SINGAPORE Trends and Developments Contributed by: Sheena Jacob, Sherman Poon and Andre Choo, CMS
Cyber-insurance cover is low compared to Europe and USA The cyber-insurance market is much smaller than expected, with many businesses reluctant to invest in plans and undergo the necessary review for the purpose of obtaining insurance. The Singapore busi - ness cyber-insurance market was valued at only USD56.72 million in 2025 and is projected to only grow to USD87.42 million by 2030 (see here ). Insurers have responded to rising claims and systemic risks by tightening underwriting standards, narrowing cover - age, and imposing stricter cybersecurity preconditions (see here and here ). Policies now commonly require demonstrable cyberhygiene, incident response plan - ning, and regular security testing (see here ). Legal and Regulatory Developments in Singapore Issuance of implementation directives In 2025, the government issued implementation direc - tives to several tech titans to combat government impersonation scams, relying on provisions under Part 4 of the Online Criminal Harms Act 2023 (OCHA) applying to designated online services. Between June 2024 and June 2025, the SPF identified an estimated 2,000 advertisements and online profiles on Facebook linked to government impersonation scams. Under the issued implementation directive, Meta was required to adopt measures such as facial recognition to pre - vent such scams on Facebook (see here ). Apple and Google were also directed to take certain steps to pre - vent spoofing of Singapore government agencies via their phone messaging platforms (see here ). Pursuant to Section 51 of the OCHA, failure to comply with an implementation directive may result in fines of up to SGD1 million, as well as additional daily fines of up to SGD100,000. These directives issued to Meta, Apple and Google are the first to be made under the OCHA since the provisions empowering authorities to issue implementation directives came into force on 24 June 2024. The issuance of implementation directives to Apple and Google also indicates that their respective phone messaging platforms have been added to the initial list of designated online services, which includes Carousell, Facebook Marketplace, Facebook Adver - tisements and Facebook Pages (see here ).
were reported to the CSA in 2024, marking a 49% increase compared with 2023 (see here ). Phishing scams recorded the highest number of reported cases among all scam types in the first half of 2025, with a 10.9% increase to 3,779 cases in the first half of 2025 (see here ). The amount lost to phishing scam cases also increased significantly, rising by 134% to approximately SGD30.4 million in the first half of 2025, compared with around SGD13 million during the same period in 2024 (see here ). Evolution of ransomware into multi-dimensional extortion Ransomware continues to pose a significant threat. Ransomware attacks increased by more than 20% in 2024 (see here ). The CSA noted that ransomware threats are increasing in frequency and sophistica - tion. The attack model has evolved beyond simple data encryption. Threat actors now routinely employ “double” or “triple” extortion tactics, living-off-the- land techniques, and the exploitation of zero-day or unpatched vulnerabilities. Some also utilise social engineering, compromised credentials, and supply chain attacks to gain covert access to target networks (see here ). An example of ransomware is LockBit, first identified in September 2019, and which has become increas - ingly prevalent and sophisticated. Its prevalence has led to the CSA, Personal Data Protection Commission and the Singapore Police Force (SPF) releasing a joint technical advisory providing information on the model and recommended mitigation measures (see here ). In Singapore, the manufacturing sector is the prima - ry target of ransomware, accounting for 31.58% of reported incidents. Other affected industries include wholesale trade (12.87%) and real estate (11.11%), emphasising the ransomware threat’s reach into both industrial and service-oriented sectors (see here ). The reputational and regulatory risks associated with data leakage increase pressure on victims to resolve inci - dents quickly. At the same time, law enforcement and regulators continue to discourage ransom payments, highlighting the tension between commercial realities and public policy objectives.
300 CHAMBERS.COM
Powered by FlippingBook