Cyber Resilience as a License to Operate: Temasek’s Portfolio‑Based Approach to Security and AI

For over 50 years, the global investment company Temasek has selected its portfolio based on long-term structural trends “with tomorrow in mind,” as the company says. One of those long-term trends – watched closely by Temasek’s Chief Information Security Officer, Cheri Lim – is the evolution of Artificial Intelligence (AI) as both a tool of and a threat to cybersecurity.  

In this conversation, Lim describes Temasek’s portfolio‑based cybersecurity and resilience model, her concerns about the black box of the supply chain, and the potential benefits to cybersecurity from agentic AI. Those are long-term trends too, which Lim considers increasingly inseparable from business success. 

Elizabeth Heathfield: Welcome to FS-ISAC’s podcast, FinCyber Today. I'm Elizabeth Heathfield. In today's evolving cybersecurity landscape, building a scalable and repeatable model for success is critical. I recently sat down with Temasek’s CISO, Cheri Lim, to discuss how they've accomplished this over the last 50 years and her portfolio-based approach to cybersecurity.

Heathfield: So Temasek has a 50-year history of building a scalable and repeatable model of success. Talk about your role in enabling that.

Cheri Lim, Chief Information Security Officer, Temasek: First of all, Elizabeth, thank you for having me on your podcast. In fact, I think one of the key areas we realized early in the stage was really the fact that cybersecurity is a strategic risk for all companies.

And that to us, having a sound cyber resilience capability across not just Temasek but the portfolio is ultimately very important. And therefore, there was also this thinking: as we digitalize, we need to invest in cyber and invest in cybersecurity resilience. Which, in today's environment, if you look at a company that's not focused on cyber resilience, it's actually not in the trend towards growth, because cyber resilience is now almost part and parcel of a business license to operate. It plays a critical role, in a sense, in enabling business. It enables that business value in terms of your business continuity, your sustainability.

And if you have a secure digitalization effort – be it in terms of end users or your clients – there is confidence in the trust that you build. Knowing full well that the data that they share with you or the data that you have is secure. Knowing full well that even in downtime, you know your business can continue.

And then when we go into this specific aspect, we almost look at ourselves as cyber stewardship. One of the early visions that we had was really looking at Temasek being able to drive some of these collective resilience together with a portfolio and the ecosystem. Cyber is a team sport, and therefore, we believe that we have to come together to build that mindset across the organizations that we have a stake in.

Heathfield: So, tell me, how do you assemble your cybersecurity program as a portfolio?

Lim: At Temasek, we look at ourselves as a network organization. So cybersecurity is not a single company- or enterprise-level effort. Not only do we want to ensure that as an organization we are secure and we are resilient, but that has to translate into that network mindset, where we talk about this ideal or concept of collective resilience.

When we come together as a network organization, as an ecosystem, this is where we drive that cyber resilience on the broader perspective. And if our portfolio companies do not invest in cyber, it actually weakens their position to succeed. Because, as I shared earlier, we believe that cyber is a strategic risk. And it's a topic that we take to the boardroom.

Their leadership has to recognize that you need to invest in cyber. You need to put in effort in building that resilience, because your reputation in the event of a breach is important and your business continuity must be there. And through building resilience, not just from a cyber perspective, over and above that, it contributes to the entire organization’s resilience.

Heathfield: Obviously, as coming from an FS-ISAC point of view, that is music to my ears in terms of it being a collective effort. So how do you translate intelligence and information across your network? And how do you leverage the latest in security tools to be able to do that as well?

Lim: I think going back to this idea of a network organization, we know we cannot operate alone. Our assets are portfolio companies, and the ecosystem plays a very important part in building that overall resilience. So one of the key areas we look at in terms of our purpose is really working with some of our portfolio companies and even the ecosystem, the regulators, the key stakeholders, and the vendor space to kind of bring that together. So, for example, I think the first part of things you'll be looking at, potentially, is information sharing. That could come across in terms of best practices.

Certainly, there's a set of principles in terms of the solution stack from an architectural lens. We look at whether it's platform agnostic, how interoperable it is. And then we also ensure a certain level of efficacy by conducting proof of concept to test whether indeed the solution is doing what it's supposed to be doing, and then also looking at whether it fits our security requirements and needs.

So that's a whole set of established protocols that we look at when we evaluate tooling and solutioning. Beyond that, those are broad principles. We spend so much effort in deciding what kind of value a tool or solution is to us because, when we make that move, it is an investment that we take not just for us as a company, but at the same time, that same tool which we believe is effective addresses some of the security needs across the ecosystem.

We will also establish a more technical program with the stakeholders and the vendors so that it could be offered across the ecosystem or portfolio. And they too have benefits.

I think these are also areas that FS-ISAC has started having meaningful groups look at some of these tooling exchange challenges that we meet. Same thing – we do it with our portfolio companies, we do it with the ecosystem, and we have also built a very good bilateral partnership with some of the local government agencies as well.

Heathfield: The fact that you have cross-sector visibility can help you see issues in the supply chain earlier than maybe some others might see it. And obviously, supply chain risk is one of the biggest issues facing the financial sector. So I'd love to hear more from you on how you are able to leverage that visibility that you have and help protect the financial sector both in Asia Pacific but also more broadly and be able to share out that information early because you are getting some indicators of potential supply chain vulnerabilities and things like that, maybe even before others do in the sector.

Lim: Yeah, So, you’re absolutely right. I think we've seen the supply chain increasingly affecting companies. It has to be multifold.

I think our first part really is how do you onboard your vendors. If you rely on your vendors and trust them to do a certain level, there's the contractual side of the house. That's also the part where you also need to do a certain level of due diligence – do they meet a certain level of criteria from a security angle and from a contractual angle.

And beyond that, I think onboarding of your vendor with a set of questionnaires to ensure that due diligence is done is one step. The second step, we do need to rely on some level of solutioning, especially with how fast these threats are moving, to monitor some of the high-risk vendors that we may have. You need to set criteria about what constitutes a vendor in the high-risk zone, and you need to put in place a certain level of monitoring to effectively safeguard yourself. And there must also be an established process for the vendor to declare to you if they are suffering a breach that may affect you. And there must be a certain level of SLA being set.

Beyond that, I think there are also companies, cyber companies, that are looking into building capabilities that illuminate the supply chain risk that a company has. And this is also where we believe in investing in some of these catalytic solutions to safeguard against supply chain risk.

And in terms of the supply chain, I think one clear area that we definitely need to have is the ability to understand who your third-party, fourth-party, fifth-party vendors are. Beyond that, what is the SBOM sort of interconnectivity? So, for example, if you have a vendor that relies on this specific component and that component is now being affected, you will be able to trace back to see whether you are potentially being breached.

And that in terms of illumination of the supply chain risk will be something that is highly valuable and required in terms of safeguarding our risk. Now that will definitely help if you can bring such a technical capability into our security solutioning for our monitoring.

Heathfield: So you mentioned AI and that you're investing in some of that. Now it occurs to me that the whole SBOM traceability question was around a lot two years ago. And then it kind of, at least from my perspective, it sort of went away. And now potentially you could be using agents to be monitoring and tracking SBOMs in a way that is scalable, right? Because people were talking about ‘well, they change all the time and everybody's always updating software all the time. So how can you keep an SBOM current?’ Now, maybe that is possible. So I'd love to hear your thoughts on, you know, how you guys are leveraging AI and thinking about AI in the next six to 12 months in terms of your cyber tooling.

Lim: So I think AI will change the game, to be honest. From company to company, everyone is adopting AI to different levels. I think there is a lot of excitement about bringing AI to enhance productivity. But I personally think that, as a security professional, what's most important before the deployment of AI is to ensure you have a fantastic or well-established AI governance framework. Which means that, with every AI or every model – in this case, GenAI model or LLM – that you deploy, there is a level of security taken in that deployment to ensure it's secure and to ensure that as it continues to function and use the data in your environment for the productivity purpose, etc., that it's safeguarded against any of these hallucinations, and things like that.

And there's also a certain level of testing in the models to ensure that they continue to perform the way they should be performing without any of those drifts that may occur, certain breaches, with certain safety or security considerations that will affect a company.

So, it's foundational that every company should be looking at establishing an AI governance framework before even going into how you want to leverage the AI capability for cyber, for your productivity, etc.

Beyond the AI governance framework, there ought also to be a committee that looks at, for example, responsible use of AI, right? What are the use cases that you can use that lie with your ethical considerations, your safety parameters, and your security? And that certainly is not a question or a problem that the cyber folks can address. It requires several stakeholders in the company to look at that.

And then when we are done with these, then we can start looking at how AI can transform the way we do cyber. I'm very excited about this because it is an area of interest. But with agentic AI, these complex models or even SLMs, small language models, I believe there are new capabilities that we can definitely tap into in terms of the agentic side of the house. This will include things like, perhaps, automated triage in terms of all the alerts from a security monitoring lens. It could also be automated in investigation and even response, helping the analysts, so your analysts don't have to comb through so much data.

And the other aspect of things is that if each of these agentic AI could communicate with each other, each agent potentially will perform a specific task, right? But as they perform a specific task – I know the industry is moving towards the MCP protocol for communication. And if one agentic AI could potentially communicate with another agent on another platform using the same protocol, that would then open up things for us to have even greater efficacy and efficiency in driving some of the cyber work.

To be honest, we are playing catch-up. The adversarial AI space from an attacker's viewpoint has evolved so much and so fast that I don't think a white hat from an AI agent's perspective is fast enough.

So, for all the providers who are looking at deploying agentic AI to your client, I think this is a shout-out to them that when they develop this model, they must have security in mind, as well as the development of these AI agents for cyber. It could potentially translate into an independent third-party trust and safety report about the AI models that are used in this agent and how they continuously build that robust process to ensure secure AI agents in your space to drive the cyber workloads. And that has to happen.

Heathfield: What else do you think, looking forward – what do you see as the portfolio with AI, with quantum, what do you see as the portfolio of technologies that CISOs and security teams need to be thinking about right now and making sure that they're able to put the governance and frameworks in place to be able to adapt to, given how fast everything's moving?

Lim: Yeah. Right now, I think the focus must be on AI and how you secure it. I think one of the key challenges in securing AI is that it's really how the model evolves. It is a black box to us. If it's provided as a SaaS, if it is provided by the service provider as a package, and that would be something that vendors or the solutions provider – if they want to make a difference – they should and ought to be transparent about the trust and safety indicators. Or report … the robust process they do to build them and continuously ensure they behave the way they should.

While companies who intend to invest in AI, be it for productivity, or your cyber tools, etc., I think a key aspect of securing these AIs is in terms of the identities of the AI agents, for example, or the identities of a machine identity versus a human identity. Because at the end of the day, you will be authorizing your agentic AI agents to actually perform certain tasks. But of course, there's always a human in the loop for some of these more sensitive loads.

But what's important is if your identity is picked up – this is an AI agent doing this, this, this – it goes back to the fundamental concept of how you build security for the company that's multilayered. And a lot of it depends on the access control and goes back to the identity – that's tech. And if we can do that from an AI identity perspective, it's a good start to helping you with the monitoring and whatnot.

And you could also then do a certain level of user and system behavioral analytics, use AI to check AI on whether the identity, in this case a machine identity, is doing what it should be sentient to do or is actually doing something else. So some level of monitoring will happen, but the human in the loop will always be required. Just in what aspect? And how do you behave more intelligently beyond what these agents are able to do?

Heathfield: Anything else that you wanted to cover? I think we've had a great conversation, but I'd love to hear if there's any other points that you wanted to make.

Lim: On the topic of AI – it is exciting times and I'm really looking forward to leveraging some of these capabilities. It's going to be transformational, but we just have to do it in a safe and secure manner.

FinCyber Today

FinCyber Today is a podcast from FS-ISAC that covers the latest developments in cybersecurity, contemporary risks, financial sector resilience and threat intelligence.

Our host Elizabeth Heathfield leads wide-ranging discussions with cybersecurity leaders and experts around the world who bring practical ideas on how to confront cyber challenges in the financial sector, improve incident response protocols, and build operational resilience.

Amid the clutter and noise, FS-ISAC Insights is your go-to destination for clarity and perspectives on the future of finance, data, and cybersecurity from C-level executives worldwide.

© 2026 FS-ISAC, Inc. All rights reserved.

Listen on

FS-ISAC members around the world receive trusted and timely expert information that increases sector-wide knowledge of cybersecurity threats.

Learn More