newsfilter.io
Panel

Cybersecurity: Anticipating the Next Trojan Horse

  • Artificial intelligence, machine learning, and big data are expected to play a growing role in cyber attack detection, though unsupervised learning remains in early development stages; criminals are already leveraging AI to generate unrecognizable malware, automate randomized attacks at scale, and optimize evasion of antivirus services.
  • Singapore's Cyber Security Agency anticipates defining critical information infrastructure (CII) and responsibilities within an upcoming omnibus bill, aiming to facilitate information sharing between entities and regulators while potentially regulating the industry to reduce information asymmetry.
  • The Personal Data Protection Act is expected to be strengthened to mandate the reporting and disclosure of personal data loss incidents, driven by the projection that 26% of the global economy will be digital within the next three years.
  • Future cybersecurity strategies are predicted to shift from preventing system unavailability to preventing data exfiltration, moving toward "zero trust" models and the convergence of physical and digital security.
  • Global cooperation is expected to expand through increased government-to-government memorandums of understanding and the eventual development of international conventions similar to the UN Convention for the Law of the Sea to govern cross-border information flow via a multi-stakeholder approach.
  • The cybersecurity industry faces significant risks from over-regulation, poor regulation, and data localization laws that could segment the global internet and threaten companies reliant on aggregated global data.
  • Human-vector attacks and technically unsophisticated methods are predicted to persist as primary threats, with cyber crime driven by a growing internet-using demographic in Asia and among youth where governance is absent.
  • Market self-regulation is expected to fail due to misaligned incentives, particularly where consumers lack direct motivation to purchase secure IoT products, necessitating targeted public education starting from nursery school.
  • Investment in security research is currently skewed 90% toward endpoint security rather than core network security, which is structurally limited by the synthetic and evolving nature of the environment for supervised machine learning.
  • C-suite executives are expected to view cybersecurity as a critical business continuity issue only after experiencing major breaches, requiring organizations to dedicate substantial resources to security to operate effectively.
  • The lack of a global cyber crime convention and jurisdictional scaling issues for policing are expected to perpetuate the global cyber crime economy, while a "natural security instinct" deficit in the general population is predicted to persist without intervention.