Singapore Proposes New Security Guidelines To Beef Up Financial Resilience

Singapore is looking to introduce changes to existing guidelines on technology risk and business continuity management that will require financial organisations to implement more measures to boost their operational resilience. These aim to better prepare them for a physical and cybersecurity threat landscape that is rapidly changing, according to industry regulator Monetary Authority of Singapore (MAS). 

The proposed changes would be made to the Technology Risk Management (TRM) and Business Continuity Management (BCM) guidelines that were first established in 2013 and 2003, respectively, to put in place security practices and controls to address technology risks as well as organisational response and recovery process to minimise impact of business disruptions.

MAS said on Thursday the changes included guidance on cyber surveillance, secure software development, and the management of security risks brought about by the Internet of Things (IoT). They also aimed to boost the development of business continuity plans to better account for interdependencies across business units within the financial institution and connections with external service providers, the authority said. 

Banks and financial institutions, for example, increasingly were investing in emerging technologies such as APIs (application programming interfaces), smart electronic devices, and virtualisation, to improve service delivery and efficiency. If these were not implemented and managed properly, they might increase the cyber attack surface, MAS noted, adding that the new guidelines looked to manage such risks.

The proposed changes also would require financial institutions to conduct business continuity management audits through a unit independent of staff involved in the planning and execution of such plans, such as internal audits. 

MAS's chief cybersecurity officer Tan Yeow Seng said: "A cyber attack can result in a prolonged disruption of business activities. Threats are constantly present and evolving in sophistication. We cannot afford to be complacent. Financial institutions must, therefore, remain vigilant and have in place effective technology risk management practices and robust business continuity plans to ensure prompt and effective response and recovery."

In a separate announcement, MAS also unveiled plans to form a new technology group that encompass a data analytics group, information technology department, and technology and cyber risk supervision department. 

The move was made to focus the authority's technology capabilities under one group and drive its digital transformation. It also would support a more integrated approach to providing technology applications and systems as well as improve the management of evolving technology risks in the financial industry, said MAS.

The Singapore government in January also formed a committee and released guidelines to beef up cybersecurity protection and capabilities in the telecommunications industry, including implementation best practices for IoT systems and electronic Know Your Customer (eKYC) technology that allows mobile operators to digitally authenticate service registrations. A "multi-year roadmap" was being planned to identify cyber threats and develop the capabilities and products needed to strengthen the country's connectivity infrastructure. 

RELATED COVERAGE

Singapore banks given more time to adopt e-payment protection guidelines

Originally scheduled to come into effect at the end of January, e-payment user protection guidelines will now be rolled out on June 30, after industry regulator Monetary Authority of Singapore agrees to give local banks more time to implement the necessary support systems.

Singapore banks offered $21M in funds to boost cybersecurity capabilities

Monetary Authority of Singapore is dishing out S$30 million (US$21.88 million) in a new grant to help local financial institutions boost their cybersecurity operations and skillsets, funding up to half of such expenses.

Singapore unveils implementation guides, forms industry committee to boost telecom security

Industry regulator has set up a committee comprising government officials and industry experts to establish a "multi-year roadmap" that aims to identify cyber threats and develop capabilities and tools needed to better secure Singapore's telecommunications sector, including IoT deployments.

APAC consumers want IoT devices, but fear data leaks

Majority of consumers in Asia-Pacific already own at least one Internet of Things (IoT) device and plan to buy more, but 81 percent fear their personal data is being leaked and 71 percent worry about being monitored without their consent.

SingHealth data breach reveals several 'inadequate' security measures

Investigation into the July 2018 incident reveals tardiness in raising the alarm, use of weak administrative passwords, and an unpatched workstation that enabled hackers to breach the system as early as August last year.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more