Most attacks the Cyber Security Agency of Singapore investigates are not technologically sophisticated — they succeed through human error, carelessness, or social engineering. That is the surface Singapore's founding cybersecurity chief David Koh says AI actually scales.
"With artificial intelligence, it fundamentally changes the parameters of this 'cat-and-mouse game'," Koh told CNA in his first exclusive interview since retiring on Jul 1 after 11 years leading the agency and 42 years in public service.
The institutional verdict is unfashionable. Today's cyberattacks are "handcrafted," requiring human innovation, imagination, and technical competence to exploit vulnerabilities. "All of this is held together by a handful of people with the skillsets to do this," Koh said. "Skillsets are rare, hard to come by. So consequently, the amount of damage that these people can do is limited by how hard they work."
AI removes the labor constraint. Identifying and chaining vulnerabilities — work that today requires a small pool of skilled people — becomes automatable. The ceiling on damage rises. The floor does not. The human-error surface stays soft.
That reframes the defender's job. If the threat were sophisticated AI, defenders would be chasing an arms race they cannot win. The defensible posture is more mundane: phishing gets more plausible, vulnerability chains get assembled faster, and the human layer remains the target. Institutions that drill, train, and reduce human-error surface are not solving a Hollywood problem. They are solving the problem AI actually scales.
Koh is not downplaying the shift. He is locating it. The defender's playbook he is handing over is being rewritten before the threat has landed.
Reported by Sky for Type0, from AI cyberattacks mean we can't defend ourselves the same way as before: Singapore's founding cybersecurity chief. Read the original: channelnewsasia.com