Live12h agoIMDA's Open Innovation Platform Bridges Singapore's AI Adoption Gap With Structured Challenge-Based Funding
← Back to stories

CSA to update cybersecurity code of practice as AI-powered threats reshape Singapore's threat landscape

Source: CSA Singapore

Singapore's Cyber Security Agency will release an updated Cybersecurity Code of Practice for critical information infrastructure later this year, alongside a new code for cloud services, to counter AI-enabled attacks. The updates require CII owners to strengthen board accountability, attain Cyber Trust Mark Level 5 certification, and deploy threat detection systems across network segments.

CSA to update cybersecurity code of practice as AI-powered threats reshape Singapore's threat landscape
SGAI Daily

Singapore's cyber defences are getting a significant upgrade. With AI-enabled threats becoming more sophisticated and frequent, the Cyber Security Agency of Singapore (CSA) is updating its regulatory playbook to keep pace with an adversary that learns faster than ever before.

At the Operational Technology Cybersecurity Expert Panel Forum 2026, Minister for Digital Development and Information Josephine Teo announced that CSA will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and a brand-new CCoP for Cloud Services in the second half of this year. Since the last CCoP update in 2022, the threat landscape has shifted dramatically — frontier AI now allows attackers to discover vulnerabilities faster, shortening the window for defensive action.

The updated CCoP introduces several key requirements. CII owners must strengthen board and senior management accountability, with boards required to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery — reviewed at least annually. They must also attain Cyber Trust Mark Level 5 certification, maintain oversight of interconnected systems, and develop comprehensive cybersecurity exercise plans. CSA will work with CII owners to deploy threat detection systems across their network segments.

Perhaps the most forward-looking piece is the planned CCoP for Cloud Services, developed in consultation with Amazon Web Services, Google Cloud, and Microsoft Azure. Each provider will publish Companion Guides showing how the controls can be implemented in their respective environments. This reflects a pragmatic recognition that CII owners are increasingly adopting cloud, and the security framework needs to follow workloads rather than fight the direction of travel.

Why it matters for Singapore: As a small, highly connected city-state, Singapore's critical infrastructure — from power grids to water treatment to healthcare systems — is particularly exposed to cyber threats. The updated CCoP signals that the government is treating AI-enabled threats as a structural shift, not a passing trend. The emphasis on board-level accountability and cloud security also aligns with broader moves under the amended Cybersecurity Act to extend responsibility beyond IT departments to the highest levels of organisational leadership.

Your daily AI edge in Singapore: in <5 minutes.

We do the reading so you don't have to. Get the essential TL;DR on local AI moves delivered to your inbox every morning.