The Great Cybersecurity Divide

Brendan Dowling (Ambassador for Cyber Affairs and Critical Technology · Australian Department of Foreign Affairs and Trade), Steven Matainaho (Permanent Secretary, Department of ICT · Papua New Guinea Government), Tupou Baravilala (Director-General, Transformation, Cybersecurity and Communications · Ministry of Communications, Fiji), Kuan Seah Chua (Deputy Commissioner of Cybersecurity / Deputy Chief Executive (Development) · Cyber Security Agency of Singapore)

RSA Conference 2025 · Day 1 · Policy · Policy & Government

Overview

The global digital divide is shrinking — billions of people across the Asia-Pacific are gaining internet access via subsea cables and satellite networks — but the cybersecurity divide is not. As connectivity reaches some of the world's most remote communities, scams, ransomware, and nation-state interference are arriving at the same time, often targeting populations with no experience defending against digital threats. At RSA 2025, voices rarely heard at the world's largest cybersecurity conference delivered a direct message to the industry: the products and services you build are not designed for our context, our budgets, or our languages — and people are being harmed as a result. ---

Watch on YouTube

Visual summary for The Great Cybersecurity Divide by Brendan Dowling, Steven Matainaho, Tupou Baravilala, Kuan Seah Chua
Visual summary for The Great Cybersecurity Divide by Brendan Dowling, Steven Matainaho, Tupou Baravilala, Kuan Seah Chua

Key moments

  1. 3:00 Indo-Pacific connectivity rollout spreading vulnerabilities faster than opportunities
  2. 4:06 Ransomware attacks shutting down hospitals in Pacific island nations already occurring
  3. 9:12 Fiji balancing cybersecurity investment against active climate-driven community relocation
  4. 17:45 Singapore lost SGD 1.1B to scams in 2024 despite world-class cyber infrastructure
  5. 16:03 Singapore-Google Android on-device scam detection achieves 84% malware-scam reduction
  6. 28:46 PNG: 40-to-80% connectivity jump triggered 67% surge in detected cyber threats
  7. 29:11 PNG calls on vendors to become development partners, not just product sellers
  8. 37:20 Small Pacific nations demand inclusion in global cyberspace norms negotiations

The Great Cybersecurity Divide

Speakers: Brendan Dowling (Australian DFAT, moderator), Tupou Baravilala (Ministry of Communications, Fiji), Kuan Seah Chua (Cyber Security Agency of Singapore), Steven Matainaho (PNG Government)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch on YouTube: https://www.youtube.com/watch?v=dZNQL1mX5FU

Reading time: ~9 minutes

TL;DR

The global digital divide is shrinking — billions of people across the Asia-Pacific are gaining internet access via subsea cables and satellite networks — but the cybersecurity divide is not. As connectivity reaches some of the world's most remote communities, scams, ransomware, and nation-state interference are arriving at the same time, often targeting populations with no experience defending against digital threats. At RSA 2025, voices rarely heard at the world's largest cybersecurity conference delivered a direct message to the industry: the products and services you build are not designed for our context, our budgets, or our languages — and people are being harmed as a result.

Introduction

At 8:30 a.m. on the final Wednesday of RSA Conference 2025, a panel convened that stood apart from the rest of the program in a meaningful way. There were no American technology executives, no Silicon Valley founders, and no representatives from the major European regulatory bodies that dominate most policy discussions. Instead, the stage was occupied by officials from Fiji, Papua New Guinea, and Singapore — three nations at very different points on the spectrum of digital development, but united by a common reality: the cybersecurity tools, frameworks, and services that dominate the global market are not built for them.

Moderated by Brendan Dowling, Australia's Ambassador for Cyber Affairs and Critical Technology, the panel featured Tupou Baravilala (Director-General, Transformation, Cybersecurity and Communications, Fiji), Kuan Seah Chua (Deputy Commissioner of Cybersecurity, Singapore's Cyber Security Agency), and Steven Matainaho (Permanent Secretary, PNG's Department of ICT). Together, they represented a region undergoing generational change — and facing consequences that the cybersecurity industry has been too slow to address.

The Stakes: Connectivity Without Security Is Worse Than No Connectivity

Dowling opened with a stark framing: in the Indo-Pacific, the vulnerabilities created by rapid digital expansion may be spreading faster than the opportunities it creates. Subsea cables, low-Earth-orbit satellites, and expanding mobile networks are connecting hundreds of millions of people who have never before had internet access — including residents of remote Pacific islands, highland villages in Papua New Guinea, and rural communities across Southeast Asia.

The development potential is real. Digital service delivery by governments, access to education and healthcare, e-commerce, financial inclusion — these are life-changing opportunities for communities that have historically been cut off from them. But the same connectivity that delivers those benefits also exposes those communities to ransomware, financial scams, disinformation, and nation-state interference — without the cybersecurity infrastructure or skilled workforce to defend against any of it.

"As people are getting connected, the vulnerabilities are spreading possibly at a greater rate than the opportunities are," Dowling said. ▶ Watch: The connectivity-vulnerability trade-off (2:49)

The panel documented a pattern of attacks that illustrated the problem with specificity: hospitals in small Pacific Island nations shut down by ransomware; Indonesian government data centers paralyzed in a ransomware attack; Laotian government agencies taken offline; significant attacks on critical infrastructure in Australia, Fiji, and Papua New Guinea. These incidents involved the most basic, well-documented TTPs — vulnerabilities that should have been patched, configurations that should have been hardened, credentials that should have been protected by multi-factor authentication. The gap is not technical sophistication on the attacker's side; it is capacity on the defender's side.

Fiji: Connecting a Hundred Islands While Preparing for Climate-Driven Relocation

Tupou Baravilala described Fiji's situation with a clarity that cut through any tendency to treat "small island developing state" as a polite abstraction. Fiji has fewer than a million people, more than three hundred islands (110 of them populated), and a population that is 50% under the age of thirty. After connecting to the Southern Cross Cable in 2000, Fiji has since seen four additional undersea cables land, bringing 95% connectivity coverage. A national digital strategy is actively driving digital transformation across government and the private sector.

But Baravilala was candid about the compounding challenges. Cybersecurity budgets must compete with climate change adaptation — and in Fiji, climate change is not a future policy concern but a present operational reality. Communities are already being relocated from coastal areas due to rising sea levels and increasing storm intensity. "When we're looking at resilient ICT infrastructure, we have to bear in mind that as we're building all of this infrastructure, we're also building for climate resilience," she said. ▶ Watch: Climate and cybersecurity intersection (10:22)

She also described a recent visit to Rotuma — one of Fiji's most remote islands, home to roughly 2,000 people and geographically closer to neighboring countries than to Fiji's capital. The island is now part of an ITU-supported "smart island" project deploying smart classrooms, telecenter community labs at health centers and government stations, and last-mile connectivity solutions. The insight that emerged from the visit: even within Fiji's 95% coverage, the remaining 5% is not just a coverage gap — it is a usage gap. Having a tower on one side of a mountain means nothing for the village on the other side.

Baravilala closed with a point about global governance: Fiji participates in the UN's Open-Ended Working Group on cybersecurity norms, and she emphasized the importance of ensuring that small nations are present in the rooms where the rules of cyberspace are being written. "Making sure that everyone is in the room to be able to be heard." ▶ Watch: Global norms and inclusive participation (37:19)

Singapore: A Small State That Invested Early and Is Now Paying It Forward

Kuan Seah Chua offered a different kind of contrast. Singapore — 700 square kilometers, five million people, no natural resources — made a deliberate early bet on ICT infrastructure and human capital that has paid significant dividends. The country is executing its Smart Nation 2.0 strategy, which addresses digital trust, digital society, and digital economy as integrated objectives.

But Singapore is not resting on its success. Chua was blunt about one vulnerability that has resisted technical solutions: scams. Singapore lost approximately 1.1 billion Singapore dollars to scams in 2024 — up from around 600 million the previous year. "That's a lot of money," Chua said. "And we only have five million people." ▶ Watch: Scam losses and the scale of the problem (17:55)

In response, Singapore launched a partnership with Google to deploy on-device scam and malware detection on Android devices — the first deployment of its kind globally. The result: an 84% reduction in malware-related scams. That outcome demonstrates both the potential and the limit of technical solutions. The remaining 16% includes social engineering attacks and voice-based fraud that on-device detection cannot catch.

Singapore's ASEAN engagements provide a model for regional capacity building. The ASEAN Singapore Cybersecurity Centre of Excellence, established in 2016 with a 10-million-dollar Singapore investment over ten years, provides workshops, training, and policy dialogue for the broader region. A separate UN-Singapore Cybersecurity Fellowship has run six cohorts with more than a hundred fellows from 82 countries. ▶ Watch: ASEAN capacity building and regional investment (18:03) Singapore is also building a national cyber command center — Phase 1 of a SGD 300 million program — that it intends to operate through public-private partnerships.

Papua New Guinea: A Nation of a Thousand Languages Catching Up Fast

Steven Matainaho brought the most striking numbers to the conversation. Papua New Guinea has a population of approximately 12 million spread across 475,000 square kilometers and more than 1,000 islands. It has more than 800 languages — roughly 12% of all languages spoken on Earth, with an average of 5,000 to 6,000 speakers per language. It shares its main island with Indonesia, and its geography makes connectivity provision uniquely challenging.

Between 2020 and the time of the conference, PNG moved from 40% internet connectivity to 80% — a rapid expansion driven by deliberate telecommunications market liberalization. That expansion brought dramatically increased cyber exposure: PNG's national SOC detected a 67% increase in cyber threats over the previous 12 months, with the trajectory described as exponential. ▶ Watch: PNG's connectivity jump and threat surge (29:21)

PNG's response has been to build systematically: a cybersecurity act passed in 2022, a national cybersecurity center and security operations center established, with monitoring now covering 80% of public bodies and being extended to SMEs and startups. Public enterprises are being developed to commercialize cybersecurity and digital identity services.

Matainaho's framing of the vendor relationship was particularly pointed. He invited technology and cybersecurity companies to think of themselves as "development partners" rather than vendors serving a niche market. PNG's opportunities span the entire value chain — from policy development and legislative drafting to product deployment, skills training, and operational support. "We like to see these vendors as development partners because we have a growing industry in cybersecurity." ▶ Watch: Vendors as development partners (30:47)

What the Industry Can Do

The Q&A surfaced several concrete asks that the panel directed at the RSA audience. On threat intelligence: the new national SOCs and cyber command centers being built across the region need partnerships to operationalize the intelligence they are collecting. PNG's SOC, for example, is gathering data on threat patterns that would be valuable for any vendor's global picture — but it cannot act on that data alone.

On culture: trust-based communities across the Pacific and Southeast Asia have adopted digital technology rapidly — QR codes and e-wallets spread during COVID with striking speed — but the same cultural openness that accelerated adoption also makes people more susceptible to social engineering. Building digital resilience requires working with provincial councils, chiefs, and community leaders, not just government IT departments.

On design: products built for enterprise clients in large markets often carry cost structures, language assumptions, and configuration complexity that makes them inaccessible for organizations with low ICT budgets and limited technical staff. The panel was not asking for charity — it was asking for commercial models that fit different markets. "The GDP of a small island developing state is less than even some of the big tech giants that we see," Baravilala noted. ▶ Watch: GDP context and affordability (10:12)

Notable Quotes

"As people are getting connected, the vulnerabilities are spreading possibly at a greater rate than the opportunities are."

— Brendan Dowling, Australian DFAT ▶ 2:49

"The GDP of a small island developing state is less than even some of the big tech giants that we see."

— Tupou Baravilala, Fiji ▶ 10:12

"We lost last year about 1.1 billion worth of dollars to scams. That's a lot of money. And we only have five million people."

— Kuan Seah Chua, Singapore CSA ▶ 17:55

"We like to see these vendors as development partners because we have a growing industry in cybersecurity."

— Steven Matainaho, Papua New Guinea ▶ 30:47

"Making sure that everyone is in the room to be able to be heard."

— Tupou Baravilala, Fiji ▶ 37:19

Key Takeaways

  • The cybersecurity divide is widening even as the digital divide shrinks. Connectivity is expanding rapidly in the Indo-Pacific, but cybersecurity capability — in products, services, skills, and institutional capacity — is not keeping pace.
  • Attacks are already happening at scale. Hospitals shut down by ransomware in Pacific island nations, government data centers paralyzed in Indonesia, critical agencies compromised in Laos — these are not theoretical risks. They reflect simple, preventable vulnerabilities exploited against under-resourced defenders.
  • The affordability-security trade-off is real. Countries choosing between affordable technology and secure technology are being forced to accept insecurity as the price of connectivity. This is a market design failure, not a user choice.
  • Singapore's model demonstrates what early investment yields. The 84% reduction in malware scams from the Google on-device partnership, the ASEAN Centre of Excellence, and the national cyber command program show what systematic investment over time produces — and how it can be shared regionally.
  • Papua New Guinea's 40-to-80% connectivity jump in five years created an exponential surge in cyber threats. The national SOC, cybersecurity legislation, and vendor-as-partner model offer a replicable framework for nations at earlier stages of the same transition.
  • The industry's default market assumptions exclude most of the world. Products designed for enterprise clients in large markets — with corresponding price points, language assumptions, and configuration complexity — are not accessible to the organizations and governments that need them most. Building for these markets is both a commercial opportunity and a contribution to global security.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This panel deserves more attendance than it got at 8:30 a.m. on the conference's last day. Voices from Fiji, PNG, and Singapore deliver a specific, operational critique of the security industry's market assumptions that no amount of Western policy discussion replicates. PNG's 40-to-80% connectivity growth in five years paired with a 67% YoY threat surge is the most vivid data point on the table, and the Singapore scam loss figure — SGD 1.1B in a country of five million — makes the problem concrete in ways that PowerPoint decks about 'the global threat landscape' never do.

Heather Calloway (CISO) — STRONG ACCEPT

Pacific and Southeast Asian voices on the cybersecurity divide: Fiji, Papua New Guinea, and Singapore explain that connectivity is expanding across the Indo-Pacific faster than security capability, that ransomware has already hit hospitals in Pacific Island nations, and that the industry's products are not designed for their context, budgets, or languages.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025