Ini adalah perjalanan di tempatan sebuah kecil. Ketika di siapkan kecil dan seorang perjalanan di tempatan, di mana desikasi yang berlaku di tempatan sebuah kecil, tapi sebuah perjalanan di tempatan sebuah kecil. Daun kemungkinan nanti, kelihatan kecil boleh membuat kecil digital. Kecil dan diperluatan kecil adalah kecil. Ketika diperluatan sebuah kecil, kecil, bukan sebuah kecil untuk kerja kerja. Tapi, kecil kecil dalam kecil, kecil dan kecil, diperluatan sebuah kecil. Ketika diperluatan ini, saya bercakap dengan kecil gara, yang berlaku di tempatan sebuah kecil, di tempatan sebuah kecil. Selepas kecil di SAAF, di mana dia berlaku di jeneral, dia juga berlaku kecil, di tempatan sebuah kecil, di tempatan sebuah kecil. Dia sudah mencari kecil, kecil untuk mencari kecil, di tempatan sebuah kecil. Selamat datang ke dalam kecil, di tempatan sebuah kecil, di tempatan sebuah kecil, saya Bavan Jai Pragas, Deputy Opinian Editor. Jani hari ini, saya adalah Gaurav Keeriti. Gaurav, terima kasih. Terima kasih banyak terima kasih. Gaurav, saya bercakap beberapa komentar di kecil di kecil, terima kasih banyak terima kasih. Gaurav, saya bercakap dengan beberapa komentar di kecil di kecil di kecil, terima kasih banyak terima kasih. темu juga. Jadi musuh ber взять. Tapi saya macam registriberie, retur darah dalam kesaksat yangibatRem Star untuk jawab. Sekarang pen extending huau yang tinggi, buat kira-kira tetap ke° tuvokan nampak terbuka. Itu tidak mereka yang yangoursan yang sangat nampak. Betul Digital, olah tentu ada uang melambar kegunaan kondisi dan saya rasa yang terakhirnya, kemudian cyber security sangat segera dipercaya. Dan untuk mengatakan segera kemudian cyber security yang berlaku, itu terlalu berharap dengan banyak penggunaan. Inilah, seorang yang mempunyai computer science, mengatakan segera dipercaya. Jadi, ini adalah kepercaya. Tapi kemudian, apabila anda menghukutkan kemudian, ia berharapkan berbual, jika saya menggunakan kemungkinan tentang kemungkinan kemungkinan, itu tidak mempercaya seperti yang yang anda ingin menangkirkan. Yang kedua yang terakhir adalah bahawa, most people want to go about their daily lives, online, shopping, banking, etc. without having this constant fear of omegunis, there are terrible people out there trying to steal all my money with a fake website, whatever it is. And because of those two features, people would rather not deal with the challenge of cyber. Both of those actually can be addressed. First, is that we can speak in plain English. We don't have to use technical terms to persuade people that, "Hey, I don't need to say it, use complex credentials." Use a strong password, because the stronger your password is, the harder it is for the bad guy to break in. It's kind of like keys. The more complex the key it is, the harder it is for them to pick the lock. Simple analogies make it much more accessible. The second thing is, we can stop terrifying people. Cyber security is a real threat, but so are many other things that they have to deal with. And we just teach them that, "Look, there are risks out there, learn how to manage them and proceed with your life. Just learn to spot signs of danger and keep yourself safe online." The other challenge is that cyber security as a profession is a very beligued profession. We feel very hard done by. And it's partly because we have to deal with three kind of dynamics. One is that we have competitors who want to see us fail. And every industry has competitors who want to see us fail. But we also have adversaries. We have bad guys who are hackers who want to see us fail as well. And very few other industries have adversaries. And the actual hackers want to break in. The third and the most fascinating is we have unwilling customers. Even our customers find cyber security frustrating. Like, "Why do I need to change my password again? Why does it need to be so long? Why does it need to be unique?" All of those things frustrate people because security does come in the way of usability sometimes. And there is a trade-off. So all of those three things make people feel that cyber is kind of the bad guy. But I like to remind people, "We're not the bad guy. The bad guy is out there." And in order to keep you safe from the bad guy, we kind of have to do a few things to keep you protected. Right. Make me think about Game of Thrones. The bad guy is beyond the balls. Yes. You know, tied to that mythos warning from the CAC was a very specific directive. About corporate balls that they need to take direct personal accountability for cyber defense, rather than delegating it entirely to IT. I thought that was very interesting and new. I have not seen it from other governments. Broadly speaking, what is your take on what is happening in Singapore's boardrooms right now? Directors stepping up? Or is there a bit of inertia? Well, I think directors have already stepped up. And the specific warning that CSA gave was targeted at the new threat posed by AI. Or at least the new nature and the dynamics of threats posed by AI. So we have been quite fortunate that in Singapore, from a regulatory perspective, we have imposed stricter requirements for cyber security on critical information infrastructure. So essential systems, things that power electricity, things that provide us clean drinking water, provide our transportation and our media. So many of the key sectors already have had to deal with cyber security as a conversation at the boardroom. The conversation is good, but what CSA is saying is that AI has made things a bit more complex. It's not that AI has introduced new threats. It's just made threats better cheaper faster. I mean, AI is a productivity tool. It's a productivity tool for you and me. Right. It's also a productivity tool for hackers. They are building better viruses, better cheaper faster. And the skillet which AI allows them to work, the challenge is that it could overwhelm us. It is a cat in mouse game, but when the mouse gets superpowers, well, the cats need to be worried. So that's kind of the space that we're in right now. And one of the most obvious examples of how AI has changed the game is fishing. I would say about 10 years ago, we'd had all these posters around Singapore. Spot the signs of fishing, look for typos, look for grammatical errors, you know. Obvious errors. At this point, if I get an email with a typo, that's the human. That's the one I'm going to trust because the perfect emails are being written by AI. The perfect deep-fake images and videos are all done by AI. And we're now in a reality where AI is able to generate a universe that looks plausible. The websites look real, the pictures look real, the videos look real, the text looks real. And people get easily fooled. And that's the challenge of AI. So CSE is just warning people that things are going to get even more tricky. Bords need to take it even more seriously. Individuals need to be aware of all of these changes and adapt to it. Let's focus on small businesses, you know, which you've called the unprotected 99% of our economy. I believe you've set up strong keep specifically to address this massive gap. I've read your commentaries and speeches you often argue that the basic flow of cyber hygiene isn't actually cost prohibitive. One gets a sense that, however, that many small businesses still perceive it as far to expensive. Why does that miss perception persist in what do you think is the real hurdle here? Yeah, I mean, that's a great question. It's complex. We start with, let's zoom out and look at the companies in Singapore, around the world. So in Singapore, we have something like 400,000 companies, of which how many of them actually have a person in their company with the title called Cybersecurity Something, like a CSO or a cyber security technical expert, less than 1%. So you have a situation in which 99% of your companies don't have anybody with cyber security talent or technical know-how. As a result of that, many of them feel that cyber security is inaccessible and you go back to your first question, why do people not want to talk about or read about cyber, they find it either terrifying or boring. So smaller companies struggle because they sit in this kind of gap. Bigger companies have the time, the money and the technical know-how to understand what cyber security is all about and to implement it. Smaller companies don't have the time, don't have the money and don't have the technical know-how, or at least they think they don't have the money and the technical know-how. As a result, you've got this kind of distribution where enterprises have cyber, smaller companies do not. And I think it's an inequitable distribution of protection. So there is a social problem there as well, which I'm concerned about. In some ways, it's a little bit like vaccination if you rewind back to the COVID days. And you imagine for some reason the government decided, and not sure any government ever would do this, but the government decided that the COVID vaccine is $100,000. Well guess what? Your well-off individuals would all get the COVID vaccine and they'd go about their lives very happily. And then your disadvantaged individuals would not get the vaccine and they'd be living in fear. So that becomes a huge distribution issue. And I don't want that to happen in cyber security, but that's what's happening on the world right now. The challenge is that the cyber industry has also focused its attention on enterprises. So they've built tools that work if you've got a big budget and if you've got somebody who understands cyber security. So the tools are designed for them. Why? Because selling something to a big bank is worth a lot more than selling something to a small bakery. The analogy I love to give to explain how you can build for smaller companies at a price point that makes sense is IKEA. If you have a lot of money and you want to get a dining table, hire a carpenter. carpenter will come in with professional skills, measure your dining room, cut down a beautiful American walnut tree, polish it and give you a custom dining table for your room that everybody will see.
say is that's beautiful, that's a beautiful dining table. If you don't have money, where do you go? You go to IKEA. IKEA's table has never seen a carpenter or a tree in its life. It's like plastic and wood chips squashed together with legs you have to screw in yourself. But it's 39 bucks. And IKEA doesn't make tables cheaper by outsourcing cheaper carpenter to cheaper carpenter's or finding cheaper trees from South America. That's not their model. They've built a completely different way of designing and selling tables. We need to do that for cybersecurity. Today's cybersecurity is a professional skill set, carpenter's, very proud skills, very high quality tools, high quality materials. Can we build an IKEA, which is cheap, good enough and relatively durable? Now, are you going to have a dining party for the ambassador and the president at the Nicar table? Maybe not fit for purpose, but at least it's better than eating on the floor for our daily news. And so that's what we are trying to build at Strongkeep and what I think the industry needs to start adapting to. If you have a situation where 99% of the smaller companies are not protected, they become the target and the access point to bigger companies. We call the supply chain. If I'm an attacker and I want to get into a big bank, breaking into that bank is going to be really hard. But if I manage to get into a smaller company that they rely on, a law firm and accounting firm, HR software firm, and I can break in through there, I have all the exact same access that I did if I broke into the bank. But it's so much easier to break into that small company. So supply chain becomes a huge risk for enterprises and boards going back to your earlier question are starting to think, hey, what are my supply chain risks? Who are the companies I depend on and send my data to and could actually cause a huge cyber risk for me if they aren't protected? So we're starting to see that same conversation on vaccination. Let's say I'm a, I don't know, maybe a bakery or a laundromat, a clinic down here in Topo, you opposite new center. I've not had cybersecurity. I've not heard about it throughout the time my business has been operational. And now you're coming to me and saying that I need it. I've survived without it all this while. Yeah. Why do I need it? No, that's exactly the question many of the customers ask as well. Two parts to the answer. One is that many of them now need it because it's either by regulation or procurement. So either the government has decided for healthcare, for example, all GPs needed, whether you think you need it or not, you have to do it. The others by procurement, if you're selling to a bigger enterprise today and the board is like, hey, I want to manage my supply chain risks, they will put it in their procurement documents. In order to sell to me, you need to show me proof that you have met all of these cyber standards. So that's the second reason. But if I would answer this as a conceptual question, the philosophy behind many SMEs is we're too small to be a target. Nobody's going to go after me. I've survived so long. Nothing really happened. One of my early customers in this quite fascinating, when he walked into his office had like a little alter in the front office. And he told us that his primary strategy for deterring cyber attacks was an amulet that he bought. And he had this prayer amulet which was his cyber deterrence. And I was like, that's great. I mean, I guess actually it has worked because you've not had an incident. But it's kind of like having that same prayer amulet against COVID. Maybe you just didn't get it because you were lucky. And not having caught COVID doesn't mean that the vaccine is not worth the money. It just means you were lucky not to get it. Going back now to CSA's point about AI, if it becomes better cheaper faster for attackers to attack, well then at some point you will be in the process. This contagion, this virus is going to spread to a point where it hits you, whether you're a bakery or a small clinic or a law firm or an accounting firm or whatever it is, you will at some point have something. I would say well over half of my customers, when we on board them, have some sort of dominant virus in one of their laptops. And that's natural. It's been stealing their data. It's been logging their keys. It's been doing something on their laptops for years. And they just have not had a problem with it. People are only worried about cybersecurity when it prevents them from using their system. They're like, "Oh my gosh, I can't log in." Or the website gets defaced. But if it's just stealing data and they don't notice it, most people are kind of okay with that. But that's actually wrong because whatever it starts stealing credit card data, whatever it starts stealing your customers credit card data. So there's a whole bunch of risks that people don't think about. And AI is going to make all of that come to the front. It is going to become easier for them to attack. Just thinking about attitudes to cybersecurity among the small businesses that you work with. What would you say in comparison with the region or globally that we people think about cybersecurity in Singapore? Are we better? So it's hard for me to say globally what the attitudes are. From what I've seen, actually, I would say we are more aware. And I think we're partly more aware because as a matter of public policy, we've been very vocal about the threat of cybersecurity. We also have a very active and very good regulator that's been pushing out both education and awareness as well as policy and regulation to make sure that people understand that this is a serious problem. And to some extent, I think Singapore is one of the forefront jurisdictions in pushing out regulation for cybersecurity. Many other countries reference what Singapore has done in their own work. So I would say that actually smaller businesses in Singapore understand it. They are prepared to do something about it. The challenge is many of them think that they can't afford it or they can't do anything about it. So it's a, I know, but I can't do. And that's the gap, kind of, too. So on cybersecurity, one of the things our newsroom colleagues and those of us on the opinion desk spent quite a bit of bandwidth last year on was tracking the much talked about state linked cyber threat group known as UNC traded six. I myself wrote a couple of commentaries about it. For a small, highly connected state like Singapore, it's a threat of this skill something that can really be, you know, solved or is the real task simply to detect hardened systems and keep brazing the cause for attackers. Yeah, it's a tough question. I would actually reframe it a little bit. So you use the word solved. I think solved is kind of the wrong word. Right. Foreign cyber threats are more like thunderstorms to manage, not problems to solve. You can't solve a thunderstorm. You can build mitigation. You can build sheltered walkways. You can build better drainage. Once in a while, the sheltered walkway will blow over. The drain will overflow and you'll learn some lessons from it. But you can't solve thunderstorms. You can just manage it. And so I do think there is a change in the way we think about how to deal with cyber security. Again, stepping back, we live in a world where the dark web, which is a place where all of these kind of online criminals look, is the third largest economy in the world. So the WF estimates that you've got, you know, US, China and the dark web at somewhere between six to 10 trillion dollars. I mean, let that number sit in like there is almost 10 trillion dollars of economic activity in the underworld. At that point, you think it's ever going to go away. You think we're going to solve it? We're not. We're just going to have to figure out how to manage it. And there's this kind of old African proverb. It's not about running faster than the line. It's about running faster than the guy next to you. And that's kind of where Singapore has to be. And just don't want to be the target that the line goes after. We have to raise our baselines, protect ourselves a little bit better. And as you said, just implement the basic controls to frustrate the guy long enough to say, Hey, this clinic is not worth the effort. I'm going to move to another clinic. I'm going to move to another target in another country because they're easier. And that's all that we can do. This will never be a solved problem. The other challenge that state sponsored or state linked attackers is just one type of attacker. There are two others. So you've got a state linked ones, which, you know, that's their day job they're paid for by the government. You've got criminals and those criminals, I mean, some of them are state linked, some of them are not. Some of them just want the money. And some of them, you know, I just out there to prove themselves. They're just egotistical individuals who want to prove that they can break into a system for the glory, for the fame, for whatever it is. And those ones are dangerous, slightly problematic in many ways. Then you've got a third type, which are ideological. These are the guys who take a very binary view on values, on religion, on, you know, political affiliations and attack the other side. The most visible one on this is the pro-abortion anti-abortion hackers in the US. So if you run an abortion clinic in the US, you will have anti-abortion hackers going after your website. If you run a pro-abortion campaign or an anti-abortion campaign, you'll have pro-abortion hackers hacking your website as well. So that's an ideological. There's no money to be gained. They're not state-sponsored. But they want to prove that their values are better than yours by taking down the other side. So you've got a variety of attackers and you've got to thunderstorm to just manage. This dynamic is going to remain. One of the things I've been writing about more broadly is about, you know, global governance, a variety of issues, for example, critical underwater infrastructure, other emerging threats. What is your sense of global governance when it comes to dealing with these threats? I mean, it's enough being done. If the people who used to do it are not interested in doing it anymore, should the smallest dates be stepping up? I mean, I'll speak from my own perspective. In previous jobs, I was much more exposed to international conversations. Today, I occupy a role as a cyber expert at the United Nations invites on a needs basis. So once every few months, they will invite me to give specific inputs on specific cyber threats and how global governance can adapt or deal with those types of threats. And the answer is, and you're asking the risk guy, are they doing enough? I say no. I honestly believe that the threat has escalated to a point where global governance needs to go beyond good to have and kind of needs to implement must-haves. And again, going back to COVID, at the point where
we were recommending people to take precautionary measures, it wasn't working. And so states decided to start pushing the vaccinations, pushing state to state kind of diplomatic controls around travel. And then you had a sudden control over the virus. People don't think of cybersecurity in the same way, but the economic impact is quite significant in almost the same magnitude. If smaller companies become a contagion, actually your bigger enterprises are going to suffer as well. And it's not just in Singapore, it's around the world. The countries need to coordinate a lot better. Governance needs to be a lot more tight. The challenge now is we live in a fairly unprecedented era where the global mechanisms of governance are either being dismantled or sidelined. And that's a huge challenge. We spent more than a decade building up a number of platforms, summit the United Nations, to set up norms of responsible behavior, state-to-state behavior and cybersecurity, just rules of the road. And this was a great thing. It was endorsed and ratified by most countries. And Southeast Asia in particular was very progressive about this. But now that whole conversation is taken a little bit of a backseat and starting to get sidelined. Again, we go back to this challenge between security and usability. If you are seeking the opportunities of technology, then controlling the risks of it becomes a burden to you. And we're now in an AI arms race. And to some extent, we're in a geopolitical technological arms race. Some countries say they want to be AI champions. And in order to become faster movers in AI, you kind of have to remove some of the safety systems that keep those technologies under control. There was a very famous case. And I don't know the full details, but the case was that the Department of Defense asked Anthropic to release certain security controls so that they could use it. And Anthropic said, no. And so the Department of War in the US then said, well, we'll use OpenAI instead. That's a very specific and sharp example of how safety and security systems can cost you business. And if you're in an arms race literally, in this case, to build a leadership role geopolitically around AI, you will take certain decisions that slow down the pace of governance. And I think that's the wrong decision. I think we're now in an era where humanity needs to decide what is the role that AI plays in society? And how do we manage this technology before it becomes a bigger risk? I do wonder if the people who do cyber security risk experts like yourself, are they at the table when policy is being set, whether it's at a company level or at government level, I mean, Singapore, we know that that is the case, but I do wonder at the MNC level, is that happening? Increasingly yes. I think increasingly boards are starting to recognize. So you talk about, at the government level, you've got government agencies. In most countries in the world, now have some form of agency or organization that is specifically charged with looking at cyber security, or digital risk, or digital security as a whole. So Singapore, we have CSA. And that has a role in all of these public policy conversations to say, yes, this technology is amazing, but we need to implement some controls, or we need to be safe in how we implemented or executed or adopted. So that conversation happens at the policy level. At the company level, so you've got big enterprises, and they have boards. Most of your bigger organizations, the purpose of a board is to steer a company in the right direction. And that means good governance, and that includes risk management. There are many risks, oil price rising, currency fluctuations, leadership, staff culture, all of these are risk they manage. Cyber is another risk that they manage. And so they're starting to ask the questions of the people at the management level. As a board member, I don't want to see my bank or my company go down because of a cyber attack. What are you management doing about this risk? And then the manager will be like, oh, we have a chief information security officer. Let him brief you on the plans. Let him brief you on the risks. Let him brief you on the tools. Part of my role involves going to those kind of boards and giving them updates on like, hey, this is new thing called quantum. Let me tell you more about it. This is a new thing called agentic AI. Let me tell you more about the risks balanced with the opportunities. But the risks primarily because that's my expertise. So boards are having the conversation. And to be fair, they are having much more elevated conversations about risk rather than tools, about exposure rather than compliance. They're not like, oh, what standard are we compliant to? That's like five years ago conversation. Now they're like, what are the new risks that we need to be aware of? And how do we as a board make the right decisions to govern this company to be a lasting one? So that's a great conversation to have. You talked about agentic AI. I was at a conference over the weekend AI engineer fascinating and really seeing for oneself how fast the technology is evolving and that the mass use is really upon us. Specific to agentic AI, what do you see as the kind of near-term risk where it comes to cybersecurity and opportunities? The opportunities are tremendous. I mean, my company uses AI to build, we use AI to run the company. We're building AI for other customers to use. We are securing the AI that they are using to build that thing. So it's layers of layers of AI. So AI is part of our lives. It's going to be here to stay and it's going to increase. I mean, when I plan for my holidays, I use AI. I'm sure all of you are challenging fitting your way through all sorts of things. Italy last year. And people are challenging and clodding their way through all sorts of things, which you never would have imagined you would have done three to four years ago. So AI is here to stay and it's going to grow. The risks will become very tremendous when it starts to conflict with identity. Let's say, for example, you used AI to search for your holiday plans two years ago. A year from now, actually, you can give your credit card to AI and you can book the restaurants for you. Should you give your credit card to AI and let it book restaurants for you? At some point, we're going to have that dilemma, because it's already a possibility. We have plenty of my colleagues are already in that situation where AI is buying stuff for them online. But once you start having your credit card details, it has your email address, it has your name, it has your-- I mean, it has all of your details. It can start to do things as you. And AI is inherently-- we call it probabilistic systems. You have deterministic systems and probabilistic systems. And explain what those means. Deterministic systems are old computer programs. If this, then that. If I go to a computer program 10 years ago, what color is the sky? I'll have a list of options. It's blue or black. I have a blue or black. And if you answer red, the program will not accept it, because there's only two options available. Deterministic software. Probabilistic software is sometimes the sky is blue, sometimes the sky is black. Sometimes it's green, depending on which country you're in. Sometimes it's gray, if you're in London, sometimes it's red in the morning, sometimes it's purple in the night. There's a whole range of colors because it's a probabilistic curve now. And you can't tell what the answer might be, because based on probabilities, it could be a range of different colors. It could even be not a color. The sky actually has no color. It is the refraction of the light that bounces against the ozone. It's like, that is a factually correct answer. So you can't actually predict what it's going to do. And as a result of that inherent unpredictability, which is what the system is built for, giving it your credit card and your email address, becomes a really risky thing to do, because it can do damage as well. And we've seen cases where people had agents running for them and it deleted their calendar. Why? Oh, I feel very busy nowadays. Can you help me free up some of my calendar? Yeah, sure. I'll delete it. I mean, that is a factually correct answer to the problem. You asked me that you thought you were very busy. Can you help me free up my calendar? Yeah, I'll delete the calendar. Problem solved. That's not what you wanted to do. So there are risks that we're going to see, but these are new risks that we've never dealt with before. Right. I'm actually in the process of experimenting with building my own agent. Good luck, Aina. Let me know if you need some security. Second brain for a journalist. Yeah, no, I have-- I mean, all my team have one as well. Right. So we all have named agents working with us, but because I'm cyber, we built it in a very secure way to manage our work securely. And that's part of our own considerations as well. So you will have to think about how that works for you. Cool. To wrap up on a practical note, we just talked about a range of issues. But what can actually be fixed in the short to medium term? Perhaps we break it down explicitly by audience. What is the single most critical action required now from, say, the corporate boards, from the small business owners, and finally, from everyday users? Yeah. Great questions again. I mean, if you're a board of an enterprise, you should not be asking about, what tools do we have in place, what technologies are we using. You should be asking conceptual questions like, how long will it take before we know that there's a cyber incident? How fast can you detect that there's a burglar running around our building? How long will it take for you to contain this threat? How long will it take for you to catch the guy? And how long will it take for you to recover the damage that this person has done? So those are the kind of questions that are at the conceptual level. And then that forces the right behavior at the management level to find out quickly, contain it quickly, and recover quickly. That's the expectation. For smaller businesses, actually, it's a much simpler problem. The challenges, again, they've imagined this to be a very expensive, ownerless problem to solve. Philosophically, only four things can go wrong in cyber. Number one, you download something. The virus, it's a malware, it's something bad. So you download something. Number two, you click on something. You went to a phishing website, a scam website, a link that looks like the banking website, but it's not. Number three, your credentials are stolen. You have a username and password, which is admin and password,
password one, two, three, you know, easily guessed, easily broken. And number four, your systems are insecure. So you've got an old version of Windows, you didn't patch your software, you didn't patch your devices. So just generally insecure. Those are philosophically the only four things that can ever go wrong in cybersecurity. Hey, I just exploits these four things in different ways. Solving these four problems is like less than 30 bucks a month. Honestly, and if you actually have the expertise to do it yourself, you can probably go even lower than that. I give a lot of talks to SMEs. And one of my opening slides is you can do all of this for free with enough technical know how and you can Google your way to do most of it for free. But if you don't have the time to spend a little bit of money, get some tools. So for SME owners, it's simple and very affordable. For ordinary users, I my number one advice is multifactor authentication. And I know I said I wouldn't use the term, but basically have some sort of external device that allows you to validate that you're logging into your Facebook, your Instagram, your whatever system that you're using online. Just make sure it pings another device to check that it's really you. And having that simple additional layer makes it so much more frustratingly difficult for an attacker to break in because now I've got to hack two things. I've got to hack your website account and I've got to figure out is it a phone? Is it a token? Is it another laptop? What's what's the other factor that this person is using? So for individual users, you know, just have that two factor authentication and multifactor authentication enable and that makes it so much harder. I mean, there's a whole bunch of other common sense things you can do, but I will say that this alone makes it dramatically more hard for the attackers. Just on two F/A, after this, we are going to go for lunch. I'll probably pay by pay now. Just frustrates me, you know, the friction points. I mean, there's several times I have to click. I have to, you know, is there a trade off there that, you know, do I just have to stomach this friction? I will give a very simple analogy. I mean, actually locking your door is painful. It's an extra step. We need to do every day when you leave your apartment, like close the door, lock it. Some people have two locks. Some people have a grill on purpose. So they've got a door lock and then they've got a grill that they need to lock as well. Singapore is relatively safe. You can kind of get away with just having one lock. But that process of introducing a lock in and of itself adds friction, but it also adds security. So there is a trade off between security and usability. And that tension will always exist. Of course, there is a third dimension called cost. If you wanted to be both secure and very usable, you spend more money. You have a biometric facial recognition door lock, you know, wow, seamless. Like you just stand in front of your door. The door opens, not cheap. If you live in a very unsafe neighborhood and I don't mean somewhere in Singapore in another country and I've grown up in countries where it's very unsafe, you have a door lock, you have another lock on top of it, you have a padlock, you have a grill and you have a grill outside your gate as well. So you have multiple layers of security and then your windows are all grilled as well because you're worried about people getting through the windows. So you take many, many, many layers of precaution because you live in an area of higher risk. I would say the same thing is true for online. If you are logging into a social media account, have a strong password, maybe 2FA. If you're logging into your bank account where all your money is, maybe put in a little bit more controls over it. So it really is about managing the risk and understanding that there's always going to be a trade-off between security and usability, but it keeps you safe. And that's actually ultimately the skill that you need to operate in the modern world. You can't cross the road without looking left and right. It slows you down, but it keeps you safe. God have given us a lot to think about. Thank you very much for coming into your opinion. Thanks for having me. I'm Baban Jai Pragas. You can email us your thoughts on this discussion. Our address is in the show notes. You can find links to the strict time cyber security coverage and opinion columns also in the show notes. This episode was edited by Amiru Karim. Thank you for listening. Send your feedback to
[email protected]. Find us on Apple podcasts, Spotify or within our StraightStimes app. Thanks for listening.