Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019
COI Report – Part IV Page 100 of 425 27.6 Sze Chun discovering on 5 July 2018 that SQL queries were made to the SCM database since 27 June 2018, and informing Ernest of the same ....... 168 Series of measures taken on 6 and 7 July 2018 to secure the domain administrator accounts and domain controllers ........................................... 169 27.7.1 Creating anew set of domain administrator accounts and removing the old accounts from the administrator groups of their respective domains ............ 169 27.7.2 Performing full antivirus scans on all domain controllers ............................. 169 27.7.3 Creating and enforcing a GPO to block the access of domain administrator accounts to servers ......................................................................................... 170 27.7.4 Creating and implementing a GPO to prevent remote connections to domain controllers ....................................................................................................... 170 27.8 Ernest’s continued refusal to escalate the matter on 6 July 2018 ................ 170 Arranging to meet Woon Lan on 9 July 2018 .............................................. 172 Assessment of IHiS’ incident response from 5 to 8 July 2018 .................... 172 28 EVENTS OF 9 JULY 2018 .............................................................................. 173 28.1 Shutting down Citrix Server 2 ..................................................................... 173 Meeting amongst various members of the Infrastructure Services Division at pm ......................................................................................................... 173 Raising the matter to Clarence Kua and Serena Yong ................................. 175 Meeting at ConnectionOne and the decision to escalate the matter to Benedict Tan ............................................................................................................... 176 Informing Bruce, Kim Chuan and Prof. Kenneth ........................................ 177 Assessment of IHiS’ incident response on 9 July 2018 ............................... 179