SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
In terms of cybersecurity regulation, the Cybersecu - rity Act 2018 (see further details at 1.2 Cybersecurity Laws ) was updated in 2024 to keep pace with chang - es in technology, business models and the cyberthreat landscape. In so doing, the amendments will allow the Cyber Security Agency (CSA) to extend their reg - ulatory oversight to important systems and entities not previously covered under the Cybersecurity Act 2018, adopting a risk-based approach to regulating entities for cybersecurity. In particular, the amend - ments extend the Act’s scope to regulate additional systems where compromise could be detrimental to Singapore’s national interests to better account for new technology and business models. 1.2 Cybersecurity Laws Cybersecurity and cyber-risk management in Sin - gapore is broadly regulated by a set of overlapping pieces of legislation which address the issues of national cybersecurity, cybercrimes and personal data protection. In addition, certain sectoral regulators are empowered to directly address cybersecurity issues in their respective sectors through regulatory codes, guidelines, notices, and instruments. Cybersecurity Act 2018 (Cybersecurity Act) The Cybersecurity Act is the dedicated cybersecurity law which sets out the overarching framework for the oversight of national cybersecurity issues in Singa - pore, including the designation of computer systems (physical and virtual) as Critical Information Infrastruc - ture (CII) in essential sectors and co-ordinating the national response to cybersecurity incidents, amongst other things. Under the Cybersecurity Act, the Com - missioner of Cybersecurity is empowered to issue binding codes of practice, standards of performance and directions to regulated entities. The Cybersecurity Act requires owners of CII to notify the Commissioner of Cybersecurity in the event of the occurrence of certain cybersecurity incidents related to their CII. A cybersecurity incident refers to an act or activity carried out without lawful authority on or through a computer or computer system that jeopard - ises or adversely affects its cybersecurity or the cyber - security of another computer or computer system.
Since 2022, the Cybersecurity Act provides for the licensing of certain cybersecurity service providers (CSPs). At present, this includes CSPs that provide penetration-testing and managed security operations centre monitoring services. To keep up with the evolving cybersecurity threats and nature of businesses, the Cybersecurity (Amendment) Bill was passed in Singapore Parliament on 7 May 2024 to expand the CSA’s oversight to new entities beyond CII owners. The four new categories of enti - ties are: • essential service providers who use CII owned by a third-party; • major foundational digital infrastructure (FDI) ser - vice providers; • entities of special cybersecurity interest (ESCI); and • owners of systems of temporary cybersecurity concern (STCC). Importantly, the amendments have extended the defi - nition of CIIs to include any computer or computer system, whether they are physical or virtual, located wholly or partly in Singapore which may be designat - ed as CII. Such designation may arise if the Commis - sioner is satisfied that the computer or computer sys - tems are necessary for the continuous delivery of an essential service, and the loss or compromise of such systems will have a debilitating effect on the availabil - ity of the essential service in Singapore. On 31 Octo - ber 2025, several key provisions of the Cybersecurity (Amendment) Act 2024 came into force. Please refer to 2.2 Critical Infrastructure Cybersecurity Require- ments for more details. Computer Misuse Act 1993 (CMA) The CMA sets out the enforcement and penalty frame - work against perpetrators of cyber-related offences, such as the unauthorised access to and modification of computer material, unauthorised use or intercep - tion of a computer service, unauthorised obstruction of use of a computer and unauthorised disclosure of a password or access code. The CMA empowers the police and other government authorities to investigate and prosecute perpetrators of cybercrimes. Where an offence under the CMA is committed by any person outside Singapore, the person may be dealt with as
283 CHAMBERS.COM
Powered by FlippingBook