Key provisions of Singapore’s Cybersecurity (Amendment) Act 2024 take effect today.
Key points
- Oversight extends to virtual and third-party-owned Critical Information Infrastructure.
- New categories of regulated entities are introduced.
- Incident reporting is expanded.
- Enforcement powers are strengthened.
UK cloud and technology providers supporting Singaporean critical infrastructure may now fall within scope. Designated foundational digital infrastructure providers, such as major cloud and data centre operators, can also be regulated. UK organisations should review contracts with Singapore customers for incident reporting and security obligations.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.