit. 5 Looking back, the FS-ISAC has laid an important foundation for effective cyber defence in APAC. This has become even more significant as cyber threats continue to evolve in speed, scale and complexity. Evolving Cyber Threat Landscape

6 Over the past 10 years, we have observed four broad shifts in cyber threats against the financial sector.

(a) First, attacks are getting more sophisticated. Attacks today go beyond email phishing, inbox compromise, or DDoS attacks. Ransomware infections, and attacks through less well defended third-party vendors and suppliers, as well as AI-enabled impersonations are increasingly commonplace. (b) Second, attackers are increasingly targeting the weak links in our highly interconnected financial sector ecosystem, such as third party service providers, and even customers. This effectively extends the attack surface to these entities, expanding the potential entry points for compromise. (c) Third, the profile of threat actors has also become more diverse, ranging from financially motivated cybercriminals, activist groups, to less organised, opportunistic threat actors such as script kiddies. (d) Fourth, geopolitical tensions around the globe have heightened cyber activity For example: Russian state-sponsored cyber threat actors targeted Ukrainian and NATO-aligned critical infrastructure at the onset, and ongoing Russia-Ukraine conflict [ Link ]. Countries such as Japan also observed increased ransomware and DDoS attacks from suspected Russia-aligned groups due to imposing sanctions along with other countries. [ Link ] , whether from hacktivists seeking to project influence, cybercriminal groups exploiting uncertainty for financial gain, or state-linked actors pursuing broader strategic objectives.

7 Today, Singapore’s cyber threat landscape remains a microcosm of the broader APAC region. Ransomware attacks and data exfiltration continue to post a serious threat to FIs in this part of the world. These incidents often stem from familiar weaknesses such as inadequate access controls and unpatched vulnerabilities on edge devices, which allow attackers to steal data and encrypt FI systems for ransom. 8 Third-party breaches represent another area of concern. In the Singapore context, we will remember last year's ransomware attacks on corporate printing service providers Toppan Next Tech In Apr 2025, a ransomware attack on printing vendor Toppan Next Tech (TNT) in April 2025 resulted in the extraction of names and addresses belonging to over 11,000 customers of DBS Bank and the Bank of China, later leading to a subsequent publication of compromised Traffic Police data online [ Link ] . and Datapost In May 2025, a ransomware attack on Singapore-based data handling vendor DataPost exfiltrated personal data, including names, addresses, and annual bonus records belonging to at least 146 Income Insurance policyholders. [ Link ] , which caused operational disruptions and exposure of customer data. 9 At the same time, the threat of digital fraud is evolving rapidly. The increasing use of deepfakes has enabled threat actors to impersonate trusted individuals with a growing degree of sophistication. MAS has been made aware of deepfake cases in which senior FI executives, government officials and politicians were impersonated to induce FI employees to transfer funds into fraudsters’ bank accounts. 10 These deepfake incidents highlight an important reality. Increasingly, threat actors are not only targeting vulnerabilities in our systems. They are also targeting trust itself. Their objective is to create confusion, undermine confidence, and disrupt the trusted relationships that our institutions so dearly rely upon. Frontier AI Risks

11 Most recently, frontier AI is posing broader and deeper challenges that the sector must now confront. Both global cybersecurity agencies and security researchers highlight the potential for frontier AI to identify, chain and exploit vulnerabilities at both scale and speed. Frontier AI is fundamentally reshaping how cyber risks can arise and scale. AI is not a separate risk category, but a force multiplier that amplifies existing threats across the cyber landscape. 12 In this context, cyber hygiene has never been more important. The fundamental security principles of timely patching, securing administrator accounts with strong authentication such as MFA, maintaining an accurate inventory of software assets, and retiring systems before they reach end-of-support remain core tenets of protecting institutions against both current and future cyber-attacks. 13 However, the manner in which we execute cyber hygiene will require changes. The time taken to patch must reduce, with proper testing and change management maintained, to avoid introducing unintended resilience or security issues. FIs will be hard pressed to keep up with the patching cadence, given the significant number of vulnerabilities frontier AIs is and will continue to surface. Enhanced approaches must be considered. This includes moving from a patching mindset to a vulnerability management mindset such as using virtual patching to block malicious traffic. 14 To match the speed of the frontier AI enabled attackers, FIs will also need to up their ante to adopt AI-enabled defences - to improve in areas such as code security, patch prioritisation, and intrusion detection. 15 In this regard, not all FIs are equally positioned to invest in advanced AI-powered defences and have dedicated threat intelligence teams. Some FIs face the same risks with far less resources and expertise. Those who lag behind in defending against AI-enabled threats could become weak links in the wider ecosystem, eroding our collective defence. We thus have a shared interest to bring everyone along. 16 One avenue to so is to help every defender stay abreast emerging threats by improving sharing across the sector. When FIs have a clearer view of both emerging threats and countermeasures, they will be better placed to prioritise their limited resources to take effective pre-emptive measures. We see FS-ISAC taking up the thought leadership to issue timely advisories on frontier AI risks and translate emerging concerns into practical guidance for FIs.

17 Advisories, however, are heavily reliant on timely information-sharing by FIs who are at the frontline that first identify emerging threats. This is where trusted cyber information-sharing platforms such as FS-ISAC become invaluable. I am told that cyber threat levels across the Americas, APAC, and EMEA regions are regularly updated through FS-ISAC workgroup discussions, providing situational awareness that extends far beyond what any single institution's tools and frameworks can offer. Therefore, the industry must work together to improve information sharing so that insights such as emerging AI-enabled threats can be quickly disseminated and acted upon. Uplifting the Cyber Workforce 18 As our workforce upskills in AI tools, FIs must not neglect training in core cybersecurity competencies. Teams are still needed to scrutinise AI-generated outputs, distinguish genuine threats from false positives, what leads to prioritise, and decide when to escalate cases. While automated solutions may reduce the load of repetitive security-related tasks, incident coordination, stakeholder communication and accountability remain innately human responsibilities. 19 The security analysts, managers and intelligence professionals in this room are indispensable in our collective cyber defense. Notwithstanding the plethora of tools, and increasing automation of our security operations, our defenders still form the last line of defence. Threats may grow more sophisticated, but it is your skill, judgement and vigilance that will ultimately determine how our industry responds. 20 For APAC, the role of our defenders is more important now than ever. The region is increasingly exposed to fast-moving and sophisticated cyber threats that warrant timely and coordinated responses. Regional intelligence sharing and collaboration can therefore no longer be viewed as a voluntary contribution by a few institutions; it must become common practice across each and every member within the APAC community. 21 This is why events such as this Summit are so essential. Cyber defence is a team sport. Much like football, no single player wins the match alone; the coordination and trust between teammates is essential in delivering a good outcome. 22 Let me close by thanking FS-ISAC once again for its leadership, and for convening this community over the past decade in Singapore. I hope the discussions at this Summit will deepen the trust, insights and practical cooperation that our sector will need to stay resilient in the years ahead. Thank you.