SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
Where the owner of the CII is unable to submit the prescribed details via calling the specified telephone number within a reasonable time, the owner may pro - vide the details by text message to the specified tel - ephone number or in writing via the form on CSA’s website. Supplementary details of the cybersecurity incident/ circumstance must be provided in writing in the form set out on CSA’s website within 72 hours after becoming aware of such occurrence. This includes any updates and supplementary details following from the initial notification, the cause of the cybersecurity incident, the impact of the cybersecurity incident and what remedial measures have been taken. A final incident report containing all the details in the initial notification and supplementary details (and any updates thereto) must be submitted via the form on CSA’s website within 30 days after the submission of the supplementary details. Sections 16I(1) and 17E(1) of the Cybersecurity Act also impose similar reporting obligations on desig - nated providers responsible for third-party-owned CII and owners of STCCs. When the new Parts 3C and 3D under the Cybersecu - rity (Amendment) Act are brought into force, there will be reporting obligations imposed on ESCIs and major FDI service providers as well. A single cyber-incident may trigger parallel reporting obligations under other regulatory regimes, depend - ing on the nature of the affected information and the regulated sector. If the incident involves a notifiable personal data breach, the organisation may also have to notify the PDPC within the statutory timeline and, where required, notify affected individuals. 2.4 State Responsibilities and Obligations Under Section 5 of the Cybersecurity Act, the Commis - sioner of Cybersecurity has a duty to monitor cyber - security threats in or outside of Singapore, advise the government or any other public authority on the national needs and policies in respect of cybersecu - rity matters generally, and respond to cybersecurity incidents that threaten the national security, defence,
economy, foreign relations, public health, public order or public safety, or any essential services of Singa - pore, whether such cybersecurity incidents occur in or outside Singapore, among other duties. Additionally, SingCERT routinely issues cybersecurity and cyber-hygiene advisories and alerts. SingCERT also works with the sectoral regulators to issue rel - evant alerts and advisories to industry players and to inform companies and affected individuals on cyber - security threats and incidents. The CSA has established programmes to raise base - line cyber-resilience across the economy and institu - tionalise engagement with industry partners. The SG Cyber Safe Programme provides structured support for organisations to strengthen cybersecurity, and the SG Cyber Safe Partnership Programme is intended to mobilise industry partners to develop training con - tent, products, services and outreach initiatives that encourage adoption of good cybersecurity practices. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Please refer to 1.2 Cybersecurity Laws for a summary of the sectoral cybersecurity laws applicable to the banking and finance sector. In the banking and finance sector, the MAS has issued a set of legally binding Notices on TRM and Cyber Hygiene which apply to FIs (eg, banks, insurers, capi - tal markets services licence holders, operators, and settlement institutions of designated payment sys - tems). These Notices impose obligations on FIs to enhance information security and mitigate the growing risks of cyberthreats. The TRM Notices include requirements to: • put in place a framework and process to identify critical systems; • make reasonable efforts to maintain a high avail - ability of critical systems;
288 CHAMBERS.COM
Powered by FlippingBook