Back
About RSIS
Introduction
Building the Foundations
Welcome Message
Board of Governors
Staff Profiles
Executive Deputy Chairman’s Office
Dean’s Office
Management
Distinguished Fellows
Faculty and Research
Associate Research Fellows, Senior Analysts and Research Analysts
Visiting Fellows
Adjunct Fellows
Administrative Staff
Honours and Awards for RSIS Staff and Students
RSIS Endowment Fund
Endowed Professorships
Career Opportunities
Getting to RSIS
Research
Research Centres
Centre for Multilateralism Studies (CMS)
Centre for Non-Traditional Security Studies (NTS Centre)
Centre of Excellence for National Security
Institute of Defence and Strategic Studies (IDSS)
International Centre for Political Violence and Terrorism Research (ICPVTR)
Research Programmes
National Security Studies Programme (NSSP)
Social Cohesion Research Programme (SCRP)
Studies in Inter-Religious Relations in Plural Societies (SRP) Programme
Other Research
Future Issues and Technology Cluster
Research@RSIS
Science and Technology Studies Programme (STSP) (2017-2020)
Graduate Education
Graduate Programmes Office
Exchange Partners and Programmes
How to Apply
Financial Assistance
Meet the Admissions Team: Information Sessions and other events
RSIS Alumni
Outreach
Global Networks
About Global Networks
RSIS Alumni
Executive Education
About Executive Education
SRP Executive Programme
Terrorism Analyst Training Course (TATC)
International Programmes
About International Programmes
Asia-Pacific Programme for Senior Military Officers (APPSMO)
Asia-Pacific Programme for Senior National Security Officers (APPSNO)
International Conference on Cohesive Societies (ICCS)
International Strategy Forum-Asia (ISF-Asia)
Publications
RSIS Publications
Annual Reviews
Books
Bulletins and Newsletters
RSIS Commentary Series
Counter Terrorist Trends and Analyses
Commemorative / Event Reports
Future Issues
IDSS Papers
Interreligious Relations
Monographs
NTS Insight
Policy Reports
Working Papers
External Publications
Authored Books
Journal Articles
Edited Books
Chapters in Edited Books
Policy Reports
Working Papers
Op-Eds
Glossary of Abbreviations
Policy-relevant Articles Given RSIS Award
RSIS Publications for the Year
External Publications for the Year
Media
Cohesive Societies
Sustainable Security
Other Resource Pages
News Releases
Speeches
Video/Audio Channel
External Podcasts
Events
Contact Us
S. Rajaratnam School of International Studies Think Tank and Graduate School Ponder The Improbable Since 1966
Nanyang Technological University Nanyang Technological University
  • About RSIS
      IntroductionBuilding the FoundationsWelcome MessageBoard of GovernorsHonours and Awards for RSIS Staff and StudentsRSIS Endowment FundEndowed ProfessorshipsCareer OpportunitiesGetting to RSIS
      Staff ProfilesExecutive Deputy Chairman’s OfficeDean’s OfficeManagementDistinguished FellowsFaculty and ResearchAssociate Research Fellows, Senior Analysts and Research AnalystsVisiting FellowsAdjunct FellowsAdministrative Staff
  • Research
      Research CentresCentre for Multilateralism Studies (CMS)Centre for Non-Traditional Security Studies (NTS Centre)Centre of Excellence for National SecurityInstitute of Defence and Strategic Studies (IDSS)International Centre for Political Violence and Terrorism Research (ICPVTR)
      Research ProgrammesNational Security Studies Programme (NSSP)Social Cohesion Research Programme (SCRP)Studies in Inter-Religious Relations in Plural Societies (SRP) Programme
      Other ResearchFuture Issues and Technology ClusterResearch@RSISScience and Technology Studies Programme (STSP) (2017-2020)
  • Graduate Education
      Graduate Programmes OfficeExchange Partners and ProgrammesHow to ApplyFinancial AssistanceMeet the Admissions Team: Information Sessions and other eventsRSIS Alumni
  • Outreach
      Global NetworksAbout Global NetworksRSIS Alumni
      Executive EducationAbout Executive EducationSRP Executive ProgrammeTerrorism Analyst Training Course (TATC)
      International ProgrammesAbout International ProgrammesAsia-Pacific Programme for Senior Military Officers (APPSMO)Asia-Pacific Programme for Senior National Security Officers (APPSNO)International Conference on Cohesive Societies (ICCS)International Strategy Forum-Asia (ISF-Asia)
  • Publications
      RSIS PublicationsAnnual ReviewsBooksBulletins and NewslettersRSIS Commentary SeriesCounter Terrorist Trends and AnalysesCommemorative / Event ReportsFuture IssuesIDSS PapersInterreligious RelationsMonographsNTS InsightPolicy ReportsWorking Papers
      External PublicationsAuthored BooksJournal ArticlesEdited BooksChapters in Edited BooksPolicy ReportsWorking PapersOp-Eds
      Glossary of AbbreviationsPolicy-relevant Articles Given RSIS AwardRSIS Publications for the YearExternal Publications for the Year
  • Media
      Cohesive SocietiesSustainable SecurityOther Resource PagesNews ReleasesSpeechesVideo/Audio ChannelExternal Podcasts
  • Events
  • Contact Us
    • Connect with Us

      rsis.ntu
      rsis_ntu
      rsisntu
      rsisvideocast
      school/rsis-ntu
      rsis.sg
      rsissg
      RSIS
      RSS
      Subscribe to RSIS Publications
      Subscribe to RSIS Events

      Getting to RSIS

      Nanyang Technological University
      Block S4, Level B3,
      50 Nanyang Avenue,
      Singapore 639798

      Click here for direction to RSIS

      Get in Touch

    Connect
    Search
    • RSIS
    • Publication
    • RSIS Publications
    • How ASEAN’s Cybersecurity Push Could Protect People and Economies
    • Annual Reviews
    • Books
    • Bulletins and Newsletters
    • RSIS Commentary Series
    • Counter Terrorist Trends and Analyses
    • Commemorative / Event Reports
    • Future Issues
    • IDSS Papers
    • Interreligious Relations
    • Monographs
    • NTS Insight
    • Policy Reports
    • Working Papers

    CO24189 | How ASEAN’s Cybersecurity Push Could Protect People and Economies
    Muhammad Faizal Bin Abdul Rahman

    06 December 2024

    download pdf

    SYNOPSIS

    As ransomware attacks and cyber scams surge across Southeast Asia, ASEAN is stepping up to create a more secure regional cyberspace.

    Source: Pixabay
    Source: Pixabay

    COMMENTARY

    With cyber criminals targeting the region’s critical infrastructure, including data centres, and young and old users at risk of falling victim to digital scams, ASEAN’s efforts are not only about digital security — they’re also aimed at protecting economic and social stability.

    In October 2024, ASEAN members launched two major initiatives. First, the ASEAN Regional Computer Emergency Response Team (CERT) opened its Singapore headquarters to boost collaboration on cybersecurity incident response, with Malaysia leading as the first overall coordinator. This response team focuses on critical areas including information-sharing and strengthening public-private partnerships to bolster defences across the region.

    In the same month, the Cyber Security Agency of Singapore and Malaysia’s National Cyber Security Agency introduced the Norms Implementation Checklist. This list of action points aims to guide ASEAN nations in promoting responsible behaviour in cyberspace, based on United Nations cybersecurity norms.

    Responding to a Surge in Cyberattacks

    This year, the region has experienced a spate of major ransomware attacks. For example, a major incident occurred in June, when the Brain Cipher ransomware group disrupted the data centre operations of more than 200 government agencies in Indonesia.

    Critical information infrastructure supports government and other essential services, so any disruption can cause severe socio-economic impacts that undermine public trust in government.

    The threat of disruption from cybersecurity incidents extends to the private sector where, for example, in Singapore, three out of five companies polled had paid ransom during cyberattacks in 2023.

    In addition, cyber scams are a major crime concern: they often impact vulnerable groups and are now so common they have become a regional security threat. The rapid pace of digitalisation in Southeast Asia, coupled with low digital literacy and the ease of conducting online financial transactions, has facilitated a sharp increase in cyber scams such as phishing and social media scams.

    Tackling cyber scams at the source is challenging. Transnational organised crime groups thrive in Southeast Asian countries with limited cybersecurity and insufficient law enforcement capabilities. They often collude with local power structures: for example, they operate in conflict areas near the border of Myanmar, where they collude with militia groups.

    Given these increasing threats, the launch of the ASEAN Regional CERT is a promising effort to enhance cooperation among Southeast Asian countries. The eight functions of the response team — which include information-sharing, training and exercises, as well as developing partnerships with academic institutions and industry — aim to strengthen regional coordination on cyber incident response.

    Incident response is a critical part of the region’s attempts to mitigate the impact of malicious cyber activities such as ransomware and the epidemic of cyber scams.

    Strengthening ASEAN’s Strategic Position in Cyberspace

    In 2018, ASEAN agreed to subscribe in principle to the 11 UN norms of responsible state behaviour in cyberspace. While their full potential has not yet been realised, these 11 norms, set out in the UN’s Norms Implementation Checklist, could play a crucial role in helping ASEAN member states progress from “in principle” to “in practice” in the cybersecurity space. These norms aim to guide countries’ national cyber policies to align with the rules-based international order set out by the UN.

    Source: Australian Strategic Policy Institute
    Source: Australian Strategic Policy Institute

    Adherence to these cyber norms (such as fostering inter-state cooperation on security, preventing misuse of information and communications technologies, and cooperating to stop crime and terrorism) could, ideally, complement the work of the ASEAN Regional CERT in responding to malicious cyber activities and fighting cyber scams.

    Regional implementation of these norms could contribute to an environment of trust and confidence among ASEAN countries, to create stability in Southeast Asia’s cyberspace.

    There are strategic reasons for creating regional cyberspace stability. As the UN Secretary-General Antonio Guterres has warned, cyberspace is increasingly being exploited as a weapon in conflicts — by criminals, non-state actors, and even governments. This trend is inimical to ASEAN’s regional ambitions, strengthening the argument for nations in the region to proactively adopt a cyber rules-based order.

    What’s more, ASEAN aims to be a zone of peace, freedom and neutrality. This goal emphasises keeping the region free from interference by external powers that could create insecurity. As ASEAN established this goal in 1971 during the analogue era and Cold War, it is only appropriate that the organisation develop new initiatives to adapt to the digital era and Cold War 2.0.

    ASEAN should also promote the Norms Implementation Checklist as a guide for other countries that are its dialogue partners but are embroiled in geopolitical and cyber rivalry (such as China and the United States).

    Observers warn that the inability of the regional group to address the Myanmar civil war and rising tensions in the South China Sea, both of which involve cyber activities, is eroding its relevance. This crisis consequently shapes how some ASEAN members and external powers view ASEAN centrality. It is also among the reasons why non-ASEAN security arrangements — such as the Quad, Indo-Pacific Four and Japan-Philippines-US Trilateral Summit — are establishing cooperative efforts, including on cybersecurity, in the Indo-Pacific.

    Taking the lead on cybersecurity, both through the Norms Implementation Checklist and the ASEAN Regional CERT, is therefore crucial to the security of people and economies in Southeast Asia.

    It could also prevent ASEAN’s centrality in regional security matters from eroding further. But this is contingent on ASEAN nations providing sufficient resources, policy thinking and political will to make these two initiatives deliver results.

    About the Author

    Muhammad Faizal Abdul Rahman is a Research Fellow (Regional Security Architecture Programme) with the Institute of Defence and Strategic Studies (IDSS) at S. Rajaratnam School of International Studies (RSIS), Nanyang Technological University (NTU), Singapore. The commentary was originally published in Creative Commons by 360info™.

    Categories: RSIS Commentary Series / Country and Region Studies / International Politics and Security / Non-Traditional Security / Global / East Asia and Asia Pacific / South Asia / Southeast Asia and ASEAN
    comments powered by Disqus

    SYNOPSIS

    As ransomware attacks and cyber scams surge across Southeast Asia, ASEAN is stepping up to create a more secure regional cyberspace.

    Source: Pixabay
    Source: Pixabay

    COMMENTARY

    With cyber criminals targeting the region’s critical infrastructure, including data centres, and young and old users at risk of falling victim to digital scams, ASEAN’s efforts are not only about digital security — they’re also aimed at protecting economic and social stability.

    In October 2024, ASEAN members launched two major initiatives. First, the ASEAN Regional Computer Emergency Response Team (CERT) opened its Singapore headquarters to boost collaboration on cybersecurity incident response, with Malaysia leading as the first overall coordinator. This response team focuses on critical areas including information-sharing and strengthening public-private partnerships to bolster defences across the region.

    In the same month, the Cyber Security Agency of Singapore and Malaysia’s National Cyber Security Agency introduced the Norms Implementation Checklist. This list of action points aims to guide ASEAN nations in promoting responsible behaviour in cyberspace, based on United Nations cybersecurity norms.

    Responding to a Surge in Cyberattacks

    This year, the region has experienced a spate of major ransomware attacks. For example, a major incident occurred in June, when the Brain Cipher ransomware group disrupted the data centre operations of more than 200 government agencies in Indonesia.

    Critical information infrastructure supports government and other essential services, so any disruption can cause severe socio-economic impacts that undermine public trust in government.

    The threat of disruption from cybersecurity incidents extends to the private sector where, for example, in Singapore, three out of five companies polled had paid ransom during cyberattacks in 2023.

    In addition, cyber scams are a major crime concern: they often impact vulnerable groups and are now so common they have become a regional security threat. The rapid pace of digitalisation in Southeast Asia, coupled with low digital literacy and the ease of conducting online financial transactions, has facilitated a sharp increase in cyber scams such as phishing and social media scams.

    Tackling cyber scams at the source is challenging. Transnational organised crime groups thrive in Southeast Asian countries with limited cybersecurity and insufficient law enforcement capabilities. They often collude with local power structures: for example, they operate in conflict areas near the border of Myanmar, where they collude with militia groups.

    Given these increasing threats, the launch of the ASEAN Regional CERT is a promising effort to enhance cooperation among Southeast Asian countries. The eight functions of the response team — which include information-sharing, training and exercises, as well as developing partnerships with academic institutions and industry — aim to strengthen regional coordination on cyber incident response.

    Incident response is a critical part of the region’s attempts to mitigate the impact of malicious cyber activities such as ransomware and the epidemic of cyber scams.

    Strengthening ASEAN’s Strategic Position in Cyberspace

    In 2018, ASEAN agreed to subscribe in principle to the 11 UN norms of responsible state behaviour in cyberspace. While their full potential has not yet been realised, these 11 norms, set out in the UN’s Norms Implementation Checklist, could play a crucial role in helping ASEAN member states progress from “in principle” to “in practice” in the cybersecurity space. These norms aim to guide countries’ national cyber policies to align with the rules-based international order set out by the UN.

    Source: Australian Strategic Policy Institute
    Source: Australian Strategic Policy Institute

    Adherence to these cyber norms (such as fostering inter-state cooperation on security, preventing misuse of information and communications technologies, and cooperating to stop crime and terrorism) could, ideally, complement the work of the ASEAN Regional CERT in responding to malicious cyber activities and fighting cyber scams.

    Regional implementation of these norms could contribute to an environment of trust and confidence among ASEAN countries, to create stability in Southeast Asia’s cyberspace.

    There are strategic reasons for creating regional cyberspace stability. As the UN Secretary-General Antonio Guterres has warned, cyberspace is increasingly being exploited as a weapon in conflicts — by criminals, non-state actors, and even governments. This trend is inimical to ASEAN’s regional ambitions, strengthening the argument for nations in the region to proactively adopt a cyber rules-based order.

    What’s more, ASEAN aims to be a zone of peace, freedom and neutrality. This goal emphasises keeping the region free from interference by external powers that could create insecurity. As ASEAN established this goal in 1971 during the analogue era and Cold War, it is only appropriate that the organisation develop new initiatives to adapt to the digital era and Cold War 2.0.

    ASEAN should also promote the Norms Implementation Checklist as a guide for other countries that are its dialogue partners but are embroiled in geopolitical and cyber rivalry (such as China and the United States).

    Observers warn that the inability of the regional group to address the Myanmar civil war and rising tensions in the South China Sea, both of which involve cyber activities, is eroding its relevance. This crisis consequently shapes how some ASEAN members and external powers view ASEAN centrality. It is also among the reasons why non-ASEAN security arrangements — such as the Quad, Indo-Pacific Four and Japan-Philippines-US Trilateral Summit — are establishing cooperative efforts, including on cybersecurity, in the Indo-Pacific.

    Taking the lead on cybersecurity, both through the Norms Implementation Checklist and the ASEAN Regional CERT, is therefore crucial to the security of people and economies in Southeast Asia.

    It could also prevent ASEAN’s centrality in regional security matters from eroding further. But this is contingent on ASEAN nations providing sufficient resources, policy thinking and political will to make these two initiatives deliver results.

    About the Author

    Muhammad Faizal Abdul Rahman is a Research Fellow (Regional Security Architecture Programme) with the Institute of Defence and Strategic Studies (IDSS) at S. Rajaratnam School of International Studies (RSIS), Nanyang Technological University (NTU), Singapore. The commentary was originally published in Creative Commons by 360info™.

    Categories: RSIS Commentary Series / Country and Region Studies / International Politics and Security / Non-Traditional Security

    Popular Links

    About RSISResearch ProgrammesGraduate EducationPublicationsEventsAdmissionsCareersVideo/Audio ChannelRSIS Intranet

    Connect with Us

    rsis.ntu
    rsis_ntu
    rsisntu
    rsisvideocast
    school/rsis-ntu
    rsis.sg
    rsissg
    RSIS
    RSS
    Subscribe to RSIS Publications
    Subscribe to RSIS Events

    Getting to RSIS

    Nanyang Technological University
    Block S4, Level B3,
    50 Nanyang Avenue,
    Singapore 639798

    Click here for direction to RSIS

    Get in Touch

      Copyright © S. Rajaratnam School of International Studies. All rights reserved.
      Privacy Statement / Terms of Use
      Help us improve

        Rate your experience with this website
        123456
        Not satisfiedVery satisfied
        What did you like?
        0/255 characters
        What can be improved?
        0/255 characters
        Your email
        Please enter a valid email.
        Thank you for your feedback.
        This site uses cookies to offer you a better browsing experience. By continuing, you are agreeing to the use of cookies on your device as described in our privacy policy. Learn more
        OK
        Latest Book
        more info