Mechanical & Electrical (M&E) vendors supporting Singapore Government projects increasingly operate at the intersection of Operational Technology (OT) and Information Technology (IT). Systems such as Building Management Systems (BMS), CCTV, access control, lifts, sensors, and industrial controllers are no longer isolated mechanical components — they are networked, IP-based, and cyber-exposed.
To manage these risks, Government projects involving Critical Information Infrastructure (CII) are governed by strict cybersecurity requirements. This article provides a practical, vendor-friendly overview of the key cybersecurity controls you are expected to comply with, based on the CII cybersecurity specifications — and how compliance is validated through SSCT / SSAT assessments.
Why This Matters for M&E Vendors
Even if:
-
Your systems are on-premise
-
Your network is air-gapped
-
You do not manage IT systems directly
You are still responsible for:
-
Securing IP-enabled OT devices
-
Hardening systems before deployment
-
Providing justification for any non-compliance
-
Passing independent cybersecurity assessments
Failure to meet these requirements can delay the project timeline and hence, payment and risk penalties.
1. Asset Management
Asset management is a foundational cybersecurity requirement. Simply put: you cannot secure what you do not know you have.
M&E vendors are expected to maintain an accurate and complete inventory of all systems within scope, including both OT and IT components.
Minimum Information Expected
For each asset, the inventory should typically include:
-
Device name or identifier
-
IP address
-
System role or function
-
OS / firmware version
During SSCT / SSAT, assessors will cross-check this inventory against:
-
Network scans
-
Vulnerability Assessment scope
-
System architecture diagrams
2. Secure System Architecture & Segmentation (Network Architecture)
OT systems must be:
-
Logically and physically segregated from corporate IT networks
-
Designed using defence-in-depth principles
-
Protected with network zoning, firewalls, or gateways where applicable
Even in air-gapped environments:
-
Segmentation within the OT network is still expected
-
Critical controllers should not sit on flat networks
3. Access Control & Authentication
Requirements include:
-
Unique user accounts (no shared admin passwords)
-
Strong authentication for administrative access, multi-factor authentication required
-
Role-based access base on minimum access rights and permission to perform the tasks
-
Remove all unnecessary accounts
For OT systems:
-
Default passwords must be changed
4. System Hardening & Secure Configuration
All systems must be securely configured using:
-
CIS Benchmarks, where available
-
If CIS benchmarks are not available, OEM or Principal hardening guidelines
This applies to:
-
-
Servers
-
Workstations
-
Network devices
-
OT controllers and appliances
-
- All services and applications that are not necessary must be disabled and removed
All non compliance items must be documented and justified
5. Logging, Monitoring & Audit Trails
Systems must:
-
Generate security and operational logs
-
Protect logs from unauthorised modification
-
Retain logs according to project requirements
Even if logs are stored locally:
-
They must be reviewable during assessment
-
Logging should cover authentication, configuration changes, and system events
- For systems with insufficient storage to meet the requirements, centralized logging server is required
6. Malware Protection & Removable Media Controls
Given that many OT environments are air-gapped:
-
Malware introduction via USB and removable media is a key risk
- Anti-malware must be installed and scan performed regularly
Requirements include:
-
All removable media must be disabled
-
Controlled procedures for data transfer into OT environments
-
Documentation of media handling processes and signature update
7. Vulnerability Assessment (VA) – Mandatory for All IP Devices
Vulnerability assessment is a process of identifying, assessing and discovering security vulnerabilities on a computer system, including IT and OT systems or networks.
Key points:
-
All IP-based devices must undergo Vulnerability Assessment
(CCTV cameras, BMS servers, controllers, network switches, etc.) -
VA is not limited to servers or IT systems
-
Identified vulnerabilities must be:
-
Remediated, or
-
Documented with justification
-
Unresolved vulnerabilities without justification are considered non-compliance.
8. Penetration Test (PT)
Beyond vulnerability assessments, penetration testing may be required for certain systems to assess whether identified weaknesses are practically exploitable. This enables the understanding of real-world risk exposure and take appropriate remediation actions.
Such testing is to be performed by licensed third-party penetration testing service providers.
Further details on our penetration testing capabilities are available on our website.
9. Backup, Recovery & System Resilience
Systems must:
-
Have defined backup and recovery procedures
-
Ensure configuration and system data can be restored
-
Protect backups from unauthorised access or tampering
10. Security Testing & Independent Validation
Compliance is not self-declared.
All applicable systems must undergo:
-
SSCT (System Security Compliance Testing) or
-
SSAT (System Security Acceptance Testing)
Key characteristics:
-
Performed by an independent third party
-
Validates all requirements are actually met
-
Covers technical validation and host configuration review, with all compliances and non-compliances documented
For M&E vendors, this means:
-
Your delivered system will be reviewed
-
Gaps discovered during SSCT/SSAT must be addressed or justified
Final Thoughts
Cybersecurity is no longer optional for M&E systems in Singapore Government projects.
Even in air-gapped OT environments, secure configuration, vulnerability management, and independent assessment are mandatory.
Understanding these requirements early helps M&E vendors to:
-
Reduce project delays
-
Avoid costly redesigns and rework
-
Build trust with Government agencies and principals
If you deploy IP-enabled OT systems, cybersecurity compliance is now part of your delivery responsibility — not an afterthought.
Preparing early and aligning with SSCT / SSAT expectations will significantly reduce assessment risks.
Perennial Consultancy supports M&E vendors in achieving SSCT / SSAT readiness through independent assessments, gap analysis, and remediation guidance.
Visit our website to learn how we can support your project.








