Retail News CRM

Tag: Security

  • Apple’s Key Supplier Tata Boosts Security Measures Amid Dark Web Data Leak Investigation

    Apple’s Key Supplier Tata Boosts Security Measures Amid Dark Web Data Leak Investigation

    Tata Electronics, a primary supplier for tech giant Apple in India, has increased its internal security measures following a potential leak of confidential client files on the dark web, according to a source from Tata and two industry representatives.

    In response to the incident, Tata has engaged an international consultant to perform a forensic audit. The company has also reported the incident to the Indian government and its customer base. The source from Tata chose to remain anonymous due to the sensitive nature of the situation.

    The cybercrime group known as World Leaks claimed responsibility for uploading over 200,000 files onto the dark web. These files allegedly include design documents for components used by both Apple and Tesla, another of Tata’s clients. The authenticity of the data remains unverified.

    Tata acknowledged the occurrence of a “cybersecurity incident” but assured that its operations were not affected, without providing further details.

    In addition to Apple and Tesla, the leaked data is believed to include at least 16 files and folders from Taiwan Semiconductor Manufacturing Co (TSMC) and 23 from Qualcomm. Both companies supply parts for iPhones.

    Increased Security Measures

    Following the breach, Tata Electronics strengthened security protocols across all its facilities and offices. Remote access to sensitive internal tools, such as those used for placing purchase orders, was limited to a select group of employees. Prior to the incident, these tools were more accessible. The updated protocols apply across Tata Electronics and are not limited to specific factories.

    The investigation into the breach continues, with Apple’s security team reportedly collaborating closely with Tata. The security enhancements include stricter regulations for accessing Tata’s official network from outside the company’s premises.

    Implications for Tata and its Clients

    Tata Electronics, led by former Intel and Applied Materials executive Randhir Thakur, is a critical part of Apple’s strategy to expand iPhone production outside China. However, the breach poses a significant setback to Apple’s supply chain. Tata is also facing scrutiny over alleged farmland contamination near one of its iPhone parts plants in India.

    World Leaks claimed to have published more than 204,341 files containing Tata Electronics data, amounting to over 630.4 gigabytes. The exposed documents include purported “product reliability test” details of a TSMC component and mechanical specifications for a power management integrated circuit from Qualcomm.

    Despite the challenges, India is expected to manufacture 26% of the world’s iPhones by 2026, a significant increase from the 6% it produced four years ago, as reported by research firm Counterpoint.

    Questions & Answers

    How has Tata Electronics responded to the data breach?
    Tata Electronics has increased internal security measures, limited remote access to sensitive systems, and engaged an international consultant for a forensic audit.

    What does the leaked data purportedly contain?
    The data allegedly contains design documents from Apple and Tesla, and files from Taiwan Semiconductor Manufacturing Co and Qualcomm.

    What are the potential impacts of the breach on Tata and its clients?
    The breach could interrupt Apple’s supply chain and increase scrutiny on Tata, which is already facing allegations of farmland contamination in India.

  • Taiwan Boosts Communications Security with Five New Undersea Cables: A Step Towards Network Resilience

    Taiwan Boosts Communications Security with Five New Undersea Cables: A Step Towards Network Resilience

    Taiwan is set to elevate its national communications infrastructure’s robustness by building five new undersea communications cables. This ambitious step is part of a comprehensive strategy aimed at reinforcing the resilience and reliability of the nation’s communications systems.

    Strengthening Communications Infrastructure

    The Minister of Digital Affairs, Lin Yi-jing, revealed the plans at the sixth meeting of the Presidential Office’s Whole-of-Society Defense Resilience Committee. Two of the proposed cables will be international, while the remaining three will facilitate domestic communication.

    The planned cables will incorporate an armor-like protective layer designed to minimize potential damage arising from natural disasters or external interferences. Lin emphasized the necessity of maintaining smooth connectivity, particularly during emergencies such as typhoons and earthquakes, when uninterrupted communication is of paramount importance. However, the minister has not yet revealed a construction timeline for these new undersea cables.

    Addressing Challenges

    In recent years, Taiwan has experienced several instances of damages to its undersea communications cables, with suspicion falling on interference from foreign civilian vessels. To counter this, the legislature passed amendments earlier this month, introducing stronger penalties for acts of cable sabotage. These penalties include prison sentences and the seizure of vessels and equipment involved in such acts.

    Three-Dimensional Defensive Communications Network

    The proposed undersea cables expansion aligns with the ministry’s vision of a “three-dimensional defensive communications network,” an initiative designed to strengthen connectivity via land, sea, and air.

    In addition to the undersea cables, the nation plans to incorporate low-Earth-orbit (LEO) satellite capacity through Amazon’s satellite constellation and initiate a high-orbit geosynchronous satellite built by US manufacturer Astranis. These satellite systems are set to offer backup connectivity in case of disruptions to terrestrial or subsea networks.

    On land, the ministry plans to build disaster-resilient base stations, increase its fleet of vehicles equipped with satellite communication capabilities, and procure numerous mobile diesel generators. Lin identified that during recent typhoons, power outages at base stations, rather than network failures, were the primary cause of most mobile service disruptions. Mobile generators, he added, have served as an effective solution to this issue.

    Moving Forward

    Through strategic investments in subsea cables, satellite systems, and terrestrial infrastructure, Taiwan aims to significantly bolster its communications network’s resilience against both natural and man-made disruptions.

    Questions & Answers

    What is the purpose of the proposed undersea cables?
    The proposed undersea cables aim to strengthen the resilience of Taiwan’s national communications infrastructure, particularly during emergencies such as typhoons and earthquakes.

    What will the new cables feature to enhance their durability?
    The new cables will incorporate an armor-like protective layer designed to minimize potential damage from natural disasters or external interference.

    What other measures are included in Taiwan’s strategy to strengthen its communications infrastructure?
    In addition to the undersea cables, Taiwan plans to incorporate low-Earth-orbit (LEO) satellite capacity, initiate a high-orbit geosynchronous satellite, build disaster-resilient base stations, increase its fleet of vehicles equipped with satellite communications, and procure numerous mobile diesel generators.

  • Asia’s Telecom Titans Rise to Meet Cybersecurity Challenges: A Dive into 5G Security and Fraud Prevention

    Asia’s Telecom Titans Rise to Meet Cybersecurity Challenges: A Dive into 5G Security and Fraud Prevention

    As the telecommunications sector in Asia rapidly moves towards 5G technology, cloud-native architectures, and digital services, operators throughout the region contend with intensifying cyber threats. These threats, which range from data breaches to scams and fraud within mobile networks, impact not only businesses, but also a considerable number of consumers. Consequently, governments and mobile operators are implementing stricter regulations and enhancing enforcement strategies. In addition, they are investing in more sophisticated security systems to safeguard national networks.

    Increasing Cybersecurity Risks and Consumer Fraud in the Region

    The Asia Pacific region has experienced some of the highest levels of mobile fraud, digital scams, and identity-based attacks globally. A 2025 report commissioned by GSMA revealed that the percentage of consumers who fell victim to scams increased from 31% to 43% over the past year. Additionally, 81% of those surveyed said they are willing to switch financial providers to achieve better security. Consumers prefer solutions that prioritize verification, offer a confirmation-of-payee feature, provide safer payment tools, and allow for simple “official call-back only” habits for enhanced protection.

    Cybersecurity trust in Southeast Asia is dwindling as the number of cyber scams continue to rise. A significant number of mobile users have reported encounters with fraudulent calls, SMS, and online impersonation attempts. According to the GSMA’s Intelligence 2024 Report on Telco Security Landscape and Strategies – Asia Pacific, there is an urgent need for innovative telecom security solutions.

    Telecom Operators Enhancing Defenses and Security Practices

    Asian governments have started to enact laws and establish regulatory frameworks aimed at protecting critical infrastructure and personal data. These measures obligate telecom operators to bolster their networks’ security.

    In China, the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law (PIPL) regulate telecom operators. These laws demand strict protection of critical information infrastructure, data handling, security reviews, and compliance obligations. As a result, operators are compelled to integrate security measures from the inception of their projects.

    In South Korea, the Personal Information Protection Act (PIPA) regulates telecom operators. The legislation mandates the implementation of measures to securely handle data, maintain accountability, and safeguard user privacy. Though primarily regulating data protection rather than network infrastructure security, PIPA forms a crucial regulatory framework for safeguarding personal data as 5G networks and virtualization continue to grow across the country.

    In Japan, the Cybersecurity Basic Act and related national cybersecurity strategies guide the broad infrastructure protection framework. Telecom operators, including those exploring advanced network innovations such as virtualized RAN or 6G-ready systems, are expected to comply with government-endorsed security standards, threat-sharing mechanisms, and incident-response protocols.

    In the Philippines, national cyber defenses are progressively strengthening. The Cybercrime Prevention Act of 2012 (RA 10175) and the National Cybersecurity Plan 2023-2028 establish a legal framework and outline strategies for enhancing resilience across critical infrastructure.

    Several major telecommunications firms are investing in AI-based network analytics to bolster security and operational efficiency. For instance, Globe Telecom deploys AI and machine learning for anomaly detection across its infrastructure. Similarly, PLDT is mitigating phishing, DDoS attacks, and other cyber threats through its cybersecurity operations center and collaboration with government agencies.

    India, driven by its enormous telecom market, has introduced some of the region’s most comprehensive cybersecurity rules. CERT-In mandates prompt incident reporting, strict log retention for 180 days, and real-time collaboration with national cyber emergency response teams. The Department of Telecommunications now requires 5G network elements to be procured from trusted vendors under the Trusted Telecom Portal policy.

    Singapore has set up a robust cybersecurity framework for its telecom sector. Under the Cybersecurity Act, telecom and infocomm systems can be designated as Critical Information Infrastructure (CII), which mandates operators to implement a cybersecurity code of practice, conduct audits, and quickly report incidents.

    Building Collective Defense: Collaboration, Standards, and Shared Cyber Intelligence

    Given the scale and interconnectedness of modern telecom networks, many operators acknowledge the limitations of tackling cyber threats individually. As a result, collaborative initiatives, public-private partnerships, and industry-wide frameworks are emerging as fundamental strategies for defense.

    The theme of the 19th edition of the Telecom Review Leaders’ Summit was ‘Tech Intelligence Beyond Mobility.’ The event held in Dubai, UAE, facilitated discussions among leading experts on the evolving challenges of protecting information in an increasingly connected world. The summit served as a collaborative platform for telecom-based cybersecurity collaboration, standardization, and knowledge sharing.

    The Need for Collective Defense, Transparency, and Regulatory Backing in Asia

    The security challenge faced by Asia’s telecom sector is not limited to individual operators or markets. Scams, fraud, cross-border intrusion threats, and the growing complexity of virtualized networks have necessitated a regional and systemic response.

    The continual rise in consumer fraud, data protection failures, and regulatory scrutiny necessitates treating cybersecurity in the same vein as infrastructure policy, consumer protection, and national security. To cope with these risks, operators need to prioritize transparency, share threat intelligence, and adopt common security standards. Regulators should support these efforts with clear rules, consistent enforcement, and incentives that reward genuine compliance.

    By embracing an approach that combines strong governance, robust technical controls, and cross-border collaboration, Asia’s telecom sector can build networks that not only offer connectivity but also provide meaningful protection for users in an increasingly hostile digital environment.

    Questions & Answers

    What is the current state of cybersecurity in Asia’s telecom industry?
    The telecom industry in Asia is grappling with increasing cybersecurity risks, including data breaches, scams, and fraud within mobile networks. Governments and mobile operators are responding by implementing stricter regulations, enhancing enforcement strategies, and investing in advanced security systems.

    What measures are being taken to improve cybersecurity in Asia’s telecom industry?
    Governments across Asia are enacting laws and regulatory frameworks to protect critical infrastructure and personal data. Telecom operators are obligated to bolster their network security and are investing in AI-based network analytics to enhance security and operational efficiency.

    What strategies are recommended for managing cybersecurity risks in the telecom industry?
    Telecom operators need to prioritize transparency, share threat intelligence, and adopt common security standards. Regulators should support these efforts with clear rules, consistent enforcement, and incentives that reward genuine compliance. Collaborative initiatives, public-private partnerships, and industry-wide frameworks are also recommended.

  • Indonesia Asserts Rice Self-Sufficiency, Ceases Imports in Boost for National Food Security

    Indonesia Asserts Rice Self-Sufficiency, Ceases Imports in Boost for National Food Security

    Indonesia has announced that it will not be importing rice for any purpose in the coming year, due to ample domestic production capabilities. This announcement was made at a recently held ministerial summit in Jakarta. High-level officials from various government bodies including the Coordinating Ministry for Food Security, the Ministry of Trade, and the Central Statistics Agency were in attendance.

    Domestic Demand to be Met by Local Production

    Tatang Yuliono, who is the Deputy for Trade and Distribution Coordination at the Coordinating Ministry for Food Security, has affirmed that local production will be capable of satisfying all domestic demand. This encompasses both household consumption and industrial processing requirements.

    In line with this, the government has dismissed a proposal made by the Ministry of Industry to import nearly 381,000 tonnes of rice in 2026 for industrial purposes. Authorities believe the domestic supply will suffice. This policy of no imports will be enforced across the nation, inclusive of free trade zones like Sabang in Aceh.

    Yuliono further stated that related ministries will be continually reassessing food import policies in the future through commodity balance meetings.

    Strong Agricultural Performance in 2025

    The Indonesian government’s confidence in their domestic production capabilities stems from their successful agricultural performance in 2025. This was the year in which the country ceased imports of both rice and corn. By mid-2025, the nation’s rice reserves had reached an all-time high of about 4 million tonnes. This significantly stabilized the market and provided support to disaster-stricken regions.

    Official data reveals that rice production in 2025 is anticipated to hit 34.77 million tonnes, marking an increase of 13.54% on a year-on-year basis. This surge is attributed to favorable weather conditions and supportive policies for farmers implemented under President Prabowo Subianto’s administration. Corn production is also set to reach approximately 4 million tonnes by the end of the year, ensuring an adequate supply for both domestic consumption and the poultry sector.

    Questions & Answers

    Why has Indonesia decided not to import rice next year?
    The Indonesian government believes it has sufficient domestic production capabilities to satisfy all local demand for rice, eliminating the need for imports.

    How has the government responded to the Ministry of Industry’s proposal to import rice for industrial use?
    The government has dismissed this proposal, stating that the domestic supply of rice will be adequate for industrial use.

    What factors have contributed to the projected increase in rice production in 2025?
    The expected rise in rice production is attributed to favorable weather conditions and farmer support policies under President Prabowo Subianto’s administration.

  • App Lock Security Coming to Android 17: A Much-Anticipated Upgrade for User Privacy

    App Lock Security Coming to Android 17: A Much-Anticipated Upgrade for User Privacy

    In a rapidly digitalizing world, smartphones have become the vaults of our sensitive data, often stored within various applications. These applications, at times, require an additional layer of security for optimal safeguarding. Android, despite its Private Space feature, lacks a user-friendly method to secure these apps. However, this could potentially change with the forthcoming major update of Google’s mobile operating system (OS).

    App Lock Feature in Android 17

    In a bid to enhance the security on its platform, Google might finally incorporate a native app lock feature in its Android 17 update. This function is expected to operate at the system level of the OS. Recent investigations into the code of an Android Canary release revealed indications of this feature.

    The code introduced a fresh App Lock Application Programming Interface (API), compatible with any default launcher. This implies that the function will not be exclusive to Pixel phones but will be available across all Android devices.

    Bridging the Gap

    Android users may already be using app locks and might be puzzled by this update. However, it’s essential to note that these locks are not native to the OS. Instead, they are solutions developed independently by Original Equipment Manufacturers (OEMs), such as OnePlus.

    Google’s indigenous solution, known as Private Space, differs significantly from elementary app locking. Apps within Private Space are entirely segregated from the rest of the OS, function under a separate user profile, and are challenging to access.

    On the contrary, an app lock feature merely secures apps, necessitating face unlock, fingerprint authentication, or a passcode for access. Apart from this, the apps stay connected to the rest of the operating system and can be placed on the home screen. Google already provides a similar feature with its Google Photos app.

    Tech giant Apple was one of the first major brands to introduce an app lock feature with its iOS 18. In contrast, Samsung, Google, and Motorola don’t have this feature. Samsung supports a Secure Folder, and Motorola has its own Moto Secure menu containing folders, both of which function similarly to Google’s Private Space.

    A Much-needed Feature

    The introduction of an app lock feature is a move many find surprising it wasn’t implemented earlier in more devices. It strikes the ideal balance between security and convenience, potentially serving a broader user base than any isolated space.

    Questions & Answers

    What is the new feature expected in Android 17?
    There are indications that Android 17 may include a native app lock feature.

    How does the app lock feature differ from Google’s Private Space?
    Unlike the Private Space, which completely isolates certain apps from the rest of the OS, an app lock merely requires face unlock, fingerprint authentication, or a passcode for access, while the apps remain connected to the rest of the operating system.

    Which other major brand has an app lock feature?
    Apple was one of the first major brands that introduced an app lock feature with iOS 18.

  • OCBC Enhances Customer Security with Innovative In-App Calling Feature to Combat Rising Fraud

    OCBC Enhances Customer Security with Innovative In-App Calling Feature to Combat Rising Fraud

    Singapore’s OCBC bank is set to introduce a secure in-app calling feature across its retail and business banking platforms. This move comes as a response to a significant increase in scams involving impersonation and a decreasing faith in traditional phone-based verification systems.

    Introducing In-App Calls

    OCBC’s new in-app calling feature will be incorporated into its digital banking apps. This feature offers customers a safer, more convenient way of contacting the bank’s customer service center, particularly for those travelling overseas. Users will be able to avoid international dialing charges thanks to this feature.

    The feature will be made progressively available to retail customers starting November 2025, following its initial rollout to corporate users via the OCBC Business app in June 2025. This development is highly relevant considering the bank handles over 8,000 calls from overseas customers each month.

    Moving Away from SMS OTPs

    As the entire industry begins to shift away from SMS One-Time Passwords (OTP), OCBC recognizes the increasing threats posed by scammers who exploit phishing techniques and social engineering attacks. The availability of personal data online has also compromised the effectiveness of traditional security questions.

    To provide a more secure communication channel, OCBC will route calls directly through its authenticated app environment. This environment is secured using biometrics or access credentials and a digital or hard token. Security questions will only be used for high-risk transactions.

    Expansion to Outbound In-App Calls

    OCBC plans to extend the in-app calling feature to outbound calls by the first half of 2026. This will allow contact center and anti-fraud teams to connect with both retail and business customers via the secure app environment.

    Impersonation scams have become a significant concern in Singapore, especially those involving government officials. The use of in-app calls can help users distinguish between legitimate outreach and fraudulent calls as they are significantly more challenging for scammers to mimic.

    Enhancing OCBC’s Digital Security Framework

    The introduction of the in-app calling feature is part of OCBC’s wider strategy to bolster trust and safety in digital banking. This strategy spans across retail, SME, and corporate segments.

    As scams become more sophisticated and tactics more inventive, banks in Singapore are speeding up their transition away from vulnerable verification methods. They are working towards strengthening secure, app-based ecosystems to ensure customer safety and trust.

    Questions & Answers

    What is the purpose of OCBC’s new in-app calling feature?
    The new in-app calling feature is designed to provide customers with a safer and more convenient way to contact the bank’s customer service center, particularly for those travelling overseas.

    When will the in-app calling feature be available to retail customers?
    The in-app calling feature will be made progressively available to retail customers starting from November 2025.

    How does the in-app calling feature enhance security?
    The in-app calling feature enhances security by routing calls directly through an authenticated app environment, secured using biometrics or access credentials and a digital or hard token. Security questions will only be used for high-risk transactions.

  • Exposed: WhatsApp Flaw Unveils Billions of User Numbers, Is Your Privacy At Risk?

    Exposed: WhatsApp Flaw Unveils Billions of User Numbers, Is Your Privacy At Risk?

    A team of Austrian researchers has reportedly found a way to extract the phone numbers of 3.5 billion WhatsApp users, leaving many to wonder if their own information has been compromised.

    Method of Extraction

    Any user can determine if a number is registered on WhatsApp by performing a simple search within the platform. If the number in question is associated with a WhatsApp account, the searcher will be privy to the account’s profile picture and user name. Scientists from the University of Vienna in Austria employed this very strategy to gather the phone numbers of 3.5 billion WhatsApp users.

    In their search for vulnerabilities within WhatsApp’s end-to-end encryption system, the Austrian team discovered that the application lacked an important security measure known as rate-limiting protection. Such a feature would thwart the abuse of WhatsApp’s number-checking function. By exploiting this absence of protection, the team was able to obtain 30 million WhatsApp numbers registered in the U.S. within just 30 minutes. By the conclusion of their research, they had amassed the WhatsApp numbers of 3.5 billion users worldwide.

    The extraction process was remarkably simple: the researchers merely altered the number sequence. In doing so, they could determine whether a number was registered on WhatsApp. Of the 3.5 billion users whose numbers were collected, approximately 57% had their privacy settings configured to display their profile picture to anyone. Given this, the researchers were able to easily collect these users’ profile pictures. They were also able to view the profile text of 29% of these users.

    A Neglected Flaw

    Interestingly, WhatsApp’s parent company, Meta, was alerted to this vulnerability in 2017 by a different team of researchers. Despite this, Meta failed to address the issue, meaning it remained straightforward to determine whether a number was registered on WhatsApp.

    Earlier this year, the Austrian researchers brought their findings to Meta’s attention, emphasizing the severity of the security risk this flaw presents to WhatsApp users. Their concern is that malicious entities could exploit this loophole to obtain photos and phone numbers of a significant number of WhatsApp users.

    Fortunately, in October of this year, Meta finally implemented a stricter rate-limiting measure on WhatsApp. This has ensured that such large-scale contact discovery is no longer feasible on the platform. The researchers have securely deleted their database containing the extracted phone numbers and associated data.

    Other messaging platforms, such as Signal, already incorporate rate-limiting protection. This means that mass-scale contact discovery, like what previously occurred on WhatsApp, is not possible on these platforms.

    Previous Security Breaches

    This is not the first instance of Meta’s apps coming under scrutiny due to security flaws. Last year, a database containing information on 530 million Facebook users was publicly leaked online. Intriguingly, bad actors exploited a vulnerability akin to the one found in WhatsApp, accessing data by utilising Facebook’s feature that allows users to search profiles by entering a phone number. This allowed them to scrape the personal data of 530 million users.

    WhatsApp may have its benefits, such as being free, supporting end-to-end encryption and accommodating group video calls. However, after learning of its security flaws and data collection practices, some users are considering alternatives. Platforms like Signal, which collects minimal data and provides advanced privacy features, are becoming increasingly popular.

    Questions & Answers

    What are the implications of the Austrian researchers’ findings?

    The research highlights a major flaw in WhatsApp’s security system. This loophole could potentially be exploited by cyber criminals to extract photos and phone numbers of a large number of WhatsApp users.

    Has this flaw been addressed?

    Meta, WhatsApp’s parent company, has taken measures to rectify this flaw. In October of this year, a stricter rate-limiting measure was applied to WhatsApp, preventing such extensive contact discovery from taking place.

    What alternatives exist for WhatsApp users concerned about security?

    Signal is one such alternative. The platform already has rate-limiting protection in place, and it collects almost no data from users. It also offers advanced privacy features, such as concealing your IP address during calls, and preventing others from taking screenshots of your conversations.

  • Balancing Speed and Security: UOB CEO Wee Ee Cheong’s Take on AI Adoption in Fintech

    Balancing Speed and Security: UOB CEO Wee Ee Cheong’s Take on AI Adoption in Fintech

    United Overseas Bank (UOB) CEO, Wee Ee Cheong, recently expressed his concerns over the potential risks that come with the swift implementation of technology. He emphasized that in the financial services sector, ensuring security and maintaining trust is crucial to prevent undesired consequences.

    Striking a Balance between Progress and Risk

    There’s no denying that the integration of artificial intelligence (AI) brings about a myriad of advantages. However, it is equally important to recognize that with these benefits comes an array of risks. These risks can take various forms, from distorted results due to faulty data interpretation, breaches of data privacy, to the rise of sophisticated fraudulent activities. Wee Ee Cheong highlighted that the pace at which these technologies are adapted should be tempered with appropriate security measures.

    According to Wee, “Speed without security is fragile. The foundation of lasting relationships is trust,” while speaking at the Singapore FinTech Festival in 2025. He underscored the importance of regulatory transparency and the need for standardization within the industry.

    AI: An Aid, Not a Substitute

    Wee also shed light on the broader societal implications of the widespread use of AI, emphasizing that technology cannot and should not replace humans.

    “AI cannot replicate the empathy in advice, the ethics in decision-making, or the leadership and judgement that builds trust over time,” said Wee. He stressed the role of AI as a tool to assist humans in improving efficiency and increasing productivity rather than replacing them.

    A “Mindset-First” Approach

    Wee proposes that the financial sector should adopt a “mindset-first approach”. This approach centers on problem-solving guided by purpose and value, as opposed to a “technology-first approach” that promotes innovation solely for its own sake.

    As an illustration of this approach, he mentioned initiatives at UOB such as a program that has assisted 1,000 SMEs in Southeast Asia in the initial stages of AI integration and efforts to improve the skills of the bank’s 32,000 employees through an innovation academy.

    By working together, Wee believes we can shape a financial industry that is resilient, adaptive, and aligned with society’s changing needs and values.

    Questions & Answers

    What are the potential risks associated with the rapid adoption of AI in the financial sector?
    Answer: Risks can range from data misinterpretation leading to inaccurate results, violation of data privacy, and the emergence of sophisticated fraud schemes.

    What is the role of AI according to UOB CEO, Wee Ee Cheong?
    Answer: Wee views AI as a tool to aid humans in increasing efficiency and productivity, not as a replacement for human empathy, ethics, leadership and judgement.

    What approach does Wee advocate for in the financial sector regarding technology adoption?
    Answer: Wee advocates for a “mindset-first approach” that focuses on problem-solving guided by purpose and value, as opposed to a technology-centric approach that promotes development purely for the sake of innovation.

  • Singtel, Ericsson And Hp Launch 5g+ Workspace: Revolutionizing Esim Management And Enterprise Security

    Singtel, Ericsson And Hp Launch 5g+ Workspace: Revolutionizing Esim Management And Enterprise Security

    In a joint venture with Ericsson and HP Inc, Singtel has launched a service featuring the Ericsson Enterprise Virtual Cellular Network. This service automates eSIM profile management, allowing zero-touch provisioning and secure access to corporate applications from nearly any location. This automation gives enterprises total control over eSIM activation and deployment, thus simplifying operations and reducing IT overhead.

    5G+ Workspace and HP’s Role

    The 5G+ Workspace is also equipped with HP’s enterprise-grade, AI-ready laptops and digital workplace tools. This combination simplifies device management for modern, geographically dispersed teams. Each device is fitted with Singtel’s 5G+ eSIM during production, ensuring secure connectivity straight out of the box. The intelligent management platform automatically activates 5G connectivity according to company policies, enabling IT teams to manage devices, monitor usage, and optimize the employee experience throughout the device’s lifecycle.

    Addressing Hybrid Work Challenges

    With 76% of employers in Singapore transitioning to hybrid work models, concerns about connectivity, security, and IT complexity have emerged. Singtel’s 5G+ Mobile Workspace addresses these concerns by offering a secure, intelligent mobility platform that supports cloud-native, AI-driven applications on a large scale.

    Benefits of the 5G+ Mobile Workspace

    The 5G+ Mobile Workspace provides flexible, secure, and cost-effective real-time communications, including voice, messaging, and video, without the need for additional infrastructure investment. Security is enhanced through SingVerify and Mobile Protect, which authenticate digital identities and block threats before they reach users’ devices, even when abroad.

    Enterprise Mobility Management

    Singtel’s unified dashboard allows IT teams to have full visibility and control over enterprise mobility. From a single interface, teams can monitor device usage, enforce compliance, allocate resources, and apply access policies by app, user, or location. This efficient approach eliminates the need for on-site infrastructure and simplifies operations across distributed workforces.

    The platform also supports the direct activation of advanced network services like network slicing, which facilitates high-speed data transfer and real-time analytics.

    5G+ Coverage and Performance

    Singtel’s nationwide 5G+ coverage, including the 700 MHz spectrum, ensures stronger indoor connectivity, ultra-low latency, and speeds up to four times faster. Singtel has demonstrated the scalability of its 5G+ network at high-traffic events, maintaining seamless connectivity even during peak demand.

    Questions & Answers

    What is the purpose of the Ericsson Enterprise Virtual Cellular Network?
    The Ericsson Enterprise Virtual Cellular Network automates eSIM profile management. This allows for zero-touch provisioning and secure access to corporate applications from almost any location.

    How does the 5G+ Workspace benefit distributed teams?
    The 5G+ Workspace simplifies device management for modern, geographically dispersed teams. It automatically activates 5G connectivity according to company policies, enabling IT teams to manage devices, monitor usage, and optimize the employee experience throughout the device’s lifecycle.

    What security measures does Singtel’s 5G+ Mobile Workspace offer?
    The 5G+ Mobile Workspace enhances security through SingVerify, which authenticates digital identities, and Mobile Protect, a network-level defense that blocks threats before they reach users’ devices, even when users are abroad.

  • Ooredoo Unveils Cutting-Edge Cybersecurity Solutions to Enhance Global Market Protection

    Ooredoo Unveils Cutting-Edge Cybersecurity Solutions to Enhance Global Market Protection

    Ooredoo Group is stepping up to tackle the multifaceted challenges of cybersecurity, launching advanced services across its varied markets in collaboration with Innovatix Systems, a software development powerhouse. This initiative aims to fortify customers’ digital assets by incorporating robust security measures from the very beginning, offering a proactive approach to counter the escalating threats in the cyber landscape.

    Seamless Security for the Digital Age

    Operating throughout the Middle East, North Africa, and Southeast Asia, Ooredoo has strategically partnered with Innovatix to provide continuous protection via a suite of critical security platforms. Their offering encompasses managed security services, a 24/7 security operations center (SOC), as well as sophisticated endpoint detection and response (EDR) and extended detection and response (XDR) solutions. Notably, these services promise flexibility through vendor-agnostic support, ensuring real-time monitoring and effective incident management.

    Leading the Charge in Cybersecurity

    Najib Khan, Group Chief Business Services Officer, emphasized the importance of synchronizing security with technological progress. “It is critical that security keeps pace with innovation. With Innovatix, we are extending world-class cybersecurity services to millions of users across multiple countries—multilingual, scalable, and localized—giving our customers the confidence to innovate securely,” he stated.

    A Fortress Against Digital Threats

    Innovatix’s Chief Executive, Ahmed Al Mannai, echoed this sentiment, noting that their combined capabilities allow them to deliver defense-grade cybersecurity solutions that adhere to the highest international standards while being tailored to local market needs. “Together with Ooredoo, we are ensuring that businesses and individuals can operate with confidence,” he added, underlining the importance of collaboration in the face of rising cyber vulnerabilities.

    The new services are already operational in Qatar, Tunisia, Kuwait, and the Maldives, with plans to expand further across Ooredoo’s operating territories by the end of 2025. Of note, the offering is available in Arabic, English, and French, cleverly ensuring consistency for users from Algeria to the Maldives without missing a beat.

    Ooredoo’s initiative underscores a commitment to delivering proactive, scalable, and market-responsive protection designed to keep pace with increasingly sophisticated cyber threats. As they say in the tech world, a good defense might just be the best offense—especially in a digital landscape as dynamic as today’s.

    Questions & Answers

    How does Ooredoo’s partnership with Innovatix enhance cybersecurity offerings?
    The collaboration allows Ooredoo to deliver comprehensive cybersecurity services that are multilingual, scalable, and localized, thereby meeting the unique needs of diverse markets.

    What specific cybersecurity services are included in Ooredoo’s new offering?
    The services include managed security services, a 24/7 security operations center, endpoint detection and response, and extended detection and response solutions.

    When does Ooredoo plan to roll out these services across all operating companies?
    Ooredoo aims to extend these advanced cybersecurity services across all its operating companies by the end of 2025.

  • Globe Business and Blackpanda Unveil Budget-Friendly AI Cybersecurity Solutions for Philippine Enterprises

    Globe Business and Blackpanda Unveil Budget-Friendly AI Cybersecurity Solutions for Philippine Enterprises

    Globe Business has joined forces with Blackpanda, the region’s premier cyber incident response specialist, to provide affordable, enterprise-grade cybersecurity solutions tailored for businesses in the Philippines. Their innovative partnership promises a fixed-cost incident response and digital forensics service designed to help organizations promptly detect, contain, and recover from cyberattacks. This offering, fondly dubbed a “cyber fire department,” includes continuous vulnerability scanning, dark web monitoring, and seamless access to cyber insurance, making it an invaluable resource for local enterprises aiming to neutralize digital threats swiftly.

    KD Dizon, Head of Globe Business, emphasizes the growing urgency of the situation:

    Cyber threats remain a pressing challenge for businesses of all sizes, and AI is amplifying both the sophistication and frequency of these attacks. Our partnership with Blackpanda makes immediate, expert incident response—once prohibitively expensive—accessible to organizations across the Philippines.

    The Rising Tide of Cyber Risks in Southeast Asia

    The threat landscape is escalating in the Philippines and Southeast Asia, fueled by inadequate cybersecurity preparedness, AI-driven vulnerabilities, and skyrocketing costs of attacks. Globe underscores the necessity for robust threat intelligence, skilled incident responders, collaboration, and the latest security technologies. In 2024 alone, 85% of Philippine firms reported AI-related attacks, while 84% faced supply chain breaches, with almost a third unable to detect these intrusions. The cost of breaches across ASEAN averaged an alarming USD 3.23 million last year, with the financial services sector suffering the most, racking up an average cost of USD 5.57 million. The region also witnessed a staggering 29% uptick in cyber incidents, accompanied by a rise in ransomware and phishing activities.

    Transforming Cybersecurity Accessibility with IR-1

    Historically, enterprise-level incident response services have been financially out of reach for many businesses, with hourly rates soaring to USD 500 and annual retainers typically ranging from USD 25,000 to USD 100,000. Blackpanda aims to disrupt this trend with its flagship solution, IR-1, which blends incident response, continuous vulnerability scanning, and cyber insurance support into a budget-friendly subscription model. This transformative approach lowers the financial barriers for firms, enhancing their operational resilience and cybersecurity posture.

    Gene Yu, CEO of Blackpanda, shares the vision behind this collaboration:

    Globe’s reach and trust in the Philippine market make them the ideal partner to scale our IR-1 cyber emergency subscriptions nationwide. By delivering always-on access to expert response through Globe’s trusted network, we’re ensuring that a small manufacturer in Cebu or a growing fintech in Makati can access the same level of cyber emergency support as multinational corporations.

    The IR-1 solution boasts automated access to cyber insurance with coverage up to USD 10 million, continuous monitoring for potential risks, and elite response teams located across Asia—Manila, Singapore, Tokyo, and Hong Kong. Unlike its competitors, IR-1 supports any endpoint detection and response (EDR) solution, offering enterprises maximum freedom and flexibility.

    Questions & Answers

    How will the partnership between Globe Business and Blackpanda benefit Filipino companies?
    The partnership aims to provide accessible, enterprise-grade cybersecurity solutions to Filipino businesses, allowing them to swiftly detect and respond to cyber threats without the prohibitive costs historically associated with such services.

    What are the key features of the IR-1 solution offered by Blackpanda?
    IR-1 includes automated access to cyber insurance, continuous attack surface monitoring, dark web scanning, and support for any endpoint detection and response solution, ensuring comprehensive coverage and flexibility for businesses.

    What trends are driving the increase in cyber incidents in Southeast Asia?
    The rise in cyber incidents is largely attributed to low cybersecurity readiness, the growing number of AI-related threats, and the increasing costs of attacks, necessitating urgent action and investment in cybersecurity measures.

  • NEC Boosts Japan’s Cyber Defense with Cutting-Edge Innovations at Locked Shields 2025

    NEC Boosts Japan’s Cyber Defense with Cutting-Edge Innovations at Locked Shields 2025

    NEC Corporation has made a significant leap in enhancing its cybersecurity expertise by taking part in Locked Shields 2025, a premier international cyber defense exercise organized by the NATO Cooperative Cyber Defense Center of Excellence (CCDCOE).

    A Global Cyber Defense Showcase

    From May 6 to 9, this annual exercise brought together approximately 40 countries, including NATO allies, to gauge their readiness against intricate, real-time cyberattacks. Seventeen multinational teams participated, with Japan and Australia joining forces in a joint delegation. Notably, the Japanese team was a melting pot of talent, including representatives from the Ministry of Defense, various government agencies, private companies, and other significant organizations.

    An Interactive Defensive Landscape

    In its pivotal role, NEC spearheaded the design and construction of the exercise environment for the Japanese team, equipping them with essential network and analytical infrastructure. The scenarios simulated tested technical resilience and strategic decision-making, tackling legal, technical, and operational responses to a myriad of sophisticated cyber incidents. Think of it as a chess game where every move could deter a cyber adversary.

    Investing in Future Security

    NEC is not just playing catch-up; it is actively fueling its growth by merging advanced cybersecurity technologies with hands-on training experience that bolsters Japan’s economic security and safeguards crucial infrastructure. As a testament to this commitment, the company plans to launch a Cyber Intelligence & Operation Center in Japan in October 2025. This center will offer vital services to the Japanese government, critical infrastructure providers, and Japanese companies navigating the international landscape.

    Paving the Way for Digital Security

    Looking ahead, NEC is poised to play a crucial role in fostering a secure digital society. By bolstering cyber defense capabilities and supporting economic security through sophisticated cybersecurity services, the company is not merely reacting to threats but actively shaping a safer future for the digital economy.

    Questions & Answers

    What was the purpose of NEC’s participation in Locked Shields 2025?
    NEC’s involvement aimed to enhance its cybersecurity capabilities and support Japan’s economic security by engaging in one of the world’s largest international cyber defense exercises.

    Who were part of the Japanese delegation at the exercise?
    The Japanese contingent included representatives from the Ministry of Defense, various government agencies, private enterprises, and other organizations, showcasing a collaborative effort in cybersecurity.

    What future plans does NEC have to strengthen cyber security?
    NEC plans to establish a Cyber Intelligence & Operation Center in Japan by October 2025, aiming to provide essential cybersecurity services to the government and critical infrastructure stakeholders.

  • CommBank Launches AI Bots to Combat Scams and Enhance Customer Security

    CommBank Launches AI Bots to Combat Scams and Enhance Customer Security

    The Commonwealth Bank of Australia (CBA) is leveraging the power of artificial intelligence to combat the rising tide of scams targeting unsuspecting Australians. In an innovative move, the bank has deployed “a fleet of thousands of AI-powered bot profiles” specifically designed to engage with scammers, gather crucial intelligence, and disrupt their illicit operations.

    AI Bots on the Frontlines Against Scams

    This impressive initiative comes from Apate.ai, a cyber-intelligence firm that evolved from Macquarie University. Each day, Apate.ai unleashes thousands of these smart conversational bots to thwart scammers who rely on text messages and voice calls to deceive their victims. The launch of this bot network follows a successful pilot program from late 2024, showcasing the potential of AI in consumer protection.

    A Honeypot System for Scammers

    At the core of Apate.ai’s operations is an innovative “honeypot” system, explained Dali Kaafar, the company’s CEO and founder. In collaboration with telecommunications partners, the firm maintains an expansive and ever-growing array of dedicated phone numbers that are specifically designed to attract scammers. “When a scammer dials or messages one of these numbers, they actually engage in conversations with one of our AI-powered bots and not a person,” Kaafar elaborated, emphasizing the ingenious trap set for fraudsters.

    The Evolution of Retail security

    The integration of such technology marks a significant step not just in banking but across the entirety of retail, as businesses grapple with the constant threat posed by scammers. While traditional methods of fraud prevention still have their place, the adoption of advanced AI technologies offers a fresh line of defense, transforming the way retailers and banks protect their customers and maintain their trust.

    With creativity and intelligence, CBA and Apate.ai are setting a precedent that may very well redefine how industries combat financial fraud in the digital age. In a world where scams are becoming as common as avocado toast on brunch menus, it pays to have sophisticated tools in your corner.

    Questions & Answers

    How is Commonwealth Bank using AI to combat scams?
    The Commonwealth Bank of Australia is utilizing a network of thousands of AI-powered bots to engage with scammers, gathering intelligence and disrupting their operations.

    What technology underpins Apate.ai’s scam-fighting strategy?
    Apate.ai’s approach is based on a “honeypot” system that employs dedicated phone numbers designed to attract scammers and engage them in conversations with AI bots.

    Why is the integration of AI significant for the retail industry?
    The use of AI in combating scams represents a revolutionary step for the retail industry, as businesses increasingly adopt advanced technologies to protect consumers and safeguard trust.

  • Addressing Security Challenges: The Upsurge of AI in Business Operations

    Addressing Security Challenges: The Upsurge of AI in Business Operations

    The global marketplace is undergoing a seismic shift as companies rapidly embrace artificial intelligence. A recent McKinsey report reveals that 78% of organizations are already utilizing AI, and a staggering 92% plan to ramp up their investments in this transformative technology over the next three years. Gartner even predicts that by 2029, AI agents will take charge of a whopping 80% of customer interactions.

    However, riding the AI wave isn’t all sunshine and rainbows. The reality is that only 1% of firms can be classified as AI-mature. Alarmingly, a significant 70% of businesses falter during AI deployment, and about 85% of projects fail to meet expectations. Rather than being the panacea many hoped for, AI has entangled companies in a web of challenges, including breaches of sensitive data, mishandled operations, and sophisticated security attacks—each leading to reputational damage and financial hits that could sink a ship.

    Addressing the Challenges of AI Adoption

    These pressing challenges raise an essential question: How can businesses successfully and safely integrate AI into their operations? In today’s fast-paced tech environment, speed alone isn’t enough. The new gold standards are robust security, data privacy, and user protection.

    In a proactive move, OplaCRM—a growing SaaS company specializing in AI-driven CRM and B2B sales solutions—has forged a partnership with VinCSS, a prominent regional cybersecurity firm. This collaboration aims to establish a standard for cybersecurity across OplaCRM’s AI offerings.

    Innovating with Security in Focus

    As part of this partnership, OplaCRM will subject its products to rigorous penetration testing by VinCSS before they hit the market. This will enable swift identification and resolution of any security vulnerabilities lurking beneath the surface. Additionally, VinCSS will help incorporate password-free authentication, utilizing FIDO2-compliant passkeys to boost user experience while fortifying defenses against emerging threats tied to traditional credential systems.

    Through this alliance, OplaCRM doesn’t just bolster its own security measures; it also enhances the safety of its customers and end users. This synergistic approach is a win-win, proving that collaboration can yield significant benefits.

    Educating for a Secure Future

    The two companies are committed to engaging the wider business community through educational events focused on the secure adoption of AI. These sessions arm participants with practical insights to navigate risks, stay informed on industry trends, and develop secure roadmaps for AI deployment. In an era where AI is becoming part and parcel of business strategy, VinCSS and OplaCRM make it clear: cybersecurity is no longer optional—it’s imperative.

    Their collaborative efforts stand as a model of how technological innovation and robust security can go hand in hand, empowering businesses to tap into the full potential of AI while safeguarding their operations and customers.

    What would happen if an AI program gave an unexpected answer during a critical moment? Well, it might be a good time to double-check those security measures!

    Questions & Answers

    What percentage of companies are currently using AI?
    According to McKinsey, 78% of organizations utilize AI, with 92% planning to invest further in the next three years.

    What are the main challenges companies face when deploying AI?
    Major challenges include AI-induced data breaches, incorrect AI actions, and overall deployment failures, with 70% of companies facing struggles in this area.

    How does the partnership between OplaCRM and VinCSS enhance AI security?
    Their collaboration involves penetration testing of OplaCRM products, integration of password-free authentication, and a shared commitment to educating businesses on secure AI adoption.

  • Viettel Cyber Security’s Free Service Uncovers Risks for Philippine Businesses

    Viettel Cyber Security’s Free Service Uncovers Risks for Philippine Businesses

    In response to the growing need for enhanced cybersecurity, Viettel Cyber Security (VCS) has launched a free, innovative cyber threat check service specifically designed for businesses in the Philippines.

    The service provides real-time alerts on threats such as data breaches and compromised company accounts, along with personalized recommendations. Customers can access the service by simply entering their domain, allowing the system to conduct an automated scan.

    The VCS free cyber threat check quickly evaluates a company’s cybersecurity status. Within minutes, businesses receive a detailed report outlining vulnerabilities and risks, complete with metrics, severity scores based on asset value and threat intensity, and actionable recommendations from VCS. This real-time, no-cost service offers expert insights, helping companies of all sizes proactively protect their digital assets, prioritize critical risks, and strengthen their defenses—without the need for complex setup.

    The VCS free cyber threat check report offers essential insights into cybersecurity risks, helping businesses identify and address potential vulnerabilities. The report detects:

    • Compromised Accounts: Provides details on any compromised accounts associated with the organization.
    • Data Leaks: Supplies information on data breaches that may have exposed sensitive information.
    • Brand Phishing: Identifies fraudulent websites and phishing attempts that imitate the organization’s brand.
    • Impersonation Threats: Detects unauthorized entities attempting to impersonate the brand or business.
    • Unusual Open Ports: Highlights any open ports that could pose security risks.
    • Malware Infections: Identifies systems within the organization that may be infected with malicious software.
    • Web Security and Protocol Configuration: Assesses the security settings of the company’s web assets.

    After completing the scan, VCS compiles the findings and offers customized recommendations, including actionable solutions for each identified vulnerability. This detailed report helps businesses proactively enhance their cybersecurity measures and effectively manage risks.