MCI - Ministry of Communication and Information of the Republic of Singapore

08/04/2026 | Press release | Distributed by Public on 08/04/2026 21:02

MDDI's Response to PQ on Critical Information Infrastructure Cybersecurity Incidents in 2025 and Mandated Remediation Timelines and Review of Penalties for Non-compliance

Parliament Sitting on 4 August 2026

Question for Written Answer

39. Mr Jackson Lam asked the Minister for Digital Development and Information (a) how many cybersecurity incidents affecting critical information infrastructure were reported in 2025; (b) what remediation timelines are mandated; and (c) whether penalties for non-compliance with the Cybersecurity Act 2018 have been reviewed.

Answer

For security reasons, the Government does not disclose the number of cybersecurity incidents affecting Critical Information Infrastructure (CII), as doing so could reveal information that may be useful to malicious actors. The Government treats any attack on CII seriously, given that the provision of essential services could be disrupted and that sensitive data could be exfiltrated. Last year's Operation Cyber Guardian was one such example, in which a multi-agency response was mounted against threat actors targeting our four telecommunication operators.

The Cybersecurity Act does not prescribe remediation timelines for cybersecurity incidents, as every incident is unique and the remediation work required will vary accordingly. Mandating timelines could also result in remediation efforts being rushed, and potentially ineffective. Instead, the Act mandates timelines for CII owners to notify the Cyber Security Agency of Singapore (CSA) of cybersecurity incidents, with a full report submitted within 30 days of the initial notification. CSA and Sector Leads work closely with CII owners to ensure timely and effective remediation. For complex cases, there are provisions to extend the deadline.

The penalties for non-compliance were reviewed when the Cybersecurity Act was amended in 2024. In addition to the existing criminal penalties, the 2024 amendments introduced civil penalties to complement the existing enforcement regime. This gives the Commissioner of Cybersecurity, with the consent of the Public Prosecutor, greater flexibility to pursue a wider range of enforcement actions based on factors such as the nature of the offence and the relevant annual turnover of the regulated entity.

MCI - Ministry of Communication and Information of the Republic of Singapore published this content on August 04, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 05, 2026 at 03:03 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]