Chapter 1
Cyber Threats Singapore Faces
NATIONAL CYBER
SECURITY COMMAND
NATIONAL
CYBER THREAT
MONITORING
CENTRE (NCTMC)
NCTMC plays a key role in maintaining cyber situational
awareness to aid in the discovery of cyber threats that
are of national significance.
NCTMC also forewarns the nation’s critical sectors
on emerging cyber threats unique to their operating
environment.
In cyber incidents involving multiple sectors, the centre
will coordinate with the Sector Leads to provide quick
and timely alerts to cross-sector threats as part of the
national-level response.
NATIONAL
CYBER INCIDENT
RESPONSE CENTRE
(NCIRC)
As the National Cyber Incident Manager, NCIRC
maintains strategic oversight of significant cyber
incidents in the critical sectors to assess Singapore’s
cyber posture.
SingCERT is the national CERT. Under the aegis
of NCIRC, it tracks the broader Singapore cyber
landscape to identify significant threats, and
issues cybersecurity advisories to Singaporeans.
SingCERT also works with foreign CERTs to
manage cross-border cyber incidents.
(NCTAC)
CRITICAL
INFORMATION
INFRASTRUCTURE
(CII)
NCIRC is the operational arm of NCSC that responds
to cyber threats and incidents affecting the critical
information infrastructure in Singapore.
During cyber crises, NCIRC is responsible for
coordinating cross-sector incident response efforts
and directing national-level mitigation measures.
NATIONAL
CYBER THREAT
ANALYSIS CENTRE
THREATS TO
NCTAC conducts all-source research and analysis
to provide strategic insights on the Singapore
cyber landscape.
NCTAC’s research and analysis also include geopolitical
perspectives, which often underpin the motivations and
actions of cyber actors.
Cyber-attacks on CIIs can result in widespread disruptive
and destructive impact on society and the economy.
A particularly severe attack could even have spillover
effects on the region and the rest of the world. Cyberattackers are constantly sharpening their ability to
carry out such attacks, and their objectives range from
financial gain to ideological or nationalistic causes.
CSA has identified 11 CII sectors. They are: Energy,
Water, Banking & Finance, Government, Healthcare,
Media, Infocomm, Land Transport, Maritime, Aviation,
and Security & Emergency. In 2016, several CIIs were
affected by malware infection, in particular, ransomware.
To better guard against such threats and attacks, the
Government has been conducting cyber exercises over
the years to improve the critical sectors’ readiness and
incident response plans. In March 2016, Exercise Cyber
Star, a multi-sector exercise was conducted by CSA.
It brought together representatives from the Infocomm,
Energy, Banking & Finance, and Government sectors to
exercise their responses to a nationwide cyber-attack.
NCTAC’s insights aim to inform CSA operations,
national cyber policy-making, and contribute to
public education.
10
11