AI Is Rewriting the Rules of Cyber Defence, Says Singapore's Founding Cybersecurity Chief
Source: CNA
When David Koh stepped down as founding chief executive of Singapore's Cyber Security Agency (CSA) in July after 42 years in public service, he left behind a cybersecurity landscape that looks almost nothing like the one he helped build. In his first exclusive interview since retiring, Koh warned...

When David Koh stepped down as founding chief executive of Singapore's Cyber Security Agency (CSA) in July after 42 years in public service, he left behind a cybersecurity landscape that looks almost nothing like the one he helped build. In his first exclusive interview since retiring, Koh warned that artificial intelligence is rewriting the rules of cyber defence in ways that demand a complete rethink of Singapore's approach to online security.
The warning is not abstract. Koh described how AI can automate the process of identifying and chaining together software vulnerabilities — what he called "a weak hinge here, a loose lock there" — to open a door that previously took skilled human operators weeks or even days to construct. With AI, that timeline compresses to hours or minutes. The speed and scale of attacks could multiply, and the traditional advantage of obscurity — that older or proprietary systems were simply too niche to be worth attacking — evaporates when AI can cheaply probe any target.
Singapore has not yet been hit by an AI-enabled cyberattack, Koh confirmed, but the country's defenders are already grappling with the implications. He pointed to critical operational technology systems — power plants, electrical grids, train networks — that have historically required state-level resources to compromise. AI lowers that bar. Meanwhile, the current industry standard of developing a security patch within two to three weeks may no longer be adequate when attack construction happens in minutes. Koh suggested that defenders will need continuous monitoring rather than annual security audits, and that board-level attention is now essential.
Koh also reflected on three incidents that reshaped his understanding of Singapore's cyber risk profile. The 2024 CrowdStrike outage, though not an attack, forced manual check-ins at Changi Airport and delayed over 100 flights — a vivid reminder that technical resilience is only half the equation. The 2021 Colonial Pipeline ransomware attack showed that unsophisticated actors, not just state-backed groups, can trigger cascading economic disruption. And the 2020 SolarWinds supply-chain compromise demonstrated how hidden code can be injected into trusted software updates, reaching hundreds of downstream victims before detection.
Why it matters for Singapore: As a highly digitised city-state that depends on uninterrupted connectivity for everything from banking to transport, Singapore's exposure to AI-powered threats is uniquely acute. Koh's post-retirement advisory role at CSA and the Ministry of Digital Development and Information signals that the government takes these risks seriously — but the interview makes clear that the defence playbook is still being written. For Singapore's businesses and critical infrastructure operators, the message is unambiguous: the standard annual audit and two-week patching cycle will not survive contact with an AI-enabled adversary. The question is not whether AI will change the threat landscape, but whether Singapore's defenders can adapt faster than the attackers.


