INTRODUCTION
“Cybersecurity is important for Singapore given our high dependence
on information technology and the Internet, and cybercrime is also
growing. Cyber-attacks can take many forms and come from many
sources. They range from defacements of website and data theft,
often by persons who hide behind the anonymity of cyberspace [and]
can also include systemic threats”
Deputy Prime Minister Teo Chee Hean,
Committee of Supply, 6 Mar 2013
Cyber-attacks are increasingly frequent, sophisticated
and impactful. Globally, we have seen a surge in the
number of cyber incidents, such as ransomware, cyber
theft, banking fraud, cyber espionage and disruptions to
Internet services. Attacks on systems that run utility plants,
transportation networks, hospitals and other essential
services are more frequent. Successful attacks result in
disruptions which could cripple economies, and lead to
loss of life.
The advent of the Internet of Things will further
increase the attack surface. Left unchecked, malicious
entities can find more ways to launch attacks, steal data
and make cyberspace dangerous for all. The result is a
cyberspace that is hostile, and where basic interactions
and transactions cannot be trusted.
Singapore has consistently taken cyber threats seriously
and developed timely responses. Our cybersecurity
journey started a decade ago with the first Infocomm
Security Masterplan in 2005. The Masterplan was a
coordinated effort to secure Singapore’s digital environment
and strengthen public sector cybersecurity capabilities.
Since then, Singapore’s cybersecurity capabilities have
grown. With the formation of the Singapore Infocomm
Technology Security Authority (SITSA) in 2009, we
developed the capability to coordinate national-level
responses against large-scale cyber-attacks, particularly
against our critical information infrastructures.
Our
Smart
Nation
Journey
6
INTRO
OUR CYBERSECURITY
JOURNEY SO FAR
2005 Infocomm Security Masterplan (ISMP)
(2005-2007)
The Info-communications Development
Authority (IDA) launched Singapore’s first
Infocomm Security Masterplan to coordinate
cybersecurity efforts across the Government.
A key priority was building basic capabilities
within the public sector to mitigate and respond
to cyber threats.
In 2015, the Cyber Security Agency of Singapore
(CSA) was formed as the central agency to oversee
and coordinate all aspects of cybersecurity for the
nation. CSA is empowered to develop and enforce
cybersecurity regulations, policies, and practices.
2008 Infocomm Security Masterplan
(2008-2012)
The second Masterplan focused especially on
the security of Singapore’s CIIs, with a vision of
making Singapore a ‘Secure and Trusted Hub’.
While much has been achieved so far, the threats have
also become more sophisticated. We are even more
dependent on digital technology, especially as we
develop a Smart Nation of digitally-enabled businesses
and lives. Cybersecurity, beyond a necessity to defend
and protect, is also an enabler for our future economy
and society.
2009 Singapore Infocomm Technology
Security Authority (SITSA)
SITSA was established under the Ministry of
Home Affairs (MHA) to safeguard Singapore
against cyber-attacks and cyber-espionage.
SITSA’s responsibilities as a national specialist
authority included overseeing the preparation
and securing of CIIs against cyber threats.
This Strategy is a statement of Singapore’s vision
and priorities for cybersecurity. It aims to catalyse
participation by all stakeholders - government
agencies, the cyber industry, professionals and
students, academia and researchers, and providers
of essential services. Together, we will ensure the
resilience of our national infrastructure and a safer
cyberspace, supported by a vibrant ecosystem that
provides good jobs and economic opportunities for
Singaporeans. It also signals Singapore’s willingness
to forge strong partnerships with the international
community to combat the transnational nature of
cyber threats.
Singapore is transforming to become
a Smart Nation, where Singaporeans
are empowered by technology to lead
meaningful and fulfilling lives, where
digital connectivity leads to stronger
community bonds, and where the
power of networks, data and
infocomm technologies is harnessed
to create economic opportunities.
Smart Nation is a whole-of-nation
rallying call for citizens, companies,
and government agencies to work handin-hand to seize the many possibilities
of digital technology. We are putting in
place the necessary infrastructure and
policies to build capabilities, and to create
a conducive ecosystem where people and
companies co-create innovative solutions
to enhance the lives of our citizens.
2013 National Cyber Security Masterplan
(NCSM2018)
The third Masterplan expanded to cover the
wider infocomm ecosystem, which includes
businesses and individuals, in addition to
the previous focus on CIIs. It sought to make
Singapore a ‘Trusted and Robust Infocomm Hub’.
2013 National Cybersecurity R&D (NCR)
Programme
The National Cybersecurity R&D Programme
was established in October 2013 to develop
R&D expertise and capabilities in cybersecurity
for Singapore. It aims to improve the
trustworthiness of cyber infrastructure, with
emphasis on security, reliability, resilience and
usability. It is now co-managed by the National
Research Foundation and the Cyber Security
Agency of Singapore.
2015 Cyber Security Agency of Singapore
(CSA)
CSA was established under the Prime Minister’s
Office (PMO) and is managed administratively
by the Ministry of Communications and
Information (MCI). With its formation, all
agencies and initiatives related to cybersecurity
– the Singapore Computer Emergency Response
Team (SingCERT), national cybersecurity
master-planning and development functions
from IDA, and SITSA – were brought under
a single agency.
CSA is dedicated to the development of
cybersecurity, protection of CIIs and essential
services, and coordination of national efforts
against large-scale cyber incidents. CSA
is also empowered to develop and enforce
cybersecurity regulations, policies, and practices.
It will coordinate efforts across government,
industry, academia, businesses and the people
sector, as well as internationally.
2015 Cybercrime Command
The Ministry of Home Affairs (MHA)
established the Cybercrime Command as
a unit within the Criminal Investigation
Department (CID) of the Singapore Police
Force (SPF). The Command works closely with
other law enforcement agencies and industry
stakeholders, including the INTERPOL Global
Complex for Innovation (IGCI) located in
Singapore, to investigate cybercrimes.
2016 National Cybercrime Action
Plan (NCAP)
The NCAP was launched by the Ministry
of Home Affairs (MHA) in July 2016. The
plan spells out the priorities needed in the
fight against cybercrime. These include
a) the need for public education on staying
safe in cyberspace; b) the development of
capabilities to fight cybercrime; c) strengthening
cybercrime laws; and d) building local and
international partnerships.
2014 National Cyber Security Centre (NCSC)
The NCSC was formed as part of SITSA, to
maintain cyber situational awareness, correlate
cybersecurity events across sectors, and
coordinate with the respective lead agencies to
provide a national-level response to large-scale,
cross-sector cyber incidents.
INTRO
7