Singapore tightens rules governing critical services sectors to counter AI cyberthreats

Sign up now: Get ST's newsletters delivered to your inbox

Advances in AI are making cyberattacks increasingly sophisticated.

Advances in AI are making cyberattacks increasingly sophisticated.

PHOTO: REUTERS

  • Singapore requires all board members of critical infrastructure owners to be accountable for cybersecurity.
  • A new legally binding cybersecurity code for cloud services will be introduced in 2026 to ensure cloud providers have strong safeguards.
  • The Cyber Security Agency of Singapore will deploy local threat detection tools and work with cloud providers to help CII owners secure their systems effectively.

AI generated

SINGAPORE – Operators of Singapore’s critical information infrastructure (CII) will need to use a homegrown intrusion detection tool and ensure board-level involvement in cybersecurity matters to counter growing threats.

These are among a host of tougher mandatory cybersecurity requirements under the Cybersecurity Code of Practice that will take effect by end-July.

The locally developed threat detection tool has come on the heels of state-sponsored cyber-espionage group UNC3886’s attack on Singapore’s four major telcos Singtel, StarHub, M1 and Simba Telecom detected in July 2025.

The tool, developed by the Ministry of Defence’s Centre for Strategic Infocomm Technologies, has already been deployed in selected CII systems. A wider rollout across all 11 CII sectors is being planned to strengthen Singapore’s defence against such advanced persistent threats.

The 11 CII sectors are aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government.

Announcing the new rules on July 22, Minister for Digital Development and Information Josephine Teo said: “Sophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go in deep into interconnected systems.”

Teo also pointed out that UNC3886 is not the first to target Singapore’s CII systems, nor will it be the last.

“AI has challenged the longstanding assumption that the complexity of operational technology systems keeps them safe from attack,” said Teo, who was referring to systems that operate heavy industrial machinery like those in power plants or transport networks.

She was speaking at the sixth edition of the Operational Technology Cybersecurity Expert Panel Forum.

Advances in AI are making cyberattacks increasingly sophisticated, enabling threat actors to discover vulnerabilities faster, and launch attacks at a greater scale.

For example, Anthropic’s latest Claude Mythos Preview model is said to be able to autonomously uncover unknown software vulnerabilities and engineer exploits.

A recent intelligence report by cybersecurity company Check Point Research also found that AI had helped to automate the bulk of cyberattacks that previously required skilled human hackers.

Teo said that AI has lowered the barrier of entry for cyberattackers to target industrial systems. For example, in May 2026, amateur hackers used AI to map a Mexican municipal water utility’s network and generate malicious code.

But many industrial systems remain opaque. “We are caught by surprise when something seems wrong with operations. By then, the attacker may have compromised systems for weeks,” said Teo.

As such, Singapore needs to respond by locking down systems to strengthen its baseline defence, so attackers are denied an easy win, she said.

The updated measures in the Cybersecurity Code of Practice is one way of ensuring this.

CII owners are also required to ensure their entire boards – not just a single director – account for cybersecurity under the updated code. Previously, CII owners only needed to ensure at least one board member had knowledge of cybersecurity risks to provide guidance to senior management.

The Cyber Security Agency of Singapore (CSA) said that AI-enabled threats have accelerated the speed and scale of cyberattacks, and board-level oversight and accountability has become more important.

“Ultimately, cybersecurity is a business risk that requires sustained leadership and oversight from the board, rather than being viewed solely as a technical or operational issue.”

Boards will now also have to maintain a documented cyber resilience framework setting out the organisation’s risk tolerance, mitigation and recovery measures, and review it at least annually.

The updated Cybersecurity Code of Practice will also mandate that CII owners obtain the highest-tier cybersecurity certification, Cyber Trust Mark Level 5, for their non-CII systems that support their business operations and services.

Level 5 certification requires preparedness in all of 22 domains, including governance, asset protection and secure access. Lower-level certification requires preparedness in fewer domains.

The move was previously announced at a debate on the Ministry of Digital Development and Information’s budget in March.

CII owners have until the end of 2027 to comply with the requirement to obtain the Cyber Trust Mark certification.

Locking down systems also extends to cloud environments as CII owners increasingly adopt them, said Teo.

A new legally binding code will also be introduced later in 2026 to require CII owners using cloud services to ensure their providers have adequate safeguards against cyber threats.

“A compromised vendor or partner can be just as vulnerable an entry point as misconfigured internal system,” said Teo.

The upcoming Cybersecurity Code of Practice (Cloud), which will be issued under the Cybersecurity Act, will require CII owners to work with their vendors to put in place security controls and operational arrangements to ensure their environments are secure.

The new code will set out requirements governing the secure deployment, operation and management of CII systems hosted on the cloud. These details will be shared later. CII owners are responsible for ensuring the requirements are met.

CSA has conducted a series of closed-door consultations with auditors and CII owners that have or are exploring the adoption of cloud services to ensure the requirements are robust, practical and can be implemented by operators.

The new code will also be accompanied by companion guides jointly developed by CSA and cloud providers, including Amazon Web Services, Google Cloud and Microsoft Azure. Each guide sets out how the code’s requirements can be implemented within that provider’s cloud environment.

See more on