INTRODUCTION “Cybersecurity is important for Singapore given our high dependence on information technology and the Internet, and cybercrime is also growing. Cyber-attacks can take many forms and come from many sources. They range from defacements of website and data theft, often by persons who hide behind the anonymity of cyberspace [and] can also include systemic threats” Deputy Prime Minister Teo Chee Hean, Committee of Supply, 6 Mar 2013 Cyber-attacks are increasingly frequent, sophisticated and impactful. Globally, we have seen a surge in the number of cyber incidents, such as ransomware, cyber theft, banking fraud, cyber espionage and disruptions to Internet services. Attacks on systems that run utility plants, transportation networks, hospitals and other essential services are more frequent. Successful attacks result in disruptions which could cripple economies, and lead to loss of life. The advent of the Internet of Things will further increase the attack surface. Left unchecked, malicious entities can find more ways to launch attacks, steal data and make cyberspace dangerous for all. The result is a cyberspace that is hostile, and where basic interactions and transactions cannot be trusted. Singapore has consistently taken cyber threats seriously and developed timely responses. Our cybersecurity journey started a decade ago with the first Infocomm Security Masterplan in 2005. The Masterplan was a coordinated effort to secure Singapore’s digital environment and strengthen public sector cybersecurity capabilities. Since then, Singapore’s cybersecurity capabilities have grown. With the formation of the Singapore Infocomm Technology Security Authority (SITSA) in 2009, we developed the capability to coordinate national-level responses against large-scale cyber-attacks, particularly against our critical information infrastructures. Our Smart Nation Journey 6 INTRO OUR CYBERSECURITY JOURNEY SO FAR 2005 Infocomm Security Masterplan (ISMP) (2005-2007) The Info-communications Development Authority (IDA) launched Singapore’s first Infocomm Security Masterplan to coordinate cybersecurity efforts across the Government. A key priority was building basic capabilities within the public sector to mitigate and respond to cyber threats. In 2015, the Cyber Security Agency of Singapore (CSA) was formed as the central agency to oversee and coordinate all aspects of cybersecurity for the nation. CSA is empowered to develop and enforce cybersecurity regulations, policies, and practices. 2008 Infocomm Security Masterplan (2008-2012) The second Masterplan focused especially on the security of Singapore’s CIIs, with a vision of making Singapore a ‘Secure and Trusted Hub’. While much has been achieved so far, the threats have also become more sophisticated. We are even more dependent on digital technology, especially as we develop a Smart Nation of digitally-enabled businesses and lives. Cybersecurity, beyond a necessity to defend and protect, is also an enabler for our future economy and society. 2009 Singapore Infocomm Technology Security Authority (SITSA) SITSA was established under the Ministry of Home Affairs (MHA) to safeguard Singapore against cyber-attacks and cyber-espionage. SITSA’s responsibilities as a national specialist authority included overseeing the preparation and securing of CIIs against cyber threats. This Strategy is a statement of Singapore’s vision and priorities for cybersecurity. It aims to catalyse participation by all stakeholders - government agencies, the cyber industry, professionals and students, academia and researchers, and providers of essential services. Together, we will ensure the resilience of our national infrastructure and a safer cyberspace, supported by a vibrant ecosystem that provides good jobs and economic opportunities for Singaporeans. It also signals Singapore’s willingness to forge strong partnerships with the international community to combat the transnational nature of cyber threats. Singapore is transforming to become a Smart Nation, where Singaporeans are empowered by technology to lead meaningful and fulfilling lives, where digital connectivity leads to stronger community bonds, and where the power of networks, data and infocomm technologies is harnessed to create economic opportunities. Smart Nation is a whole-of-nation rallying call for citizens, companies, and government agencies to work handin-hand to seize the many possibilities of digital technology. We are putting in place the necessary infrastructure and policies to build capabilities, and to create a conducive ecosystem where people and companies co-create innovative solutions to enhance the lives of our citizens. 2013 National Cyber Security Masterplan (NCSM2018) The third Masterplan expanded to cover the wider infocomm ecosystem, which includes businesses and individuals, in addition to the previous focus on CIIs. It sought to make Singapore a ‘Trusted and Robust Infocomm Hub’. 2013 National Cybersecurity R&D (NCR) Programme The National Cybersecurity R&D Programme was established in October 2013 to develop R&D expertise and capabilities in cybersecurity for Singapore. It aims to improve the trustworthiness of cyber infrastructure, with emphasis on security, reliability, resilience and usability. It is now co-managed by the National Research Foundation and the Cyber Security Agency of Singapore. 2015 Cyber Security Agency of Singapore (CSA) CSA was established under the Prime Minister’s Office (PMO) and is managed administratively by the Ministry of Communications and Information (MCI). With its formation, all agencies and initiatives related to cybersecurity – the Singapore Computer Emergency Response Team (SingCERT), national cybersecurity master-planning and development functions from IDA, and SITSA – were brought under a single agency. CSA is dedicated to the development of cybersecurity, protection of CIIs and essential services, and coordination of national efforts against large-scale cyber incidents. CSA is also empowered to develop and enforce cybersecurity regulations, policies, and practices. It will coordinate efforts across government, industry, academia, businesses and the people sector, as well as internationally. 2015 Cybercrime Command The Ministry of Home Affairs (MHA) established the Cybercrime Command as a unit within the Criminal Investigation Department (CID) of the Singapore Police Force (SPF). The Command works closely with other law enforcement agencies and industry stakeholders, including the INTERPOL Global Complex for Innovation (IGCI) located in Singapore, to investigate cybercrimes. 2016 National Cybercrime Action Plan (NCAP) The NCAP was launched by the Ministry of Home Affairs (MHA) in July 2016. The plan spells out the priorities needed in the fight against cybercrime. These include a) the need for public education on staying safe in cyberspace; b) the development of capabilities to fight cybercrime; c) strengthening cybercrime laws; and d) building local and international partnerships. 2014 National Cyber Security Centre (NCSC) The NCSC was formed as part of SITSA, to maintain cyber situational awareness, correlate cybersecurity events across sectors, and coordinate with the respective lead agencies to provide a national-level response to large-scale, cross-sector cyber incidents. INTRO 7

Select target paragraph3