Singapore Tightens Cyber Defence Guidelines For Financial Services Sector

Singapore Tightens Cyber Defence Guidelines For Financial Services Sector

Revised guidelines on technology risk management include instructions for financial institutions to exercise “strong oversight” of arrangements with third-party service providers to ensure data confidentiality and details of the responsibility of senior management.

Singapore has revised its current set of guidelines on technology risk management for financial institutions to include, amongst others, “strong oversight” of their partnerships with third-party service providers to ensure data confidentiality. The updated list also comprises updated guidance on security controls and stress tests as well as the appointment of third-party vendors and senior IT executives.

Detailed under the Technology Risk Management Guidelines, the revisions were made to keep pace with emerging technologies and shifts in the current threat landscape, said the Monetary Authority of Singapore (MAS) in a statement Monday.

Noting that financial institutions increasingly were tapping cloud technologies and APIs (application programming interfaces), the industry regulatory underscored the need to incorporate security controls and stronger risk mitigation strategies as part of these organisations’ technology development and deployment lifecycle. 

“The recent spate of cyber attacks on supply chains, which targeted multiple IT service providers through the exploitation of widely-used network management software, is a clear indication of a worsening cyber threat environment,” it added.

The use of third-party services providers, for instance, likely would be provided using IT and might involve confidential customer data stored by the service provider. Any system failure on security breach on the part of these providers could adversely impact the financial institution’s customers and operations.

Also Read: How a Smart Contract Audit Works and Why it is Important

The guidelines highlighted the need to assess and manage the company’s exposure to technology risks that might affect the confidentiality and availability of IT systems and data at the third-party service provider, before a contractual agreement or partnership was established. Financial institutions also should ensure, on an ongoing basis, that the third party adopted “a high standard of care and diligence” in safeguarding data confidentiality and integrity as well as system resilience.

In addition, financial institutions must establish processes to enable the “timely analysis and sharing” of cyber threat intelligence within the sector and conduct drills to stress test their cyber defences, via the simulation of real-world attack tactics and procedures. 

Stronger oversight should further extend to human skillsets, including contractors and service providers, where financial institutions should ensure all personnel had the requisite competence to perform the necessary IT functions and manage technology risks. 

This should include the appointment of CIO or CISO and the financial institution’s board must comprise members with the necessary knowledge to offer “effective oversight of technology and cyber risks”, said MAS. 

MAS’ chief cyber security officer Tan Yeow Seng said: “Technology now underpins most aspects of financial services. Not only are financial institutions adopting new technologies, they are also increasingly reliant on third party service providers. The revised guidelines set out MAS’ higher expectations in the areas of technology risk governance and security controls in financial institutions.”

Also Read: Data Centre Regulations Singapore: Does It Help To Progress?

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

4 days ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

5 days ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

6 days ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

2 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

2 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

3 weeks ago