Skip to main content

Speeches

Official Opening of the 4th Brunei Cybersecurity Conference (CySec 2026) by The Minister of Transport and Infocommunications

Official Opening of the 4th Brunei Cybersecurity Conference (CySec 2026)

 

Keynote Address

 

Yang Berhormat Dato Seri Setia Mohd Riza bin Dato Paduka Haji Mohd Yunos
Minister of Transport and Infocommunications,

 

Minister in-charge of Cybersecurity

 

Tuesday 15 September 2026
The Rizqun International Hotel
Negara Brunei Darussalam

 

 

Assalamu’alaikum warahmatullahi wabarakatuh and a very good morning.

[SALTATION]

 

  1. It is a distinct honour to join all of you this morning for the opening of the 4th Brunei Cybersecurity Conference, CySec 2026, held under the vital theme: “Resilient by Design: Protecting Critical Infrastructure.”
  1. I extend a warm welcome to our delegates from across the region and beyond, to our distinguished speakers, exhibitors, partners and all participants.
  1. Your presence here reflects a fundamental truth: cybersecurity is no longer merely a technical consideration. It has become the bedrock upon which our Government operates, our economy functions and our essential services are delivered. Ultimately, it is central to how our people live.

WHERE WE STAND TODAY

  1. Brunei Darussalam today stands at a pivotal stage in its cybersecurity journey. Over recent years, we have progressively built the foundations of our national cybersecurity architecture. The Cyber Security Order, passed in 2023, subsequently enacted as Cyber Security Act in 2024, coupled with the Brunei Darussalam National Cyber Security Strategy 2023–2027, will continue to guide our national direction. The enforcement of the Personal Data Protection Order provides clearer guidance, particularly covering operational technology and cloud security.
  1. We have moved beyond simply building the framework. We are now at the stage of living by it, implementing it, strengthening it, and, most importantly, being accountable for it.
  1. This is particularly critical for our Critical Information Infrastructure, or CII. Under the Cyber Security Act, our ten essential service sectors cover energy, info-communications, healthcare, banking and finance, defence and security, emergency services, aviation, the functioning of Government, media and water. Critical Information Infrastructure owners and operators within these sectors carry responsibilities to understand their cybersecurity risks, protect their systems and report and respond effectively when cybersecurity incidents occur.
  1. However, designation alone is not resilience. The true measure of our progress must be whether that designation results in stronger systems, better preparedness, and measurable improvements on the ground.

THE THREAT ENVIRONMENT HAS CHANGED

  1. At the very time our national framework matures, so too has the threat environment around us. The speed, sophistication and complexity of cyber threats are escalating and Artificial Intelligence is accelerating this change.
  1. We are already looking beyond AI as a simple tool used by people, towards agentic and increasingly autonomous systems capable of operating and adapting at machine speed.
  1. For defenders, this changes the equation considerably. The barrier to launching sophisticated cyberattacks is becoming lower, while the speed and scale at which attacks can be carried out are becoming significantly greater.
  1. Against this evolving landscape, five cyber threats warrant particular attention: AI-enabled phishing, scams and impersonation; ransomware and cyber extortion; data breaches and credential theft; supply-chain and third-party compromises; and attacks targeting Operational Technology and Critical Information Infrastructure.
  1. This has profound implications for Operational Technology and Critical Information Infrastructure. The systems that keep our lights on, our water flowing, our energy supplied, and our aviation networks moving were often designed for reliability and continuity not for the hostile cybersecurity environment of today.
  1. As industries modernise, digitalise, and automate, more of these systems become connected. And every new connection creates both an opportunity and a potential vulnerability.
  1. For Brunei Darussalam, this is not an abstract scenario. A successful attack against our critical infrastructure would directly affect the everyday services upon which our people, businesses, and economy depend.
  1. Beyond critical infrastructure, we must also confront another dimension of this challenge: the erosion of digital trust. AI-enabled scams, fraud, impersonation, and disinformation are becoming increasingly sophisticated. These are no longer mere online inconveniences. They cause financial loss, undermine confidence in digital services, and, at scale, become matters of national concern.
  1. This is why MTIC will continue to work closely with relevant ministries, departments, and law enforcement agencies, through the National Cybersecurity Committee, as one of the platforms for coordination, public awareness and our collective response to cybercrime.
  1. The lesson is clear: cyber threats do not respect organisational or sectoral boundaries. Neither, therefore, can our response.

 

FROM PROTECTION TO “RESILIENT BY DESIGN”

 Distinguished Guests Ladies and gentlemen,

 

  1. This brings me to the theme of this year’s conference: “Resilient by Design” Traditionally, cybersecurity has focused heavily on protection building walls to keep threats outside our systems. Protection remains essential.
  1. But we must also accept a more difficult reality: no system can assume that every threat will always be prevented. The more important question therefore becomes: If an attack succeeds, can our critical systems withstand it? Can essential services continue? Can we recover quickly, safely and confidently?
  1. That is the essence of resilience. Resilience cannot be an afterthought, added only after an incident has occurred. It must be designed into our systems from the very beginning from architecture and procurement, to development, deployment and operations. Ultimately, it must be embedded into the cybersecurity culture of every organisation entrusted with national responsibility. This is what it means to be resilient by design.
  1. In translating this principle into practice, Cyber Security Brunei is currently strengthening the guidance available to Government, CII owners and industry. This includes the updated Code of Practice for Critical Information Infrastructure, complemented by two newly introduced areas of policy guidance.
  1. The first is the AI Security Policy Guidelines. As Artificial Intelligence becomes increasingly embedded across Government, industry and society, we must ensure its adoption takes place within a clear and responsible governance framework.
  1. Importantly, we must look beyond today’s generative AI towards agentic and autonomous AI understanding not only the risks these technologies may introduce, but also how they can strengthen our own cybersecurity capabilities. Our objective should not be to hold back innovation, but to ensure we can embrace it safely, responsibly and confidently.
  1. The second is the Secure by Design Policy Guidelines. This brings the theme of our conference directly into practice by embedding security considerations throughout the entire lifecycle of a system from its earliest design and procurement, through development and deployment and ultimately into its operation.
  1. This becomes even more relevant as AI-assisted software development makes application creation increasingly accessible. Innovation should be encouraged. But greater accessibility must be accompanied by greater responsibility.
  1. Taken together, the updated Code of Practice for CII, the AI Security Policy Guidelines and the Secure by Design Policy Guidelines will provide an increasingly coherent foundation for organisations to build and operate systems that are resilient by design.
  1. Moving forward, I would also encourage Cyber Security Brunei to progressively develop more sector-specific guidance, recognising that the cybersecurity realities of energy, finance, healthcare and transport are not necessarily the same. Similarly, efforts to harmonise incident-reporting requirements should continue, so that our response becomes clearer, more consistent and more coordinated across all sectors.

 

RESILIENCE ACROSS OUR ECONOMY

  1. But national cyber resilience cannot belong to Government and Critical Information Infrastructure Our businesses particularly our small and medium enterprises form the backbone of our digital economy and are themselves increasingly exposed to cyber threats. They too must be equipped to protect themselves.
  1. I am therefore pleased to note the introduction by Cyber Security Brunei of TERAS Siber, our national baseline cybersecurity certification scheme for organisations of all sizes.
  1. Its five pillars — Trusted Access, Endpoint Defence, Resilient Data, Active Response and Secure Culture translate cybersecurity into practical, understandable measures that organisations can adopt. I strongly encourage our businesses, including our SMEs, to embrace these baseline practices.
  1. Our longer-term ambition should extend beyond national adoption. As Brunei Darussalam participates in an increasingly integrated ASEAN digital economy, we should work towards greater regional recognition of such standards and certifications, supporting our businesses as they diversify and scale across Southeast Asia.
  1. This broader question of trust is equally important as we advance the aspirations of Digital Brunei 2030. Digital transformation can only succeed when citizens and businesses have confidence in the systems they use.
  1. The ongoing implementation of Brunei ID, in close collaboration with the Ministry of Home Affairs, is an important part of this trusted digital ecosystem, providing the foundation for a single authoritative digital identity while enabling safer and more convenient access and services for citizens and businesses.
  1. As more issuers and verifiers of digital credentials are progressively onboarded across Government, industry and academia, that foundation of trust will become increasingly vital to our wider digital economy.

 

BUILDING NATIONAL CAPABILITY

Distinguished Guests Ladies and gentlemen,

 

  1. Technology and policy alone, however, will not make us resilient. Ultimately, resilience depends on people.
  1. One of our greatest challenges is therefore ensuring that Brunei Darussalam develops a sufficiently strong cybersecurity talent pipeline to support our national requirements including the needs of our ten essential service sectors.
  1. I am pleased to note that Cyber Security Brunei is developing the Brunei National Cybersecurity Competency Framework, or BNCCF, based on the internationally recognised NIST NICE Framework.
  1. Expected, insya Allah, by the first quarter of 2027, this framework will map the knowledge, skills and abilities required across cybersecurity roles and establish clearer career pathways for our professionals.
  1. This should complement our wider national efforts to strengthen ICT competencies and help us develop cybersecurity not merely as a technical occupation, but as a sustainable and respected professional career pathway.
  1. At the same time, Cyber Security Brunei, together with the Brunei Cybersecurity Association, academia, industry and other partners, must continue strengthening our workforce through Cyber Skills and Growth programmes and other capacity-building initiatives.
  1. International partnerships will remain important to this effort. Our collaboration with the International Telecommunication Union (ITU), which included the Asia-Pacific CyberDrill and Conference hosted in Brunei Darussalam in 2024, has expanded into areas including Child Online Protection policy assistance and cybersecurity capacity development.
  1. More recently, engagement with EU CyberNet provides another avenue through which Brunei Darussalam can strengthen technical expertise and benefit from international experience in cybersecurity and countering cybercrime.
  1. Through these partnerships, I hope we can progressively build the expertise and institutional capability that may one day support the establishment of our own Cyber Academy or Centre of Excellence, insya Allah.

RESILIENCE IS A SHARED RESPONSIBILITY

Distinguished Guests Ladies and gentlemen,

  1. The message I wish to leave with you today is this: national cyber resilience cannot be delivered by Cyber Security Brunei alone. Nor can it be achieved through legislation, technology, or compliance alone.
  1. It requires Government, CII operators, businesses, technology providers, academia and our people to understand that each of us forms part of the same digital ecosystem. A weakness in one part of that ecosystem can ultimately affect many others.
  1. This is particularly relevant to the sectors upon which our connectivity and economy depend. In MTIC transport portfolio, aviation and maritime connect Brunei Darussalam physically to the world, while digital infrastructure increasingly underpins how those sectors operate. I am therefore encouraged that this conference also includes a Maritime Cybersecurity Workshop conducted by the University of Plymouth’s Cyber-SHIP Lab, with further substantive engagement anticipated thereafter. Such collaboration demonstrates precisely the direction we must take translating national cybersecurity policy into sector-specific understanding, capability and action.
  1. I reiterate, as Brunei Darussalam continues its digital transformation, our measure of success cannot simply be how much technology we adopt. It must also be how confidently we can depend on it; how securely we can use it; and how quickly we can respond and recover when it is challenged.
  1. That is the shift from cybersecurity as protection to cybersecurity as resilience. And that is why resilience must be built not after an incident, but by design.

 

CLOSING

 

  1. In closing, I extend my deepest appreciation to Cyber Security Brunei and the Brunei Cyber Security Association for their vision and efforts in organising this conference, as well as to our local and international partners, sponsors, speakers and participants.
  1. Over these two days, I encourage all of you not only to exchange knowledge and experience, but also to identify practical opportunities for collaboration that can strengthen the resilience of Brunei Darussalam and our wider region.
  1. Cybersecurity is ultimately a shared responsibility. And the resilience we build today will determine the confidence with which we pursue our digital future tomorrow.
  1. With the kalimah Bismillahir Rahmannir Rahim, it gives me great pleasure to officially declare the 4th Brunei Cybersecurity Conference, CySec 2026 with the theme, “Resilient by Design: Protecting Critical Infrastructure.”, open. Thank you

Wabillahi Taufik Walhidayah, Wassalamu’alaikum warahmatullahi wabarakatuh.