MDDI's Response to PQ on Critical Information Infrastructure Cybersecurity Incidents in 2025 and Mandated Remediation Timelines and Review of Penalties for Non-compliance
4 August 2026
Parliament Sitting on 4 August 2026
Question for Written Answer
39. Mr Jackson Lam asked the Minister for Digital Development and Information (a) how many cybersecurity incidents affecting critical information infrastructure were reported in 2025; (b) what remediation timelines are mandated; and (c) whether penalties for non-compliance with the Cybersecurity Act 2018 have been reviewed.
Answer
For security reasons, the Government does not disclose the number of cybersecurity incidents affecting Critical Information Infrastructure (CII), as doing so could reveal information that may be useful to malicious actors. The Government treats any attack on CII seriously, given that the provision of essential services could be disrupted and that sensitive data could be exfiltrated. Last year’s Operation Cyber Guardian was one such example, in which a multi-agency response was mounted against threat actors targeting our four telecommunication operators.
The Cybersecurity Act does not prescribe remediation timelines for cybersecurity incidents, as every incident is unique and the remediation work required will vary accordingly. Mandating timelines could also result in remediation efforts being rushed, and potentially ineffective. Instead, the Act mandates timelines for CII owners to notify the Cyber Security Agency of Singapore (CSA) of cybersecurity incidents, with a full report submitted within 30 days of the initial notification. CSA and Sector Leads work closely with CII owners to ensure timely and effective remediation. For complex cases, there are provisions to extend the deadline.
The penalties for non-compliance were reviewed when the Cybersecurity Act was amended in 2024. In addition to the existing criminal penalties, the 2024 amendments introduced civil penalties to complement the existing enforcement regime. This gives the Commissioner of Cybersecurity, with the consent of the Public Prosecutor, greater flexibility to pursue a wider range of enforcement actions based on factors such as the nature of the offence and the relevant annual turnover of the regulated entity.
