MAS 演講稿 · 2026-07-14

「警惕、韌性與信任:守護亞太金融業」——新加坡金融管理局副局長(金融監管)Ho Hern Shin 女士在 FS-ISAC 亞太峰會上的主題演講,2026年7月14日

Ho Hern Shin · 新加坡金融管理局副局長(金融監管) · FS-ISAC 亞太峰會(7月14日)

要點

  • 「與新加坡金融管理局合作於2017年建立的FS-ISAC亞太地區情報分析中心從3家成員機構增長至超過130家,覆蓋該地區20個國家。」
  • 「2025年針對新加坡第三方服務商的勒索軟體攻擊導致大規模資料洩露:Toppan Next Tech在4月影響超過11,000名星展銀行和中國銀行客戶,DataPost在5月影響至少146名Income Insurance保單持有人。」
  • 「深度偽造技術被日益用於冒充金融機構高管、政府官員和政治人物,以誘導員工將資金轉入欺詐者的賬戶。」
  • 「前沿人工智慧被認定為力量倍增器,使威脅行為者能夠以規模和速度識別、連結並利用漏洞來放大現有網路威脅。」
  • 「核心網路衛生措施——進行適當測試和變更管理的及時補丁、使用多因素認證保護管理員賬戶、維護準確的軟體資產清單以及在系統達到生命週期終點前進行退役——仍然是防禦當前和新興網路攻擊的基礎防線。」
  • 「通過FS-ISAC等區域威脅情報平臺進行及時資訊共享至關重要,該平臺定期更新美洲、亞太和EMEA地區的網路威脅級別,對於集體態勢感知和協調的行業韌性是必需的。」

完整譯文(繁體中文)

MAS 英文原文譯文 · 翻譯日期: 2026-09-14

峰會主席、寺來先生、尊敬的來賓們、女士們和先生們,大家早上好。2 首先,請允許我感謝FS-ISAC組織了本次峰會,並祝賀各位,因為我們在新加坡紀念FS-ISAC成立十週年。3 2017年,MAS和FS-ISAC合作建立了亞太地區情報和分析中心,促進網路安全威脅情報在整個地區的共享和分析。這是加強亞太地區金融機構(FIs)網路韌性的重要一步。在此之前,金融部門內部的情報共享是臨時性的、零散的、無組織的。金融機構主要各自行動收集網路威脅情報,對外部網路威脅形勢的集體態勢感知十分有限。建立FS-ISAC亞太情報中心基於一個堅定的信念:一個聯絡緊密的、進行情報共享的社群,其韌性會遠優於任何單獨行動的防禦者。4 在過去十年中,這一願景已成現實。最初只有該地區三家成員企業的組織已發展成一個擁有超過130個成員、涵蓋亞太地區20個國家的社群。除了成員數量的增長,FS-ISAC現已成為亞太地區金融機構之間進行有意義的情報共享的重要「go to」平臺。FS-ISAC還通過其情報報告、威脅通話(威脅通話是由FS-ISAC亞太情報團隊舉辦的雙週網路討論,涵蓋最新的網路威脅趨勢和地區網路威脅級別的更新(由其金融機構成員社群整理彙總)),以及舉辦像本次峰會這樣的活動,幫助機構促進凝聚力並提高對新興威脅的認識。5 回顧過去,FS-ISAC為亞太地區有效的網路防禦奠定了重要基礎。這一點變得尤為重要,因為網路威脅在速度、規模和複雜性上持續演變。網路威脅形勢的演變

6 在過去十年中,我們觀察到了金融部門所面臨網路威脅的四大轉變。

(a)首先,攻擊變得越來越複雜。如今的攻擊遠不止電子郵件釣魚、收件箱洩露或DDoS攻擊。勒索軟體感染、通過防禦較弱的第三方供應商和服務商的攻擊,以及由AI驅動的冒充已日益普遍。(b)其次,攻擊者越來越多地針對我們高度互聯的金融部門生態系統中的薄弱環節,如第三方服務提供商,甚至客戶。這實際上將攻擊面擴充套件到這些實體,擴大了潛在的入侵點。(c)第三,威脅參與者的構成變得更加多樣化,從經濟利益驅動的網路犯罪分子、激進組織到不那麼有組織的、機會主義的威脅參與者,如指令碼小子。(d)第四,全球地緣政治緊張局勢加劇了網路活動。例如:俄羅斯國家支援的網路威脅參與者在衝突開始時針對烏克蘭和北約聯盟的關鍵基礎設施進行了攻擊,俄烏衝突仍在進行中【連結】。日本等國家也因同其他國家一起實施制裁而遭受來自疑似與俄羅斯結盟的組織的勒索軟體和DDoS攻擊增加【連結】,無論是來自試圖投射影響力的駭客激進分子、利用不確定性尋求經濟收益的網路犯罪集團,還是追求更廣泛戰略目標的國家關聯行為體。

7 今天,新加坡的網路威脅形勢是更廣泛的亞太地區形勢的一個縮影。勒索軟體攻擊和資料外洩對這一地區的金融機構仍然構成嚴重威脅。這些事件通常源於熟悉的薄弱之處,如不充分的訪問控制和邊緣裝置上的未修補的漏洞,這些漏洞允許攻擊者盜取資料並加密金融機構系統以勒索贖金。8 第三方洩露是另一個令人關切的領域。在新加坡的背景下,我們將記得去年企業列印服務提供商Toppan Next Tech(2025年4月,列印供應商Toppan Next Tech(TNT)在2025年4月遭到勒索軟體攻擊,導致超過11000名DBS銀行和中國銀行客戶的姓名和地址被提取,後來導致洩露的交通警察資料隨後在網上釋出【連結】)和DataPost(2025年5月,新加坡資料處理供應商DataPost遭到勒索軟體攻擊,洩露了至少146位保誠保險投保人的個人資料,包括姓名、地址和年度獎金記錄【連結】)遭到的勒索軟體攻擊,這些攻擊造成了運營中斷和客戶資料洩露。9 與此同時,數字欺詐的威脅在迅速演變。深度偽造的日益使用使威脅參與者能夠以越來越高的精細程度冒充可信賴的個人。MAS已獲悉多起深度偽造案例,其中金融機構高管、政府官員和政治人物被冒充,以誘導金融機構員工向欺詐者的銀行賬戶轉賬。10 這些深度偽造事件突顯了一個重要現實。威脅參與者越來越多地不僅針對我們系統中的漏洞。他們也在針對信任本身。他們的目標是製造混亂、破壞信心,並破壞我們機構非常依賴的可信賴關係。前沿AI風險

11 最近,前沿AI對該部門提出了更廣泛更深層的挑戰。全球網路安全機構和安全研究人員都強調了前沿AI在規模和速度上識別、連結和利用漏洞的潛力。前沿AI從根本上改變了網路風險如何出現和擴充套件的方式。AI不是一個單獨的風險類別,而是一個力量倍增器,放大了網路環境中現有威脅。12 在這種背景下,網路衛生從未像現在這樣重要。及時修補、使用強身份驗證(如MFA)保護管理員賬戶、維護準確的軟體資產清單以及在系統到達支援終止前登出系統,這些基本的安全原則仍然是保護機構免受當前和未來網路攻擊的核心原則。13 然而,我們執行網路衛生的方式將需要改變。修補所花費的時間必須減少,同時保持適當的測試和變更管理,以避免引入無意的韌性或安全問題。鑑於前沿AI目前和將來會發現的大量漏洞,金融機構將很難跟上修補的節奏。必須考慮更強化的方法。這包括從修補思維轉向漏洞管理思維,如使用虛擬修補來阻止惡意流量。14 為了跟上前沿AI驅動的攻擊者的速度,金融機構還需要加倍努力採用AI驅動的防禦——在程式碼安全、修補優先化和入侵檢測等領域進行改進。15 在這方面,並非所有金融機構都能均等地投資先進的AI驅動防禦並擁有專屬的威脅情報團隊。一些金融機構面臨相同的風險,但資源和專業知識遠少。在防禦AI驅動的威脅方面落後的那些機構可能會成為更廣泛生態系統中的薄弱環節,削弱我們的集體防禦。因此,我們有共同的利益來共同推進。16 一條途徑是幫助每個防禦者通過改善部門間的共享來跟上新興威脅。當金融機構對新興威脅和對策有更清楚的瞭解時,他們將更好地能夠優先考慮他們有限的資源採取有效的預防措施。我們看到FS-ISAC發揮思想領導力,釋出關於前沿AI風險的及時諮詢,並將新興問題轉化為金融機構的實際指導。

17 然而,諮詢在很大程度上依賴於首先識別新興威脅的最前線金融機構進行及時的資訊共享。這就是像FS-ISAC這樣的受信任的網路資訊共享平臺變得無價之寶的地方。我被告知,美洲、亞太和EMEA地區的網路威脅級別通過FS-ISAC工作組討論定期更新,提供的態勢感知遠遠超過任何單一機構的工具和框架所能提供的範圍。因此,業界必須共同努力改善資訊共享,以便像AI驅動的新興威脅這樣的見解能夠快速傳播和付諸行動。提升網路勞動力18 當我們的勞動力在AI工具中提升技能時,金融機構不必忽視核心網路安全能力的培訓。仍然需要團隊來審查AI生成的輸出、區分真實威脅和誤報、確定要優先考慮的內容以及決定何時升級案件。雖然自動化解決方案可能會減少重複性安全任務的負擔,但事件協調、利益相關者溝通和問責仍然本質上是人類責任。19 這個房間裡的安全分析師、經理和情報專業人員在我們的集體網路防禦中是不可或缺的。儘管工具繁多,我們的安全運營日益自動化,但我們的防禦者仍然形成了防線。威脅可能會變得更加複雜,但最終決定我們行業如何應對的是你們的技能、判斷力和警覺性。20 對於亞太地區,我們防禦者的角色現在比以往任何時候都更加重要。該地區日益暴露於快速變化和複雜的網路威脅,需要及時和協調的應對。因此,地區情報共享和合作不再能被視為少數機構的自願貢獻;它必須成為亞太社群內每個成員的普遍做法。21 這就是像這樣的峰會如此重要的原因。網路防禦是一項團隊運動。就像足球一樣,沒有單一的球員獨自贏得比賽;隊友之間的協調和信任對於取得良好成果至關重要。22 讓我再次感謝FS-ISAC的領導力,以及在過去十年中在新加坡聚集這個社群。我希望本峰會的討論將加深信任、見解和實際合作,這是我們部門未來保持韌性所需的。謝謝。

英文原文

MAS 官網原始記錄 · 抓取日期: 2026-09-14

Summit Chair, Terai-san, Distinguished Guests, Ladies and gentlemen, a very good morning to all of you. 2 First, allow me to thank FS-ISAC for organising this Summit, and to congratulate you as we mark FS-ISAC’s 10th anniversary here in Singapore. 3 In 2017, MAS and FS-ISAC collaborated to establish the Asia Pacific Regional Intelligence and Analysis Centre, to encourage regional sharing and analysis of cybersecurity threat intelligence. This represented a significant step in strengthening cyber resilience of financial institutions (FIs) across APAC. Prior to this, intelligence sharing within the financial sector community had been opportunistic, patchy, and unorganised. FIs largely went about their own way to gather cyber threat intelligence, and collective situational awareness of the external cyber threat landscape was limited. The establishment of the FS-ISAC APAC Intelligence Centre was anchored upon the firm belief that a well-connected, intelligence-sharing community would be far more resilient than any single defender acting in isolation. 4 Over the past decade, this vision has taken root. What began with just three member firms in the region has grown into a community of more than 130 members spanning 20 countries in APAC. Beyond the growth in membership numbers, FS-ISAC is today a key “go to” platform for meaningful intelligence sharing amongst FIs in APAC. FS-ISAC also has helped institutions foster cohesion and strengthen awareness of emerging threats through its intelligence reports, threat calls Threat calls are bi-weekly webinars hosted by FS-ISAC’s APAC intelligence team which cover the latest cyber threat trends and updates on the regional cyber threat level (collated by its FI member community). , and hosting events like this Summit. 5 Looking back, the FS-ISAC has laid an important foundation for effective cyber defence in APAC. This has become even more significant as cyber threats continue to evolve in speed, scale and complexity. Evolving Cyber Threat Landscape

6 Over the past 10 years, we have observed four broad shifts in cyber threats against the financial sector.

(a) First, attacks are getting more sophisticated. Attacks today go beyond email phishing, inbox compromise, or DDoS attacks. Ransomware infections, and attacks through less well defended third-party vendors and suppliers, as well as AI-enabled impersonations are increasingly commonplace. (b) Second, attackers are increasingly targeting the weak links in our highly interconnected financial sector ecosystem, such as third party service providers, and even customers. This effectively extends the attack surface to these entities, expanding the potential entry points for compromise. (c) Third, the profile of threat actors has also become more diverse, ranging from financially motivated cybercriminals, activist groups, to less organised, opportunistic threat actors such as script kiddies. (d) Fourth, geopolitical tensions around the globe have heightened cyber activity For example: Russian state-sponsored cyber threat actors targeted Ukrainian and NATO-aligned critical infrastructure at the onset, and ongoing Russia-Ukraine conflict [ Link ]. Countries such as Japan also observed increased ransomware and DDoS attacks from suspected Russia-aligned groups due to imposing sanctions along with other countries. [ Link ] , whether from hacktivists seeking to project influence, cybercriminal groups exploiting uncertainty for financial gain, or state-linked actors pursuing broader strategic objectives.

7 Today, Singapore’s cyber threat landscape remains a microcosm of the broader APAC region. Ransomware attacks and data exfiltration continue to post a serious threat to FIs in this part of the world. These incidents often stem from familiar weaknesses such as inadequate access controls and unpatched vulnerabilities on edge devices, which allow attackers to steal data and encrypt FI systems for ransom. 8 Third-party breaches represent another area of concern. In the Singapore context, we will remember last year's ransomware attacks on corporate printing service providers Toppan Next Tech In Apr 2025, a ransomware attack on printing vendor Toppan Next Tech (TNT) in April 2025 resulted in the extraction of names and addresses belonging to over 11,000 customers of DBS Bank and the Bank of China, later leading to a subsequent publication of compromised Traffic Police data online [ Link ] . and Datapost In May 2025, a ransomware attack on Singapore-based data handling vendor DataPost exfiltrated personal data, including names, addresses, and annual bonus records belonging to at least 146 Income Insurance policyholders. [ Link ] , which caused operational disruptions and exposure of customer data. 9 At the same time, the threat of digital fraud is evolving rapidly. The increasing use of deepfakes has enabled threat actors to impersonate trusted individuals with a growing degree of sophistication. MAS has been made aware of deepfake cases in which senior FI executives, government officials and politicians were impersonated to induce FI employees to transfer funds into fraudsters’ bank accounts. 10 These deepfake incidents highlight an important reality. Increasingly, threat actors are not only targeting vulnerabilities in our systems. They are also targeting trust itself. Their objective is to create confusion, undermine confidence, and disrupt the trusted relationships that our institutions so dearly rely upon. Frontier AI Risks

11 Most recently, frontier AI is posing broader and deeper challenges that the sector must now confront. Both global cybersecurity agencies and security researchers highlight the potential for frontier AI to identify, chain and exploit vulnerabilities at both scale and speed. Frontier AI is fundamentally reshaping how cyber risks can arise and scale. AI is not a separate risk category, but a force multiplier that amplifies existing threats across the cyber landscape. 12 In this context, cyber hygiene has never been more important. The fundamental security principles of timely patching, securing administrator accounts with strong authentication such as MFA, maintaining an accurate inventory of software assets, and retiring systems before they reach end-of-support remain core tenets of protecting institutions against both current and future cyber-attacks. 13 However, the manner in which we execute cyber hygiene will require changes. The time taken to patch must reduce, with proper testing and change management maintained, to avoid introducing unintended resilience or security issues. FIs will be hard pressed to keep up with the patching cadence, given the significant number of vulnerabilities frontier AIs is and will continue to surface. Enhanced approaches must be considered. This includes moving from a patching mindset to a vulnerability management mindset such as using virtual patching to block malicious traffic. 14 To match the speed of the frontier AI enabled attackers, FIs will also need to up their ante to adopt AI-enabled defences - to improve in areas such as code security, patch prioritisation, and intrusion detection. 15 In this regard, not all FIs are equally positioned to invest in advanced AI-powered defences and have dedicated threat intelligence teams. Some FIs face the same risks with far less resources and expertise. Those who lag behind in defending against AI-enabled threats could become weak links in the wider ecosystem, eroding our collective defence. We thus have a shared interest to bring everyone along. 16 One avenue to so is to help every defender stay abreast emerging threats by improving sharing across the sector. When FIs have a clearer view of both emerging threats and countermeasures, they will be better placed to prioritise their limited resources to take effective pre-emptive measures. We see FS-ISAC taking up the thought leadership to issue timely advisories on frontier AI risks and translate emerging concerns into practical guidance for FIs.

17 Advisories, however, are heavily reliant on timely information-sharing by FIs who are at the frontline that first identify emerging threats. This is where trusted cyber information-sharing platforms such as FS-ISAC become invaluable. I am told that cyber threat levels across the Americas, APAC, and EMEA regions are regularly updated through FS-ISAC workgroup discussions, providing situational awareness that extends far beyond what any single institution's tools and frameworks can offer. Therefore, the industry must work together to improve information sharing so that insights such as emerging AI-enabled threats can be quickly disseminated and acted upon. Uplifting the Cyber Workforce 18 As our workforce upskills in AI tools, FIs must not neglect training in core cybersecurity competencies. Teams are still needed to scrutinise AI-generated outputs, distinguish genuine threats from false positives, what leads to prioritise, and decide when to escalate cases. While automated solutions may reduce the load of repetitive security-related tasks, incident coordination, stakeholder communication and accountability remain innately human responsibilities. 19 The security analysts, managers and intelligence professionals in this room are indispensable in our collective cyber defense. Notwithstanding the plethora of tools, and increasing automation of our security operations, our defenders still form the last line of defence. Threats may grow more sophisticated, but it is your skill, judgement and vigilance that will ultimately determine how our industry responds. 20 For APAC, the role of our defenders is more important now than ever. The region is increasingly exposed to fast-moving and sophisticated cyber threats that warrant timely and coordinated responses. Regional intelligence sharing and collaboration can therefore no longer be viewed as a voluntary contribution by a few institutions; it must become common practice across each and every member within the APAC community. 21 This is why events such as this Summit are so essential. Cyber defence is a team sport. Much like football, no single player wins the match alone; the coordination and trust between teammates is essential in delivering a good outcome. 22 Let me close by thanking FS-ISAC once again for its leadership, and for convening this community over the past decade in Singapore. I hope the discussions at this Summit will deepen the trust, insights and practical cooperation that our sector will need to stay resilient in the years ahead. Thank you.