Debated in Parliament on 11 Nov 2013.
Mr Zaqy Mohamad asked the Minister for Communications and Information in light of the fire at the SingTel Bukit Panjang Exchange on 9 October 2013 resulting in loss of telecommunications services to consumers and businesses (a) if he can provide an update on the status of the IDA investigation; (b) what lessons have already been learnt from the case; (c) what actions the Government will take even as the investigation continues; and (d) what businesses and consumers can do to make themselves more prepared in future.
Mr Yee Jenn Jong asked the Minister for Communications and Information in light of the disruption to connectivity due to the fire at the SingTel Exchange at Bukit Panjang (a) whether our network is sufficiently resilient to withstand disasters and terrorist attacks; (b) whether there is a need to separate the provision of the national network from retail operators; and (c) whether there are plans to introduce different tiers of service levels and redundancies for critical business and Government operations.
Mr Zaqy Mohamad asked the Minister for Communications and Information (a) when will IDA make a decision on and what are its considerations in allowing the SingTel-owned NetLink Trust to buy out the country's fibre network builder, OpenNet, after six Singapore broadband players and a coalition of Asia-Pacific carriers have jointly opposed the move; and (b) whether IDA will review the need and funding for a second NetCo to enable greater network and exchange independence for the future.
Mdm Speaker, may I have your permission to answer Question Nos 8 to 10 together?
Yes, please.
Mdm Speaker, IDA is still investigating the incident. It has formed a review panel, comprising relevant telecommunications network and fire experts, to assist in the investigation. The investigation will cover the following areas: (i) the cause of the incident; (ii) whether the incident could have been avoided; (iii) whether operators took all necessary action to restore services expeditiously; (iv) whether affected businesses had acquired diversity options and, if so, whether these options were effective when the incident happened; and (v) determine measures to be
Page: 36
put in place to ensure that such incidents do not happen again. Last week, SingTel revealed the preliminary findings from its internal investigation on the cause of the fire. However, as IDA's investigation is still on-going, it would not be appropriate for me to comment on the facts of the case, or to draw any conclusions.
Madam, the Government takes this incident very seriously. We recognise that a resilient telecommunications network is very important to the country. There are four components to the concept of resilience. The first is Diversity. The second is Resistance. The third is Redundancy, and the fourth is Recovery.
"Diversity" means providing more than one way for telecommunications signals to be routed. "Resistance" refers to the ability of the infrastructure to withstand threats, including foreseeable and avoidable human errors, with minimal disruption or failure such that operations continue. "Redundancy" refers to the concept of having "spares". It means putting, on standby, additional equipment or services which cut over if the primary equipment fails. Recovery means the ability to respond to incidents and to restore services expeditiously with minimal delay. Getting the most optimal level of resiliency means making the right investments in Diversity, Resistance, Redundancy and Recovery.
Focusing on diversity alone does not make the network more resilient. For example, if an operator built a duplicate network, but did not invest in adequate facilities to recover from an outage, it would end up with two networks that are not resilient. It is the combination of enhancements to Diversity, Resistance, Redundancy and Recovery that matters.
A second NetCo, to be fully diversified, must have a completely different set of exchanges, cannot share the same routes through which cables run, cannot share any common point, including ducts, and must separately run into every premise. It will be many times more expensive than the Next Gen NBN, which avoided the expense of having to build its own ducts and exchanges. For the consumer, they will still have to choose between one of the two networks. So, the service that the consumer buys will still not be diversified.
Let me turn to what actions the Government will take even as investigations continue. IDA has, over the years, taken steps to progressively improve resiliency. Since 1998, IDA has put in place the Telecom Service Resiliency Code which places strict requirements on operators of key network infrastructure. This is to ensure that they invest in and enhance the resilience of their networks
Page: 37
to prevent outages, as well as having processes for quick service recovery in the event of an incident. IDA has penalised operators under the Resiliency Code where IDA believes operators could have prevented or taken shorter restoration time.
The Member asked what lessons have been learnt from this incident. We take the opportunity to learn from every incident that happens, and review policies and regulations to enhance resilience. In January 2013, M1 suffered a mobile telephone outage. IDA conducted an in-depth review of the resiliency of the three mobile operators' networks. So, apart from imposing a record fine on M1, IDA's investigation also identified areas of improvement for the sector. While the review highlighted that the three mobile operators' networks generally meet international standards, IDA felt that further improvements can be made. For example, international experts indicated that no country has required its operators to build a full geo-redundant mobile network at the core level. This is where an operator puts in place at least two sets of replicated network equipment, housed at different geographical locations, so that in the event that one location is brought down, the other location is capable of immediately taking over the full load and capacity. This is an option that IDA is currently considering. IDA will implement an audit framework by the second half of next year and is in discussion with the mobile operators on the scope of the audit, which would cover the network design, technical processes, business continuity planning, and infrastructure and facilities to support the mobile network. IDA will also work with the mobile operators on implementing enhancements in areas, such as network design, by minimising the number of single points of failure, upgrading network architecture to support full redundancy, and implementing better business continuity planning.
In the same way, Government intends to wait for the outcome of IDA's investigations. Based on the findings, we will review if further policy measures are necessary, including having similar audit framework for other networks. In the meantime, certain works have been suspended, pending a full review of various procedures.
Let me address the issue of what end users can do. For critical sectors, such as the financial sector, regulators, such as the Monetary Authority of Singapore, require financial institutions to maintain resilience in their systems. End users and businesses that require higher resiliency can adopt various strategies, by diversifying the risk through path or exchange diversity from the same operator, by using different technology platforms, for example, fibre vs wireless, or by purchasing services from different network operators. As their needs vary, it would be impractical to require the telecom operators to offer only a fixed menu
Page: 38
of tiers. Rather, end users need to work closely with their telecom service providers in order to ensure that the telecom service offered is well integrated into their enterprise systems.
While telecommunication service providers are required to provide sufficiently clear explanations to consumers and businesses on their resiliency service offerings, consumers and businesses may make the effort to have a better understanding of these offerings before deciding on an approach that suits their needs. In this regard, I urge users which have certain business requirements, to relook at their diversity options and ensure that they have good alternatives in place.
Finally, Madam, on the Consolidation Application of OpenNet, I would like to reiterate that the sale of Open Net is unrelated to the incident at the Bukit Panjang Exchange. IDA had correctly stated that ownership should not be confused with diversity. I understand that IDA has received feedback from various parties concerning the Consolidation Application and is reviewing them. They will be able to issue a decision soon.
The Telecom Competition Code requires the IDA, when assessing consolidation applications, to take into account all factors in accordance with the standards spelt out in the Code. These include ensuring that the proposed consolidation does not result in a substantial lessening of competition in any telecommunication market in Singapore or harm the public interest. In its review, IDA will take into account the feedback received from the public consultation exercise, including the submission from the industry coalition.
Mdm Speaker, I thank the Minister for his comprehensive reply. He spoke about Disaster Recovery and Business Continuity Planning, and there was quite a bit of stress in terms of infrastructure. Such things also involve typically process and ensuring that there is regular updating of these processes and performance of the tasks, like how you would do fire drills. What is IDA's framework with regard to this, and has SingTel been performing these exercises prior to the fire?
Also, do the requirements involve the other operators? I also note that M1 and Starhub were also affected as they link back to the OpenNet infrastructure.
The Minister also touched on IDA's new audit framework that is to be launched in the second half. Will that also mean that IDA will now practically audit service providers? The proactiveness is important. Is it also time to look
Page: 39
at more stringent requirements because of our heavy dependence, compared to other developed countries, on the communications infrastructure today?
To answer the second question first, the Member is right that when we have the audit framework in place, it means that we will have to go out and check on a regular basis as to whether the requirements that we have put in place in the Code are being implemented by the operators. We want to look at our requirements in a comprehensive manner. I mentioned just now the example of the M1 outage and what we have learnt from that incident. We have reviewed some of the requirements that we want to put into the audit framework, which we have now released to the public for consultation. We will do so for other networks that I mentioned in my reply earlier. We think this is the best way to move forward, because it is important for us to ensure that, given the complexity of the systems, that our requirements must be heightened to meet all possible circumstances.
On the first question: at the moment, what we have is a resiliency code that places certain requirements on all our network operators, especially the large operators whose network has a wide impact. They are supposed to follow the requirements, and as and when an incident happens, an audit would be done by IDA to find out whether they had adopted the requirements.
Finally, we will leave it to the operators to do their own audit checks and their own internal assessments to make sure that they have all the requirements in place. At the network level, we want to have certain redundancy and resiliency. At the business end, as I had mentioned in my reply, it is something for the operators and the businesses to decide what level of redundancy and resiliency the businesses would like to have.
We are concerned about the critical infrastructure, and, at the network level, we have requirements which are in place; at the consumer end, we have basically left it to them to decide on a commercial basis.
Going forward, with the audit framework in place, we hope that would further strengthen, not only the resiliency code, but the regular audits will also ensure our operators are in line. We cannot be too prescriptive because we recognise that technology moves ahead at different speeds. What we want to do is to impose certain requirements that are necessary to ensure the operators have good recovery in case an incident happens, a certain level of resilience should be built within the operators' network, and the need for certain types of
Page: 40
network diversity.