Vietnam lost over half a billion US dollars due to cyberattacks in 2017.
The state of information security in Vietnam over the past few years has been very complex and unpredictable.
Sharing information at the National Security World Conference and Exhibition held on April 5th, Lieutenant General Hoang Phuoc Thuan, Director of the Cyber Security Department, Ministry of Public Security, stated that in 2017, Vietnam faced three major information security issues, most notably a series of large-scale, high-intensity cyberattacks targeting key sectors and important national infrastructure.
The vast majority of these attacks occur through physical transmission infrastructure such as international transmission lines, national intra-network transmission lines, and core service infrastructure. Furthermore, most attacks are no longer spontaneous or isolated but have become systematic, large-scale campaigns. In addition, according to Mr. Nguyen Trong Duong, Director of the Vietnam National Computer Emergency Response Center (VNCERT), the spread of malware is also becoming a serious concern. Malware is becoming increasingly sophisticated and complex, especially multi-purpose malware that encrypts data, extorts money, and steals data all at once.
|
For example, the Wannacry malware, which attacked nearly 250 Vietnamese businesses in mid-2017, caused significant damage. Meanwhile, Mr. Nguyen Thanh Hai, Director of the Information Security Department of the Ministry of Information and Communications, stated that cyberattacks tend to focus on vulnerabilities and weaknesses in IoT devices, particularly surveillance cameras. This will create many difficulties for the government, especially when implementing e-government or smart city projects.
According to Mr. Nguyen Thanh Hai, 2017 had several noteworthy highlights: firstly, the level of attention to information security and safety among organizations, businesses, the government, and the general public had increased; and secondly, the legal framework for ensuring information security and safety had become relatively complete.
At the Cybersecurity: Who's in Control? workshop organized by RMIT Vietnam this week, Associate Professor Mathews Nkhoma, Head of the Business and Management Faculty at RMIT Vietnam, also stated that the extremely rapid development of network connectivity and the dizzying pace of digital transformation make Asia, especially Vietnam, vulnerable to cyberattacks.
He said that, according to a 2017 report on cyber risks in the Asia-Pacific region by Marsh & McLennan, organizations and businesses in Asia take 1.7 times longer than elsewhere in the world to detect an attack, and 78 percent of internet users in Asia have no training in cybersecurity.
He emphasized that Vietnam was among the top ten most vulnerable countries and a target of cyberattacks from 2015 to 2017. In 2017 alone, Vietnam lost $542.8 million due to cyberattacks.
There is a severe shortage of personnel in cybersecurity.
Professor Matthew Warren, Deputy Director of the Centre for Cyber Security Studies at Deakin University, added that robust cybersecurity is a fundamental element of a nation's development and prosperity in the global economy, and is crucial for national security.
“Global security risks and vulnerabilities now affect every organization and its customers. The complexity of cybersecurity makes it even harder for organizations to understand these risks and therefore harder to control,” Professor Warren said.
He also emphasized the link between human resources and the complexity of maintaining security. From a cybersecurity perspective, human resources can fail due to lack of experience, inadequate training, and misjudgments. Therefore, investing in developing cybersecurity skills, as well as recruiting and retaining cybersecurity personnel, is crucial for organizations.
"There is currently a shortage of one million cybersecurity professionals globally," the professor said, adding that this number is projected to increase to 1.5 million by 2019.
Regarding the skills needed by future cybersecurity professionals, Professor Warren stated that they will require technical expertise to operate critical security technologies, organizational skills to guide policy and risk assessment, interpersonal skills to work with others, and soft skills for communication.



