Chapter 1 Cyber Threats Singapore Faces NATIONAL CYBER SECURITY COMMAND NATIONAL CYBER THREAT MONITORING CENTRE (NCTMC) NCTMC plays a key role in maintaining cyber situational awareness to aid in the discovery of cyber threats that are of national significance. NCTMC also forewarns the nation’s critical sectors on emerging cyber threats unique to their operating environment. In cyber incidents involving multiple sectors, the centre will coordinate with the Sector Leads to provide quick and timely alerts to cross-sector threats as part of the national-level response. NATIONAL CYBER INCIDENT RESPONSE CENTRE (NCIRC) As the National Cyber Incident Manager, NCIRC maintains strategic oversight of significant cyber incidents in the critical sectors to assess Singapore’s cyber posture. SingCERT is the national CERT. Under the aegis of NCIRC, it tracks the broader Singapore cyber landscape to identify significant threats, and issues cybersecurity advisories to Singaporeans. SingCERT also works with foreign CERTs to manage cross-border cyber incidents. (NCTAC) CRITICAL INFORMATION INFRASTRUCTURE (CII) NCIRC is the operational arm of NCSC that responds to cyber threats and incidents affecting the critical information infrastructure in Singapore. During cyber crises, NCIRC is responsible for coordinating cross-sector incident response efforts and directing national-level mitigation measures. NATIONAL CYBER THREAT ANALYSIS CENTRE THREATS TO NCTAC conducts all-source research and analysis to provide strategic insights on the Singapore cyber landscape. NCTAC’s research and analysis also include geopolitical perspectives, which often underpin the motivations and actions of cyber actors. Cyber-attacks on CIIs can result in widespread disruptive and destructive impact on society and the economy. A particularly severe attack could even have spillover effects on the region and the rest of the world. Cyberattackers are constantly sharpening their ability to carry out such attacks, and their objectives range from financial gain to ideological or nationalistic causes. CSA has identified 11 CII sectors. They are: Energy, Water, Banking & Finance, Government, Healthcare, Media, Infocomm, Land Transport, Maritime, Aviation, and Security & Emergency. In 2016, several CIIs were affected by malware infection, in particular, ransomware. To better guard against such threats and attacks, the Government has been conducting cyber exercises over the years to improve the critical sectors’ readiness and incident response plans. In March 2016, Exercise Cyber Star, a multi-sector exercise was conducted by CSA. It brought together representatives from the Infocomm, Energy, Banking & Finance, and Government sectors to exercise their responses to a nationwide cyber-attack. NCTAC’s insights aim to inform CSA operations, national cyber policy-making, and contribute to public education. 10 11

Select target paragraph3