* SIX CYBER DEFENCE
ESSENTIALS
i
WHY
CYBER
DEFENCE?
“\f you know the enemy and know yourself, you need not fear the result
of a hundred battles” — Sun Tzu.
Behind every cyber threat is a person or persons, whether they are casual hackers or
more sophisticated groups. As such, a purely compliance approach to cybersecurity
will not be effective, as perpetrators keep up-to-date with the latest cybersecurity
policies made available on the Internet to constantly find new ways to bypass security
protections to gain entry into networks.
Hence, a cyber defence strategy needs to be nimble and comprehensive, which would
begin with an assessment of the threats against an organisation. A simple starting
point is to identify an organisation’s key cyber assets, and the potential threats and
risks to those assets. Thereafter, an organisation decides on the appropriate tools and
controls to mitigate the risks to these assets.
This approach aims to create a business environment that reduces soft-spots
(vulnerabilities) in IT networks and infrastructure as much as possible. Through
continuous vigilance and authentication safeguards, organisations can quickly detect,
outwit cyber-attackers and create a safer and secure environment for businesses,
employees and customers.
WHY
THESE
6 ESSENTIALS?
“The whole is greater than the sum of its parts” — Aristotle.
The Cyber Security Agency of Singapore (CSA) advocates establishing cyber defence
through an “integrated defence-in-depth” — which entails setting up multiple layers of
defence in a well-integrated manner.
This achieves synergy and creates a multiplier-effect on organisations’
cybersecurity effectiveness.