Singapore legislation

Regulation 4

of Cybersecurity (Systems of Temporary Cybersecurity Concern) Regulations 2025

Regulation 4

Report of cybersecurity incident in respect of system of temporary cybersecurity concern

Subregulation 1

For the purposes of section 17F(1) of the Act, where a cybersecurity incident mentioned in section 17F(1)(a), (b) or (c) of the Act occurs, the owner of a system of temporary cybersecurity concern must notify the Commissioner of the occurrence of the cybersecurity incident in the following form and manner:

(a)

by submitting the following details in the manner specified in paragraph (2), within 2 hours after becoming aware of the occurrence:

(i)

the system of temporary cybersecurity concern which the cybersecurity incident relates to;

(ii)

the name and contact number of the owner of the system of temporary cybersecurity concern;

(iii)

the nature of the cybersecurity incident, whether it was in respect of the system of temporary cybersecurity concern or an interconnected computer or computer system, and when and how it occurred;

(iv)

the resulting effect that has been observed, including how the system of temporary cybersecurity concern or any interconnected computer or computer system has been affected;

(v)

the name, designation, organisation and contact number of the individual submitting the notification;

(b)

by providing to the fullest extent practicable the following supplementary details in writing in the form set out on the Internet website at https://www.csa.gov.sg within 72 hours after becoming aware of the occurrence:

(i)

any updates and supplementary details in respect of the details submitted under sub‑paragraph (a);

(ii)

the cause of the cybersecurity incident;

(iii)

the impact of the cybersecurity incident on the system of temporary cybersecurity concern or any interconnected computer or computer system, or on the business operations of the owner of the system of temporary cybersecurity concern;

(iv)

what remedial measures have been taken;

(c)

by providing a final incident report containing the following details in writing in the form set out on the Internet website at https://www.csa.gov.sg within 30 days (including any Sunday and public holiday) after the submission mentioned in sub‑paragraph (b) is made:

(i)

the details submitted under sub‑paragraphs (a) and (b);

(ii)

to the fullest extent practicable, any updates and supplementary details in respect of the information submitted under sub‑paragraphs (a) and (b).

Subregulation 2

The details mentioned in paragraph (1)(a) must be submitted —

(a)

by calling the telephone number specified by the Commissioner; or

(b)

if the owner is unable to submit the details in the manner set out in sub‑paragraph (a) within a reasonable time —

(i)

by text message to the telephone number specified by the Commissioner; or

(ii)

in writing, in the form set out on the Internet website at https://www.csa.gov.sg, to the electronic address specified by the Commissioner.

Subregulation 3

For the purposes of section 17F(1)(a), (b) and (c) of the Act, the following are prescribed cybersecurity incidents in respect of a system of temporary cybersecurity concern or an interconnected computer or computer system:

(a)

any unauthorised hacking of the system of temporary cybersecurity concern or the interconnected computer or computer system to gain unauthorised access to or control of the system of temporary cybersecurity concern or interconnected computer or computer system;

(b)

any installation or execution of unauthorised software, or computer code, of a malicious nature on the system of temporary cybersecurity concern or the interconnected computer or computer system;

(c)

any man‑in‑the‑middle attack, session hijack or other unauthorised interception by means of a computer or computer system of communication between the system of temporary cybersecurity concern or the interconnected computer or computer system, and an authorised user of the system of temporary cybersecurity concern or the interconnected computer or computer system, as the case may be;

(d)

any denial of service attack or other unauthorised act or acts carried out through a computer or computer system that adversely affects the availability or operability of the system of temporary cybersecurity concern or the interconnected computer or computer system.

Subregulation 4

In this regulation —

Definition

“interception”, in relation to a communication to or from a system of temporary cybersecurity concern or an interconnected computer or computer system, includes —

(a)

listening to or the recording of the communication; and

(b)

acquiring the substance, meaning or purport of that communication;

Definition

“interconnected computer or computer system” means any computer or computer system under the control of the owner of a system of temporary cybersecurity concern, or under the control of a supplier to the owner, that is interconnected with or that communicates with the system of temporary cybersecurity concern.