Debated in Parliament on 11 May 2015.
Mr Zaqy Mohamad asked the Minister for Communications and Information in respect of the Prime Minister's speech at the Founders Forum Smart Nation Singapore Reception on 20 April 2015, whether there have been any cybersecurity incidents involving IT systems belonging to the Government.
Around the world, the information technology (IT) systems of various governments are probed regularly and experienced daily attacks. In October 2014, the United States (US) media reported that computer networks in the US State Department email network were breached. This breach also ended up infecting some computers in the White House. This case is still under investigation, and agencies like the National Security Council and the Federal Bureau of Investigation have reportedly declined
Page: 134
to comment on the investigation.
In cybersecurity, it is said that the difference is not between organisations that have been breached and those that have not. Rather, it is between organisations that know they have been breached and those who are still unaware that they have been breached.
This is why the Government takes cyber security very seriously and invests in systems to monitor its IT networks and to detect attacks. To ensure the continued effectiveness of our defensive measures, we are neither able to comment on the specific nature of these defences nor on the attacks that have been detected.
We can confirm that the Government's IT networks are probed all the time. While most of these attempts are unsophisticated, we have also detected serious and advanced attacks. For example, during the passage of the Computer Misuse and Cybersecurity Bill in March 2013, the House was informed that, in the lead-up to the Asia-Pacific Economic Cooperation (APEC) 2009 meetings held in Singapore, there were at least seven waves of malicious email attacks which targeted members of the APEC Organising Committee and APEC delegates from various countries. In a more recent case that occurred last year, the Government detected a security breach in the Ministry of Foreign Affairs IT system. Immediate steps were taken to isolate the affected devices and appropriate security measures were implemented to further strengthen the network.
The Government takes cybersecurity very seriously. The Cyber Security Agency works with the Infocomm Development Authority (IDA) the lead agency for the protection of Government IT systems to ensure a high level of vigilance over the security of our Government networks and readiness to respond rapidly and appropriately to any incident. IDA works closely with Government agencies to ensure good security practices, which cannot remain static but must adapt to the new and emerging modus operandi of the attackers. Due to the nature of their operations, some agencies are, unfortunately, highly attractive to potential cyberattackers and will need to do even more to defend and protect their networks.