Conversations with Francis Yeow
By Tan Beng Yang and Emerald Lo
Francis Yeow is Vice President, Cybersecurity and Compliance, at ST Logistics. He oversees cybersecurity, regulatory compliance, cyber risk, assurance and data protection. In this interview, he offers an honest look at a career in cybersecurity, explains how AI is reshaping both threats and opportunities, and shares why young people should be prepared to step beyond their comfort zones.
Could you introduce yourself and tell us what you do?
I am the Vice President of Cybersecurity and Compliance department at ST Logistics and serve as the company’s Data Protection Officer. My role is to protect the organisation from digital threats, manage cyber risk, meet cybersecurity and data protection obligations, including those under the PDPA, and oversee cyber assurance and audits.
What does a typical day look like for you?
Because I wear many hats, no two days are the same. On a quieter day, I begin by reviewing cybersecurity news and incidents from around the world. I try to understand what went wrong elsewhere and what we can do to prevent the same thing from happening to us. Those are the days when I can focus on learning and strengthening our defenses.
On a difficult day, we may be dealing with a cyber incident or a new threat that could affect us. The pace changes immediately: decisions must be made quickly, the pressure is intense and the situation can evolve by the minute. Other days are filled with meetings, strategic decisions and discussions with customers about cybersecurity.
Do the hours ever stretch beyond the normal workday?
The most predictable thing about cybersecurity is that the hours can be unpredictable. When an incident occurs, you cannot simply stop at 6 p.m.; the team may need to work through the night until the situation is contained. At a previous company, I once spent more than 48 hours in the office responding to an incident. It was so intense that I barely noticed how much time had passed.
What has kept you motivated to stay in the industry despite the hours?
I have asked myself that question many times. There were moments when I considered changing careers, and several friends have left the profession. A sense of purpose has kept me going. I work to support my family and my organisation, of course, but I also believe that my work contributes to Singapore and the wider community.
Cybersecurity is a shared responsibility. Law enforcement agencies, organisations and individuals all have a part to play. By protecting my organisation’s systems, I am also helping to make the wider community more secure. Ultimately, it is about building a safer digital environment for the next generation, because they will inherit the consequences of the choices we make today.
How is AI changing your work?
AI is advancing rapidly, and cyber threats are evolving alongside it. It is not only creating new risks; it is also making familiar threats faster to execute, easier to scale and more convincing.
Cybersecurity professionals must keep learning; it is simply part of the profession. A decade ago, cloud computing brought a major shift, and we had to learn quickly how to secure it. AI is today’s defining development. We need to understand how to use it responsibly, defend against AI-enabled attacks and protect AI systems from threat actors.
Technology itself is neutral. Threat actors can use AI to strengthen their attacks, while cybersecurity professionals can use it to improve detection, analysis and defence. AI can reduce work that once took days to a matter of hours, but speed alone is not enough. People must still validate the results, understand the context and make sound decisions.
Many young people worry that AI will take over their jobs. What would you say to them?
New technologies often create anxiety before they become part of everyday life. Aeroplanes and cars once seemed unfamiliar and even frightening; today, they are ordinary tools. I believe AI will follow a similar path. The challenge is not to avoid it, but to understand it, adapt to it and use it well.
The greater risk is not simply that AI may change jobs; it is that people may refuse to adapt as work changes around them. Those who learn to use new tools, exercise judgement and keep developing their skills will be best placed to find opportunities in that change.
AI is here to stay. Whether young people benefit from it will depend on how well they understand it and how willing they are to experiment, learn and use it responsibly. Headlines often focus on fear because fear attracts attention. Look beyond those headlines, examine the evidence and form your own informed view.
How is AI specifically affecting the compliance industry?
AI has accelerated compliance work. Many checks that were once highly manual, labour-intensive and time-consuming can now be supported by automation. Used well, AI can reduce the time required and help minimise routine human error.
However, over-reliance on AI creates its own risks. If people accept its output without supervision or independent checking, errors may go unnoticed. That is why we need a “human in the loop”: AI can support the work, but accountability, context and final judgement must remain with people.
Looking back, what led you into cybersecurity?
I did not enter cybersecurity because of the money, nor did I have a detailed plan to pursue it. In some ways, the career chose me. Before graduating from NUS, I was fortunate to receive an offer from a government agency to work in cybersecurity. Although I had taken cybersecurity modules at university, I would not say it was my passion then. Once I started working, however, I realised that the profession offered a sense of purpose far beyond earning a living.
The work continues to engage me because no two days are alike. Although it is an office-based profession, it is not simply about sitting in front of a screen. Much of the job involves making sense of complex situations, solving problems and making decisions under pressure. I enjoy the challenge of thinking on my feet.
That is why I describe cybersecurity as a career rather than simply a job. A job may be something you do for a salary; a career is something you build deliberately over time. You think about the capabilities you need, the experiences that will stretch you and the direction in which you want to grow.
You have moved across many organisations. What went into planning your career?
Earlier in my career, I moved across several organisations and sectors. I am grateful that the government gave me my first opportunity and introduced me to cybersecurity. I later joined the private sector because I wanted to step beyond my comfort zone, broaden my perspective and experience how different organisations operate. I also spent a period working outside Singapore. The environments varied, but the fundamentals of cybersecurity remained relevant wherever I went.
I encourage young people to consider opportunities beyond Singapore. Singapore’s international outlook can be an advantage when working abroad. Living and working in another country exposes you to different cultures, ways of thinking and approaches to business. If you return home later, you bring back a broader perspective and a richer set of experiences.
I was certainly nervous when I first moved overseas. Fear is natural whenever we step beyond what is familiar. In my experience, however, the fear was temporary. Once I became engaged in the work, built relationships and adapted to the environment, the unfamiliar gradually became normal.
Why do you encourage young people to look beyond places like London and New York?
I often advise young people not to focus only on well-known destinations or multinational companies. Emerging markets, including countries such as Laos or Vietnam, can offer equally meaningful experiences. In a less conventional environment, your skills and perspective may have a visible impact, and you may gain responsibilities and learning opportunities that are harder to find in a crowded, highly competitive market.
What mindsets have helped you in your career?
A willingness to take an unconventional path has been important in my career. I grew up in a family with limited means, so I learned early not to take opportunities for granted. Difficult choices still brought fear, but I came to understand that fear can inform a decision without controlling it.
Resilience matters just as much. Every career brings setbacks, criticism and outcomes that do not go to plan. You need the courage to face problems, learn from them and keep moving. Changing course when the evidence shows that something is wrong is not failure; it is sound judgement. The important thing is not to walk away at the first sign of difficulty.
You also volunteer in the community. Could you share more about that?
I volunteer as a mediator with the Community Mediation Centre, helping neighbours resolve disputes. When people live close to one another, disagreements are inevitable. The original issue may be small, but different perspectives and poor communication can cause it to escalate. My role is to help both sides understand each other’s concerns, identify common ground and work towards a practical resolution.
Mediation has taught me to listen carefully and pause before acting. Those habits are valuable in cybersecurity. During an incident, the instinct is often to rush towards a solution. I encourage my colleagues to step back long enough to see the bigger picture: What happened? What is the real impact? What must we do now, and how can we prevent it from happening again? Calm, informed decisions are usually better than hasty ones.
What advice would you give young people today?
Young people need to balance purpose, learning and financial needs. Salary matters, but it should not be the only consideration. A demanding opportunity may still be worthwhile if it offers meaningful experience, strong mentors or skills that will grow in value over time. Someone else may start on a higher salary, but the capabilities you build can create greater opportunities throughout your career.
Make education and career choices with intention. A variety of internships can be useful, but each experience should help you build a skill, test an interest or move towards a clearer goal. There is a difference between ten years of continuous growth and one year of experience repeated ten times. What matters is not simply how many roles you have held, but what you learned, how your responsibilities grew and how each step prepared you for the next.
What practical steps can students take to prepare for a career in cybersecurity?
When I meet a fresh graduate, I look for curiosity, practical judgement, resilience and a willingness to learn. Cybersecurity can be stressful, and no two incidents are exactly alike. Textbooks provide essential foundations, but professionals must also be able to assess unfamiliar situations, ask the right questions and respond sensibly as circumstances change.
Start by following cybersecurity incidents, emerging technologies and industry developments. Do not stop at reading what happened. Ask why it happened, how the organisation responded and what might have prevented it. With AI, go beyond being a user: learn how the technology works, where it can fail and how it can be secured. That depth of understanding will help you contribute practical ideas in interviews, and more importantly, solve real problems when you enter the profession.