Debated in Parliament on 5 Feb 2018.
Order for Second Reading read.
Mr Speaker, Sir, I beg to move, “That the Bill be now read a Second time.”
Digitalisation has opened up new possibilities to enhance our modern lives, but they have also exposed us to cybersecurity threats. In recent years, we have not only seen an increasing number of cyberattacks worldwide, but also a wider range of targets, including individuals, large organisations like Equifax, and Government agencies.
Singapore remains an attractive target to attackers because of our high dependence on Internet-based transactions. In 2017 alone, we saw attacks against our Government agencies, universities, financial institutions, both large and small enterprises, and individuals who had their computers locked by ransomware.
Protection against cyberattacks needs to start with organisations and individuals taking responsibility for the cybersecurity of their own computer systems. However, it is also important for us to work collectively, especially in protecting our essential services, against cyberattacks. As we have seen in other countries, such cyberattacks can have a debilitating impact on the economy and society: (a) last year, the United Kingdom's (UK’s) National Health Service (NHS) had to cancel at least 6,900 appointments due to the WannaCry ransomware attack; (b) in the Ukrainian capital of Kiev, the power grids were hacked twice by cyberattackers in 2015 and 2016, leading to power disruptions that affected over 200,000 citizens during winter; and (c) in 2015, a massive cyberattack that reportedly intended to destroy important national communication channels took the French television (TV) network, TV5Monde, off the air for several hours.
Computer systems directly involved in the provision of essential services are termed Critical Information Infrastructure (CII). There is an urgent need for the Government to be more actively involved with the CII owners in defending against cyberattacks.
We have identified CII in 11 sectors: Energy; Water; Banking and Finance; Healthcare; Transport which includes Land, Maritime, and Aviation; Infocomm, Media and Security and Emergency Services, and Government.
Even with efforts to protect CII, we cannot expect to detect and foil every cyberattack. This is why it is also necessary to investigate cybersecurity threats and incidents, and to mitigate the consequences of successful attacks.
Currently, section 15A of the Computer Misuse and Cybersecurity Act (CMCA) empowers the Minister for Home Affairs to issue a certificate to authorise or direct a person or an entity to take measures to comply with requirements necessary to prevent, detect or counter a threat to any class of computers or computer services, if the Minister is satisfied that it is necessary to do so for the purpose of preventing, detecting or countering any threat to the national security, essential services, defence or foreign relations of Singapore. However, CMCA, which mainly deals with cybercrimes, such as the unauthorised access of computer material, does not provide a regulatory framework for the routine and proactive protection of CII.
Therefore, the Cybersecurity Bill seeks to establish a legal framework for the oversight and maintenance of national cybersecurity in Singapore, with an emphasis on the proactive protection of CII against cyberattacks. The Bill has three key objectives: (a) to strengthen the protection of CII against cyberattacks; (b) to authorise the Cyber Security Agency of Singapore (CSA) to prevent and respond to cybersecurity threats and incidents; and (c) to establish a licensing framework for cybersecurity service providers.
Parts 3 and 4 of the Bill set out a framework for CSA to request for cybersecurity information on CII and during investigations of cybersecurity threats and incidents. The Bill protects such information by requiring specified persons who obtain it when performing their functions or discharging their duties to keep it confidential, and by specifying the circumstances where it can be disclosed.
The Cybersecurity Bill does not provide powers to prosecute cybercriminals. CMCA and other relevant legislation will continue to govern the investigation and the prosecution of cybercrime perpetrators and the detection and apprehension of such offenders.
The Bill is intended to apply concurrently with other laws and regulations enacted in Singapore, including existing sectoral laws. In formulating this Bill, the Ministry of Communications and Information (MCI) and CSA studied cybersecurity legislation which other countries, such as Germany, Estonia, the United States (US), Thailand and Vietnam, have implemented or are considering. These laws cover areas, such as imposing obligations on CII owners to protect their CII, requiring cybersecurity audits to be conducted, making the reporting of cybersecurity incidents mandatory, encouraging companies to share cybersecurity information with the Government, prevention of cybersecurity attacks and, finally, industry regulations. Our Bill is in line with these international developments.
We also consulted industry associations, cybersecurity professionals, sector regulators, potential key CII stakeholders and the general public. In response to requests for more time to provide feedback, we extended our public consultation to six weeks. Respondents were generally supportive of the Bill. They shared the Government’s concerns on cybersecurity threats and the impact of cyberattacks on Singapore. Respondents also provided useful feedback that allowed us to identify aspects of the Bill that could be refined when drafting the Bill, including simplifying the licensing framework. I would like to thank all respondents for their feedback and suggestions.
Sir, allow me now to go through the key proposals of the Bill.
Clause 4 of the Bill allows the Minister-in-charge of Cybersecurity to appoint a Commissioner of Cybersecurity to administer the Bill. This appointment will be held by the Chief Executive of CSA. Today, CSA works with sector regulators to coordinate cybersecurity efforts to protect CII within their respective sectors. The sectors have varying levels of cybersecurity readiness, and sector regulators have varying legislative powers to regulate CII within their sectors on cybersecurity matters. The Cybersecurity Bill will provide CSA with the necessary powers to proactively protect our CII and respond to cybersecurity threats and incidents.
Clause 4 allows the Minister to appoint Assistant Commissioners (ACs) to assist the Commissioner to oversee and enforce cybersecurity requirements on the CII owners. The intention is to appoint senior officers from sector regulators as ACs to perform this role in respect of CII in their respective sectors. This is because such officers understand the unique contexts and complexities of their sectors and will be best placed to advise the Commissioner on the necessary requirements so as to strike a balance between their sectors’ operational needs and national cybersecurity considerations.
Clause 7 allows the Commissioner to designate as a CII, any computer or computer system that is necessary for the continuous delivery of an essential service set out in the First Schedule, and the loss or compromise of the computer or computer systems will have a debilitating effect on the availability of the essential service. This clause also requires the Commissioner to inform the CII owner how he can submit representations against the designation.
CSA has worked closely with sector regulators to identify the list of essential services as set out in the First Schedule. An essential service is defined in clause 2 as any service essential to the national security, defence, foreign relations, economy, public health, public safety or public order of Singapore. New essential services may be added from time to time to the First Schedule by the Minister exercising powers under the Bill if necessary.
The Bill will require CII owners to comply with statutory obligations to ensure the cybersecurity of their CII. All owners of CII, whether from the public or private sector, will be subjected to the same statutory obligations under the Bill. These obligations include furnishing primarily technical information relating to CII (clause 10); complying with codes of practice and standards of performance (clause 11); complying with written directions (clause 12); informing the Commissioner of the change in the ownership of CII (clause 13); reporting cybersecurity incidents in respect of CII (clause 14); conducting cybersecurity audits and risk assessments of CII (clause 15); and finally, participating in cybersecurity exercises (clause 16).
No action under the Bill will be taken against CII owners for cybersecurity breaches so long as they comply with their obligations thereunder.
CII owners who disagree with particular decisions of the Commissioner, such as the CII designation, may appeal to the Minister. This is provided for in clause 17.
To strengthen CSA’s ability to prevent and respond effectively to cybersecurity threats and incidents, Part 4 of the Bill empowers the Commissioner to investigate cybersecurity threats and incidents. These powers in clauses 19 and 20 are calibrated according to the severity of the cybersecurity threat or incident and measures required for response. The Commissioner may authorise incident response officers to exercise these investigation powers. In addition, the Minister has powers to require cybersecurity measures under clause 23 for the purpose of countering serious and imminent threats.
The key intent is to provide for powers to respond to cybersecurity threats or incidents affecting CII. But because of the interconnected nature of computer systems, the powers will also be used for investigating major cybersecurity threats and incidents on computer systems that are not CII, for example, large-scale cyberattacks affecting multiple sectors. It is not our intent to use these powers to respond to each and every cybersecurity threat or incident in Singapore, as computer owners are ultimately responsible for the cybersecurity of their own computers.
Clause 19 allows the Commissioner to request persons to furnish specified information that is necessary for the investigation of cybersecurity threats or incidents, for the purpose of: (a) assessing their impact or potential impact; (b) preventing any or further harm arising from the same cybersecurity incident; and (c) preventing a further cybersecurity incident.
The maximum penalty under clause 19 is $5,000 or six months’ imprisonment or both, for offences, such as willfully misstating information or refusing to provide required information without reasonable excuse.
Clause 20 allows the Commissioner to authorise incident response officers to exercise more intrusive investigative powers as are necessary to investigate and prevent serious cybersecurity threats or incidents. For example, the Commissioner may require the owner of a computer to scan the computer for cybersecurity vulnerabilities. Clause 20(3) prescribes a set of criteria for determining what constitutes a "serious" cybersecurity threat or incident, such as when it creates a risk of significant harm being caused to a CII.
The Commissioner may, under clause 20(5), take possession of any computer or equipment without the owner’s consent for the purpose of further examination and analysis, if the Commissioner is satisfied that: (a) this is necessary for the purpose of the investigation; (b) there is no less disruptive method of achieving the purpose of the investigation; and (c) after consultation with the owner, and after considering his business and operational needs, the benefit from doing so outweighs the detriment caused to him.
Such powers are necessary given the potential impact from serious cybersecurity threats and incidents, which can disrupt our essential services, potentially cause physical damage and harm, and affect our economy and our way of life. The Bill clearly spells out how these powers may be exercised. These powers are calibrated and there are safeguards built into the Bill, such as what I have just described.
The maximum penalty under clause 20(7) is $25,000 fine or two years’ imprisonment or both, for offences, such as failure without reasonable excuse to comply with a direction or requirement of an incident response officer, under clause 20(2)(b) or (c).
Clause 23 allows the Minister to authorise or direct any person or organisation to take measures for the purpose of countering serious and imminent threats. Clause 23 is a re-enactment with slight modifications of section 15A of CMCA. This section will be repealed. CMCA will correspondingly be renamed as the Computer Misuse Act, or CMA in short, at the same time that the Cybersecurity Bill is passed. The offences and penalties under clause 23 are the same as those under section 15A of CMCA.
The Bill recognises that information disclosed to CSA under the Bill is often confidential. Information disclosed to CSA may be used to determine if a computer system is a CII (clause 8), technical information relating to a CII (clause 10), or information given pursuant to an investigation into a cybersecurity threat or incident (clause 19 or 20).
Therefore, under clause 43, the Commissioner and other specified persons must preserve the secrecy of information that may come to their knowledge as a result of performing their functions or discharging their duties under the Bill. Such information includes matters relating to a computer system, as well as the identity of persons who furnished the information. It will be a criminal offence under clause 43(4) if specified persons fail to preserve the secrecy of such information or unlawfully discloses such information. The maximum penalty is $10,000, or one year’s imprisonment, or both.
However, clause 43 provides for the sharing of information in certain circumstances, such as for the purposes of prosecution under the Bill, or to disclose to the Police any information which discloses the commission of an offence under CMA.
We recognise other persons may have information on whether CII owners are complying with their obligations specified in Part 3 of the Bill, and we want to encourage the disclosure of such information to the Commissioner. Clause 45 provides for the protection of these informers in relation to proceedings for an offence under Part 3 of the Bill.
As cybersecurity risks become more widespread, the demand for credible cybersecurity services will grow. Some cybersecurity services can be sensitive because the service providers performing them can have significant access into their clients’ computer systems and networks and gain a deep understanding of the cybersecurity vulnerabilities. Such services, if abused, can compromise and disrupt the clients’ operations even after the service provider’s job has been completed. Furthermore, there is asymmetry of information; many organisations, especially smaller ones, may not know which cybersecurity service providers are ethical or offer reliable services.
Part 5 of the Bill provides for a licensing framework for cybersecurity service providers that service the Singapore market. For a start, the licensing framework will be a light touch in view that this is a new initiative and there is a need to strike a good balance between industry development and cybersecurity needs. Only providers of two types of cybersecurity services will be licensed, namely, penetration testing and managed security operations centre (SOC) monitoring. These providers have access to sensitive information from their clients, and the services are also relatively mainstream in our market and, hence, have a significant impact on the overall cybersecurity landscape.
Clause 24 requires providers of licensable cybersecurity services that are specified in the Second Schedule to apply for a licence. It will be an offence to provide such services without a licence. The maximum penalty is a $50,000 fine, or two years’ imprisonment, or both.
We do not intend to require companies to be licensed for providing licensable cybersecurity services to their related companies. In addition, the term "cybersecurity service", as defined in clause 2, only covers a service provided by a person for a reward to another person, and excludes a service provided in-house to an employer.
Financial penalties may be imposed under clause 32 for non-compliance with licensing conditions or for other regulatory breaches that are not an offence, such as the failure to keep and retain proper records. The maximum penalty is $10,000 for each non-compliance but not exceeding, in the aggregate, $50,000.
The licensing officer is required under clause 33 to give licensees an opportunity to submit representations before the imposition of financial penalties. Under clause 35, cybersecurity service providers may appeal to the Minister against specific decisions of the licensing officer, such as the refusal to grant a licence and licensing conditions.
Sir, the Government cannot achieve a more secure cyberspace alone. We will partner public and private sector stakeholders in the journey to strengthen the protection of CII. CSA will adopt a deliberate process for the designation of CII across the different sectors, in consultation with their owners and the relevant sector regulators where possible. CSA will also implement programmes to help the sector regulators assist CII owners in getting ready to fulfil their obligations under the Bill.
We will also engage the industry further on the licensing conditions for licensed cybersecurity service providers under clause 27 of the Bill. The licensing framework will be operationalised at a later stage, after the rest of the Bill.
Sir, the Cybersecurity Bill is one part of Singapore's Cybersecurity Strategy to strengthen the nation's cybersecurity posture. With cyber threats growing globally, this Bill is timely to empower CSA to safeguard essential services from disruptions by cyberattacks, prevent and respond to cybersecurity threats and incidents, and to establish a licensing framework to improve the credibility of cybersecurity services in Singapore. Sir, I beg to move.
*Question proposed.*
Mr Speaker: Mr Zaqy Mohamad.
Thank you, Mr Speaker, for allowing me to speak on this important Bill. I first have to declare my interest. I work for a firm that provides cybersecurity and risk services.
Mr Speaker, the Cybersecurity Bill is timely, given its focus to strengthen the defences of our essential services and CII from cybersecurity threats from both private and state players.
We have seen growing evidence of how countries are being threatened by digital sabotage which targets essential services to cause disruption to the economy, as well as to confuse and demoralise citizens.
The Ukraine experience, as the Minister has shared earlier on, was one that is almost becoming a cyber-hacking "testbed" for other foreign state actors. On 23 December 2015, the control centres of three Ukrainian electricity distribution companies were taken control of, where malicious hackers opened breakers which caused more than 200,000 households to lose power. Nearly a year later, on 17 December 2016, a single transmission substation in northern Kiev lost power. These instances of sabotage took place on the tail of a political revolution in Kiev and the annexation of Crimea.
While similar attacks have not shown to be highly-motivated acts of sabotage in Singapore, in September last year, CSA had reported that several critical sectors were subjected to cyberattacks, and that the Singapore Government had been subjected to a malware attack by state-sponsored hackers. We have been fortunate that the recent Wannacry, Meltdown and Spectre malware attacks have not disrupted our essential services.
Nonetheless, these attacks are a clear and present danger to a compact nation like Singapore, where a politically or militarily motivated actor can use cyber warfare to sabotage our critical infrastructure and economy. Current international laws have not been effective to address cross-border hacking and state-sponsored attacks. In most cases, agencies have had difficulty to pin down hacking incidents to individuals or governments.
I believe the Cybersecurity Bill is a good start for Singapore to ensure that our essential services and sectors are well-protected and defended to prevent criminals or state players from threatening our economy and our way of life.
I welcome that this Bill looks into proactive measures to have owners of CIIs to be more accountable for reporting and the security readiness of their CIIs. It is important that relevant stake players provide timely reports of attacks and I fully support that the CSA drive industry-wide knowledge sharing and push for effective cyber defence measures.
Countries, such as Germany, Japan and the US, have already enacted cybersecurity legislation. In the Association of Southeast Asian Nations (ASEAN), Thailand and Vietnam are also considering similar legislation. Thus, this Bill is a timely reflection of our commitment to securing our nation and our status as a top-tier international hub and financial hub.
From the view of the industry, one of the key concerns will be whether the cost of compliance and the costs of systems upgrades will be significant. Consumers will also be concerned if these additional costs will be passed on to them, as many of these CII owners provide essential services, such as transport, water, electricity and communications.
We must strike a balance to protect our national and citizens' interests but yet be clear on what security standards and architectures that CIIs need to comply with, so that the costs incurred in upgrades and security operations will not overburden industry and consumers. The cyber arms race is not about to recede and will only intensify and hackers will continue to try to find weaknesses in systems to exploit. In this regard, I would like to make some suggestions.
One, it will be ideal if CSA can take the lead, together with the sector regulators, to set industry-wide leading practices, shared services and threat intelligence, so that CII players can achieve security readiness in a cost-efficient manner and yet be effective in deterring and responding to security threats.
Two, this Bill will drive greater accountability from the CII owners, and failure to comply with this new law will be criminal in nature. I support the need to make the owners of the CIIs accountable, but I hope that CSA be very clear on the benchmarks or, if appropriate, security architectures that CII owners need to comply with upfront. This will also help the relevant CIIs to plan their security roadmap effectively and better understand the investments they need to make. Otherwise, the industry risks putting in piecemeal measures that could be costly. It would also not be good if CII owners take a reactive approach to only wait for audit results and taking action only when told that they need to comply to them from time to time. Under the law, they will only be criminally penalised when they have not complied with a directive from the Commissioner. This may be too late if an incident happens. So, will the Ministry be providing the CIIs with specific benchmarks they need to achieve or a checklist of cybersecurity measures that need to be in place?
Three, I would like also to suggest that the Ministry and the sector regulators consider funding R&D for cybersecurity technology and operations centrally or within sectors. The involvement of CSA and sector regulators can catalyse CII operators to share findings and insights to accelerate cybersecurity enhancements. There are many common insights that could be derived from research and leading practices within specific sectors. This will help CII operators develop quicker and more effectively.
Mr Speaker, since 2015, the Ministry has been doing public and closed door consultations. I would like to ask the Minister, through the consultation exercises, whether the Ministry has performed an assessment of the readiness of the current CIIs in the various essential services sectors to comply with CSA's security requirements. Has the Ministry estimated how much it will cost for the CIIs to comply with the Cybersecurity Bill's requirements? What is the timeline that CIIs have come back that they need to get fully ready and compliant?
Under the Cybersecurity Bill, the Minister, the Commissioner and his deputies are given the authority to investigate and get CIIs to disclose information to assist with investigations. Citizens will be concerned that, as part of investigations, the authorities may need to access data residing within the CIIs and this may breach the privacy of individuals. What are the safeguards put in place to ensure that the broad investigation powers under this Bill do not invade the privacy of individuals and consumers?
Mr Speaker, under this regime, the Cybersecurity Bill will complement CMCA, which will be renamed CMA. What is the rationale of keeping the Acts separate as they both deal with essentially cybercrime? How would enforcement operations be divided across the two pieces of legislation to deal with cybercriminals involved in attacks, such as Ransomware, Malware or Distributed Denial of Services (DDOS) attacks? The same crime can technically be applied across both critical infrastructure and non-critical, and common information technology (IT) systems. So, is there a duplication of effort or duplication of resources? What features under the new Bill will enable our agencies to better address as well crimes arising from overseas actors?
Currently, the CIIs are defined based on systems located here in Singapore. Given that some CII operators may use technologies, such as cloud services or outsourced managed services based overseas, how does the regulator plan to designate these systems as CII, as the data and application may not reside, wholly or in part, in Singapore?
Mr Speaker, the Bill will put in place a licensing regime to providers of penetration testing and managed SOC monitoring services. I support this initiative as it will put in place a credible ecosystem to support our CIIs. This will also promote our service providers to be better trained and specialised to meet the standards required by the regulators. However, I would like to seek clarity from the Minister why does CSA only register companies and not allow for the licensing or registration of individuals. In this emerging field of cybersecurity, there are many global experts, or even white-hat hackers, whose expertise may be useful as freelancers to advise CII owners. Why does the Ministry not consider allowing individuals to be contracted by the CII owners?
From a manpower perspective, Mr Speaker, cybersecurity resources are in demand today. How is the Ministry planning to uplift the capabilities that we have to fulfil demand once the Bill comes into force? Do we have a significant capability gap today and how long does the Ministry estimate for us to fulfil this gap?
I would like to suggest that the Ministry put in more resources to build up cybersecurity capability that will help CIIs fund training and international exposure for their personnel for security training. The Ministry may also wish to facilitate manpower exchanges with leading technology research labs or CIIs overseas with leading practices. Some of the CIIs named are in sectors that are facing slowdown and may find it difficult to prioritise funds for this in the short term. Such a capability fund can help adoption, especially within the immediate future.
Mr Speaker, the defence of our nation, our people and its economy needs a new approach in this digital age. Countries have the ability to combine conventional and cyber tactics to weaken an opponent's defence by disrupting its essential services and its economy, and also to maximise confusion and uncertainty using both simple and sophisticated technologies in innovative ways.
This Bill is timely to stress the importance of strengthening our CIIs in the interest of national security. We have been developing our Total Defence capabilities across five pillars – military, civil, economic, social and psychological defence. It has worked for us for several decades. In this digital era and considering the emerging threat of hybrid warfare, it may be time for the Government to update our approach. Perhaps, it may be time to add a sixth pillar to our Total Defence framework in the area of cybersecurity or digital defence to counter the new threats in this digital era. Mr Speaker, I support this Bill.
Mr Speaker: Mr Pritam Singh.
Mr Speaker, this is a significant Bill which establishes a framework for the oversight and maintenance of cybersecurity in Singapore. Its ambit and reach are understandably wide in view of the reliance both the public and private sectors, including individuals, place on computer programmes, systems and services, and the devastating prospect of debilitating cyberattacks on critical sectors of the economy.
More specifically, the loss or exposure of private information may also erode trust in the Government, statutory agencies and private companies as the release of such information in the public realm can seldom ever be completely reversed.
I understand the Bill has received significant feedback from industry with an excess of 60 companies, many of them large corporates, and separately, a healthy number of industry associations – not forgetting civic-conscious and interested individuals – providing feedback to the Ministry on this Bill. For that reason, my clarifications will be limited to the Bill's broad principles and impulse, centring on queries that pertain to the operation of the envisaged Cybersecurity Act in practice.
The first clarification pertains to clause 7 of the Bill covering companies and entities that host CII that are partly located overseas for business reasons or simply logistical convenience. As a part of a Singaporean entity's CII ecosystem may be located overseas, how does the Bill ensure that this bifurcation does not render a particular CII susceptible to compromise or cyberattacks since CII computers and computer systems based overseas are not covered by this Bill?
Separately, in light of the feedback received, how common are such hybrid arrangements amongst public and private sector CII owners and is the Ministry concerned that some entities may seek to locate some elements of their CII overseas to hedge against the reach of the Act and, as a consequence, compromise its regulatory reach?
I have a similar clarification with regard to ownership of a CII, particularly if the owner is an offshore entity or individual. What regulatory oversight will the Bill realistically have over CII owners who operate outside our jurisdiction, and would this not represent a loophole?
Secondly, I seek some clarity on the compliance costs that are likely to result for both public and private sector entities as a result of this Bill. Feedback on such costs were received by the Ministry and there was a suggestion that grants should be extended to help organisations offset these costs. Can the Minister give us some sense or an estimate of the dollar value of the compliance costs of the Cybersecurity Bill with regard to, for example, CIIs in sectors referred to in Schedule 1 of the Bill – perhaps those covering the Civil Aviation Authority of Singapore (CAAS), the Public Utilities Board (PUB) and some public hospitals? Finally, how much would be set aside in the Budget for grants arising out of an increase in such compliance costs?
Thirdly, I understand from feedback to the Ministry that there was some concern about what constituted a significant security incident. The language of the Bill in clause 14 focuses on prescribed incidents suggesting that subsidiary legislation will clarify such words and terms. As the Bill imposes a duty on owners of CII to report incidents, can the Minister give the House a general sense, with examples of the specific thresholds of hypothetical incidents which may require reporting under the Bill.
With this as a backdrop, can the Minister also share with Parliament what punishment would be effected by this Bill against a company like Uber – assuming it is a CII – which caused the compromise of personal information, such as names, email addresses and personal contact numbers, of close to 380,000 Singaporeans and tried to conceal the same, as reported in November last year? How far does this Bill go to take a CII owner to task for non-reporting should a similar Uber-like episode occur after this Bill becomes law?
What other actions would the Government consider against entities that are negligent in securing their computer systems, particularly if such an incident is aggravated through willful concealment?
Fourthly, clause 19 of the Bill gives extraordinarily broad powers to the Commissioner of Cybersecurity and his officers to investigate cybersecurity threats and incidents against companies, entities and even individuals with respect to any computer or computer system in Singapore, not just CIIs. The ambit of these powers is best exemplified by clause 19(1)(a) of the Bill, which gives the Commissioner and any authorised officer the power to remove or make copies of a hard disk, for example, even if it is only to assess the impact or potential impact of a cybersecurity threat. Non-compliance carries with it a fine of up to $5,000 and/or an imprisonment term of up to six months.
For avoidance of any doubt, notwithstanding the remarks in the Report on Public Consultation on the draft Cybersecurity Bill where it was stated that such powers are to be applied in a calibrated manner and, more importantly, in response to major cybersecurity incidents against non-CIIs, can the Minister confirm the envisaged threshold of what qualifies as a major incident, so that the House is reassured that the Commissioner's powers will be used very judiciously and not against Government critics and individuals?
Coming back to the Uber example, does the Government foresee using such powers against foreign companies that operate in Singapore?
To conclude, Mr Speaker, I am concerned about how much Singaporeans are actually aware of their online signature and the importance of cybersecurity. While we seek to protect key infrastructure against cyberattacks, every Singaporean, who uses his or her smartphone to pay for goods and services or uses it as a social engagement tool, is susceptible to cyberattack or hacking. This prospect is likely to increase as Singapore undertakes its Smart Nation drive with more focus and coordination.
The CSA is in a privileged position to educate Singaporeans on security tips as we transition to a more cashless economy and live online, as many of us already do. What measures can Singaporeans look forward from the Government to protect them from cybersecurity threats in our Smart Nation journey? Mr Speaker, notwithstanding the clarifications sought, I support this Bill.
Mr Speaker: Mr Christopher de Souza.
Mr Speaker, Sir, the Cybersecurity Bill is a forward-looking piece of legislation that ensures that our laws keep pace with the threats that we face as a nation.
The year 2017 has been called the Year of the Data Breach. Even within the first six months of 2017, the number of records stolen in breaches numbered almost two billion – even more than the whole of 2016, which was 1.4 billion. New malware samples reached an all-time high of 57.6 million in the third quarter of 2017, according to McAfee Labs Threat Report December 2017.
This is not just a matter of privacy or lost personal data – there are financial, security, proprietary interests at stake. A class action suit was initiated in the US last year against Equifax for data breach. They alleged that criminals used the stolen data to "apply for mortgages, credit cards, student loans, tap into bank debit accounts, file insurance claims and rack up substantial debts." Stolen identity also poses an international problem, a terrorist problem. Last month, Thai police arrested a man who allegedly forged passports, including Singapore passports, for groups, including a terrorist group.
Furthermore, breaches in cybersecurity can have debilitating effects on essential services. WannaCry, the first ransomware worm, crippled the healthcare system in England. It "shut down computers in more than 80 NHS organisations in England alone", cancelling almost 20,000 appointments in an appointment-based healthcare system, five hospitals resorted to diverting ambulances, unable to handle any more emergency cases. So, what we are debating today is serious.
Wannacry was a ransomeware worm and, by "worm", we are talking about a malware programme that is able to self-replicate to infect other computers and infiltrate through the connections in a computer network. The NotPetya in Ukraine, which utilised a hacked version of a major accounting programme widely used in Ukraine, affected companies in many different sectors, from shipping to pharmaceuticals and to outside Ukraine through multinational companies. Worse still, NotPetya encrypts files with no chance of recovery, that is, it was not a ransomeware.
Stuxnet, a different computer worm, caused a proportion of machinery in Iran’s nuclear facility to spin out of control in 2010. This cyberattack was executed through infected Universal Serial Buses (USBs), overcoming the "air gap". Since then, new methods to jump over an air gap has emerged. No sector has been spared cyberattacks, with commercial and healthcare sectors targeted the most.
This threat is not something remote to Singapore. The threat is real and palpable. Although Singapore’s critical infrastructure was not hit by Wannacry, Singapore malls were among the victims of that ransomware.
Within the past five years, there were notable occasions of security breaches. In 2014, Singapore’s Ministry of Foreign Affairs' IT system was breached. One thousand and five hundred SingPass users' IDs and passwords were reported to be potentially compromised and illegally accessed. In 2017, 850 Ministry of Defence (MINDEF) personnel’s National Registration Identity Card (NRIC) numbers, birth dates and telephone numbers were stolen following a cyberattack. Additionally, the National University of Singapore (NUS) and the Nanyang Technological University (NTU) reported an attack by "advanced persistent threat" (APT) actors that sought to "steal research and Government-related information."
These and many other instances are like red, flashing lights warning us to be vigilant. So, I concur with Minister Yaacob Ibrahim's point that we need to act and we need to act now.
Cybersecurity threats are nearer than we think. They could hit us faster than we can react and they could hit us harder than we can imagine. Therefore, this forward-looking Bill goes upstream to secure our information infrastructure through preventive and reactive compliance, so as to give us the upper hand and arsenal we can deploy against those who seek to do us harm.
Some key features of this Bill’s regulatory framework include: (a) reporting and investigating of breaches to facilitate damage control and prevent future occurrences under clauses 14, 19 and 20; (b) licensing of cybersecurity service providers in Part 5; and (c) regular auditing under clause 15 to ensure compliance and accountability. To facilitate accountability and promote compliance, clause 45 protects informers’ identities.
In today's age of technology, more infrastructure is being built, not from concrete and steel but, rather, in the realm of intangible cyberspace. This trajectory is bound to continue as Singapore moves toward being a "Smart Nation". Some of the future initiatives announced recently include digitalising of healthcare records even at the level of a private general practitioner (GP) through the National Electronic Health Record (NEHR) and the promoting of cashless payments.
As we seek to increase leveraging the conveniences and prowess of modern technology, it is critical that we protect and prevent attacks and crises from threatening our cyber infrastructure. The important place they have in the running of our country is reflected in this Bill’s designation of CII. This designation spans 11 broad areas of essential services set out in its First Schedule.
Cybersecurity in a computer network would only be as strong as the weakest link. A single vulnerability may be exploited to infect other areas and other computers in the network. Since computer networks extend beyond territorial boundaries and cyberattacks know no physical boundaries, clause 3 of this Bill extends regulation to computer networks that are wholly or partly in Singapore.
This Bill has been carefully calibrated for a consistent framework over the different sectors yet providing space for flexibility for purpose-oriented, sector-suited rules and practices. For example, the Commissioner’s written directions may be issued to a class of CII owners under clause 12(1); the Commissioner to direct more frequent audit above the two years "in any particular case" under clause 15(1)(a).
The Bill also provides for flexible codes of practice under clause 11 to be promulgated to promote best practices in cybersecurity. It is important that this regulatory skeleton provides sufficient flexibility to accommodate for changes in the realm of cyberspace and allow for careful calibration of regulation in the future. If there are too many regulations, the higher threshold to entry may perhaps shrink our well of cybersecurity expertise to draw from, harming our cybersecurity resilience, for example, through an over-reliance on a single provider which may multiply knock-on effects of a breach. Hence, the regulatory framework, in my view, needs to remain flexible for future refinement of regulatory controls.
This flexibility is especially crucial because technology is an ever-evolving landscape. Cybersecurity depends on innovation to keep up, keep ahead and remain effective. Recently, MINDEF invited white hat hackers to hack into MINDEF’s Internet-facing domains. This method of exposing vulnerabilities maximised the talent pool available locally and overseas. The non-prohibitive cost estimated at $100,000, compared to up to a million dollars for hiring a dedicated vulnerability assessment team. This is attractive fiscally. Would the Minister clarify how this Bill would affect non-mainstream methods of strengthening cybersecurity, such as white hats?
In this fast-changing technology-connected world, this Bill provides the preventive complement to the deterrent CMCA. It is a complement to that Act. It places our country to better respond to, prevent and secure the integrity of our computer systems through a strong, yet flexible, regulatory framework. For these reasons, Mr Speaker, I strongly support the Bill.
Mr Speaker: Ms Thanaletchimi.
Mr Speaker, Sir, I stand in support of the Bill. It is, indeed, a step in the right direction in light of more and more sophisticated cyber threats which have crippled a country's CII, such as that which happened to NHS in the UK, as the Minister has alluded to. The terrible impact of the cyberattack devastated hospitals and GP clinics in the UK. Its Cyber Security Centre was working round the clock to bring its systems back online when this attack resulted in surgeries being cancelled, ambulances being diverted and patient records missing after it became the highest-profile victim of a global ransomware attack and was faced with renewed concern about the strength of its infrastructure. This malware blocks access to any files on PC until a ransom is paid.
This could have been a situation in Singapore if we are not better prepared. The concern over cybersecurity becomes more imminent with the Ministry of Health’s (MOH's) direction to move into NEHR for patients, which is an excellent initiative. With access to one patient record across public and private healthcare sectors, framework, structure, audits, cybersecurity governance and oversight, including educating the stakeholders and providing relevant continuous training, becomes paramount.
Our country’s information infrastructure has to be protected and well-preserved from infiltration and attack in the name of cyber-terrorism. The special focus of the 11 key sectors, such as Government, security and emergency, healthcare, telecommunications, banking and finance, energy, water, media, land transport, air transport and maritime, demonstrates the critical nature of the sector that could cripple the entire Singapore in terms of economy and threaten our lives to its devastation.
With this as backdrop, I am, indeed, heartened to see the Government’s inclusive effort to garner stakeholder’s feedback and support on the Cybersecurity Bill. It is, indeed, notable that the public consultation on the Bill, which was originally scheduled from 10 July to 3 August 2017, was extended to allow respondents more time to provide feedback on such an important Bill that is pertinent to safeguard the people of Singapore in all aspects.
The importance of working with the various stakeholders cannot be over-emphasised and it is equally pertinent to ensure the relevant sectors work closely with one another to implement the intricacies of the Bill and to ensure the proposed requirements are adhered to. I believe implementing it would be more challenging than enforcing the Bill.
Licensing cybersecurity service providers may not be a popular move but a necessary one to ensure that they meet the security needs. In this regard, I would like to propose the following suggestions for consideration.
There needs to be a structured means of briefing the companies, especially small and medium enterprises (SMEs), on guidelines to encourage them to adhere to the cybersecurity measures. SMEs may not have the resources and capabilities to adhere to the measures, unless they are given the impetus and financial support to put in place the necessary requirements. They may also need borrowed expertise to put in place the secured means of protecting information as they serve as a third-party vendor to some clients. It would be good for the Government to grow and provide a pipeline of those talents to assist these companies which will need them.
In the areas of training, the Government may consider grants to encourage individual personnel to take up cybersecurity courses or programmes to refresh their knowledge and to be updated on the latest advancements, as the industry transforms rapidly. This can be tied to SkillsFuture cybersecurity upskilling grants.
To enhance governance and oversight, it would be worthy to introduce an accredited framework for auditors to perform checks and provide guidance or advice on what companies can do to have a more secured portal. Establishing a national cybersecurity audit to check on the stakeholders of the 11 sectors will provide a high level of assurance for those who engage in services in the specific sector.
Effective communication mechanism or efficient connectivity to promptly inform stakeholders and companies of the specific sector or sectors that could be potential target and how to take timely precaution will serve to act as preventive means.
Companies or individuals who proved to have unintentionally violated the requirements in the Bill, should be made to go through relevant cybersecurity programmes and this should be made compulsory. In fact, it would be useful to ensure that all staff of the industry be made to attend awareness programmes in this field, so as to better protect the critical information.
Sir, I fully support the Bill that raises the level of resilience in our efforts to prevent and combat global cybersecurity attacks that periodically threatens us, especially when we least expect.
Mr Speaker: Assoc Prof Daniel Goh.
Mr Speaker, Sir, this is an important Bill that sets up the regulatory framework to protect Singapore from the increasing threat of cyberattacks. The extensive commentary and feedback received during the public consultation for the Bill show that the public recognises the importance of cybersecurity. In the responses to the feedback, we can also see the Government trying to balance the compliance burden on business with the necessary measures to protect the economy from cyberattacks.
Singapore’s cybersecurity strategy is a correct approach taken for a global city that depends on openness and connectedness to the world for its proper functioning. This approach can be described as a whole-of-Government approach that places public-private collaboration at the heart of the strategy with a strong future-oriented plan for capacity development and for value addition to the economy. This Bill is an integral part of the strategy and expresses the strategy’s approach.
I have three sets of clarifications for the Minister. The first set is more general and has to do with the strategy and its implementation; the second, on the scope of the Bill; and the third, on the specific provisions of the Bill.
The Paper setting out Singapore’s Cybersecurity Strategy was published more than a year ago in October 2016. The strategy has four pillars: building a resilient infrastructure, creating a safer cyberspace, developing a vibrant cybersecurity ecosystem and strengthening international partnerships.
I was rather surprised that there is very little mention of MINDEF in the Paper. It was mentioned once in the Paper when it was noted that MINDEF formed part of the National Cyber Incident Response Teams with CSA, the Government Technology Agency (GovTech) and the Ministry of Home Affairs (MHA). These teams are part of the plan to respond to Tier 1 cyber campaigns threatening national security and Tier 2 cyberattacks on a sector.
MINDEF is a 4G military force reliant on secure communications and information networks. It should already have well-developed cybersecurity infrastructure and capabilities. It would be a terrible waste if the military applications are not adapted for civilian use. Could the Minister share whether there are plans to synergise and share military cybersecurity knowledge and technology to develop and deepen our civilian cybersecurity infrastructure?
Afterall, as it is stated in the strategy Paper, cybersecurity is a way of putting Total Defence into action and everyone has a role in creating a safer cyberspace for everyone, and this must include the military. There are two other specific ways that the military could play a key role to realise our cybersecurity strategy objectives. These are already observed in public commentary on the strategy and many have pointed to the Israeli military as a successful example.
First, our military has a peculiar asset: the commitment of tens of thousands of full-time and operationally-ready National Servicemen. This represents a potentially significant investment of time, not only of manpower, but of brainpower, by our highly educated workforce. The time invested could be harnessed to serve both military and civilian cybersecurity needs.
A cybersecurity corps could be formed to train budding IT professionals when they are serving full-time National Service. Deferment could also be considered for these young men to obtain degrees in cybersecurity first, so that they would hone their classroom skills in the military. They could then enter the cybersecurity industry when they become operationally-ready and return to the military with enhanced knowledge and skills during their NSmen call-ups. This is a win-win method to develop a vibrant cybersecurity system for Singapore.
Second, our unique military institution could also be used to foster startups to develop Singapore’s cybersecurity industry. Israel is already ahead of everyone in this game and there are an estimated 420 cybersecurity companies in Israel today, many of which are at the forefront of innovation and exporting their technology. It is now well-known that the Israeli Defence Force acted as the incubator for the startups. We have similar institutional features here, so there is no reason why the Singapore Armed Forces (SAF) cannot also serve as such an incubator. It would be a win for the military and a win for our entrepreneurship sector and economy, too.
I move on now to the second set of clarifications on the scope of the Cybersecurity Bill. The Bill defines "critical information infrastructure" in section 7 as the computer system "necessary for the continuous delivery of an essential service", the compromise of which would lead to a serious effect on the availability of the essential service. Essential service is defined in section 2 as "any service essential to national security, defence, foreign relations, economy, public health, public safety or public order of Singapore, and specified in the First Schedule". I am surprised that higher education and research institutions are not listed as essential service in the First Schedule and would like the Minister to clarify why this is so.
There are three reasons why I am surprised. First, it was reported that the NUS and NTU both suffered separate cyberattacks in April last year. It appeared to be the work not of casual hackers but of carefully planned, sophisticated cyberattacks that might be aimed at stealing information related to the Government and research. This is an extreme cyberattack scenario which this Bill is aimed at defending against. If our top public universities are being targeted by organised hackers, who could not be named by CSA for operational security reasons, and they were going after some precious information which, again, CSA could not reveal for security reasons, then there must be critical information residing in our universities and research institutions.
Second, of course, a sophisticated, targeted cyberattack on our universities does not mean that the service provided by the universities is essential, as defined in the Bill. I am, however, inclined to argue that there is a lot of research that is going on in our universities and other associated research institutions that have to do with the continuous delivery of essential services. The theft of information related to these research projects could lead to cyberattacks or other forms of attack that could seriously affect the availability of essential services. I would like to ask the Government, therefore, to review whether the computer networks for research-related to essential services, especially Government-linked research projects, should also be considered as CIIs.
Third, our universities are central to cybersecurity innovation and training. In the Paper outlining Singapore’s Cybersecurity Strategy, four of our six autonomous universities are named as playing key roles in fostering cutting-edge research and development (R&D) and talent development. It is in the vision that each of the six universities would become a "cybersecurity centre of excellence" developing its own area of specialisation. The training of our cybersecurity workforce is also entrusted to the universities. The Singapore Institute of Technology (SIT) and the Singapore University of Technology and Design (SUTD) offer Bachelor and Master's programmes in cybersecurity. What this means is that there is a lot of meta-information on cybersecurity residing in our universities. The theft of this meta-information could compromise the general resilience of our cybersecurity infrastructure or that of specific CIIs.
I move on finally to the third and last set of clarifications that have to do with the duty to report cybersecurity incidents, as specified in section 14. I have two points of clarifications for this. The first is specific to section 14, and the second has to do with cybersecurity incident reporting in general. First, section 14(1)(b) specifies that the owner of a CII must notify the Commissioner of a cybersecurity incident in any computer or computer system under the owner’s control that is interconnected with or that communicates with the CII. This seems onerous, and yet, limiting.
It is onerous because it enlarges the scope of regulation beyond the CII into a far larger field of secondary computer systems. For the owner of a CII, this would mean the requirement of detection mechanisms in secondary computer systems. Yet, section 14(2) is not clear whether it is a legal requirement.
Would the Minister clarify whether it is a requirement for the owner of a CII to install detection mechanisms in secondary computer systems interconnected with the CII? Would the Minister also clarify whether this reporting requirement is, indeed, onerous, especially since MCI and CSA’s response to feedback during the consultation on the draft Bill stated that "computer systems in the supply chain supporting the operation of a CII will not be designated as CIIs", implying that the regulation would be more narrowly scoped.
Yet, section 14(1)(b) is limiting, if the intention is to protect the CII from cyberattacks in adjacent interconnected computer systems, as the clause is now worded to limit regulation to only secondary computer systems under the owner’s control.
I would like to ask the Minister to clarify what does "owner’s control" mean in real operational terms? What if the secondary computer system interconnected to the CII is not under the control of the CII owner? Does it mean that such a computer system would not pose a risk to the CII? If a secondary computer system not under the control of the CII would still pose a risk to the CII, then why limit reporting to secondary computer systems under the CII owner’s control? If the risk is the same regardless, then why not remove the need to report cybersecurity incidents in secondary computer systems altogether?
My final point has to do with the reporting of cybersecurity incidents beyond the CIIs. Threat reports issued by cybersecurity firms often point to the problem of under-reporting, as many companies and organisations often choose not to report or to reveal the full extent of cyberattacks and data thefts. This is understandable, as sensational news reports of major data breaches would undermine trust in these organisations and affect the bottom line of businesses.
At the same time, it is not viable for these organisations to hide such incidents from view, as it would erode the general resilience of cybersecurity infrastructure in the long run. Afterall, large-scale organised cyberattacks would likely begin with trial runs of mini attacks on non-critical computer systems. The only way forward might be to legislate mandatory reporting of all cybersecurity incidents to CSA with the assurance of confidentiality and indemnity.
Mr Speaker, Sir, the Cybersecurity Bill is a significant step forward in putting Singapore’s Cybersecurity Strategy into action. I support the Bill. It is an expression of our Total Defence culture. As such, I believe there is a greater role to be played by MINDEF to develop our cybersecurity capabilities and enhance our cybersecurity enterprises.
I also believe that the Government should look more closely at our Institutions of Higher Learning (IHLs) as they have already come under a severe cyberattack and their computer systems contain crucial information related to our essential services and meta-information related to our cybersecurity infrastructure.
Finally, I believe that we need to get the reporting of cybersecurity incidents right and there are kinks in this area in this Bill that the Minister could do well to straighten out.
Mr Speaker: Ms Joan Pereira.
Mr Speaker, Sir, the Cybersecurity Bill is an important one. It will enhance the oversight and protection of cybersecurity for our CII sectors.
I am heartened to note that we are building up our cybersecurity capabilities on a solid foundation and that the Government has been investing in developing a robust system. Last year, we ranked third globally in terms of cybersecurity spend as a percentage of gross domestic product (GDP) with 0.22%, behind Israel (0.35%) and the UK (0.26%).
However, we can do better to raise our cybersecurity standard. Just last month, the Public Accounts Committee (PAC) reported IT control problems in our public sector due to "agencies not complying with the controls put in place". I agree with the Committee’s assessment that these lapses, which cut across agencies, are significant in view of the IT security threats today.
PAC noted that the Ministry of Finance (MOF) has taken steps to deal with this problem on a whole-of-Government level, including the establishment of an interagency work group. At least one of the lapses originated from an IT vendor, which had been warned.
CSA had clarified in its report on the public consultation on the draft Cybersecurity Bill that "computer systems in the supply chain supporting the operation of a CII will not be designated as CII". However, CSA noted that CII owners have the option to impose cybersecurity requirements contractually on their vendors.
On one hand, I am concerned that this option may result in vulnerabilities. If CII owners choose not to impose cybersecurity requirements on their vendors, how robust will our systems be? Even if they do, will there be checks or audits to ensure our cybersecurity requirements are being met by the engaged vendors?
On the other hand, vendors, some of which are SMEs, may find it difficult to cope with added costs, for example, third-party costs, should they be bound by contractual cybersecurity obligations. Although reporting is compulsory, vendors, especially small ones, may not want to report as that means taking staff away from work to attend to investigations. Small companies are most vulnerable and their vulnerability may impact the CIIs which engaged them due to the sharing of data.
I would like to suggest that the Ministry assist such small companies upstream by providing a pool of trained personnel to look at how their systems can be strengthened. We have to be absolutely thorough to ensure that our systems are not being compromised through such weak links.
I now move on to the point on licensing of individual cybersecurity professionals. Due to concerns that this will pose practical difficulties for global cybersecurity service providers since they deploy employees from different parts of the world to deliver urgent services at short notice, CSA has decided to work with industry and professional association partners to establish voluntary accreditation regimes instead. But I am worried that, without licensing, we may be exposing ourselves to greater risks in the future. How do we minimise such exposures and ensure accountability and traceability?
Similarly, for personnel responsible for cybersecurity, especially senior staff, do we have checks in place to ensure that we recruit suitable persons to make sure that they are of good character with adequate proper training and who upgrade their knowledge continuously?
The cybersecurity sector is evolving rapidly and we must be careful not to compromise Internet and system hygiene in our enthusiasm to support developments and innovations in this area. While interconnectivity provides greater efficiency and productivity, in a way, we have also become more vulnerable and greater care must be taken across all networks. I conclude with my support for the Bill.
Mr Speaker: Mr Ganesh Rajaram.
Mr Speaker, Sir, I speak in support of this Bill.
Singapore has had its fair share of cybersecurity breaches these past few years. We have heard in this House about the attacks on MINDEF, as well as our two major universities, NUS and NTU. While any cyberattack is of concern, to me, what is most worrying is that the attacks, the likes of those on the Singapore universities last year, were, as the authorities have depicted, carefully orchestrated and specifically targeted. It was not the work of casual hackers.
Mr Speaker, Sir, so far, Singapore has been spared from, at least from what we know publicly, serious breaches that could undermine trust and confidence in our financial systems and national security. But for how long? "We were just lucky", said Mr David Koh, Chief Executive Officer (CEO) of CSA, to explain why Singapore escaped the brunt of global malware attacks like the WannaCry ransomware attack. According to Mr Koh, had these attackers targeted Singapore specifically, the consequences could have been quite disastrous.
This is why this Bill is so important. In a world where nation-state actors are becoming bolder in their cross-border activities, we must ensure that our national security, including cyber defence, can withstand these cyberattacks by enemies we cannot see. Cyber defence has to be a whole-of-country approach. It is not just the Government’s responsibility. It is the responsibility of every single person in this community, from the home owner to the business leader.
Singapore is one of Asia’s major technology hubs. We are very highly connected and, as a result, very vulnerable to cybercrime. Our Smart Nation aspirations will bring many benefits but also many vulnerabilities if we are not vigilant and prepared.
In a recent newsletter, cyber technology company Apvera put Singapore at the top of the list of countries from which cyberattacks could be launched. Just to clarify, this does not mean that Singaporeans are becoming hackers, but rather, we have become the No 1 potential launchpad for cybersecurity attacks because of our location, digitalisation, IT savviness as a people, and the increasing number of cloud-based and virtual servers.
Beyond the provisions of this Bill, Mr Speaker, public education has to be enhanced and ramped up. Last year, CSA commissioned a survey to find out about Singaporean attitudes to cybersecurity and cyber hygiene. Here are some findings.
One in three respondents did not manage their passwords securely. They store them on our computers and they write them down. They also use the same passwords for multiple accounts, for work and personal accounts. One in three respondents did not enable their two-factor authentication. Despite widespread use of cloud storage, mobile and other storage devices, almost half the respondents did not conduct virus scans on their devices and files. More than six in 10 respondents connected to open, non-password protected wi-fi networks in public places. Practices, such as these, pose a substantial risk to the security of their personal information and, ultimately, the cyber communities they are part of.
Mr Speaker, Sir, I would like to commend CSA for launching the "Live Savvy with Cybersecurity" campaign last year, where people from all walks of life learned about cybersecurity threats and cybersecurity hygiene. I would strongly encourage the Government to make these roadshows and campaigns a part of school curriculums right from the first time children use computers in schools. Grassroots clubs and community centres should use this campaign to reach out to the elderly, too.
Businesses should also play their part in bolstering their cybersecurity defence. Too often, CEOs are happy to invest in IT systems only when it adds to their bottom line. Few realise, until it is too late, that IT security will actually protect this bottom line. According to a commentary on channelnewsasia.com last December, the cost of security failure because of cybercrime is projected to grow to over US$2 trillion globally in 2018.
Mr Speaker, Sir, the Government can also do more. Last month, in its review of the Auditor-General’s (AG's) Report for financial year (FY) 2016/2017, PAC cited recurring weaknesses in IT controls as a major weakness. Some of the lapses pointed out by PAC included: user accounts not being properly removed when required, and staff given access to accounts and data that they should not have access to.
What is alarming is that these weaknesses and lapses were pointed out in the past by the AG, and they were still recurring. Though the Ministries concerned have made arrangements to ensure that such lapses do not happen again, this is yet another timely reminder that cybersecurity should not be taken lightly. All we need is just one lapse to bring down the entire system.
Mr Speaker, Sir, let me conclude my speech by reaffirming my strong support for the Bill. We cannot take our security for granted and, in today’s digital world, cybersecurity is as important, if not more important, than military security, as the enemy is invisible and can strike anytime and anywhere.
Mr Speaker: Mr Darryl David.
Mr Speaker, Sir, advancements in information and communications technology (ICT) have transformed our society and the way we live, work and play. We are living in an increasingly interconnected world enabled by digital technology, and the inadvertent rise of Internet of Things (IoT) will accelerate our dependency on technology to an unprecedented level in the near future.
Singapore remains one of the most connected country in the world. Internet penetration rate in Singapore is at 82.2%, much higher than the global average, and 70% of Singaporeans are active on a social media platform, more than double the global average of 34%.
The explosive growth of ICT has ushered in a golden age of digitalisation and has been instrumental in enabling research, applied science, healthcare, transportation and urban development, just to name a few areas. Building upon a robust ICT infrastructure is also the vision of transforming Singapore into a Smart Nation.
Yet, the exponential growth of ICT and our increasing dependency on digital systems have heightened our vulnerability to cyber incidents. These cyber incidents can take the form of cybercrime aimed at siphoning money from corporations and individuals; cyber terrorism and espionage aimed at crippling Government systems and pilfering sensitive information; or even seemingly innocuous cyber pranks that could lead to widespread havoc and social disruption.
In Singapore, our Government systems were also not spared from such incidents. We have heard various Members in the House already referring to the incidents and the attacks carried out against MINDEF and also our IHLs. What is more foreboding is the CSA warning that there has been a consistent and concerted effort to penetrate our Government’s IT system. Thus, the introduction of the Cybersecurity Bill is not only much needed, it is also timely. I do, however, have some points that I would like to raise for discussion and consideration.
Clause 4 of the Bill has vested the Minister with the authority to appoint a Cybersecurity Commissioner and a team of high-ranking cybersecurity officials who have a wide range of duties pertaining to the cybersecurity efforts in Singapore. Although the appointment of the team will help ensure that efforts across Ministries and Statutory Boards are coordinated and policies are implemented consistently, greater clarity perhaps needs to be given on how this jurisdiction will be established.
With the recently established GovTech taking on the role of the Chief Information Officer (CIO) of the Government, and CSA already monitoring cybersecurity, how will the newly established centralised cybersecurity office work alongside these agencies? How can we ensure that there is no duplication of duties and, more importantly, what is the unique value-add that the centralised cybersecurity office will bring to our cybersecurity ecosystem that GovTech and CSA are not already doing?
Part 3 of the Bill has vested the Cybersecurity Commissioner with the authority to designate computers and computer systems as CIIs and empower the cybersecurity office with greater oversight over these systems.
While the Bill has set out some guidelines regarding the criteria of designating CIIs, perhaps more consideration needs to be given also on how the status of a CII is designated and what constitutes the phrase, "essential services". For example, clause 1 in Part 3 of the Bill suggests that a CII can be defined as a computer or computer system that is necessary for the continuous delivery of essential services in Singapore.
Although some services might not be regarded as "essential", they could be considered significant, and any disruption of these entities could have a serious socio-economic impact. Moreover, there could also be private organisations that would require the appropriate assistance, advice and, more critically, protection in this area, too.
I noted that the Minister earlier mentioned that cybersecurity officers are going to be bound by certain very clear guidelines and perhaps even legislation or laws with regard to ensuring confidentiality when they access such information. But I think we cannot deny that there are some potential ethical dilemmas that could arise when cybersecurity officers, in the course of their work, gain access to personal data that contains identifiers when the providers of that information did not give explicit consent for the information to be used or accessed.
While it might not fall strictly under the rubrics of the proposed Bill, how can we provisionally use the Bill to manage the issue of "fake news"? I am aware that the Parliamentary Select Committee will, no doubt, present its views on how the issue of fake news can be tackled in due time but, until then, can we utilise the provisions in this Bill to take action against the perpetrators of fake news?
If someone were to hack into a Government agency’s system and issue falsehoods via the agency’s website or automated broadcast system, then can the Government take issue with the perpetrators for committing a cybercrime and also prosecute them for what their hacking resulted in? For example, if someone hacks into the Singapore Police Force (SPF) website or creates a fake SPF site to spread fake news of terror acts, how would the Government deal with the perpetrators and the ensuing chaos that possibly could result from this cybercrime?
Fake news, as we all know, can lead to widespread panic that erodes the trust in public institutions. So, can the cybersecurity office hold the perpetrators of such cybercrimes responsible for the consequences of their crimes? Or will the crimes fall under other legislation, such as the CMA? And, if so, how can the Cybersecurity Bill complement the legislation under CMA?
Mr Speaker, Sir, advancements in science and technology have always benefited humanity by enhancing conveniences in our daily lives and enabling us to do things that once existed only in our imagination.
At the same time, there will always be deviant individuals who will use science and technology for criminal activities or subversive purposes. Consider how nuclear power has allowed humanity to make significant progress, yet that same nuclear power and capability, in the hands of the wrong individual, can have catastrophic consequences for humanity.
Digitisation and Internet technological advancement are no different. As much as they have tremendous benefits for humanity, there is a dark side to this as well. At best, cyber pranksters can cause widespread inconvenience. At worst, cyber terrorists can cause the deaths of hundreds of thousands, if not, millions of innocents.
I thus believe that it is timely that the Government is taking steps to address the critical issue of cybersecurity and I stand in firm support of this Bill.
Mr Speaker: Mr Azmoon Ahmad.
Mr Speaker, good afternoon. The Internet has undoubtedly been part of our life, be it at home, at work, or while we play. We use the Internet directly or indirectly, so much so it is almost impossible to live without it – doing research for education, dynamic navigation while driving, exploring new recipes for the next party meal, or even searching for that box office movie. The Internet is now becoming an indispensable part of our daily lives. Our high dependency on the Internet has made it a part of us.
Like many things which are a part of us, it can also be deemed to be private, until when it is violated. Violation of privacy leads to dire consequences. This could mean loss of business, loss of self-esteem for an individual or even loss of life. While we want to believe that the Internet is safe and secure, however, a dark side of it exists and must be managed and controlled.
Mr Speaker, please allow me to share my own personal experience as a victim who was held ransom by a ransomware called "Locky". It happened in April 2016, where my work computer was attacked by a software virus which eventually encrypted and locked all my data files. This resulted in me not being able to open or run any of my files. It was a complete disaster as all my work was stored in the computer. It was also unfortunate that the virus attacked the backup files, both in my computer and the main server.
This eventually rendered me helpless as I could neither provide all the required information, nor could I prepare any information for my potential business acquisition. I felt intruded and my personal space had been violated. Mentally, I felt no difference than a person who had been physically violated.
At this juncture, I wished the authorities could have acted and the culprit be apprehended and be dealt with according to the rule of law. However, this never happened. Eventually, I managed to recover all the attacked files through a third-party overseas service provider, but with a fee for a few thousand US dollars. I felt that I was held ransom and the only way to recover all my files was to pay that ransom fee. This is not right and should never happen at all. However, the truth is: it did not stop. Not only did it not stop, in fact, more and bigger cyberattacks occurred in the preceding years.
Just to give Members some examples. I believe that some of my colleagues had already shared this. In October to December 2013, a cyberattack called "The Messiah" created havoc as several systems and portals were compromised. Users were redirected to suspicious and unknown websites and this undermined the confidence of Internet users. However, fortunately, the culprit was eventually apprehended.
We always thought that our military should be the last place and institution for a cyberattack to occur. Unfortunately, our MINDEF was hacked on 1 February 2017 where details of some of our Servicemen and personnel, including their Singapore NRIC numbers, telephone numbers, and birth dates were leaked.
On 14 May 2017, ransomware "WannaCry" crippled the world for three consecutive days and compromised more than 3,000 systems globally. This was considered as one of the major cyberattacks of the decade.
On 28 June 2017, "Petya", which was considered more dangerous than previously known ransomwares, created havoc as it encrypted the Master File Tree Tables for New Technology File System (NTFS), overwriting the Master Boot Record. It spread through malicious emails with booby-trapped Microsoft (MS) Office document. From there, it downloaded and ran the installer and released the software virus and spread unknowingly. This had a devastating effect as it attacked the purported highly secured Master Files which are the basis of the file structure system.
Mr Speaker, in all the cases highlighted, the cyber intrusion and cyberattack were uninvited and unlawful. It was made with malicious intent with the objective to create havoc and misery to all parties, including individuals, agencies and institutions. It undermined the confidence of everyone. Such acts must never be condoned as it will only lead to unhappiness, anger and loss of faith.
I regard such acts as similar to any physical attack on a person, as the consequence from such attack is dire, if not even more. From mental anxieties for having felt violated in their personal space to loss of valuable data and information on one’s Internet-linked devices, such as a computer, mobile phone and others, becoming a victim of a cyberattack can lead to serious consequences. It could even be far-reaching as the outreach from a cyberattack can be wide and endless.
Mr Speaker, it is always hoped and wished that the relevant authorities would be able to act appropriately and accordingly when such things happen. Thus, the Cybersecurity Bill, which is aimed at establishing a working framework in the management of and in response to cybersecurity threats, is very much welcome. In addition, a regulatory framework over the owners of CIIs and cybersecurity service providers will provide an added boost in ensuring that Singapore has a robust cybersecurity framework overall. It is my hope that the regulatory framework be regularly reviewed with higher frequency and in tandem with the fast-changing Internet landscape. With that, Mr Speaker, I wholeheartedly support the Bill.
Mr Speaker: Mr Henry Kwek.
Mr Speaker, I stand in support of the Bill. Members of this House have talked about the possibilities, as well as the dangers, offered by the Internet and we talk a lot about cybersecurity threats. So, I would not repeat those other than to point out the fact that Singapore is no less exposed to such threats.
On the contrary, as the financial services hub and a regional hub to many global corporations, we are among some of the most exposed countries in the world, making us an attractive proposition to hackers from around the world. It is key to see how vulnerable we are.
In a survey done last year by security services provider Quann of 150 senior IT professionals from Singapore, Hong Kong and Malaysia, it showed that 40% do not have an incident response plan when they are facing cyberattacks and 67% of those who had those plans admitted to not practising their incident response plans.
This stands to impact our reputation, credibility and position as a global corporate hub and a regional e-commerce platform. As Chair of ASEAN this year, Singapore has identified our aspirations to push for an ASEAN-wide e-commerce platform. For such an ambitious project, and to protect our business hub status, we need to make sure we have a strong cybersecurity framework and regime. In this regard, I am very supportive of this Bill. However, I would like to ask our Government to share more on an important issue which is: how do we keep watch on the guards?
First, how about the companies we are entrusting to protect the cyber world here? While we have certification regimes to manage such companies and ensure that they meet desirable quality standards, do we know enough about the people who are working in these companies? Do these professionals, who are certified, have a vested interest in Singapore? And what if they have interests that are contradictory to Singapore's? It is certainly not a stretch of imagination that we have foreign interests among our cybersecurity professionals here who may leverage their positions in having access to secret and confidential platforms. As such, I call for three things.
One, more thorough due diligence checks by our cybersecurity agencies on professionals. Two, re-examine the penalties for misuse of access to data, especially if the perpetrators are members of the cybersecurity industry who are supposed to guard the industry. Three, create a certification system that favours cyber professionals who have a vested interest in Singapore, people who have some real roots and deep roots in Singapore, rather than fly-by-night experts who drop by for ad hoc projects whom our laws have difficulty to reach and deter.
In addition, cybersecurity could be promoted as an engine of growth. Singapore has emerged as a trusted business hub because of our trusted regulations, our strict regulations and because of our people's trusted reputation. Properly executed, Singapore could naturally become a premier trusted business hub for Asia and for the region with regard to cybersecurity.
In conclusion, while this Bill helps to create a strong cybersecurity regime for Singapore, we must also ensure that we are not caught blind-sided by any unforeseen circumstances, for doing so would be a risk that could prove very costly for Singaporeans in many ways. But if we get this right, it can also create many opportunities for Singapore. Mr Speaker, I fully support the Bill.
Order. I propose to take a 20-minute break now. I suspend the Sitting and will take the Chair at 3.20 pm.
Sitting accordingly suspended
at 3.00 pm until 3.20 pm.
Sitting resumed at 3.20 pm
[Mr Speaker in the Chair]
*Debate resumed. (proc text)]