Singapore Overhauls Critical Infrastructure Cybersecurity Rules to Counter AI-Enabled Threats
Source: Computer Weekly
Josephine Teo, Singapore's Minister for Digital Development and Information and Minister-in-Charge of Cyber Security, used the stage at the sixth Operational Technology Cybersecurity Expert Panel Forum on Wednesday to lay out the most significant update to Singapore's critical infrastructure...

Josephine Teo, Singapore's Minister for Digital Development and Information and Minister-in-Charge of Cyber Security, used the stage at the sixth Operational Technology Cybersecurity Expert Panel Forum on Wednesday to lay out the most significant update to Singapore's critical infrastructure cybersecurity rules since 2022. The changes — spanning an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) owners, a forthcoming cloud-specific code, and a new grant-funded AI security sandbox — reflect a regulatory landscape being reshaped by the speed of AI-enabled threats.
The updated CCoP focuses on six areas: board-level accountability for cyber resilience, mandatory Cyber Trust Mark Level 5 certification for CII owners, oversight of interconnected systems that communicate with CII, deployment of threat detection systems across CII network segments, comprehensive cyber exercise planning, and robust network architecture management. Boards must now maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery — reviewed at least annually. The shift from perimeter defences to active defence reflects what Teo described as "a fundamental shift from relying on perimeter defences to actively defending against the threats."
The timing is no coincidence. Singapore's Cyber Security Agency (CSA) noted that with the emergence of frontier AI, threat actors can now discover vulnerabilities faster, shortening the window for exploitation. A separate code of practice for cloud services — being developed with companion guides from Amazon Web Services, Google Cloud, and Microsoft Azure — will be published in the second half of 2026, targeting the growing number of CII systems being hosted on public cloud infrastructure. CSA also launched an experimentation sandbox offering grants of up to 70% of project costs for non-government organisations to test AI in cyber defence activities such as penetration testing and code scanning, running through February 2027.
The updated rules arrive against a backdrop of escalating threats that have made clear the limits of traditional defences. Teo cited an attempted breach of a municipal water utility in Monterrey, Mexico, where an attacker with no prior OT knowledge used commercial AI tools to navigate from the utility's IT network to its Scada environment, research vendor documentation, and generate credentials for an automated attack — demonstrating how far an amateur can get with AI. Closer to home, CSA's response to the UNC3886 advanced persistent threat group that targeted all four of Singapore's major telcos earlier this year underscored that "our collective cyber resilience is only as strong as our weakest link," Teo said. Dragos CEO Robert M Lee, speaking at the same forum, noted that ransomware groups with reach into OT networks grew 49% year on year, and that 95% of organisations are not monitoring their OT networks for threats.
Why it matters for Singapore: These updates mark a fundamental realignment of Singapore's cyber defence strategy from reactive perimeter protection to proactive, board-driven accountability — a shift that mirrors the approach Singapore has taken with AI governance more broadly. The requirement for CII boards to personally own cyber resilience frameworks, combined with mandated Cyber Trust Mark certification and mandatory threat detection deployment, creates a compliance architecture that grows stricter as threats evolve. The cloud services code, developed jointly with the three largest hyperscalers, also sets a precedent for how critical infrastructure regulation will adapt as more essential services migrate to cloud environments. For the broader AI ecosystem, the message is clear: in Singapore, the security of AI systems and the AI-enabled security of critical infrastructure are now part of the same regulatory conversation.


