Cybersecurity 2026

SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC

• establish a recovery time objective for each critical system; • notify the MAS of a system malfunction or IT secu - rity incident; • submit a root cause and impact analysis report to the MAS of the relevant incident within 14 days; and • implement IT controls to protect customer informa - tion from unauthorised access or disclosure. The Notices on Cyber Hygiene include requirements to: • secure administrative accounts; • apply security patching; The MAS has also published Guidelines on Outsourc - ing for banks and other FIs, which set out the MAS’s expectations of entities that have entered into an arrangement for ongoing outsourced services which are obtained or received by the bank/FI. The guide - lines list measures which include requiring the relevant entities to conduct due diligence, maintain ongoing oversight, and implement contractual safeguards that preserve auditability and supervisory access. 3.2 ICT Service Provider Contractual Requirements Under the TRM Guidelines, MAS sets out principles and best practices to in relation to third-party service providers, which include: • establish baseline security standards; • deploy network perimeter defences; • implement anti-malware measures; and • strengthen multi-factor authentication. • ensuring service providers have the requisite level of competence and skills to perform IT functions and manage technology risks; • conducting IT security awareness training pro - grammes for service providers who have access to FIs’ information assets; • identifying threats and vulnerabilities applicable to information assets that are maintained or support - ed by service providers; • assessing service providers’ disaster recovery capability and ensuring that disaster recovery

arrangements are established, tested and verified to meet FIs’ business needs; • ensuring service providers are accorded the same level of protection and subject to the same security standards in data security as FIs; • involving service providers in scenario-based cyber exercises to validate FIs’ response and recovery, as well as communication plans against cyber threats; and • reporting of phishing attempts to service providers. Under the MAS Guidelines on Outsourcing, MAS expects banks/FIs to conduct a self-assessment of their existing outsourcing arrangements against the several risk management practices, including (non- exhaustive): • carefully defining terms and conditions in outsourc - ing agreements governing relationships, obliga - tions, responsibilities, rights and expectations of parties; • retaining the ability to monitor and control risks when using sub-contractor(s); • establishing a structure for monitoring and control of outsourcing arrangements; • taking into account prescribed factors in risk man - agement when outsourcing outside Singapore; and • requiring the board and senior management to pro - vide information on structure and processes when outsourcing within a group. ICT service providers may fall under the upcoming category of designated providers of major FDI ser - vices under the Cybersecurity Act. “FDI services” are services that promote the availability, latency, throughput or security of digital services, and will be specified in the Third Schedule to the Cybersecurity Act once these provisions under the Cybersecurity (Amendment) Act come into force. This will include “cloud computing service” and “data centre facility service” (as defined under the Act). Once these provisions under the Cybersecurity (Amendment) Act come into force, designated pro - viders of major FDI services will be subject to obliga - tions such as providing the Commissioner with infor - mation, reporting prescribed cybersecurity incidents,

289 CHAMBERS.COM

Powered by