Brunei Cyber Security Conference (CySec 2026) officially launched recently, bringing together government officials, industry leaders, diplomats and cybersecurity practitioners to address the growing need to strengthen the resilience of critical infrastructure.
Held at The Rizqun International Hotel from September 15 to 16, the conference was held under the theme “Resilient by Design: Protecting Critical Infrastructure” and jointly organised by Cyber Security Brunei (CSB) and the Brunei Cybersecurity Association (BCSA), with support from the Ministry of Transport and Infocommunications (MTIC).
The official opening was graced by Yang Berhormat Dato Seri Setia Awang Mohammed Riza bin Dato Paduka Haji Mohammed Yunos, Minister of Transport and Infocommunications (MTIC) and Minister-in-Charge of Cybersecurity, and Yang Berhormat Dato Seri Setia Awang Haji Sufian bin Haji Sabtu, Minister at the Prime Minister’s Office for Security and Law.
Image: MTIC
In his keynote address, Yang Berhormat Dato Seri Setia Mohd Riza bin Dato Paduka Haji Mohd Yunos said cybersecurity had become central to the operation of government, the economy and essential services.
He noted that Brunei Darussalam had reached a pivotal stage in its cybersecurity journey, with the Cyber Security Order passed in 2023 and subsequently enacted as the Cyber Security Act in 2024, alongside the Brunei Darussalam National Cyber Security Strategy 2023–2027.
Under the Cyber Security Act, ten essential service sectors have been identified as Critical Information Infrastructure (CII), covering energy, info-communications, healthcare, banking and finance, defence and security, emergency services, aviation, the functioning of Government, media and water.
CII owners and operators are responsible for understanding their cybersecurity risks, protecting their systems, and reporting and responding effectively when cybersecurity incidents occur.
However, the Minister said designation alone does not constitute resilience, with progress instead measured by stronger systems, better preparedness and improvements on the ground.
He also highlighted the changing cyber threat environment, noting the increasing speed, sophistication and complexity of attacks, with Artificial Intelligence accelerating these developments.
Among the threats requiring particular attention are AI-enabled phishing, scams and impersonation, ransomware and cyber extortion, data breaches and credential theft, supply-chain and third-party compromises, and attacks targeting Operational Technology and Critical Information Infrastructure.
As more operational systems become connected through modernisation, digitalisation and automation, the Minister said each new connection brings both opportunities and potential vulnerabilities.
Image: MTIC
He stressed that resilience must therefore be incorporated from the outset, covering the architecture, procurement, development, deployment and operation of systems.
Cyber Security Brunei is strengthening guidance for Government, CII owners and industry through an updated Code of Practice for Critical Information Infrastructure, alongside newly introduced AI Security Policy Guidelines and Secure by Design Policy Guidelines.
The AI Security Policy Guidelines seek to support responsible governance as artificial intelligence becomes more widely adopted, while the Secure by Design Policy Guidelines aim to embed security considerations throughout a system’s lifecycle.
The Minister also called for the progressive development of more sector-specific cybersecurity guidance, recognising that the cybersecurity requirements of sectors such as energy, finance, healthcare and transport can differ.
Image: MTIC
He further highlighted the importance of harmonising incident-reporting requirements to support clearer and more coordinated responses across sectors.
Beyond Government and critical infrastructure operators, the Minister said businesses, particularly small and medium enterprises, also have an important role in national cyber resilience.
He noted the introduction of TERAS Siber, a national baseline cybersecurity certification scheme for organisations of all sizes. Its five pillars are Trusted Access, Endpoint Defence, Resilient Data, Active Response and Secure Culture.
The Minister encouraged businesses to adopt these baseline practices, while noting that greater regional recognition of such standards and certifications could support Brunei businesses as they expand across Southeast Asia.
Image: MTIC
Digital trust was also highlighted as an important element of Brunei Darussalam’s digital transformation under Digital Brunei 2030.
The ongoing implementation of Brunei ID, in collaboration with the Ministry of Home Affairs, was cited as part of the trusted digital ecosystem, providing a foundation for a single authoritative digital identity and safer access to services for citizens and businesses.
On cybersecurity capabilities, the Minister said resilience ultimately depends on people and highlighted the need to strengthen Brunei Darussalam’s cybersecurity talent pipeline.
Cyber Security Brunei is developing the Brunei National Cybersecurity Competency Framework (BNCCF), based on the internationally recognised NIST NICE Framework.
Image: MTIC
Expected by the first quarter of 2027, the framework will map the knowledge, skills and abilities required across cybersecurity roles and establish clearer career pathways for professionals.
International partnerships will also continue to support national capacity-building efforts, including collaboration with the International Telecommunication Union (ITU) and engagement with EU CyberNet.
The Minister also expressed hope that these partnerships could progressively contribute towards the establishment of a Cyber Academy or Centre of Excellence in Brunei Darussalam.
CySec 2026 features more than 1,200 participants and over 40 local and international speakers, with discussions covering Critical Infrastructure Cybersecurity, OT/ICS/SCADA Security, Cloud Security, AI for Cyber Defence, Cyber Threat Intelligence, Supply Chain Security, Zero Trust Architecture, Incident Response and Cyber Resilience.
Image: MTIC
The programme also addresses current issues including ransomware, deepfakes and social engineering, alongside opportunities for participants to engage with experts, technology vendors and industry practitioners.
Running alongside the conference is the CB:CTF (Capture the Flag) competition, while a Maritime Cybersecurity Workshop is being conducted by the University of Plymouth’s Cyber-SHIP Lab.
The Minister said national cyber resilience could not be achieved by Cyber Security Brunei alone, nor through legislation, technology or compliance alone.
Image: MTIC
He emphasised the shared responsibility of Government, CII operators, businesses, technology providers, academia and the public in strengthening the wider digital ecosystem.
CySec 2026 aims to provide a platform for participants to exchange knowledge and experience while identifying practical opportunities for collaboration to strengthen cybersecurity resilience in Brunei Darussalam and the wider region.
THE BRUNEIAN | BANDAR SERI BEGAWAN