The Answer in 60 Seconds

A cyber incident at a Singapore SME triggers a layered set of obligations that operate on different timelines and to different regulators. The fastest clock is 2 hours - the Cyber Security Agency of Singapore's incident notification window for Critical Information Infrastructure (CII) operators under the Cybersecurity Act 2018, with supplementary details due within 72 hours. The next clock is 3 calendar days - the PDPC notification window under PDPA Part 6A section 26D for notifiable breaches (significant harm OR 500+ affected). For non-CII SMEs that do not meet the PDPA notifiable threshold, the response is contractual and operational - notification to insurer, customers, vendors, and any contracted counterparties. This article sets out the 72-hour playbook by hour blocks, the documents the SME should produce, and the insurance covers that respond.

The Sourced Detail

The first 72 hours after a cyber incident determine the regulatory exposure, the cover-response position, and the operational impact. The playbook is structured around the regulatory clocks that run in parallel and the decision points that operate within them.

The four clocks running in parallel

Clock 1: CSA CII notification - 2 hours. Under section 14 of the Cybersecurity Act 2018, CII operators must notify the Commissioner of Cybersecurity of a prescribed cybersecurity incident within 2 hours of becoming aware of the incident, with supplementary details due within 72 hours. CII status is designated by the Commissioner; most Singapore SMEs are not CII operators, but those in critical sectors (finance, healthcare, energy, transport, water, info-comm, government, security and emergency services, banking, media) may be.

Clock 2: PDPC data breach notification - 3 calendar days. Under PDPA Part 6A section 26D, an organisation must notify PDPC within 3 calendar days after determining a breach is notifiable (the section 26B notifiable threshold: significant harm OR 500+ affected). The 3-day clock runs from the section 26C assessment, not from the discovery of the breach.

Clock 3: Insurer notification. The cyber policy's notification window is typically "as soon as practicable" or within a stated number of days. The wording governs.

Clock 4: Contractual notification. Customer agreements, vendor agreements, and bank/financing arrangements typically include notification obligations on the SME for material incidents. The contractual clock is private but real.

Hour 0-6: Detection, triage, immediate containment

Identify and isolate. Identify the affected systems; isolate them from the broader network where possible without destroying evidence.

Preserve evidence. Forensic evidence (logs, memory dumps, attacker artefacts) must be preserved before remediation. The forensic team (internal or external) takes the lead.

Engage external resources. Notify the cyber policy's claims line; the policy typically pre-arranges access to forensic firms, legal counsel, and PR support.

Begin documentation. The incident timeline starts now. Each material event - discovery, who notified whom, decisions taken - is recorded with timestamps.

Internal escalation. Notify the designated incident-response owner; convene the response team (typically CEO, COO, CTO/IT lead, internal counsel, head of communications).

Hour 6-24: Scope assessment and CSA notification (if applicable)

Scope determination. What systems are affected? What data is involved? Is the incident ongoing or contained?

CII assessment. Is the SME a CII operator? If yes, the 2-hour CSA notification clock may already have run or be running. Submit the initial notification with the facts known.

Forensic deep-dive. The external forensic team conducts a deeper assessment. Key questions: How did the attacker get in? What did they access? Did they exfiltrate data? Are they still in the system?

Customer/counterparty awareness. Where the incident affects customer-facing services, decisions on customer communication start in this window.

Hour 24-48: Section 26C assessment and stakeholder notification

PDPA section 26C assessment. Determine whether the breach meets the section 26B notifiable thresholds: significant harm to affected individuals OR 500 or more affected individuals. Document the assessment.

Insurer notification (formal). With the scope clearer, the formal insurer notification provides the policy reference, the date and time of discovery, the nature of the incident, and the initial scope assessment.

Customer communication preparation. Where customer notification will be required (either under PDPA significant-harm threshold or contractually), the communication is drafted with legal review.

Vendor and counterparty notification. Where the incident affects vendor relationships or contractual counterparties, those notifications proceed in parallel.

Hour 48-72: PDPC notification, individual notification, public communication

PDPC notification. If the section 26C assessment determined the breach is notifiable, the PDPC notification portal submission is made within 3 calendar days of that assessment. The submission includes the prescribed information.

Individual notification. Where the significant-harm threshold is met, affected individuals are notified in a manner the organisation considers reasonable.

Public communication. A holding statement may be issued; substantive disclosure depends on the SME's industry, customer base, and listed-entity status (where applicable).

CSA supplementary notification. If the CII 2-hour notification was made, the 72-hour supplementary submission is due.

Day 4 and beyond: Remediation, regulator engagement, restoration

The first-72-hour window is the regulatory clock; the substantive remediation continues for weeks or months. Key workstreams:

  • Forensic investigation and root cause analysis.
  • Remediation of vulnerabilities; system rebuilding where required.
  • Regulator engagement (PDPC enquiry, CSA follow-up).
  • Customer and counterparty engagement.
  • Insurance claim progression.
  • Post-incident review and process improvement.

Insurance covers that respond

Cyber liability. The principal cover. Standard Singapore SME cyber policies respond to:

  • Forensic investigation costs.
  • PDPC and CSA notification engagement costs.
  • Individual notification costs (including call-centre support).
  • Public-relations / crisis-communications support.
  • Legal counsel.
  • Business interruption from the incident.
  • Cyber-extortion payments (where the policy permits and Singapore law allows).
  • Third-party liability claims arising from the breach.

Professional indemnity. Where the incident causes loss to professional clients through fabricated/affected work product or service disruption.

D&O. Where directors' duty-of-oversight allegations follow the incident.

Crime / fidelity guarantee. Where the incident involves insider involvement (employee theft, social engineering of staff to misappropriate funds).

The four documents the SME should produce

By the end of the 72-hour window, the SME should have produced:

  1. The incident timeline - structured by hour, identifying decisions taken.
  2. The PDPA section 26C assessment - documented basis for the notifiable / not-notifiable determination.
  3. The CSA initial and (if applicable) supplementary notification submissions.
  4. The PDPC notification submission (if the section 26C assessment determined notifiable).

These documents are also the evidence base for the insurance claim and for any subsequent regulatory enquiry.

Common Mistakes / What Goes Wrong

  1. Remediation before forensic preservation. Evidence lost.
  2. Delayed insurer notification. Pre-arranged forensic and legal panel access lost.
  3. Section 26C assessment not documented. The PDPC enquiry has no record.
  4. Confusing 26D 3-day from "discovery" rather than from "assessment". Misreads the clock.
  5. CSA notification deferred when CII status is unclear. Where in doubt, notify.
  6. Customer communication ahead of legal review. Public statements that constrain the SME's position.
  7. No incident-response plan tested in advance. Decisions made under pressure are worse than decisions tested in calm.
  8. Forensic team not pre-arranged through cyber policy. Selecting a team under time pressure.
  9. Vendor/counterparty notifications not coordinated with the primary regulatory response.
  10. No post-incident debrief scheduled.

What This Means for Your Business

  1. Build an incident-response plan before any incident.

  2. Map the four clocks (CSA 2-hour, PDPC 3-day, insurer, contractual) to your specific position.

  3. Pre-arrange forensic, legal, and PR resources through the cyber policy.

  4. Train the response team annually with a desktop exercise.

  5. Maintain the section 26C assessment template in operational readiness.

  6. Document the incident timeline from Hour 0.

  7. Coordinate customer and regulatory communications.

  8. Schedule the post-incident debrief as a fixed step.

Questions to Ask Your Adviser

  1. For our cyber policy, what is the notification window and the panel access at incident time?
  2. For our CII status (if applicable), what is your support model in the 2-hour window?
  3. For our PDPA exposure, what is the cyber sub-limit for forensics, notification, and individual support?
  4. For cyber-extortion payments, what is the policy position and the Singapore-law constraint?
  5. What is your post-incident debrief support model?

Related Information

Published 22 May 2026. Source verified 22 May 2026. COVA is an introducer under MAS Notice FAA-N02. We do not recommend insurance products. We provide factual information sourced from primary regulators and route you to a licensed IFA who can match a policy to your specific situation.