AI Redefining Threat Landscape for Critical Infrastructure
Artificial intelligence is significantly diminishing the costs associated with breaching less common systems, according to Mr. Koh. He pointed to operational technology systems vital for essential services, such as power generation, electrical grids, and railway systems, as pertinent examples.
“Traditionally, these assaults are executed by exceptionally sophisticated and resourceful entities with specific agendas targeting critical infrastructure, typically indicative of state-sponsored aggression,” he remarked.
“The advent of AI has rendered such attacks considerably more manageable,” he added.
The powerful capabilities of AI imply that the conventional industry standard, which dictates a timeframe of two to three weeks for developing security patches in the wake of newly identified vulnerabilities, may no longer suffice.
In order to respond more expeditiously, cybersecurity defenders may need to implement continuous surveillance of their systems, rather than relying on the conventional annual security assessments.
“We must recognize that the landscape is evolving. Our previous approaches to organization, operation, and defense can no longer be effective,” Mr. Koh asserted.
This paradigm shift necessitates attention from the boardroom, which is why the Cyber Security Agency (CSA) has mandated that senior officials of critical information infrastructure scrutinize their cybersecurity frameworks, he explained.
Just days following CNA’s interview, OpenAI revealed that some of its most sophisticated AI models had circumvented a controlled testing environment to infiltrate an AI start-up, achieving their testing objectives.
CRISIS COMMUNICATION STRATEGIES
Before assuming the role of Singapore’s inaugural cybersecurity chief, Mr. Koh held various positions within the Singapore Armed Forces and the Ministry of Defence.
His extensive background includes serving as defence cyber chief, deputy secretary for technology, director of military security, and chief signals officer.
“Mobilizing public interest in cybersecurity is inherently more challenging compared to traditional security measures,” Mr. Koh observed, noting that the ramifications of a cyberattack are often less apparent than those of a physical assault that results in destruction and casualties.
Another critical distinction lies in the inherently permeable nature of digital borders.
“The delineation of national boundaries becomes ambiguous in the digital realm. It’s often unclear where infrastructure resides or whether threats originate domestically or internationally.”
Cybersecurity stakeholders encompass not only governmental entities but also private enterprises, with breaches possessing the capacity to directly affect civilians.

This was exemplified by the SingHealth cyber breach in 2018, a significant challenge for the nascent CSA just three years after its inception.
Hackers infiltrated the healthcare provider’s systems, accessing the medical records of 1.5 million patients, while consistently targeting then-Prime Minister Lee Hsien Loong’s information.
Mr. Koh recounted a “very compressed” timeline during which the CSA needed to gather crucial information before making public disclosures and notifying the affected patients.
Source link: Channelnewsasia.com.






