MAS 演讲稿 · 2026-07-14
「警惕、韧性与信任:守护亚太金融业」——新加坡金融管理局副局长(金融监管)Ho Hern Shin 女士在 FS-ISAC 亚太峰会上的主题演讲,2026年7月14日
「警惕、韧性与信任:守护亚太金融业」——新加坡金融管理局副局长(金融监管)Ho Hern Shin 女士在 FS-ISAC 亚太峰会上的主题演讲,2026年7月14日
要点
- • 「与新加坡金融管理局合作于2017年建立的FS-ISAC亚太地区情报分析中心从3家成员机构增长至超过130家,覆盖该地区20个国家。」
- • 「2025年针对新加坡第三方服务商的勒索软件攻击导致大规模数据泄露:Toppan Next Tech在4月影响超过11,000名星展银行和中国银行客户,DataPost在5月影响至少146名Income Insurance保单持有人。」
- • 「深度伪造技术被日益用于冒充金融机构高管、政府官员和政治人物,以诱导员工将资金转入欺诈者的账户。」
- • 「前沿人工智能被认定为力量倍增器,使威胁行为者能够以规模和速度识别、链接并利用漏洞来放大现有网络威胁。」
- • 「核心网络卫生措施——进行适当测试和变更管理的及时补丁、使用多因素认证保护管理员账户、维护准确的软件资产清单以及在系统达到生命周期终点前进行退役——仍然是防御当前和新兴网络攻击的基础防线。」
- • 「通过FS-ISAC等区域威胁情报平台进行及时信息共享至关重要,该平台定期更新美洲、亚太和EMEA地区的网络威胁级别,对于集体态势感知和协调的行业韧性是必需的。」
完整译文(中文)
MAS 英文原文译文 · 翻译日期: 2026-09-14
峰会主席、寺来先生、尊敬的来宾们、女士们和先生们,大家早上好。2 首先,请允许我感谢FS-ISAC组织了本次峰会,并祝贺各位,因为我们在新加坡纪念FS-ISAC成立十周年。3 2017年,MAS和FS-ISAC合作建立了亚太地区情报和分析中心,促进网络安全威胁情报在整个地区的共享和分析。这是加强亚太地区金融机构(FIs)网络韧性的重要一步。在此之前,金融部门内部的情报共享是临时性的、零散的、无组织的。金融机构主要各自行动收集网络威胁情报,对外部网络威胁形势的集体态势感知十分有限。建立FS-ISAC亚太情报中心基于一个坚定的信念:一个联系紧密的、进行情报共享的社区,其韧性会远优于任何单独行动的防御者。4 在过去十年中,这一愿景已成现实。最初只有该地区三家成员企业的组织已发展成一个拥有超过130个成员、涵盖亚太地区20个国家的社区。除了成员数量的增长,FS-ISAC现已成为亚太地区金融机构之间进行有意义的情报共享的重要「go to」平台。FS-ISAC还通过其情报报告、威胁通话(威胁通话是由FS-ISAC亚太情报团队举办的双周网络讨论,涵盖最新的网络威胁趋势和地区网络威胁级别的更新(由其金融机构成员社区整理汇总)),以及举办像本次峰会这样的活动,帮助机构促进凝聚力并提高对新兴威胁的认识。5 回顾过去,FS-ISAC为亚太地区有效的网络防御奠定了重要基础。这一点变得尤为重要,因为网络威胁在速度、规模和复杂性上持续演变。网络威胁形势的演变
6 在过去十年中,我们观察到了金融部门所面临网络威胁的四大转变。
(a)首先,攻击变得越来越复杂。如今的攻击远不止电子邮件钓鱼、收件箱泄露或DDoS攻击。勒索软件感染、通过防御较弱的第三方供应商和服务商的攻击,以及由AI驱动的冒充已日益普遍。(b)其次,攻击者越来越多地针对我们高度互联的金融部门生态系统中的薄弱环节,如第三方服务提供商,甚至客户。这实际上将攻击面扩展到这些实体,扩大了潜在的入侵点。(c)第三,威胁参与者的构成变得更加多样化,从经济利益驱动的网络犯罪分子、激进组织到不那么有组织的、机会主义的威胁参与者,如脚本小子。(d)第四,全球地缘政治紧张局势加剧了网络活动。例如:俄罗斯国家支持的网络威胁参与者在冲突开始时针对乌克兰和北约联盟的关键基础设施进行了攻击,俄乌冲突仍在进行中【链接】。日本等国家也因同其他国家一起实施制裁而遭受来自疑似与俄罗斯结盟的组织的勒索软件和DDoS攻击增加【链接】,无论是来自试图投射影响力的黑客激进分子、利用不确定性寻求经济收益的网络犯罪集团,还是追求更广泛战略目标的国家关联行为体。
7 今天,新加坡的网络威胁形势是更广泛的亚太地区形势的一个缩影。勒索软件攻击和数据外泄对这一地区的金融机构仍然构成严重威胁。这些事件通常源于熟悉的薄弱之处,如不充分的访问控制和边缘设备上的未修补的漏洞,这些漏洞允许攻击者盗取数据并加密金融机构系统以勒索赎金。8 第三方泄露是另一个令人关切的领域。在新加坡的背景下,我们将记得去年企业打印服务提供商Toppan Next Tech(2025年4月,打印供应商Toppan Next Tech(TNT)在2025年4月遭到勒索软件攻击,导致超过11000名DBS银行和中国银行客户的姓名和地址被提取,后来导致泄露的交通警察数据随后在网上发布【链接】)和DataPost(2025年5月,新加坡数据处理供应商DataPost遭到勒索软件攻击,泄露了至少146位保诚保险投保人的个人数据,包括姓名、地址和年度奖金记录【链接】)遭到的勒索软件攻击,这些攻击造成了运营中断和客户数据泄露。9 与此同时,数字欺诈的威胁在迅速演变。深度伪造的日益使用使威胁参与者能够以越来越高的精细程度冒充可信赖的个人。MAS已获悉多起深度伪造案例,其中金融机构高管、政府官员和政治人物被冒充,以诱导金融机构员工向欺诈者的银行账户转账。10 这些深度伪造事件突显了一个重要现实。威胁参与者越来越多地不仅针对我们系统中的漏洞。他们也在针对信任本身。他们的目标是制造混乱、破坏信心,并破坏我们机构非常依赖的可信赖关系。前沿AI风险
11 最近,前沿AI对该部门提出了更广泛更深层的挑战。全球网络安全机构和安全研究人员都强调了前沿AI在规模和速度上识别、链接和利用漏洞的潜力。前沿AI从根本上改变了网络风险如何出现和扩展的方式。AI不是一个单独的风险类别,而是一个力量倍增器,放大了网络环境中现有威胁。12 在这种背景下,网络卫生从未像现在这样重要。及时修补、使用强身份验证(如MFA)保护管理员账户、维护准确的软件资产清单以及在系统到达支持终止前注销系统,这些基本的安全原则仍然是保护机构免受当前和未来网络攻击的核心原则。13 然而,我们执行网络卫生的方式将需要改变。修补所花费的时间必须减少,同时保持适当的测试和变更管理,以避免引入无意的韧性或安全问题。鉴于前沿AI目前和将来会发现的大量漏洞,金融机构将很难跟上修补的节奏。必须考虑更强化的方法。这包括从修补思维转向漏洞管理思维,如使用虚拟修补来阻止恶意流量。14 为了跟上前沿AI驱动的攻击者的速度,金融机构还需要加倍努力采用AI驱动的防御——在代码安全、修补优先化和入侵检测等领域进行改进。15 在这方面,并非所有金融机构都能均等地投资先进的AI驱动防御并拥有专属的威胁情报团队。一些金融机构面临相同的风险,但资源和专业知识远少。在防御AI驱动的威胁方面落后的那些机构可能会成为更广泛生态系统中的薄弱环节,削弱我们的集体防御。因此,我们有共同的利益来共同推进。16 一条途径是帮助每个防御者通过改善部门间的共享来跟上新兴威胁。当金融机构对新兴威胁和对策有更清楚的了解时,他们将更好地能够优先考虑他们有限的资源采取有效的预防措施。我们看到FS-ISAC发挥思想领导力,发布关于前沿AI风险的及时咨询,并将新兴问题转化为金融机构的实际指导。
17 然而,咨询在很大程度上依赖于首先识别新兴威胁的最前线金融机构进行及时的信息共享。这就是像FS-ISAC这样的受信任的网络信息共享平台变得无价之宝的地方。我被告知,美洲、亚太和EMEA地区的网络威胁级别通过FS-ISAC工作组讨论定期更新,提供的态势感知远远超过任何单一机构的工具和框架所能提供的范围。因此,业界必须共同努力改善信息共享,以便像AI驱动的新兴威胁这样的见解能够快速传播和付诸行动。提升网络劳动力18 当我们的劳动力在AI工具中提升技能时,金融机构不必忽视核心网络安全能力的培训。仍然需要团队来审查AI生成的输出、区分真实威胁和误报、确定要优先考虑的内容以及决定何时升级案件。虽然自动化解决方案可能会减少重复性安全任务的负担,但事件协调、利益相关者沟通和问责仍然本质上是人类责任。19 这个房间里的安全分析师、经理和情报专业人员在我们的集体网络防御中是不可或缺的。尽管工具繁多,我们的安全运营日益自动化,但我们的防御者仍然形成了防线。威胁可能会变得更加复杂,但最终决定我们行业如何应对的是你们的技能、判断力和警觉性。20 对于亚太地区,我们防御者的角色现在比以往任何时候都更加重要。该地区日益暴露于快速变化和复杂的网络威胁,需要及时和协调的应对。因此,地区情报共享和合作不再能被视为少数机构的自愿贡献;它必须成为亚太社区内每个成员的普遍做法。21 这就是像这样的峰会如此重要的原因。网络防御是一项团队运动。就像足球一样,没有单一的球员独自赢得比赛;队友之间的协调和信任对于取得良好成果至关重要。22 让我再次感谢FS-ISAC的领导力,以及在过去十年中在新加坡聚集这个社区。我希望本峰会的讨论将加深信任、见解和实际合作,这是我们部门未来保持韧性所需的。谢谢。
英文原文
MAS 官网原始记录 · 抓取日期: 2026-09-14
Summit Chair, Terai-san, Distinguished Guests, Ladies and gentlemen, a very good morning to all of you. 2 First, allow me to thank FS-ISAC for organising this Summit, and to congratulate you as we mark FS-ISAC’s 10th anniversary here in Singapore. 3 In 2017, MAS and FS-ISAC collaborated to establish the Asia Pacific Regional Intelligence and Analysis Centre, to encourage regional sharing and analysis of cybersecurity threat intelligence. This represented a significant step in strengthening cyber resilience of financial institutions (FIs) across APAC. Prior to this, intelligence sharing within the financial sector community had been opportunistic, patchy, and unorganised. FIs largely went about their own way to gather cyber threat intelligence, and collective situational awareness of the external cyber threat landscape was limited. The establishment of the FS-ISAC APAC Intelligence Centre was anchored upon the firm belief that a well-connected, intelligence-sharing community would be far more resilient than any single defender acting in isolation. 4 Over the past decade, this vision has taken root. What began with just three member firms in the region has grown into a community of more than 130 members spanning 20 countries in APAC. Beyond the growth in membership numbers, FS-ISAC is today a key “go to” platform for meaningful intelligence sharing amongst FIs in APAC. FS-ISAC also has helped institutions foster cohesion and strengthen awareness of emerging threats through its intelligence reports, threat calls Threat calls are bi-weekly webinars hosted by FS-ISAC’s APAC intelligence team which cover the latest cyber threat trends and updates on the regional cyber threat level (collated by its FI member community). , and hosting events like this Summit. 5 Looking back, the FS-ISAC has laid an important foundation for effective cyber defence in APAC. This has become even more significant as cyber threats continue to evolve in speed, scale and complexity. Evolving Cyber Threat Landscape
6 Over the past 10 years, we have observed four broad shifts in cyber threats against the financial sector.
(a) First, attacks are getting more sophisticated. Attacks today go beyond email phishing, inbox compromise, or DDoS attacks. Ransomware infections, and attacks through less well defended third-party vendors and suppliers, as well as AI-enabled impersonations are increasingly commonplace. (b) Second, attackers are increasingly targeting the weak links in our highly interconnected financial sector ecosystem, such as third party service providers, and even customers. This effectively extends the attack surface to these entities, expanding the potential entry points for compromise. (c) Third, the profile of threat actors has also become more diverse, ranging from financially motivated cybercriminals, activist groups, to less organised, opportunistic threat actors such as script kiddies. (d) Fourth, geopolitical tensions around the globe have heightened cyber activity For example: Russian state-sponsored cyber threat actors targeted Ukrainian and NATO-aligned critical infrastructure at the onset, and ongoing Russia-Ukraine conflict [ Link ]. Countries such as Japan also observed increased ransomware and DDoS attacks from suspected Russia-aligned groups due to imposing sanctions along with other countries. [ Link ] , whether from hacktivists seeking to project influence, cybercriminal groups exploiting uncertainty for financial gain, or state-linked actors pursuing broader strategic objectives.
7 Today, Singapore’s cyber threat landscape remains a microcosm of the broader APAC region. Ransomware attacks and data exfiltration continue to post a serious threat to FIs in this part of the world. These incidents often stem from familiar weaknesses such as inadequate access controls and unpatched vulnerabilities on edge devices, which allow attackers to steal data and encrypt FI systems for ransom. 8 Third-party breaches represent another area of concern. In the Singapore context, we will remember last year's ransomware attacks on corporate printing service providers Toppan Next Tech In Apr 2025, a ransomware attack on printing vendor Toppan Next Tech (TNT) in April 2025 resulted in the extraction of names and addresses belonging to over 11,000 customers of DBS Bank and the Bank of China, later leading to a subsequent publication of compromised Traffic Police data online [ Link ] . and Datapost In May 2025, a ransomware attack on Singapore-based data handling vendor DataPost exfiltrated personal data, including names, addresses, and annual bonus records belonging to at least 146 Income Insurance policyholders. [ Link ] , which caused operational disruptions and exposure of customer data. 9 At the same time, the threat of digital fraud is evolving rapidly. The increasing use of deepfakes has enabled threat actors to impersonate trusted individuals with a growing degree of sophistication. MAS has been made aware of deepfake cases in which senior FI executives, government officials and politicians were impersonated to induce FI employees to transfer funds into fraudsters’ bank accounts. 10 These deepfake incidents highlight an important reality. Increasingly, threat actors are not only targeting vulnerabilities in our systems. They are also targeting trust itself. Their objective is to create confusion, undermine confidence, and disrupt the trusted relationships that our institutions so dearly rely upon. Frontier AI Risks
11 Most recently, frontier AI is posing broader and deeper challenges that the sector must now confront. Both global cybersecurity agencies and security researchers highlight the potential for frontier AI to identify, chain and exploit vulnerabilities at both scale and speed. Frontier AI is fundamentally reshaping how cyber risks can arise and scale. AI is not a separate risk category, but a force multiplier that amplifies existing threats across the cyber landscape. 12 In this context, cyber hygiene has never been more important. The fundamental security principles of timely patching, securing administrator accounts with strong authentication such as MFA, maintaining an accurate inventory of software assets, and retiring systems before they reach end-of-support remain core tenets of protecting institutions against both current and future cyber-attacks. 13 However, the manner in which we execute cyber hygiene will require changes. The time taken to patch must reduce, with proper testing and change management maintained, to avoid introducing unintended resilience or security issues. FIs will be hard pressed to keep up with the patching cadence, given the significant number of vulnerabilities frontier AIs is and will continue to surface. Enhanced approaches must be considered. This includes moving from a patching mindset to a vulnerability management mindset such as using virtual patching to block malicious traffic. 14 To match the speed of the frontier AI enabled attackers, FIs will also need to up their ante to adopt AI-enabled defences - to improve in areas such as code security, patch prioritisation, and intrusion detection. 15 In this regard, not all FIs are equally positioned to invest in advanced AI-powered defences and have dedicated threat intelligence teams. Some FIs face the same risks with far less resources and expertise. Those who lag behind in defending against AI-enabled threats could become weak links in the wider ecosystem, eroding our collective defence. We thus have a shared interest to bring everyone along. 16 One avenue to so is to help every defender stay abreast emerging threats by improving sharing across the sector. When FIs have a clearer view of both emerging threats and countermeasures, they will be better placed to prioritise their limited resources to take effective pre-emptive measures. We see FS-ISAC taking up the thought leadership to issue timely advisories on frontier AI risks and translate emerging concerns into practical guidance for FIs.
17 Advisories, however, are heavily reliant on timely information-sharing by FIs who are at the frontline that first identify emerging threats. This is where trusted cyber information-sharing platforms such as FS-ISAC become invaluable. I am told that cyber threat levels across the Americas, APAC, and EMEA regions are regularly updated through FS-ISAC workgroup discussions, providing situational awareness that extends far beyond what any single institution's tools and frameworks can offer. Therefore, the industry must work together to improve information sharing so that insights such as emerging AI-enabled threats can be quickly disseminated and acted upon. Uplifting the Cyber Workforce 18 As our workforce upskills in AI tools, FIs must not neglect training in core cybersecurity competencies. Teams are still needed to scrutinise AI-generated outputs, distinguish genuine threats from false positives, what leads to prioritise, and decide when to escalate cases. While automated solutions may reduce the load of repetitive security-related tasks, incident coordination, stakeholder communication and accountability remain innately human responsibilities. 19 The security analysts, managers and intelligence professionals in this room are indispensable in our collective cyber defense. Notwithstanding the plethora of tools, and increasing automation of our security operations, our defenders still form the last line of defence. Threats may grow more sophisticated, but it is your skill, judgement and vigilance that will ultimately determine how our industry responds. 20 For APAC, the role of our defenders is more important now than ever. The region is increasingly exposed to fast-moving and sophisticated cyber threats that warrant timely and coordinated responses. Regional intelligence sharing and collaboration can therefore no longer be viewed as a voluntary contribution by a few institutions; it must become common practice across each and every member within the APAC community. 21 This is why events such as this Summit are so essential. Cyber defence is a team sport. Much like football, no single player wins the match alone; the coordination and trust between teammates is essential in delivering a good outcome. 22 Let me close by thanking FS-ISAC once again for its leadership, and for convening this community over the past decade in Singapore. I hope the discussions at this Summit will deepen the trust, insights and practical cooperation that our sector will need to stay resilient in the years ahead. Thank you.