#WorkinginCSA: Building Resilience in Singapore’s OT Environment
23 September 2026
Elizabeth Lee is a Cybersecurity Consultant in CSA’s Critical Information Infrastructure (CII) Division, and she is a part of the Foundational Digital Infrastructure Cluster, working on strengthening the cybersecurity posture of Singapore’s Infocomm and Media sectors.

1. Tell us more about your team’s work and your role in Critical Information Infrastructure (CII) Division.
Operational Technology Cybersecurity Expert Panel (OTCEP) 2026 Organising Committee
As a sector officer for the Infocomm and Media sectors, I partner with stakeholders to strengthen the cybersecurity of the systems behind Singapore's digital economy and everyday connectivity.
A typical day may involve reviewing risk assessments, discussing cybersecurity concerns with stakeholders, assessing the effectiveness of security controls, or supporting the development and implementation of cybersecurity policies and initiatives. Through engagements with various stakeholders, I have also gained a deeper appreciation of the diverse challenges faced by organisations, from managing legacy systems and operational constraints to navigating an evolving cyber threat landscape.
2. What inspired you to become interested in cybersecurity/ pursue a career in this field?
Before joining CSA, I served as a Senior Military Intelligence Expert with the Digital and Intelligence Service (DIS). Through that experience, I developed an interest in understanding emerging threats and how technology shapes the security landscape.
“Over time, I became increasingly aware that cyber incidents can have consequences beyond the digital domain. Around the world, we have seen them cripple critical infrastructure and disrupt essential services, highlighting how closely cybersecurity is linked to national security and everyday life.”— Elizabeth Lee
When the opportunity arose to join CSA through the Cybersecurity Development Programme (CSDP), it felt like a natural next step. It offered me the opportunity to deepen my cybersecurity expertise while continuing to contribute towards strengthening Singapore's digital resilience and security.
3. What are some projects you’ve worked on in CSA that you found particularly interesting or challenging?
One project that I found particularly interesting was supporting preparations for the Operational Technology Cybersecurity Expert Panel (OTCEP) 2026. As part of the organising committee in the early stages, I supported various planning efforts, including reviewing proposed conference topics and workshop submissions, as well as supporting administrative and financial processes.
OTCEP brings together OT cybersecurity experts from around the world to share their experiences, best practices and knowledge with the local OT community. Through the submission review process, I was exposed to a diverse range of topics, from threat intelligence and threat-informed defence to incident detection and response, as well as approaches to securing and hardening industrial control systems. This broadened my understanding of the challenges faced by organisations operating critical systems and the approaches that may be taken to strengthen cyber resilience.
A key considerations in the review and selection process was keeping the programme remained relevant and valuable to participants from different sectors, with varying levels of technical expertise and experience, and different areas of focus. As this was my first time curating a programme , I gained a greater appreciation of the thought required to make one both technically relevant and accessible to participants with diverse backgrounds.
4. Tell us something about your job that not many people know about.
One common misconception is that cybersecurity professionals spend most of their time hacking systems or stopping cyber-attacks in real time, complete with frantic keyboard typing and walls of monitors filled with flashing code. In reality, my day-to-day work involves far fewer dramatic moments (or more likely, none at all), and considerably more meetings and stakeholder engagements.
Many people may not realise that cybersecurity is often as much about people, priorities, and decision making, as it is about technology.
While strengthening technical defences is important, organisations frequently face practical constraints - operational requirements, resource limitations, legacy systems, and competing priorities. As a result, cybersecurity is rarely about achieving perfect security (if that even exists!). Instead, it involves understanding trade-offs and working with stakeholders to identify measures that effectively reduce risk while remaining practical and sustainable.
5. Outside of work, do you have any hobbies and interests? How do you unwind from work?

Trail at Jangsan Mountain, Busan (2026)
Outside of work, I enjoy spending time in nature and exploring the outdoors. Whether it is walking along a trail, enjoying the peace and quiet of nature, or going for a night cycle, I find these activities a good way to disconnect from the fast pace of daily life and recharge.
One of my more memorable experiences was cycling the Four Rivers route from Seoul to Busan in South Korea. The toughest segment was climbing Ihwaryeong Pass, which involved a steep ascent of around 500 metres of elevation gain. Cycling uphill with several days' worth of clothes and necessities packed into my pannier bags was physically demanding. There were also days when the weather turned cold and rainy, and I even had an unfortunate fall along the way. Despite the challenges, I completed the journey, gaining a strong sense of accomplishment, along with some very sore muscles and an achy bum.
Looking back, the experience reminded me not to focus too much on the distance remaining, but instead on making steady progress. I find that mindset equally relevant in cybersecurity, where strengthening and maintaining resilience is often a continuous process.
