FOREWORD Operational Technology (OT) systems, especially Industrial Control Systems (ICS), are an increasingly attractive target for highly-sophisticated cyber actors around the world. From the 2010 Stuxnet incident, the Ukraine power grid attack in 2015 to the recent ransomware that affected Norwegian firm Norsk Hydro, successful cyber-attacks on ICS have resulted in disruption of key infrastructure and essential services, as well as hefty financial losses. As we push towards our Smart Nation vision, Singapore, as a hyper-connected commercial hub, will need robust defences to fend off these advanced attackers. The global trend of malicious attacks on OT systems shows no signs of abating. The threat is grave as OT forms the technological bedrock of our everyday lives and the economy, especially with the growing connectivity between Information Technology (IT) and OT systems. We rely on secure OT systems to regulate our traffic lights and rail networks, power our electricity grid and synchronise sensors monitoring our water supply, among other essential services. It is therefore vital for Critical Information Infrastructure owners and regulators of these sectors in Singapore to constantly review and improve the cybersecurity posture of their ICS to ensure that their systems are secure and resilient. At our recent nationwide cyber exercise codenamed Ex CyberStar, CSA, together with all 11 CII sectors, was tested on complex cyber-attack scenarios including, for the first time, a widespread compromise of ICS. The exercise revealed certain areas for improvement in operations and processes. CSA has launched the OT Cybersecurity Masterplan to create deeper awareness and understanding of the cybersecurity landscape; including the challenges faced by OT stakeholders from the public and private sectors. The Masterplan aims to consolidate and guide the development of OT cybersecurity initiatives to address key challenges, as well as mitigate the emerging threat vectors. Cybersecurity is a collective responsibility – the government has taken the lead but we will also need everyone to play their part. We hope the OT Cybersecurity Masterplan will catalyse the collective development of localised capabilities and competencies in OT cybersecurity. To do so, CSA will work closely with our partners in the cybersecurity ecosystem and the industry sectors that own OT systems, toward a resilient OT cyber environment so that our people can enjoy the benefits and conveniences which technology brings. David Koh Commissioner of Cybersecurity and Chief Executive Cyber Security Agency of Singapore OPERATIONAL TECHNOLOGY CYBERSECURITY MASTERPLAN 2019 1

Select target paragraph3