Written Answer to Unanswered Oral Question

Extension of Government Cybersecurity Agencies' Advisory Support to Non-government Entities

Speakers

Summary

This question concerns Dr Tan Wu Meng’s inquiry into whether government agencies provide cybersecurity support to non-government entities like banks, healthcare institutions, and utilities providers. Minister for Communications and Information Mrs Josephine Teo replied that both government and non-government Critical Information Infrastructure (CII) entities are regulated under the Cybersecurity Act. She stated that the Cyber Security Agency provides support in network design and issues advisories on the latest threats and precautionary measures. Additionally, sector-specific regulators may impose further requirements for organisations within their domains, such as financial services or healthcare. The Minister emphasized that all organisations should utilise available resources to maintain strong cybersecurity hygiene and be prepared to respond effectively to attacks.

Transcript

36 Dr Tan Wu Meng asked the Minister for Communications and Information (a) whether the Cyber Security Agency and other related agencies provide advice, support and assistance to entities outside the .gov.sg Internet domain such as (i) banks (ii) NETS (iii) public healthcare institutions' intranet and internet-facing facilities (iv) utilities providers and (v) telcos to attain adequate cyber resilience against cyberattacks including distributed denial-of-service attacks; and (b) if so, what is the nature of the support.

Mrs Josephine Teo: In today’s cyber threat environment, a strong cybersecurity posture is essential. Even with best efforts, not all attacks will be prevented. There must therefore be resilience built into our systems. They must be robust and have the ability to resume normal operations without prolonged disruption.

For critical information infrastructure (CII), all entities, government and non-government, are regulated in the same way under the Cybersecurity Act. The Cyber Security Agency of Singapore provides cybersecurity support in the design of networks and systems, and issues advisories on the latest threats and the precautionary measures to be taken.

Sector regulators, such as for financial services, water and healthcare, may also have additional specific cybersecurity requirements for organisations operating within their sectors.

All companies and organisations, and not just those owning CIIs, should practise strong cybersecurity hygiene. They should make use of the resources available, to put in place the necessary cyber defences and be prepared to respond to cyber attacks swiftly and effectively.