“Vigilance, Resilience and Trust: Securing APAC’s Financial Sector” – Keynote Address by Ms Ho Hern Shin, Deputy Managing Director (Financial Supervision), Monetary Authority of Singapore, at the FS-ISAC APAC Summit on 14 July 2026
Summit Chair, Terai-san,
Distinguished Guests,
Ladies and gentlemen, a very good morning to all of you.
2 First, allow me to thank FS-ISAC for organising this Summit, and to congratulate you as we mark FS-ISAC’s 10th anniversary here in Singapore.
3 In 2017, MAS and FS-ISAC collaborated to establish the Asia Pacific Regional Intelligence and Analysis Centre, to encourage regional sharing and analysis of cybersecurity threat intelligence. This represented a significant step in strengthening cyber resilience of financial institutions (FIs) across APAC. Prior to this, intelligence sharing within the financial sector community had been opportunistic, patchy, and unorganised. FIs largely went about their own way to gather cyber threat intelligence, and collective situational awareness of the external cyber threat landscape was limited. The establishment of the FS-ISAC APAC Intelligence Centre was anchored upon the firm belief that a well-connected, intelligence-sharing community would be far more resilient than any single defender acting in isolation.
4 Over the past decade, this vision has taken root. What began with just three member firms in the region has grown into a community of more than 130 members spanning 20 countries in APAC. Beyond the growth in membership numbers, FS-ISAC is today a key “go to” platform for meaningful intelligence sharing amongst FIs in APAC. FS-ISAC also has helped institutions foster cohesion and strengthen awareness of emerging threats through its intelligence reports, threat calls
5 Looking back, the FS-ISAC has laid an important foundation for effective cyber defence in APAC. This has become even more significant as cyber threats continue to evolve in speed, scale and complexity.
Evolving Cyber Threat Landscape
6 Over the past 10 years, we have observed four broad shifts in cyber threats against the financial sector.
(a) First, attacks are getting more sophisticated. Attacks today go beyond email phishing, inbox compromise, or DDoS attacks. Ransomware infections, and attacks through less well defended third-party vendors and suppliers, as well as AI-enabled impersonations are increasingly commonplace.
(b) Second, attackers are increasingly targeting the weak links in our highly interconnected financial sector ecosystem, such as third party service providers, and even customers. This effectively extends the attack surface to these entities, expanding the potential entry points for compromise.
(c) Third, the profile of threat actors has also become more diverse, ranging from financially motivated cybercriminals, activist groups, to less organised, opportunistic threat actors such as script kiddies.
(d) Fourth, geopolitical tensions around the globe have heightened cyber activity
7 Today, Singapore’s cyber threat landscape remains a microcosm of the broader APAC region. Ransomware attacks and data exfiltration continue to post a serious threat to FIs in this part of the world. These incidents often stem from familiar weaknesses such as inadequate access controls and unpatched vulnerabilities on edge devices, which allow attackers to steal data and encrypt FI systems for ransom.
8 Third-party breaches represent another area of concern. In the Singapore context, we will remember last year's ransomware attacks on corporate printing service providers Toppan Next Tech
9 At the same time, the threat of digital fraud is evolving rapidly. The increasing use of deepfakes has enabled threat actors to impersonate trusted individuals with a growing degree of sophistication. MAS has been made aware of deepfake cases in which senior FI executives, government officials and politicians were impersonated to induce FI employees to transfer funds into fraudsters’ bank accounts.
10 These deepfake incidents highlight an important reality. Increasingly, threat actors are not only targeting vulnerabilities in our systems. They are also targeting trust itself. Their objective is to create confusion, undermine confidence, and disrupt the trusted relationships that our institutions so dearly rely upon.
Frontier AI Risks
11 Most recently, frontier AI is posing broader and deeper challenges that the sector must now confront. Both global cybersecurity agencies and security researchers highlight the potential for frontier AI to identify, chain and exploit vulnerabilities at both scale and speed. Frontier AI is fundamentally reshaping how cyber risks can arise and scale. AI is not a separate risk category, but a force multiplier that amplifies existing threats across the cyber landscape.
12 In this context, cyber hygiene has never been more important. The fundamental security principles of timely patching, securing administrator accounts with strong authentication such as MFA, maintaining an accurate inventory of software assets, and retiring systems before they reach end-of-support remain core tenets of protecting institutions against both current and future cyber-attacks.
13 However, the manner in which we execute cyber hygiene will require changes. The time taken to patch must reduce, with proper testing and change management maintained, to avoid introducing unintended resilience or security issues. FIs will be hard pressed to keep up with the patching cadence, given the significant number of vulnerabilities frontier AIs is and will continue to surface. Enhanced approaches must be considered. This includes moving from a patching mindset to a vulnerability management mindset such as using virtual patching to block malicious traffic.
14 To match the speed of the frontier AI enabled attackers, FIs will also need to up their ante to adopt AI-enabled defences - to improve in areas such as code security, patch prioritisation, and intrusion detection.
15 In this regard, not all FIs are equally positioned to invest in advanced AI-powered defences and have dedicated threat intelligence teams. Some FIs face the same risks with far less resources and expertise. Those who lag behind in defending against AI-enabled threats could become weak links in the wider ecosystem, eroding our collective defence. We thus have a shared interest to bring everyone along.
16 One avenue to so is to help every defender stay abreast emerging threats by improving sharing across the sector. When FIs have a clearer view of both emerging threats and countermeasures, they will be better placed to prioritise their limited resources to take effective pre-emptive measures. We see FS-ISAC taking up the thought leadership to issue timely advisories on frontier AI risks and translate emerging concerns into practical guidance for FIs.
17 Advisories, however, are heavily reliant on timely information-sharing by FIs who are at the frontline that first identify emerging threats. This is where trusted cyber information-sharing platforms such as FS-ISAC become invaluable. I am told that cyber threat levels across the Americas, APAC, and EMEA regions are regularly updated through FS-ISAC workgroup discussions, providing situational awareness that extends far beyond what any single institution's tools and frameworks can offer. Therefore, the industry must work together to improve information sharing so that insights such as emerging AI-enabled threats can be quickly disseminated and acted upon.
Uplifting the Cyber Workforce
18 As our workforce upskills in AI tools, FIs must not neglect training in core cybersecurity competencies. Teams are still needed to scrutinise AI-generated outputs, distinguish genuine threats from false positives, what leads to prioritise, and decide when to escalate cases. While automated solutions may reduce the load of repetitive security-related tasks, incident coordination, stakeholder communication and accountability remain innately human responsibilities.
19 The security analysts, managers and intelligence professionals in this room are indispensable in our collective cyber defense. Notwithstanding the plethora of tools, and increasing automation of our security operations, our defenders still form the last line of defence. Threats may grow more sophisticated, but it is your skill, judgement and vigilance that will ultimately determine how our industry responds.
20 For APAC, the role of our defenders is more important now than ever. The region is increasingly exposed to fast-moving and sophisticated cyber threats that warrant timely and coordinated responses. Regional intelligence sharing and collaboration can therefore no longer be viewed as a voluntary contribution by a few institutions; it must become common practice across each and every member within the APAC community.
21 This is why events such as this Summit are so essential. Cyber defence is a team sport. Much like football, no single player wins the match alone; the coordination and trust between teammates is essential in delivering a good outcome.
22 Let me close by thanking FS-ISAC once again for its leadership, and for convening this community over the past decade in Singapore. I hope the discussions at this Summit will deepen the trust, insights and practical cooperation that our sector will need to stay resilient in the years ahead.
Thank you.
***