Singapore Tightens Critical Infrastructure Cybersecurity Rules to Counter AI-Powered Threats
Source: The Straits Times
Singapore is rewriting the rules for how its most essential services defend themselves in an era where artificial intelligence has fundamentally altered the cyber threat landscape. The updated Cybersecurity Code of Practice, announced on July 22 by Minister for Digital Development and Information Josephine...

Singapore is rewriting the rules for how its most essential services defend themselves in an era where artificial intelligence has fundamentally altered the cyber threat landscape. The updated Cybersecurity Code of Practice, announced on July 22 by Minister for Digital Development and Information Josephine Teo, introduces mandatory requirements that go significantly further than previous frameworks — and notably, they put board-level accountability front and centre.
Effective from end-July 2026, operators of Singapore's 11 critical information infrastructure sectors — spanning aviation, healthcare, banking, energy, infocommunications, and government — will be required to use a locally-developed intrusion detection tool built by the Ministry of Defence's Centre for Strategic Infocomm Technologies. The tool, already deployed in selected CII systems, is being rolled out wider following the state-sponsored UNC3886 cyber-espionage campaign that compromised Singapore's four major telcos in July 2025.
The updated code also mandates that entire boards — not just a single cybersecurity-savvy director — are accountable for overseeing cyber resilience. Boards must maintain a documented cyber resilience framework covering risk tolerance, mitigation strategies, and recovery measures, reviewed at least annually. This reflects a recognition that cybersecurity can no longer be siloed as a technical function; it is now a business risk requiring sustained leadership attention.
Perhaps the most forward-looking element is a new Cybersecurity Code of Practice for cloud services, to be introduced later in 2026 under the Cybersecurity Act. CII owners using cloud providers will need to ensure their vendors meet binding security requirements, with companion guides co-developed by CSA and providers including Amazon Web Services, Google Cloud, and Microsoft Azure. This addresses a growing exposure point: as critical infrastructure increasingly migrates to the cloud, the security boundary shifts from the operator's data centre to a shared responsibility model that has proven difficult to govern.
The timing is no coincidence. The CSA cited Anthropic's Claude Mythos Preview model, which can autonomously uncover unknown software vulnerabilities, and a Check Point Research report finding that AI now automates the bulk of cyber attacks that previously required skilled human hackers. Singapore's response — mandating specific tools, board accountability, and cloud security codes — suggests a regulatory philosophy that favours prescriptive requirements over principle-based guidance when it comes to national security.
Why it matters for Singapore: As one of the most digitised economies in the world, Singapore's reliance on interconnected CII systems makes it a high-value target for state-sponsored cyber operations. The decision to mandate a homegrown detection tool (from CSIT) rather than relying on commercial alternatives signals both a sovereignty concern and a industrial strategy — building domestic cyber defence capabilities that can later be exported. For businesses operating in Singapore's CII sectors, the new requirements mean compliance costs will rise, but the regulatory clarity around cloud security and board accountability reduces ambiguity that has long been a pain point for CISOs.


