SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
• Owners of computers or computer systems designated as STCC: for example, the temporary systems used to support the distribution of critical vaccines during a pandemic could fall under this category (in effect as of 31 October 2025). • Designated entities of special cybersecurity interest (ESCI): if the function of such designated entitles perform is disrupted, or if the sensitive information contained in their computer systems is disclosed, there will be a significant detrimental effect on the defence, foreign relations, economy, public health, public safety or public order of Singapore; (to come into effect at a later date). • Designated providers of major foundational digital infrastructure services (FDI): these services pro - mote the availability, latency, throughput or security of digital services, and relate to cloud computing services and data facility services (to come into effect at a later date). The amendments to the Cybersecurity Act impose obligations on these new entities that are similar to those already in force relating to CIIs, such as: • providing the Commissioner with information; • complying with any codes of practice, standards of performance or written directions that may be issued or approved by the Commissioner; and • notifying the Commissioner of any prescribed cybersecurity incident. 2.3 Incident Response and Notification Obligations Under the Cybersecurity (Provider-Owned Critical Information Infrastructure) Regulations 2018 and Cybersecurity (Systems of Temporary Cybersecurity Concern) Regulations 2025, cybersecurity incidents that must be reported to the Commissioner include: • any unauthorised hacking of the relevant computer or computer system/STCC or the interconnected computer or computer system to gain unauthor - ised access to or control of the relevant computer or computer system/STCC or interconnected com - puter or computer system; • any installation or execution of unauthorised software, or computer code, of a malicious nature on the relevant computer or computer system/
STCC or the interconnected computer or computer system; • any man‑in‑the‑middle attack, session hijack or other unauthorised interception by means of a computer or computer system of communica - tion between the relevant computer or computer system/STCC or the interconnected computer or computer system, and an authorised user of the relevant computer or computer system/STCC or the interconnected computer or computer system as the case may be; and • any denial of service attack or other unauthorised act or acts carried out through a computer or com - puter system that adversely affects the availability or operability of the relevant computer or computer system/STCC or the interconnected computer or computer system. Since 31 October 2025, incident reporting for owners of CII was expanded to include the following circum - stances, where the CII owner: • becomes aware that the cybersecurity incident has any effect which is observable by any member of the public; • becomes aware that the cybersecurity incident was caused by or related to an exploitation of a vulner - ability which was a zero-day vulnerability at the time of the exploit; • becomes aware that any indicator of compromise that is associated with an advanced persistent threat and was previously notified in writing to the CII owner by the Commissioner of Cybersecurity was detected in relation to the cybersecurity inci - dent; and • suspects that the cybersecurity incident may have been caused by an advanced persistent threat. The competent supervisory authority for the CII incident notification regime is the Commissioner of Cybersecurity within the CSA. The CII owner must submit an initial report (with the prescribed details) of the cybersecurity incident or occurrence of one of the above-mentioned circumstances within two hours after the occurrence of the cybersecurity incident or circumstance. This notification must be made by call - ing the telephone number specified by the Commis - sioner.
287 CHAMBERS.COM
Powered by FlippingBook