Singapore tightens rules governing critical services sectors to counter AI cyber threats

They will need to use a homegrown intrusion detection tool

    • Advances in AI are making cyberattacks increasingly sophisticated.
    • Advances in AI are making cyberattacks increasingly sophisticated. PHOTO: REUTERS
    Published Wed, Jul 22, 2026 · 04:32 PM

    [SINGAPORE] Operators of Singapore’s critical infrastructure will need to use a homegrown intrusion detection tool and ensure board-level involvement in cybersecurity matters to counter growing threats posed by artificial intelligence.

    These are among a host of tougher mandatory cybersecurity requirements under the Cybersecurity Code of Practice that will take effect by end July.

    The locally-developed threat detection tool has come on the heels of state-sponsored cyber-espionage group UNC3886’s attack on Singapore’s four major telcos Singtel, StarHub, M1 and Simba Telecom detected in July 2025.

    The tool, developed by the Ministry of Defence’s Centre for Strategic Infocomm Technologies, has already been deployed in selected critical CII systems. A wider rollout across all 11 CII sectors is being planned to strengthen Singapore’s defence against such advanced persistent threats.

    The 11 CII sectors are aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government.

    Announcing the new rules on July 22, the Minister of Digital Development and Information Josephine Teo said: “Sophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go in deep into interconnected systems.”

    Asean Intelligence

    Get insights into businesses across South-east Asia

    Get the free report

    Teo also pointed out that UNC3886 is not the first to target Singapore’s CII systems, nor will it be the last.

    “AI has challenged the long-standing assumption that the complexity of operational technology systems keeps them safe from attack,” said Teo, who was referring to systems that operate heavy industrial machinery like those in power plants or transport networks.

    She was speaking at the sixth edition of the Operational Technology Cybersecurity Expert Panel Forum.

    Advances in AI are making cyberattacks increasingly sophisticated, enabling threat actors to discover vulnerabilities faster, and launch attacks at a greater scale.

    For example, Anthropic’s latest Claude Mythos Preview model is said to be able to autonomously uncover unknown software vulnerabilities and engineer exploits.

    A recent intelligence report by cybersecurity company Check Point Research also found that AI had helped to automate the bulk of cyber attacks that previously required skilled human hackers.

    Teo said that AI has lowered the barrier of entry for cyber attackers to target industrial systems. For example in May 2026, amateur hackers used AI to map a Mexican municipal water utility’s network and generate malicious code.

    But many industrial systems remain opaque. “We are caught by surprise when something seems wrong with operations. By then, the attacker may have compromised systems for weeks,” said Teo.

    As such, Singapore needs to respond by locking down systems to strengthen its baseline defence so attackers are denied an easy win, she said.

    The updated measures in the Cybersecurity Code of Practice is one way of ensuring this.

    CII owners are also required to ensure their entire boards – not just a single director – account for cybersecurity under the updated code. Previously, CII owners only need to ensure at least one board member with knowledge of cybersecurity risks to provide guidance to senior management.

    The CyberSecurity Agency of Singapore (CSA) said that AI-enabled threats have accelerated the speed and scale of cyberattacks, and board-level oversight and accountability has become more important. “Ultimately, cybersecurity is a business risk that requires sustained leadership and oversight from the board, rather than being viewed solely as a technical or operational issue.”

    Boards will now also have to maintain a documented cyber resilience framework setting out the organisation’s risk tolerance, mitigation, and recovery measures, and review it at least annually.

    The updated Cybersecurity Code of Practice will also mandate that CII owners obtain the highest-tier cybersecurity certification Cyber Trust mark level 5 for their non-CII systems that support their business operations and services.

    Level 5 certification requires preparedness in all of 22 domains, including governance, asset protection and secure access. Lower-level certification requires preparedness in fewer domains.

    The move was previously announced at a debate on the Ministry of Digital Development and Information’s budget in March.

    CII owners have till the end of 2027 to comply with the requirement to obtain the Cyber Trust mark certification.

    Locking down systems also extends to cloud environments as CII owners increasingly adopt them, said Teo.

    A new legally binding code will also be introduced later in 2026 to require CII owners using cloud services to ensure their providers have adequate safeguards against cyber threats.

    A new legally binding code will also be introduced later in 2026 to require CII owners using cloud services to ensure their providers have adequate safeguards against cyber threats.

    “A compromised vendor or partner can be just as vulnerable an entry point as misconfigured internal system,” said Teo.

    The upcoming Cybersecurity Code of Practice (Cloud), which will be issued under the Cybersecurity Act, will require CII owners to work with their vendors to put in place security controls and operational arrangements to ensure their environments are secure.

    The new code will set out requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud. These details will be shared later.

    CII owners are responsible for ensuring the requirements are met.

    CSA has conducted a series of closed-door consultations with auditors and CII owners that have or are exploring the adoption of cloud services to ensure that the requirements are robust, practical, and can be implemented by operators.

    The new code will also be accompanied by companion guides jointly developed by CSA and cloud providers including Amazon Web Services, Google Cloud and Microsoft Azure.

    Each guide sets out how the code’s requirements can be implemented within that provider’s cloud environment. THE STRAITS TIMES

    Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.

    Share with us your feedback on BT's products and services