S Iswaran
Singapore
“The Maritime and Port Authority of Singapore (MPA) has incorporated the requirements of the International Maritime Organization (IMO) 2020 regulation in its Prevention of Pollution of the Sea (Air) Regulations 2022. The Regulations are applicable to Singapore-registered ships and all other ships while they are in Singapore waters.”
“The Maritime and Port Authority of Singapore (MPA) plans to progressively roll out the charging infrastructure for electric harbour craft operations in the Port of Singapore from 2025.”
“Since 2018, the Land Transport Authority (LTA) has imposed minimum bicycle parking provisions covering different types of developments. The requirements are determined by multiple factors, including the developments’ use, location and gross floor area (GFA).”
“I had addressed similar Parliamentary Questions by Mr Gerald Giam on 29 November 2022 and 10 January 2023, as well as in my Ministerial Statement on 8 May 2023. The Member can refer to these past answers and statement as there has been no material change in the allocation of Certificates of Entitlement.”
“To encourage the uptake of electric cars, the Government has rolled out the Electric Vehicle Early Adoption Incentive and enhanced Vehicular Emissions Scheme. When taken together, it provides up to $45,000 off the Additional Registration Fee of an electric car upon registration.”
“The Land Transport Authority studies all potential changes to the Certificate of Entitlement (COE) system carefully, including conducting sensitivity analysis where appropriate.”
The complete record
Every one of 2,300 lines we hold for S Iswaran, in date order, each linked to its source. Free to read, in full, without an account. Page 19 of 46.
“Some highlights of this valuable treasure trove of Singapore's early history include Munajathu Thiratuu, the oldest Tamil book on Islamic religious poetry held by the National Library, or Hikayat Abdullah, one of the most important records of the sociopolitical landscape in Singapore, Malacca and the southern Malay kingdoms at the turn of the 19th century. These videos will be released every fortnight from April on NLB's social media channels. We have also brought a special preview of the NLB's archives to Parliament. I invite all Members to visit the Reception Hall of Parliament House to view exhibits that showcase our multicultural roots and life in early Singapore. NLB has also worked with community groups to digitise valuable historical content. Last month, Senior Minister of State Sim Ann launched the Singapore Biographical Database of Chinese Personalities to remember Pioneers who contributed significantly to Singapore in its early days. NLB and the Tamil Digital Heritage Group are already hard at work collecting historical materials on Indian dance in Singapore for a new Digital Archive of Singapore's Tamil Dance. Theatre practitioners from the Malay community will partner NLB to create a Digital Archive of Singapore Malay Theatre. These new databases will be a rich resource of our arts and cultural heritage, and they will be publicly available from December this year. Our National Archives also have much to offer. The National Archives Singapore (NAS) celebrated their Golden Jubilee last year, and their birthday wish is to encourage every Singaporean to play a part in preserving our collective memories.”
“IMDA's funding call for proposals will close by the end of this month, and I strongly encourage local companies to make use of this resource. Secondly, the Singapore Media Festival will continue to be our main platform to showcase our most promising talent and companies to the world. Last December, the Festival attracted over 23,000 media professionals and industry thought leaders and facilitated more than US$313 million worth of deals. We will expand the Singapore Media Festival to seize the opportunities created by the growing convergence of the tech and media industries and strengthen Singapore's thought leadership in the region. IMDA will share more details in the second quarter of this year. Our efforts to develop the media industry will help us tell our stories better to our fellow Singaporeans and to the rest of the world. And there is, indeed, no better story one could argue than the story of Singapore. This year’s Bicentennial commemoration will help us to understand our early history, how Raffles' landing in 1819 set us on a path to where we are today, and reflect on the attributes we will need to succeed in the future. The National Library and Archives will play an important and meaningful role in this Bicentennial commemoration. NLB will roll out a series of activities to increase engagement with Singaporeans. For example, NLB's librarians will play host and present the National Library's rare material collection with 25 specially produced videos.”
“First, we will extend the iPrep scheme to media students in tertiary schools so that they can be better prepared for the rigours of the media industry when they graduate. iPrep will provide up to $8,500 per student to cover the costs of attending industry courses, overseas internships or immersion programmes. Next, we will strengthen on-the-job training to familiarise fresh media professionals with the latest trends and tools of the trade. IMDA will launch a Story Lab Apprenticeship this year to help young media professionals gain customised training and experience in key media companies. I am glad that companies like Mediacorp, mm2 Entertainment, HBO Asia and Turner Asia Pacific have already expressed interest to come on board. IMDA will announce more details by the third quarter of this year. We will also help media professionals master digital skills to compete and thrive in today's landscape. Our CET courses have been very useful to media professionals like 37-year-old Ms Nusaibah Abdul Rahim, who is creative director of a media production company. Last December, Ms Nusaibah attended a data-driven content development workshop organised by the Singapore Media Academy and learned how to analyse data from audience insights to drive creative decision-making. IMDA will curate more of such CET courses. Mr Darryl David asked about our plans to help local media companies go global. I would like to give two examples. Firstly, IMDA's Public Service Media Digital Partnership Fund will help local media companies partner international players to co-produce digital-first public service content for our audiences. In other words, content, but it is digital first.”
“Mr Chairman, Sir, many Members have spoken in this COS debate about the need to bring Singaporeans closer together as we take Singapore forward. We agree wholeheartedly with them. Let me now share with Members how MCI is fulfilling our vision of an engaged and connected Singapore. Through the media sector, we will engage Singaporeans with shared stories of our home and nation. Through our National Library and Archives, we will cultivate a shared appreciation of our past, so that we can move into the future with confidence and a strong sense of our identity. Let me begin with the media. The digital age offers great promise for our media sector to grow. The global entertainment and media industry is expected to grow by 4.4% from 2017 to 2022. Within Southeast Asia, the media sector is likely to grow by more than 7%. There is a discernible shift towards Asia and Asian content. We are well-positioned to seize these opportunities. We are at the confluence of the East and the West. We have talented storytellers and world-class digital infrastructure. We must leverage these strengths to develop promising young talent, deepen the skills of our media workforce and prime our industry to ride the wave of growth in the global media ecosystem. 4.30 pm Mr Darryl David has asked about our plans to develop the local media industry. We are doing so through manpower development plans like our Skills Framework for Media, which maps out career pathways and skills to help media professionals stay ahead of the competition. We will enhance this Framework to meet the industry's needs for writing and storytelling skills, as well as the demand for professionals with digital skills like data analytics and social media management.”
“Thank you. This is what my younger colleagues in the Ministry called a "bold" or "edgy" video. Mr Chairman, if I may conclude, the building of a vibrant digital economy in Singapore is a shared endeavour. And the video we have just seen highlights that there are challenges, whether we are individuals, workers or smaller enterprises. In different ways, we are dealing with these challenges. And it also shows how we can collaborate and succeed. So, let us work together, as digitally-empowered businesses, digitally-skilled workers and digitally-connected citizens to realise that vision.”
“One of the volunteers, Ms Audrey Poh, shared with me that she was inspired by the participants' enthusiasm to learn as she taught them to use different apps. Our Digital Clinics have reached more than 4,000 individuals since 2017. And this was only possible with the support of 20 corporate partners and 1,000 volunteers like Ms Poh. To support many more Singaporeans like Ms Poh who are passionate about helping others, we will launch Our Singapore Fund, which will support community efforts that promote digital readiness. This is in collaboration with the Ministry of Culture, Community and Youth (MCCY), and Senior Minister of State Janil Puthucheary will be elaborating on these initiatives. Mr Chairman, I have spoken at length on our broad range of efforts to help our enterprises and people benefit from the opportunities presented by the digital economy. This is not an easy task nor is it the sole responsibility of the Government. Indeed, ultimately, every business, every worker and every citizen has to step up, overcome the challenges, and take ownership of their learning and digital transformation. Chairman, if I may have your permission to show this video which aptly captures the challenge that we are dealing with?”
“Our 11 CII sectors provide essential services, such as transport, energy and water supply, and all CII owners must adhere to the Cybersecurity Code of Practice. Regular penetration tests are also conducted to identify and rectify vulnerabilities. In addition, we have in place measures to enhance resilience, including contingency and incident response plans in the event that a cyberattack causes the disruption of essential services. We launched Digital Defence as the sixth pillar of Total Defence last month. It was in recognition of the fact that each and every citizen, business and organisation has a role to play in helping us develop robust defences against threats from cyberspace. To paraphrase the old saying, we are only as strong as the weakest cyber link. Senior Minister of State Janil Puthucheary will be sharing more details on our cybersecurity efforts. Finally, we believe that every Singaporean can be a digitally connected and engaged citizen. Building digital readiness is a national effort involving the Government, businesses, communities and individuals. This is why we are launching the Digital Participation Pledge which allows organisations to commit to one or more actionable items that help Singaporeans acquire skills and adopt technology. So far, more than 270 organisations have pledged to do their part, and we hope to see more organisations sign up so that, together, we can build a more digitally ready Singapore. I am heartened by the many volunteers and corporate partners who have come forward to volunteer at our Digital Clinics to assist citizens in using mobile devices. Standard Chartered Bank is a corporate partner with more than 200 of their staff members volunteering.”
“IMDA will launch a public consultation shortly to help us develop the right regulatory framework and policies for 5G, including the allocation of spectrum. On Mr Cedric Foo's point, we are strong advocates for open cross-border data flows, which is essential if we are to fully harness the potential of technologies like AI. 3.45 pm At the regional level, we have helped set baseline data protection principles in the region by contributing to the ASEAN Framework on Digital Data Governance. We also participate in multilateral certification mechanisms like the Asia-Pacific Economic Cooperation (APEC) Cross-Border Privacy Rules and Privacy Recognition for Processors systems. We have included commitments to promote data flows in free trade agreements, such as the Comprehensive and Progressive Agreement for Trans-Pacific Partnership. And, collectively, these initiatives will enable businesses to transfer data across borders seamlessly and securely and seize new digital opportunities. But these opportunities can only be meaningfully realised within a safe and secure cyberspace. I agree with Mr Teo Ser Luck and Assoc Prof Daniel Goh that besides helping SMEs benefit from digitalisation, we must help them protect their businesses from cyber threats. So, CSA and IMDA will expand the range of pre-approved solutions to include cybersecurity solutions later this year. This will give SMEs some guidance into the kind of solutions they can adopt and strengthen their cybersecurity measures. Dr Teo Ho Pin asked how we are protecting our CIIs. Last year, we passed the Cybersecurity Act. It empowers CSA to effectively combat cyberattacks and investigate cyber incidents. All CIIs have been designated by the end of 2018.”
“And to this end, I recently launched Singapore's Model AI Governance Framework to guide private organisations, in particular, to deploy AI solutions safely and ethically. We have also established an Advisory Council on the Ethical Use of AI and Data and launched a research programme to advance discourse on legal and ethical AI issues. Prof Lim Sun Sun will be happy to note that we are engaging partners like the Advisory Council, sector regulators and TACs to promote the adoption of the Framework. Our efforts in AI governance and ethics have also received international recognition as a World Summit on the Information Society Prizes 2019 Champion. So, this is an acknowledgment at an international fora of the work that we are doing, but we are pressing ahead because the landscape is evolving. To Mr Ong Teng Koon's query on infrastructure, we aim to ensure that we have future-ready and globally competitive digital infrastructure which is the bedrock of our digital economy. So, we plan to commence the rollout of fifth generation mobile networks, or what is more commonly known as 5G, by 2020 to maintain Singapore's competitive edge in connectivity. With 5G, businesses and citizens can experience peak data rates of up to 100 times faster than 4G, with up to 25 times lower latency, and the ability to support up to 1,000 times more devices per square kilometre. And 5G has the potential to fundamentally transform our businesses and the way they operate, given its capacity to handle many high-demand applications simultaneously, such as the connectivity of autonomous vehicles, industrial automation, the deployment of IoT and nationwide sensor networks.”
“PDPC has the expertise and resources to investigate different types of data protection breaches and, where necessary, works with external parties on investigations. Because it is cited within IMDA, the agency is also able to ride on IMDA's broader infrastructure and overheads and focus its resources on investigations and some of the core areas of work. We will continue to ensure that PDPC is adequately resourced and fit-for-purpose. I had also explained in Parliament on 12 February why public agencies are not covered by PDPA. I want to inform Ms Sylvia Lim that the reasons have not changed in the next past weeks. The data protection standards in PDPA and the Public Sector Governance Act (PSGA) are broadly aligned. Public agencies are subject to the same, if not higher standards, than the private sector. They are covered not only by PSGA but also other specific legislation and the Government Instruction Manual, which Ms Sylvia Lim has also acknowledged. When necessary, PDPC helps to link individuals with the organisation and its data protection officers to address specific data protection concerns that have been raised. PDPC can also refer parties to mediation. Mr Mohamed Irshad asked about recourse available for individuals affected by data breaches. Individuals who suffer loss can seek legal advice on available recourse, including seeking compensation directly from the organisation or by taking private action against the organisation. Individuals may also resolve data protection disputes through mediation by the Consumers Association of Singapore or the Singapore Mediation Centre. We are also preparing for new technologies like AI. Mr Vikram Nair asked about AI ethics, which is an area we are focused on, given the pervasive potential of AI technology.”
“Investment in research and development (R&D) is also an essential part of our efforts to help industries innovate and stay competitive, even as the technology landscape is rapidly evolving. Our R&D investments in the Services and Digital Economy (SDE) domain of the RIE2020 Plan have helped us build capabilities in frontier tech areas and address our national priorities. For example, through AI Singapore's Grand Challenges, we are working with academia and industry to solve major problems faced in the key sectors, such as healthcare. We must sustain this research and innovation momentum that underpins our Digital Economy strategies. I am, therefore, pleased to announce and share with Members that we will allocate a further $300 million for research in the SDE domain, almost doubling it from the current budget. This increase is part of the next phase of the National Research Foundation's RIE2020 plan, which will be announced soon. We are also establishing Digital Services Labs to unlock value from our R&D investments. This programme will work with technology providers, research and industry partners to co-develop cutting-edge technology to address business challenges. Effective regulations that keep abreast of change and innovation and world-class digital infrastructure underpin our Digital Economy vision. In that regard, we are reviewing our Electronic Transactions Act to cater for new business models, new technologies and national projects. We are also reviewing PDPA so that it continues to safeguard consumer interests while enabling the innovative use of data. To Ms Sylvia Lim's query, in 2018, the PDPC processed 1,669 complaints on data protection issues and 1,236 on Do Not Call issues.”
“So, we have seen good results from these programmes and I would like to inform Ms Tin Pei Ling that 90% of the beneficiaries continue to be in ICT roles. Many of them also stay with the same company they were placed in. We also conduct periodic reviews and work closely with key hirers of ICT professionals to assess the outcomes of our programmes. Tech companies, like Tunity, play an important role in the training and growth of our ICT workers. Through our local partners, Kaplan and Trent Global, we will also create more upskilling opportunities for our workers by bringing in renowned training curriculum by METIS for data science from the US, and Code Institute for software development from Ireland. These will help more workers and companies seize opportunities arising from the digital economy. And as every worker has different digital training needs, we will also roll out the Digital Learning Guide. It will enable employers to plan for their workers' digital training needs using a step-by-step guide. We will start with the retail and logistics sectors and progressively extend it to others. We also want to harness the talent of the many Singaporeans who are working overseas in key tech areas and who are eager to contribute to Singapore's digital transformation. To encourage such tech talent flows, I am pleased to inform Members of the launch of the Overseas Singaporeans in Tech (OST)-LinkedIn community, which is a partnership between the industry and key Government agencies. It will connect overseas Singaporean tech talent with our local tech community and keep them informed of the latest developments back home. Since the group was formed in January this year, it has managed to get in touch with over 500 Singaporeans.”
“The digitalisation of our businesses can succeed only if our workers, too, are equipped to effectively use digital technology. Many Members – Mr Cedric Foo, Mr Teo Ser Luck, Ms Tin Pei Ling and Mr Douglas Foo – have asked how we are preparing workers and growing our talent for the digital economy. And I agree with Mr Teo Ser Luck it is a challenge. It is a challenge, both of changing mindsets and developing the will to make the change happen. In 2016, we launched the TechSkills Accelerator (TeSA) programme to meet the growing demand for digitally-skilled professionals. Since then, over 61,000 training places have been taken up or committed, which accounts for about a third, slightly more, of our total ICT workforce. These courses provide opportunities for non-ICT workers to switch into a tech career, as well as for current ICT workers to take on deeper tech roles. Mr Xie Zhaoyan is one of our graduates from TeSA's Tech Immersion and Placement Programme, which helps non-ICT workers move into the field. Through the programme, he acquired software development skills which helped him make the transition from being an engineer in the oil and gas industry, to a data engineer at Amaris AI where he develops applications for clients. TeSA also has a Company Led Training (CLT) programme where, as the name suggests, companies take the lead to train ICT workers. I recently visited Tunity Technologies, a local radio frequency identification (RFID) solutions provider. The SME has helped train and hire six workers through the programme, including Ms Yeo Wan Ru. Through the programme, Wan Ru learnt skills in the Internet-of Things (IoT) domain and is now an IoT Engineer.”
“They use a pre-approved cloud-based AI solution to optimise delivery routes and dynamically reassign drivers to new routes based on the capacity and locations of available vehicles. This has enabled them to increase their deliveries by 20% and revenue by 15%. And they are now extending the platform to fellow SMEs as well. By 2020, we will roll out AI- and cloud-based solutions to every sector so that more businesses can benefit. Beyond the enterprises, we have also embarked on digital initiatives at the systems-level so that we can derive broader benefits. The nationwide e-invoicing network is one such initiative which IMDA launched in January this year. Invoicing is a key business function, but manual processes can be tedious and error-prone. With e-invoicing, businesses can streamline processes, increase accuracy and improve cash flow. The Government, on its part, is fully committed to this initiative and will prepare our system to receive e-invoices by this year. And I want to encourage all our businesses to use this nationwide network to improve their efficiency and reduce their costs. Another example is a system-level initiative is TradeTrust, which aims to streamline and digitalise our trade processes. A common challenge in the trade and logistics sectors is the inefficiency of manual cross-border trade processes. TradeTrust is an initiative to develop a set of standards to help businesses securely exchange digital trade documents. It will enhance our attractiveness as a business hub and improve the efficiency of our trading and logistics sectors. IMDA and other Government agencies are now working with industry partners to conduct proof-of-concept trials, and we will provide more details later.”
“At the opening of library@harbourfront in January, I saw seniors effortlessly reading e-newspapers and learning enthusiastically to use the different apps on their smartphones. Children were enjoying themselves in the Immersive Storytelling Room and adults were using the NLB Mobile App. 3.30 pm We want to build on this momentum by nurturing a vibrant ICM industry, comprising businesses with deep capabilities, workers who are highly skilled and a world-class digital infrastructure. We start with efforts to raise the digital capabilities of our broad base of enterprises, especially our SMEs. Mr Cedric Foo and Mr Douglas Foo have asked how we are helping businesses benefit from digital technologies, and Mr Teo Ser Luck asked about the outcomes of our efforts. Two years ago, we launched the SMEs Go Digital programme and the results have been encouraging. To date, about 4,000 SMEs have benefited from this programme, which provides access to step-by-step guides to go digital. Proven digital solutions are provided, and consultancy and project management services are also available. We have been adapting the SMEs Go Digital programme to the changing needs of businesses. For instance, working with banks and telco partners, we launched the Start Digital Pack in January this year, so that digital solutions can be adopted by companies from the moment they are established. This way, businesses benefit from the very beginning, and they can also build on these digital foundations as they scale. We are also expanding the SMEs Go Digital to meet the more complex needs of businesses as they scale. UNAG Logistics is an example. Rhyce and Gary Chng are brothers who own this local logistics and transportation company.”
“Sir, this is my first COS since joining MCI last May. I would like to thank all Members for their support of the work of MCI and also for the diverse plurality of views that Members have shared with us on the work of the Ministry. In my response, I would outline MCI's plans to secure Singapore's future in a digital age, as part of the Ministry's broader mission to connect our people to opportunities, communities and the Government. Senior Minister of State Janil Puthucheary will address cybersecurity and digital readiness, while Senior Minister of State Sim Ann will do so for the media sector and Government communications. And I will conclude with our plans for the libraries and archives. Sir, our vision is for Singapore to have a thriving Digital Economy where every business is digitally-empowered, every worker is digitally-skilled, and every citizen is digitally-connected. Every enterprise, regardless of size or stage of development, can use technology to innovate and grow. Every worker, regardless of industry or education level, can use technology to be more effective and productive. And every citizen, regardless of age or background, can use technology confidently and enrich their lives. This vision is already being realised, sometimes in quite unlikely quarters of our economy and society. Small enterprises in traditional sectors are harnessing technologies to grow. I recently met Mr Selvam, he was a former commando, who now owns Anushia Flower Shop in Little India, a testament to the diverse capabilities of our Singapore Armed Forces officers. He has used e-commerce to reach corporate clients and new customers, to increase his revenue by 50%. Young and old are embracing technology.”
“Mr Chairman, may I first seek your permission to display some slides in the course of my speech?”
“They do, and, in fact, they have a multiplicity of recourse. And I would add that, in the case of the public sector, they probably have more channels and more avenues of recourse in some ways, compared to what you see in the context of the private sector. Because essentially, for private sectors, you go to the PDPC, or you take out a specific legal action against the company on your own. Here, you have got more options because you can go through the PDPC. It would be referred to the relevant agencies. You can go to GovTech, you can go to the Ministry that oversees the relevant department, you can also make a Police report if you feel that it warrants such action. So, there should be no doubt in Members' minds that we have the appropriate recourse mechanisms. There should also be no doubt in Members' minds that the public sector's data governance standards are in no way inferior to the standards that we impose on the private sector. And, if anything, we impose a higher set of standards. That is the expectation that we have.”
“Mr Speaker, because there will be a Ministerial Statement governing many of the matters pertaining to the public healthcare system, I will keep my comments in response to the Member's queries limited, and I think we can take up clarifications after the Ministerial Statement as well. The key point I want to emphasise in my response to the Member is this: the term "recourse" for the public has been used several times in the course of this exchange. The fact of the matter is that you need recourse. It does not matter whether the recourse is under the PDPC or PDPA, the legislation or there are other established improved mechanisms. But the key point is you must have recourse. And that is my point when I said that individuals, depending on where or what circumstances they find themselves in, they can make complaints. By the way, the PDPC does receive complaints sometimes pertaining to the public sector. So, as a recipient of such complaints from the public, it does not turn them away. Rather, the standing arrangement is that they look at it and, if the jurisdiction is such that it does not come under the PDPA, they then refer it to the Government agencies involved to then follow through. In the case of the Government, the Government Technology Agency (GovTech), for example, is overall in-charge of the security and safeguard systems for data. And GovTech is the agency that does many of the reviews and ensures that the Government agencies are in compliance with the IMs and other provisions and so on. Moreover, there is also the Auditor-General's review as well, which occurs from time to time, and it includes security. My point is that members of the public should not at all be concerned that they do not have recourse.”
“What the PDPC did, because it received the complaint early in the process, was to say that it will take reference from the COI's process in determining whether there was a breach by the relevant agencies, in this case SingHealth and IHiS, and, if so, what penalty should be meted out. But the substantial portion of the recommendations was actually made through the COI process which was, in fact, initiated by the Government, not mandated by any legislation but something that was because of the judgement that was exercised. The point on recourse comes back to the same thing again. If a member of the public feels that, in some way, their data has been mishandled, then they have every opportunity to lodge a complaint with the Minister, the Ministry, the relevant department, and action will be taken. And you can also, if you think a crime has been committed, make a Police report, and that will also be investigated. So, if I can summarise, we subject our public sector to the same, if not higher, rigorous standards of data governance. And we have to do that, because if we do not, then a lot of our other efforts, in terms of wanting to build a Smart Nation and delivering, harnessing the digital technologies and all these in order to deliver better public services will all be thwarted. So, that is exactly why we take this very seriously. By and large, the PSGA, in other words, the legislation that governs the public sector data governance, takes reference from the PDPA and we also have other legislation for specific sectoral matters which can also be implied in addition.”
“So, many of the questions that the Member has raised pertain more to whether there are elements of the PDPA. For example, there is a complaints procedure where they can complain to the PDPC on, for example, the right to data. I think the Member made the point that the PDPA strikes the balance between the right to data of the individual versus the right to use the data of the enterprises. Indeed, that is the balance we are trying to strike, whether it is in the public domain or in the private domain. Because essentially, you can say the same sets of considerations apply in the public sector – that we want to ensure individual data is protected, accorded due safeguards, but, at the same time, it should be a common resource that public sector agencies can tap on in order to better serve citizens. Many of the services that we take quite for granted today actually rely on that backend sharing. So, when it comes to a complaints procedure today, there is nothing stopping an individual who feels aggrieved that their data has somehow been mishandled to launch a complaint. And they have different channels for doing so. On the SingHealth piece, the Member made the point that PDPC came out with the recommendations and so on which were very useful and so on. But actually, if you look at the morphology of the entire incident, the key recommendations that came out of this was actually from the Committee of Inquiry (COI) which the Government established. That is the process through which we derived a whole set of very detailed recommendations.”
“Mr Speaker, I thank the Member for her comments. I am not sure all of them were questions because some of them were observations. But let me interpret them. Let me start by making a more general point. I think the key conclusion we have to draw is this. When we say exempt – and that is the language that the Member has used in her question – that the public sector is exempt from the PDPA, that does not mean that the public sector is somehow subject to a different or lower standard, as might be implied, in terms of data security and safety. In fact, and that was the thrust of my reply that, one, the public sector and the PSGA, in particular, takes reference, and it is in broad alignment with PDPA. But having said that, there is a clear recognition that the mode of operation and the expectation of how data is used in order to provide an effective and efficient Public Service, implies that we do need a different methodology in the way we govern public sector data governance. That is why we have this differentiated approach. In addition to the PSGA, as I had said, we do have other legislations in place. Just for Members' information, we are by no means alone in this approach. The Canadians, for example, at the federal level, also have different laws in terms of its application to the private sector and its application to the public sector. So, it is not about differing standards or somehow having a different threshold when it comes to the public sector. In fact, we subject the public sector to the same kind of standards, if not higher standards, precisely because we know that the data that is being entrusted to the public sector is done with the confidence that it would be dealt with in a secure manner.”
“For example, when a Singaporean applies for financial assistance at a Social Service Office, the frontline officers are able to quickly evaluate his or her eligibility for financial assistance because they have access to data from other relevant agencies. In this way, we minimise the documents that need to be submitted by the applicant and improve the delivery of public services. In contrast, each private sector organisation is expected to be individually accountable for the personal data in its possession, and there is no expectation of a similar integrated delivery of services across different commercial organisations. Because of these important differences, we need and have adopted different approaches to the protection of personal data in the public and in the private sectors. That is also why the PDPA applies only to the private sector, while the PSGA and other legislation govern data protection in the public sector. We will regularly review the PDPA, PSGA and other legislation to ensure that they remain relevant and effective in safeguarding personal data in both the public and private sectors.”
“Mr Speaker, the Personal Data Protection Act (PDPA) came into force in 2012. With the gathering pace of digitalisation, we recognised the need to strengthen data protection in the private sector. PDPA establishes a baseline standard for data protection in the private sector, balanced against its need to use personal data for reasonable purposes. On its part, the Government has always taken seriously its responsibility to protect the data entrusted to the public sector and we continue to strengthen our data governance policies. Since 2001, the Government Instruction Manuals (IMs) already include measures to govern the use, retention, sharing and security of personal data among public agencies. In 2018, the Public Sector (Governance) Act (PSGA) was introduced and it provided for additional safeguards for personal data in the public sector, including criminalising the misuse of data by public servants. The data protection standards in PSGA are also aligned with the PDPA. In addition, data collected by the public sector is also protected by specific legislation, such as the Official Secrets Act, the Income Tax Act, the Infectious Diseases Act and the Statistics Act. Collectively, these laws impose a high standard of responsibility on all public agencies, with additional requirements for the protection of sensitive or confidential data. Also, regular mandatory audits are conducted to ensure that public agencies comply with the standards for data protection and the security of information and communications technology systems. PSGA allows personal data to be managed as a common resource within the public sector for better policymaking and also for more responsive public services.”
“On 1 January 2019, we switched off analogue free-to-air signals and transitioned fully to digital television (TV) or DTV. Today nine in 10 Singaporean households can watch DTV, either over the air or through their Pay TV subscriptions. Based on outreach by the Info-communications Media Development Authority (IMDA), the remainder have not switched over primarily because they do not have TVs or they already have access to free-to-air TV through other means, such as Toggle. This was not an easy transition. We had to reach out to more than 540,000 households to migrate them to DTV, and work with Mediacorp to install a nationwide DTV broadcasting network. The smooth migration was made possible by an intensive outreach campaign led by IMDA, which helped 416,000 households, or 77% of eligible households, to switch over to DTV through the DTV Starter Kit programme launched in April last year. I would also like to thank agencies, grassroots advisors and the more than 2,000 volunteers for helping us through this exercise. Although we have crossed over fully to DTV, we recognise that there are some households which may not yet have switched over. IMDA has, therefore, extended the DTV Starter Kit application deadline to 31 March 2019 to help eligible households through this transition. IMDA will also continue advising other households how to switch to DTV, and work with Mediacorp to provide technical support to households.”
“IMDA has received the AE licence application for the RuPaul's Drag Race show to be held in February 2019 and will assess the performance in accordance with the AECC.”
“The Infocomm Media Development Authority (IMDA) administers the regulatory regime for Arts Entertainment (AE) which include plays, variety shows and art exhibitions. In assessing and classifying an AE, IMDA is guided by the Arts Entertainment Classification Code (AECC) which sets out the classification system and the principles of classification. The AECC was developed in consultation with the community and aims to reflect prevailing social norms, protect the young from unsuitable content while enabling adults to make informed viewing choices. There are four classification ratings for AE: (a) General; (b) Advisory; (c) Advisory 16; and (d) Restricted 18 (R18). An AE rated R18 is age restricted and can only be viewed by those aged 18 and above. In determining an appropriate rating for an AE, IMDA takes into consideration the overall theme, the content elements, message and impact of the work and its suitability for the different age groups. An AE which deals with a more mature theme or content, including LGBT content, would be given a higher classification rating. Content that goes beyond the R18 rating will not be allowed. For an AE rated higher than "General", IMDA will issue a consumer advice to highlight content elements within the AE to enable the public to make an informed decision, as well as guide parents on the suitability of the AE for their children. The rating and consumer advice issued by IMDA for an AE must be reflected in all of its publicity materials and at ticketing booths and event venues. "RuPaul’s Drag Race" is a variety show and similar shows have been staged previously in Singapore. Past shows have generally been classified R18 in view of the mature content and have not attracted much feedback.”
“The Info-communications Media Development Authority (IMDA) is exploring the feasibility of technological solutions to block automated fraudulent calls and text messages promoting illegal activities. These include solutions adopted or being developed by other jurisdictions, such as verifying legitimate calling numbers. In general, such technologies are still nascent and their effectiveness has yet to be determined. IMDA is also working with the Ministry of Home Affairs and the Singapore Police Force to tighten the prepaid Subscriber Identity Module (SIM) card regime to prevent criminal syndicates from using prepaid SIM cards to carry out their criminal activities. Other stakeholders also play an important role in combating these calls and text messages. Our telecommunication service providers are assisting the Police to address scams and text messages that solicit illegal moneylending, online gambling or other illegal activities. The public can also take steps, such as reporting the originating number as spam and blocking it, by using the spam filtering functions on their phones. More importantly, we must help educate our loved ones so that they do not fall prey to the illegal activities being promoted through such calls and text messages.”
“I can understand that Members have a desire, and on behalf of their constituents, to know this, but I think we have to exercise judgement as to what is in our national interests and whether a public attribution serves our best interests. And as I have said, we know who the perpetrator is and appropriate action has been taken. 2.55 pm”
“Because we want to demonstrate that we are transparent and we want to ensure that all Singaporeans understand that we have nothing to hide here. We want to get to the bottom of it as much as Singaporeans do. Thirdly, if Members look at our response thereafter, we appointed a COI. Why do we appoint a COI? Because the Government wants a robust and transparent investigation and inquiry into the matter, not because we want to lay fault – although if there are, those who have been negligent or egregious, then they have to be accountable – but also because we want to learn from this, understand what went wrong and rectify them. So, if Members look at the COI report, we have released all the recommendations and material findings in full in the public version. The only parts that have been held back are those that pertain to sensitive national security matters and also patient confidentiality. Everything else is out there – unvarnished, stark but very clear on what we need to get done. So, again, if Members contrast what we have done with the responses in other domains by different parties, I think we can hold ourselves up to the best practices and standards in terms of how we responded. Finally, what are the actions we have taken? Apart from action against individuals, we have taken actions against the organisations and we have also undertaken a slew of activities and measures in order to further strengthen our cybersecurity system, some informed by the COI, others that our agencies have already been working on. That is the totality of our response. And I do not think we should reduce whether we have confidence in the sense of justice to just one specific point, that there is no public attribution of the perpetrator.”
“Mr Speaker, I think the Member's question, if I can put it in a broader context, is that, first, this incident has occurred. The basic question we have to ask ourselves is how do we ensure that Singaporeans continue to have trust and confidence in our public sector systems – IT systems and databases – because it is inevitable that when you have an incident like this, it will raise such qualms and questions. And I would say that in deriving a sense of confidence, our citizens should be looking at the totality of our response and not focus on one particular aspect of the response. Let me elaborate on what I mean. Firstly, why do we collect data and have these IT systems? Because they enable all these services, conveniences that we take for granted, whether it is in our transportation system, our healthcare system, in our dealings with various other Government agencies. The fact that we can transact with ease and convenience is because it is enabled by data and the IT systems that we have. So, firstly, we are doing this because we want to serve the interests of our citizens. The second point I would make is that, directly as a result of this, we should be looking at what has our response been, the Government's response to this. In that regard, I would highlight a few things. Firstly, we made the knowledge of the cyberattack public within days, if I recall correctly, 10 days after it was brought to the attention of CSA. I think it was 10 July that it was brought to the attention of CSA, and on 20 July, Minister Gan Kim Yong and I held a press conference and we announced it and shared it with members of the public. Why do we do that?”
“And that means if you have an unsolicited call seeking personal data, then our antenna should go up and we should be taking appropriate steps to ensure that this is a bona fide approach and not something that is a scam that is trying to take advantage of us. So, first, and if I can summarise it, overall, the data, we are monitoring the situation. There is no evidence to date in terms of its use or emergence in the Dark Web. Secondly, our agencies and, specifically, in this case, SingHealth, have reached out to all the patients to inform and advise and also, where they have had queries, they have been able to approach SingHealth. Thirdly, we have, in general, an important and repeated advisory on appropriate cyber hygiene habits that should be undertaken by all of us.”
“Mr Speaker, I thank the Member for his questions. It is a reasonable concern. Let me start by saying that in the aftermath of the incident, we have been monitoring the Dark Web to see whether the data that had been exfiltrated has emerged in any form, and, to date, there has been no evidence of that. Secondly, the kind of scenarios that the Member has highlighted about people being approached for personal data and so on and to verify, these actually have been occurring even before the cyberattack and they occur in different contexts. Because the way some of these scams, as the Member put it, are being perpetuated, is not just depending on this particular kind of incident. They are approaching it from different angles, using different resources at their disposal. So, on the one hand, we are doing everything we can in taking it absolutely seriously that this has been an incident that we should not have allowed to happen. But it having happened, we want to contain it and ensure that every measure is put in place to protect the interests of the patients. So, if Members recall, SingHealth has made an extensive outreach to all the patients through SMSes and so on to inform them and also to advise them of the risks and what they need to do and why they can be assured in terms of the security of their data. The second point I would make is, we have been emphasising, not just CSA, but the Government as a whole, whether it is this incident or any others, we have, each and every one of us, an obligation to exercise appropriate cyber hygiene habits.”
“Mr Speaker, I thank the Member for his questions. If I may reiterate my earlier response: we know the identity of the perpetrator. We have taken appropriate action. But it is not in our interest to make a public attribution, and it is not because we lack the legislative capacity to do so, if indeed it is within our jurisdiction.”
“Mr Speaker, the answer is yes. Obviously, because it is a highly interconnected world that we live in, in a sense, while we do what we can in our own jurisdiction, we also have to take reference from what is happening elsewhere. Indeed, that is why cybersecurity agencies across the world formed these partnerships to share information and also to share best practices because the threat is an evolving one. I think that is the way we continue to ensure that we are plugged in. So, the short answer to the Member's question is yes, we do. But having said that, the onus is on us to ensure that we are up to the mark, and I would add that many countries look to Singapore for best practices.”
“Mr Speaker, I thank the Member for his question. The mechanisms and the framework for doing such an audit and compliance is actually set up under the Cybersecurity Act and CSA which has oversight of the overall national cybersecurity effort, in particular, the work that is being done by the CII owners in the 11 vertical sectors, who will be the ones that oversee the execution and compliance, if you will, of the processes that are needed to continually strengthen our cybersecurity system. And, in that regard, CSA issues various directives and advisories from time to time. There is a Code of Practice that CII owners are expected to adhere to. There are provisions for regular audits, minimally once in two years but, if not, can be more frequent, if mandatorily required by CSA. And also, the audit will be conducted by an auditor that must be approved by CSA. So, we have the framework in place. As I pointed out, these have all been enabled with the legislation that came into force in August last year and, now, in having designated the CII, CSA is operationalising it and we have a mechanism to follow through on the broader imperatives that CSA has mapped out and also on the implementation of some of the COI recommendations.”
“Mr Speaker, the three streams of activity: one is the COI, the report of which has been furnished; second is the independent investigation by PDPC which took reference from some parts of the public COI report and is now concluded, and penalties have been meted out; and third is the investigation by CID which has been closed without any further action.”
“To this end, Singapore has been actively hosting and supporting regional and international discussions and cybersecurity programmes aimed at building consensus on the rules of behaviour in cyberspace. Singapore stands ready to work with all parties toward closer international cooperation in the cyber and digital sphere. Mr Speaker, Sir, to conclude, the Government takes very seriously its responsibility of ensuring the cybersecurity of our systems that are vital to the provision of essential services. The findings and recommendations of the COI into the SingHealth cyberattack have helped to sharpen our focus and given further impetus to our efforts to secure our systems and databases, especially against a sophisticated cyberattacker. But there is no permanent fix nor absolute cybersecurity. It is a constant battle against cunning adversaries with advanced capabilities. And we cannot let incidents like this derail our Smart Nation initiatives that can enhance our economic competitiveness and deliver better public services for the benefit of our citizens. We will do our utmost to strengthen Singapore's cyber defence capabilities and prevent cybersecurity breaches. However, if a breach occurs despite our best efforts, we must have the capability to detect it quickly and respond robustly to minimise the damage. Our people must stay resilient in the face of such a continuing threat while doing their part for our cyber defence. We will learn from this incident, emerge stronger and uphold the trust of Singaporeans.”
“PDPC has imposed a total financial penalty of S$1 million, comprising S$750,000 and S$250,000 on IHiS and SingHealth respectively. These are the highest penalties meted out by PDPC to date. The measures recommended by the COI will help us defend ourselves better against malicious cyber activities, including from international attackers. This was not the first instance where we were targeted and it will not be the last. Our networks are continually probed for weaknesses and regularly attacked. A cyberattack of the scale and sophistication that was launched against SingHealth could also be mounted on any one of our major IT systems, threatening the safety and security of Singapore and Singaporeans, which are of paramount importance. Singapore is firmly committed to the establishment of a rules-based international order in cyberspace. We condemn all malicious cyber activity that seeks to undermine the integrity of the international political and economic system and violates the norms of behaviour in cyberspace as set out in the 2015 United Nations (UN) Group of Governmental Experts consensus report. This includes the cyber-enabled theft of sensitive data. Such activities can have a disruptive impact on Singapore and internationally in our highly interconnected world. Singapore has consistently advocated that the international community come together to build consensus and develop a rules- and norms-based international order in cyberspace, a cyberspace that fosters trust and confidence, and one where its users can remain safe and secure. This is consistent with Singapore's fundamental stand that a rules-based multilateral system is indispensable to secure peace and stability in the international arena.”
“Beyond the measures implemented during the pause in the rollout of new Government systems, such as monitoring critical Government databases, SNDGG is also looking into improving the architecture of Government systems to enable more extensive monitoring and detection of abnormal activities. We also recognise that the Government cannot strengthen its cybersecurity alone. Therefore, the Government will enlist the expertise of the larger cybersecurity community, including ethical hackers, to help us surface and detect vulnerabilities in our information and communication technologies (ICT) systems. The Government Technology Agency (GovTech) and CSA have launched a Government Bug Bounty Programme, and have invited local and international white-hat hackers to search for and uncover vulnerabilities on five Internet-facing Government systems and websites. This will help us draw in a wide range of expertise to help identify cyber blind spots and benchmark our defences against skilled global hackers. In terms of tracking the follow-up, CSA will oversee the follow-up on the COI's recommendations across all CII sectors, which includes the public sector. To do this, CSA will work through the sector leads of the 11 CII sectors who are responsible to monitor implementation for their respective sectors and to report progress to CSA as the national cybersecurity authority. SNDGG, as sector lead for the Government sector, will monitor implementation for Government systems. We will then track overall progress via regular updates at the relevant Ministerial committees. The Personal Data Protection Commission (PDPC) has also completed its investigations of the data breach incident. Both IHiS and SingHealth have been found to be in breach of the Personal Data Protection Act.”
“Second, SNDGG and CSA reviewed the Government’s cybersecurity posture, and introduced additional measures on critical Government systems to enable us to detect and respond more quickly to cybersecurity threats. The findings and recommendations of the COI give added impetus to our efforts to continuously review and enhance the cybersecurity of Government systems. In particular, the findings reaffirmed the "defence-in-depth" approach that the public sector had adopted towards cybersecurity. The public sector will also continue to strengthen our defences on all fronts – people, process, technology and partnerships – as informed by the COI recommendations. In terms of people and processes, SNDGG will strengthen existing processes to prevent lapses and heighten vigilance. The public sector will use technology even more to support its IT staff and automate cybersecurity tasks, such as patch management, so as to carry out these tasks more reliably. SNDGG will further tighten internal checks and enhance security audits, for example, by increasing their frequency. We will also instil a stronger cybersecurity culture across the Public Service. This will be done by conducting more exercises to sharpen our officers' readiness and train all public servants in cybersecurity. Above all, we expect our officers at all levels to be aware of their responsibilities, to be accountable for their actions, and to perform their duties to the best of their ability. On the technical front, SNDGG will continue to shore up defences at the perimeter of Government systems, while introducing measures to better detect and respond to intrusions within our systems.”
“These include adhering to essential cybersecurity measures set by CSA through the Cybersecurity Code of Practice, reporting cyber incidents to CSA within prescribed timeframes, and conducting regular risk assessments and audits of their CIIs. In addition, CSA also instructed all CII owners through their sector leads to conduct thorough internal reviews of their cybersecurity posture against the gaps identified during the COI hearings. These included reviews of their people, process and technology measures, such as mandating cybersecurity training and awareness programmes, establishing a robust patch management process and implementing access management solutions to manage privileged administrator accounts. CSA has directed CII owners to implement plans to close any identified gaps and report the results. CSA will continue to actively work with the sector leads and CII owners to reinforce their cyber defences and cyber resilience and safeguard the cybersecurity of our systems and networks. I now turn to the cybersecurity of public sector systems, which is a key enabler for our Smart Nation initiatives to improve public services for our citizens and businesses. The Smart Nation and Digital Government Group (SNDGG) had already started enhancing the cybersecurity of Government systems before the cyberattack. Upon discovering the cyberattack, SNDGG paused the rollout of new Government systems from 20 July to 3 August 2018. During this pause, first, SNDGG checked and confirmed that other systems were not breached by the same attacker, whether through the IHiS system or via a separate breach.”
“First, we adopt a "defence-in-depth" strategy, with multiple layers of cyber defences to impede an attacker. These layers of defence cascade from the perimeter to within our systems, as we recognise that a sophisticated and determined attacker, given enough time and resources, may find a way through. This is why we also have capabilities in our layered defence that enable swift detection of a breach and a decisive response. Second, we seek to enhance our system defences by strengthening our people, processes and technology. Our aim is not only to monitor and respond robustly to an incident, but also to ensure a quick recovery and resilience in our system. The COI emphasised that the battle against today’s cyber threats must be based on networked defence across organisations and sectors. The COI also recognised the Government’s commitment to such collective security, by establishing CSA to coordinate our national cybersecurity efforts. CSA leads our national-level response to the cyber threat, including by reinforcing cybersecurity in all CII sectors. Immediately after the cyberattack, and even as the COI proceedings were underway, CSA instructed all CII sectors to strengthen network security by taking additional prescribed measures, such as removing non-essential connections to unsecured external networks and implementing uni-directional gateways like data diodes to prevent data leakage. CSA also accelerated the implementation of the Cybersecurity Act, which provides the legislative framework for the oversight and maintenance of national cybersecurity. The Act came into force on 31 August last year and CSA designated all CIIs by 31 December last year. All CII owners must now comply with their obligations under the Act.”
“These include stronger encryption for data, heightened monitoring of database activity, and an integrated system to aggregate and analyse threat information in real-time and rapidly isolate and contain the infected system. The COI has highlighted the need to build up collective security over our systems, given that Singapore is highly connected and a high-value target. This can be achieved by strengthening Partnerships between the Government, industry and international partners, in areas, such as threat intelligence sharing. The COI has emphasised that, ultimately, cybersecurity must be an integral part of a broader risk management framework and cannot be treated merely as a technical matter. Organisations need to strike a balance between security considerations, operational requirements and cost, and these tradeoffs and decisions must be made at the Board and Chief Executive Officer (CEO) level, and not just by the Chief Information Security Officer (CISO) and technical staff. Mr Speaker, the Government accepts all of the COI's findings and recommendations. Cybersecurity is a critical enabler of our Smart Nation ambitions. We will, therefore, fully adopt the COI's recommendations and do our utmost to ensure that our IT and database systems are secure, and that personal data collected by Government systems is well-protected. I will now elaborate on the Government’s efforts, ongoing and in response to the COI report, to strengthen cybersecurity at both the national level and across the public sector. Minister Gan Kim Yong will cover the public healthcare sector’s efforts. The Government’s approach to cybersecurity is underpinned by two key principles that have also been highlighted by the COI.”
“The detailed evidence for all of the COI's findings are in the public report, but it does not include highly sensitive information – pertaining to SingHealth's network architecture, technical vulnerabilities exploited in the attack, and the identity of the attacker – which is only in the classified COI report. Turning to the recommendations. The COI has made 16 recommendations to strengthen SingHealth's patient databases, as well as public sector IT systems which contain large databases of personal data. Seven are priority recommendations which should be implemented immediately, and nine are additional recommendations which are to be seriously considered. The recommendations fall into four broad categories – People, Process, Technology and Partnerships. On People, the COI notes that frontend users are often the weakest link targeted by attackers, and that it is line staff who are often the first to notice a security incident and respond. Hence, the recommendations include enhancing cyber hygiene practices, building a culture of cybersecurity across the entire organisation, and ensuring that IT staff are well-trained and equipped to respond to cybersecurity incidents. The COI also calls for strong institutional Processes. In incident response, for example, there should be clear plans and standard operating procedures (SOPs) and regular exercises with realistic scenarios to test their effectiveness. There should also be regular and comprehensive checks to identify vulnerabilities and high-risk areas, accompanied by audit and compliance checks, to ensure that the identified gaps have been plugged. On Technology, the COI has proposed various measures to strengthen cybersecurity to better prevent, detect and respond to future attacks.”
“However, and this is noteworthy, the COI also commended specific IHiS IT administrators who were vigilant, noticed the suspicious activities and took the initiative to follow up. Second, the COI found a number of vulnerabilities, weaknesses and misconfigurations at the technical level in the SingHealth network and database system which allowed the attacker to obtain and exfiltrate the data. Many of these could have been remedied before the attack. Third, the COI observed that although SingHealth was ultimately responsible, it had no management line of sight with regard to the assessment of the cybersecurity risks. SingHealth lacked the necessary expertise and resources and was wholly dependent on IHiS, even at the management level. The COI, having heard evidence from CSA, also established that the cyberattack was the work of a skilled and sophisticated actor bearing the characteristics of an APT group. This finding was corroborated by international expert witnesses. An APT group is a class of cyberattackers, typically state-linked, who conduct extended cyber campaigns to steal information or disrupt operations. The COI found that the attacker was well-resourced and had used advanced techniques and tools to target the SingHealth patient database and illegally exfiltrate patient data. The attacker was persistent, evaded detection for a long time and even re-entered the network after being detected. Appropriate action has been taken, and we know the identity of the attacker. But for national security reasons, I will not comment further.”
“At this juncture, on behalf of the Government, I would like to place on record our deep gratitude to the Committee for its hard work in undertaking a robust and transparent inquiry. I would also like to thank the Attorney-General's Chambers, investigators from the Cyber Security Agency of Singapore (CSA) and the Criminal Investigation Department (CID), and the Ministry of Communications and Information (MCI) officers who supported the COI, witnesses who gave evidence, as well as organisations, professionals and members of the public who contributed their views and suggestions in the course of the Inquiry. Let me now highlight the main findings of the COI. The COI has been candid in its report, which establishes the sophisticated nature of the attacker, but also gives a detailed and stark account of shortcomings at the staff and systems level that contributed to the failure to prevent the attack or limit its impact. Specifically, the COI found that while SingHealth fell victim to an Advanced Persistent Threat (APT) group, the success of the attacker in obtaining and exfiltrating the data was not inevitable. IHiS and SingHealth should have been better prepared and more robust in their actions. If they had done so, the cyberattack could have been limited or even stopped. I will now go into the findings. First, the COI found significant shortcomings at the staff level. IHiS staff did not have adequate cybersecurity awareness, training and resources to appreciate the security implications of their observations and to respond effectively to the attack. Also, certain IHiS staff holding key roles in IT security incident response and reporting failed to take appropriate or timely action, even when there were clear signs of an ongoing attack.”
“The public report contains all recommendations and material findings from the full COI report. It only excludes highly sensitive information heard by the COI in closed-door sessions. Mr Speaker, with your permission, may I ask the Clerk to distribute the notes on the COI findings and recommendations?”
“Mr Speaker, on 6 August last year, I informed this House that I had convened a Committee of Inquiry (COI) into the cyberattack on SingHealth's database system. The scale of the cyberattack was unprecedented. The personal particulars of about 1.5 million patients were illegally accessed and copied. It was malicious. Prime Minister Lee Hsien Loong's records were specifically and repeatedly targeted. And there were serious implications for public health and safety, as SingHealth's database system is part of our Critical Information Infrastructure (CII). Therefore, I convened this COI because the Government wanted a robust and transparent inquiry that would get to the bottom of this cyberattack and, in particular, the COI was asked to, firstly, establish the events and contributing factors and evaluate the incident response by the Integrated Healthcare Information Systems Private Limited (IHiS) and SingHealth. And secondly, to recommend measures to safeguard public sector information technology (IT) systems that contain large databases of personal data against similar cyberattacks. The Committee conducted a rigorous and comprehensive inquiry over five months. They examined testimonies from 37 witnesses, including local and foreign experts, as well as 26 written representations from members of the public, professional associations, organisations and companies. The COI conducted 22 days of hearings which were opened to the public except when there were implications for national security or patient confidentiality. The COI submitted its classified report to me on 31 December 2018. The COI also released a public version of the report on 10 January 2019 which my Ministry has distributed to Members of this House.”
“Mr Speaker, the Infocomm Media Development Authority (IMDA) focuses its regulatory efforts on key telecommunication services for the development of Singapore's digital economy. So, IMDA sets minimum Quality of Service (QoS) standards for the performance of these key telecommunication services, such as fixed line telephone, mobile, Internet access and fibre connection services. IMDA regularly verifies service providers' compliance with these QoS standards and takes enforcement action in the event of breaches. IMDA does not impose regulatory requirements on customer service and call centre experiences. Instead, market competition is used to elicit improvements as service providers compete by providing better customer service. IMDA tracks consumer satisfaction through the Consumer Awareness and Satisfaction Survey (CASS) and provides this feedback to the service providers so that they can make improvements. CASS 2018 showed that consumers are generally satisfied with their telecommunication service providers, and consumer satisfaction has improved in several areas, including the hotline waiting time, time taken to resolve complaints, and competency of service providers’ customer service officers.”