Table of contents exchange of letters with the minister executive summary


Ernest’s continued refusal to escalate the matter on 6 July 2018



Download 5.91 Mb.
View original pdf
Page146/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   142   143   144   145   146   147   148   149   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019

27.8 Ernest’s continued refusal to escalate the matter on 6 July 2018
541. At around am on 6 July 2018, Benjamin again raised the issue of escalating the matter, stating on a TigerConnect chat group “Ernest, the scope
of compromise is quite wide now..[a domain administrators account was
compromised before Citrix servers were compromised. I would suggest getting a
3
rd
party at this point to come in”, and that, based on their observations relating



COI Report – Part IV
Page 171 of 425

to Roy’s accounts, that IHiS’ “entire infra has been compromised…Followed by
Citrix, and successful login and queries to our scm…
542. In reply, Ernest stated “as mentioned, we need to isolate, contain and
defend first...our tightening by infra is not strong enough. even if we report now
bring down the experts, they'll say our tightening is not well done...once we
escalate to mgt, there will be no day no night. everyone I meant everyone in
IHiS will be working nonstop on this case...” Ernest has given an explanation for his reply When I referred to management in this message, I was referring to
GCIO Benedict. At the time I sent this message on 6 July 2018, it had occurred tome that I should report the incident to management. Nevertheless, I did not report the matter. I did not report because my focus was on isolating, containing and defending. I was so busy with this that I did not escalate to management about the security incident. In fact, I thought to myself, If I report the matter, what do I get If I report the matter, I will simply get more people chasing me for more updates. If they are chasing me for more updates, I need to be able to get more information to provide to them. The moment I report the security incident, the clock will start ticking as per the timelines indicated at p 11 of the IR-SOP… I avoided reporting the matter as soon as it occurred tome to report it, because the clock will start ticking. Having to provide these updates on these timelines puts a lot of pressure on my team - CSA, CSG, MOH, IHiS and SingHealth senior management, GCIO and CISO will all want more information, and all of this pressure will be on my team…”
32

32
In context of Ernest’s oral evidence, the term “CISO” was intended to refer to Cluster ISO Wee Jia
Huo.



Download 5.91 Mb.

Share with your friends:
1   ...   142   143   144   145   146   147   148   149   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page