Parliament Sitting on 11 January 2022

QUESTION FOR WRITTEN ANSWER


22. Ms He Ting Ru: To ask the Minister for Communications and Information (a) what are the precautions that should be taken in Singapore’s cyberspace to protect the digital security of Singaporeans against cyberattacks by private firms allegedly at the behest of state actors and state-backed entities; and (b) what additional and updated steps are being taken to address the risk of such attacks in the wake of developments over the last six months.

Answer:

1. Mr Speaker, the cyberspace is transnational and borderless. This means that cyberattacks can by conducted by anyone, from anywhere in the world. Regardless who the malicious actor is, putting in place cyber resilience measures to protect ourselves is key. 

2. 2021 put cybersecurity under the spotlight with a spate of cyberattacks and serious vulnerabilities discovered around the world; the most recent event of concern being the Log4Shell vulnerability found in an open-source Java package that is widely used by software developers. When there are known incidents and vulnerabilities, the Cyber Security Agency (CSA) takes immediate steps to ensure that our Critical Information Infrastructure (CII) and enterprises are secure.

3. In the case of Log4Shell, CSA called for two emergency meetings with CII sectors to issue technical details and mitigation solutions, and heightened monitoring for unusual activity. Public advisories and alerts were issued; trade associations and chambers were also briefed on the urgency for enterprises to implement the mitigation measures. 

4. To strengthen our cybersecurity, CSA encourages adopting a “zero-trust” posture. This comprises two key principles: first, do not trust any activity on your networks without first verifying it and second, ensure constant monitoring and vigilance for suspicious activities. To raise standards, CSA is developing the CII Supply Chain Programme to ensure that CII owners and their vendors adhere to international best practices for supply chain risk management. At the same time, CSA also developed actionable cybersecurity toolkits and resources for businesses under the SG Cyber Safe Programme to improve their cyber defences. These toolkits and resources can be found on CSA’s website.

5. CSA has consistently advocated that the best defence against cyberattacks is a population that is vigilant and adopts good cyber practices. Businesses and organisations are responsible for their own cybersecurity and must take action to strengthen their posture. This includes regularly updating their software and systems, and practising incident response and business continuity plans to ensure that employees are well-prepared when incidents happen. Individuals should practise good cyber hygiene and stay vigilant against phishing links. We must all strengthen our defences to participate in the digital domain safely and securely.
 
Opening Remarks by Mrs Josephine Teo, Minister of Communications and Information, at Graduation Ceremony and Launch of New Initiatives for ‘Upskill 2022’ , on 14 June 2022 Speeches Digital Readiness, Infocomm Media 14 Jun 22
The United Kingdom-Singapore Digital Economy Agreement Enters into Force Press Releases Infocomm Media 14 Jun 22
Transcript of speech by Mrs Josephine Teo, Minister for Communications and Information, at the Singapore Press Club's 50th Anniversary Press Ball, on 10 June 2022 Speeches Public Comms, Infocomm Media 10 Jun 22
Transcript of speech by Mrs Josephine Teo, Minister for Communications and Information, at Singapore Book Fair 2022 and Youths Help Seniors Go Digital Workshop on 5 June 2022 Speeches Infocomm Media, Libraries 05 Jun 22
Speech by Senior Minister of State Dr Janil Puthucheary, at the Opening of the Quantum Technology Summit, TechXLR8 Asia (part of Asia Tech x Singapore 2022), on 1 June 2022 Speeches Infocomm Media 01 Jun 22
Speech by Senior Minister of State Dr Janil Puthucheary, at the Opening of ATxEnterprise Industry Headliners Stage (Part of Asia Tech x Singapore 2022) on 1 June 2022 Speeches Infocomm Media 01 Jun 22