- 12/08/2018
- Category: Commentaries
Cybercrime comes in a lot of varieties—cyber terrorism, cyber fraud, data breach, and hacktivism—and has multidimensional risks similar to domino effects. Attacks are usually materialized in the form of malware, virus, and distributeddenial-of-service (DDoS) targeting critical infrastructures. Although the attack usually only results in short-term disruption like what has happened in the past[i], cyber-attacks could turn out to be a bad precedent which causes consequential economic harm in the long run. Recognizing the potentials and challenges in the cyberspace, ASEAN member states have recently started to incorporate cyber issues within its regional-level strategic decision-making. This article aims to closely examine three aspects in particular; why cybersecurity is worthy of attention, what are the ongoing regional cooperation related to such issues, and what are the possible alternatives to enhance cybersecurity in Southeast Asia.
Q1: What is the urgency for cybersecurity in Southeast Asia?
There are three main indicators that can be used to observe the change Southeast Asia’s digital landscape. Firstly, the digital penetration in Southeast Asia has shown an impressive trend recently. From 2008 to 2011, the internet user growth in the region doubled and the mobile phone use ratio climbed to 967.5 for every 1000 individuals.[ii] In the beginning of 2017, its internet penetration rate reached 52%, exceeding the global average which was only 50%. Other than that, its social media penetration rate also touched 42%, compared to the global average which was no more than 34%.[iii]
The second criterion is Southeast Asia’s economic internet value, which is projected to undergo an exponential growth. According to the past research, the valuation can be worth up to $200 trillion in 2025.[iv]
Lastly, cybersecurity is often mentioned in many heated regional discussions. One of the main pillars of ASEAN—the ASEAN Economic Community (AEC)—is ambitiously pursuing an economic and financial integration in Southeast Asia, one of which is the integrated payment and capital market plan contained in the ‘ASEAN Economic Community 2025 Consolidated Strategic Action Plan.’ The megaproject, however, can generate systemic cyber vulnerabilities, bearing in mind integration in nature accelerates interdependent vulnerabilities that transcend beyond national boundaries. Cyber-attacks launched against a country, for instance, can easily spread to critical points in other countries, too. In terms of risk assessment and management as well as crisis mitigation in cyberspace, ASEAN is several steps behind the European Union who dedicatedly prioritizes the issue. Even further, the EU has also released an official directive on cybersecurity binding for all of its member states.[v]
Q2: How is the progress of cybersecurity discussions under ASEAN’s cooperation framework?
Although it is true that regulation on cybersecurity in Southeast Asia still lags fairly behind the EU, ASEAN is now starting to show serious gestures to secure its cyberspace. The ‘ASEAN Economic Community Blueprint 2025’—a broad outline of AEC’s agenda until 2025—mentions the ASEAN’s affirmation to commit to “build a trusted digital ecosystem including through further strengthening cooperation on cybersecurity and developing measures to protect personal data.”[vi]
Operationalization of the framework is then derived into a document named the ‘ASEAN Economic Community 2025 Consolidated Strategic Action Plan’ with more specific and instructive contents to cyber issues. Several domains of cybersecurity that are published in the document are the importance of information exchange and knowledge transfer among ASEAN member states related to the best practices of enhancing infrastructure resilience and network security; strengthening collaboration and coordination in response to cyber incident emergency; and assessment and discussion of proper techniques and tools in preventing and mitigating error to integrated payment system.[vii]
In addition, one of ASEAN’s bodies—the ASEAN Telecommunications and Information Technology Ministers Meeting—also released a joint media statement, reaffirming its commitment on enhancing cybersecurity.[viii] Unfortunately, the aforementioned frameworks by far are no more than a normative statement which has yet touched strategic instruments that can be harnessed to achieve optimal cybersecurity.
Q3: What are upcoming obstacles faced by Southeast Asia on cybersecurity?
There are three main points worth noting on the ways forward for cybersecurity in Southeast Asia. Firstly, decision makers show limited technical capacity in identifying cyber threats and formulating prescriptions on endurance and crisis mitigation in cyberspace. On the other side, critical information and cyber infrastructures—mostly owned and operated by private sectors—position them as essential players in cybersecurity.[ix] The gap in knowledge and resource between private and government agency can be bridged by exploring the public-private partnership alternative. In reference to this mechanism is the ongoing cooperation between Singapore’s government and the telecommunication corporation Singtel.[x] What triggers another debate is how to incentivize the private sector so they are willing to invest more heavily in cybersecurity and the ideal model and configuration of public-private partnership. In the regional level, the European Union has already laid it down through official directives on public-private partnership.
Secondly, the dynamic risks and vulnerabilities in cyberspace, which in essence goes beyond state boundary, can bring out a question as to what extent ASEAN, as a regional institution, should regulate each member state’s policy. The risk of a spillover from one country’s cyberspace to another’s can be translated into shared burden and threats, which leads to an urgency to standardize cybersecurity regulations. However, how far and specific the standardization should be made, once again, prompts another tricky question. Moreover, the ASEAN Way, which by default leaves any rule and regulation non-binding, could debilitate any efforts in enforcing standardization due to the absence of penalty from ASEAN itself.
Lastly, there is a diverging level of knowledge and resources among member states in developing tools and instruments on cybersecurity. This point can clearly be seen in the ASEAN Finance Ministers’ and Central Bank Governors’ Meeting (AFMGM)[xi] held on April 2018, where Singapore was the frontrunner in cybersecurity development talks in Southeast Asia.[xii] If it is mapped, Singapore comes third worldwide in terms of investment on cybersecurity, using 0.22% from its total GDP, followed by Malaysia who invests 0.08%, compared to the rest of ASEAN member states who only contributes 0.04% from its GDP.[xiii] In average, whole ASEAN members only spend 0.06% of its GDP on securing their cyberspace, even less than half of the global average which is equivalent to 0.13%.[xiv]
[i] Gartzke, E., 2013. The Myth of Cyberwar: Bringing War in Cyberspace Back Down to Earth. International Security, 38(2), pp. 41-73.
[ii] Heinl, C. H., 2013. Regional cyber security: moving towards a resilient ASEAN cyber security regime. RSIS Working Paper,
Volume 263, pp. 1-72.
[iii] Kemp, S., 2017. Digital in 2017: Global Overview. [Online] Available at: https://wearesocial.com/sg/blog/2017/01/digital-in-2017-global-overview [Accessed 24 July 2018].
[iv] CNBC, 2017. Southeast Asia Internet Economy to Hit $50 billion in 2017, says report from Google and Temasek. [Online]
Available at: https://www.cnbc.com/2017/12/11/southeast-asia-internet-economy-to-hit-50-billion-in-2017-google-temasek.html [Accessed 24 July 2018].
[v] Campanelli, A., 2018. EU NIS Directive: The European Union’s First Cybersecurity-focused Legislation. [Online]
Available at: https://www.bitsighttech.com/blog/eu-nis-directive-the-european-unions-first-cybersecurity-focused-legislation [Accessed 24 July 2018].
[vi] ASEAN, 2015. ASEAN Economic Community Blueprint 2025. Jakarta: The ASEAN Secretariat.
[vii] ASEAN, 2017. ASEAN Economic Community 2024 Consolidated Strategic Action Plan. s.l.:ASEAN.
[viii] ASEAN Telecommunications and Information Technology Ministers Meetings, 2016. The 16th ASEAN Telecommunications and Information Technology Ministers Meeting and Related Meetings. Brunei Darussalam: The ASEAN Secretariat.
[ix] Heinl, C. H., 2013. Regional cyber security: moving towards a resilient ASEAN cyber security regime. RSIS Working Paper, Volume 263, pp. 1-72.
[x] Dane, S., 2018. Why Security Is Imperative to Digitization and Asia’s Economic Potential. [Online] Available at: https://apjc.thecisconetwork.com/site/content/lang/en/id/8630 [Accessed 24 July 2018].
[xi] ASEAN Singapore 2018 Resilient and Innovative, 2018. Joint Statement of the 4th ASEAN Finance Ministers’ and Central Bank Governors’ Meeting (AFMGM). [Online] Available at: https://www.mof.gov.sg/aseanfinance2018/newsroom/press-releases/joint-statement-of-the-4th-asean-finance-ministers’-and-central-bank-governors’-meeting-(afmgm) [Accessed 24 July 2018].
[xii] Putra, N. A., 2018. Is ASEAN Doing Enough to Address Cybersecurity Risks?. [Online] Available at: https://thediplomat.com/2018/03/is-asean-doing-enough-to-address-cybersecurity-risks/
[Accessed 24 July 2018].
[xiii] Brandon, J. J., 2018. Why ASEAN Needs to Invest More in Cybersecurity. [Online] Available at https://asiafoundation.org/2018/05/09/why-asean-needs-to-invest-more-in-cybersecurity/ [Accessed 24 Juli 2018]
[xiv] Ibid
Reviewer: Atin Prabandari, MA, & Nabeel Khawarizmy Muna, S.IP