Cybersecurity 2026

SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC

The CSA operates the Singapore Cyber Emergency Response Team (SingCERT), which is Singapore’s national cyber-incident response team for its constit - uents. SingCERT facilitates the detection, resolution and prevention of cybersecurity-related incidents and provides a public channel for incident reporting. Personal Data Protection Commission The PDPC was established in January 2013 as Singa - pore’s data protection authority. It is under the purview of the MDDI and tasked with enforcing and adminis - tering the PDPA. The PDPC is led by the Commis - sioner for Personal Data Protection. Please refer to 1.2 Cybersecurity Laws . The PDPA confers powers on the PDPC to enforce the PDPA, which include powers relating to: • alternative dispute resolution (eg, mediation); • reviews of data subjects’ access and correction requests; • investigations to ensure compliance with the PDPA (including the DNC provisions); and • voluntary undertakings. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Please refer to 1.2 Cybersecurity Laws and 1.3 Cybersecurity Regulators . 2.2 Critical Infrastructure Cybersecurity Requirements Generally, owners of CII are required to comply with a set of general duties, such as: • comply with notices issued by the Commissioner to provide information on the technical architecture of the CII; • comply with codes of practice, standards of perfor - mance or written directions in relation to the CII; • notify the Commissioner of any change in owner - ship of the CII;

• notify the Commissioner of any prescribed cyber - security incidents (please refer to 2.3 Incident Response and Notification Obligations) ; • conduct regular audits of the compliance of the CII with the Cybersecurity Act, codes of practice and standards of performance; • conduct regular risk assessments of the CII as required by the Commissioner; and • participate in cybersecurity exercises as required by the Commissioner. The Cybersecurity Code of Practice for Critical Infor - mation Infrastructure (the “CII Cybersecurity Code”) requires owners of CII to put in place security base - line configuration standards for all operating systems, applications and network devices of a piece of CII that is commensurate with the cybersecurity risk profile of that CII. The security baseline configuration standards address the following security principles: • least access privilege and separation of duties; • enforcement of password complexities and poli - cies; • removal of unused accounts; • removal of unnecessary services and applications (eg, removal of compilers and vendor support applications); • closure of unused network ports; • protection against malware; and • timely update of software and security patches that are approved by system vendors. Following the commencement of the Cybersecurity (Amendment) Act, the Cybersecurity Act has been updated to cover four additional classes of entities. • Designated providers of essential services that do not own the CII used for the continuous deliv - ery of the essential services they are responsible for (third-party-owned CII): the providers of such essential services are required to obtain legally binding commitments from the third-party to provide the necessary information or adhere to prescribed standards relating to cybersecurity, etc. The Commissioner may order such providers to cease using the third-party-owned CII if they do not obtain the legally binding commitments (in effect as of 31 October 2025).

286 CHAMBERS.COM

Powered by