FOREWORD
Operational Technology (OT) systems,
especially Industrial Control Systems
(ICS), are an increasingly attractive target
for highly-sophisticated cyber actors
around the world. From the 2010 Stuxnet
incident, the Ukraine power grid attack
in 2015 to the recent ransomware that
affected Norwegian firm Norsk Hydro,
successful cyber-attacks on ICS have
resulted in disruption of key infrastructure
and essential services, as well as hefty
financial losses. As we push towards
our Smart Nation vision, Singapore, as
a hyper-connected commercial hub, will
need robust defences to fend off these
advanced attackers.
The global trend of malicious attacks on
OT systems shows no signs of abating.
The threat is grave as OT forms the
technological bedrock of our everyday
lives and the economy, especially with the
growing connectivity between Information
Technology (IT) and OT systems. We rely
on secure OT systems to regulate our
traffic lights and rail networks, power our
electricity grid and synchronise sensors
monitoring our water supply, among other
essential services.
It is therefore vital for Critical Information
Infrastructure owners and regulators of
these sectors in Singapore to constantly
review and improve the cybersecurity
posture of their ICS to ensure that their
systems are secure and resilient. At
our recent nationwide cyber exercise
codenamed Ex CyberStar, CSA, together
with all 11 CII sectors, was tested
on complex cyber-attack scenarios
including, for the first time, a widespread
compromise of ICS. The exercise
revealed certain areas for improvement in
operations and processes.
CSA has launched the OT Cybersecurity
Masterplan to create deeper awareness
and understanding of the cybersecurity
landscape; including the challenges faced
by OT stakeholders from the public and
private sectors. The Masterplan aims to
consolidate and guide the development
of OT cybersecurity initiatives to address
key challenges, as well as mitigate the
emerging threat vectors.
Cybersecurity is a collective responsibility –
the government has taken the lead but we
will also need everyone to play their part.
We hope the OT Cybersecurity Masterplan
will catalyse the collective development of
localised capabilities and competencies
in OT cybersecurity. To do so, CSA will
work closely with our partners in the
cybersecurity ecosystem and the industry
sectors that own OT systems, toward a
resilient OT cyber environment so that
our people can enjoy the benefits and
conveniences which technology brings.
David Koh
Commissioner of Cybersecurity and
Chief Executive
Cyber Security Agency of Singapore
OPERATIONAL TECHNOLOGY CYBERSECURITY MASTERPLAN 2019
1