Singapore Unveils Three-Pronged Strategy Against AI-Enabled OT Cyberattacks on Critical Infrastructure
Source: Digital Watch Observatory
Singapore has outlined a three-priority strategy to defend critical infrastructure against AI-powered OT attacks, as Minister Josephine Teo warned that AI is enabling attackers without specialist knowledge to target power grids and telecoms networks. The framework is one of the most structured national responses to AI-enabled OT threats globally

Singapore has outlined a three-priority strategy to defend critical infrastructure against AI-powered operational technology (OT) attacks, as Minister for Digital Development and Information Josephine Teo warned that artificial intelligence is enabling attackers without specialist industrial knowledge to target power grids, water utilities, and telecommunications networks.
Speaking at the Operational Technology Cybersecurity Expert Panel Forum 2026, Teo introduced a framework built around three priorities: "lock down, find first, fix fast." The first pillar focuses on raising baseline defences across critical information infrastructure (CII) owners. Singapore's Cyber Security Agency (CSA) is releasing an updated Cybersecurity Code of Practice that shifts emphasis from perimeter-based security to continuous detection, response, and recovery. Boards and senior management will be held directly accountable for cyber resilience governance — a significant escalation of regulatory expectations for CII operators.
The "lock down" priority also extends to cloud environments. CSA will launch a separate Cybersecurity Code of Practice for Cloud later this year, governing the secure deployment and management of CII systems hosted on cloud infrastructure. Additionally, leading original equipment manufacturers and OT technology providers have committed to certification under Singapore's Cyber Trust Mark framework, strengthening supply chain security.
The second priority, "find first," centres on using AI itself as a defensive tool. CSA has launched a cybersecurity sandbox programme that partners vendors and solution providers to pilot AI-enabled security operations across critical infrastructure sectors. Teo noted that AI-assisted security testing has compressed months of analysis into days. Under the third priority, "fix fast," CSA is renewing its memorandum of understanding with industrial cybersecurity firm Dragos to deepen threat intelligence sharing and joint capability development, while pushing asset owners to automate remediation processes.
Why it matters for Singapore: The strategy arrives in direct response to demonstrated threats. Earlier this year, advanced persistent threat group UNC3886 targeted all four of Singapore's major telecommunications operators in a coordinated campaign, contained only through "Operation Cyber Guardian" — the largest cyber response operation in Singapore's history. Teo also cited an attempted breach of a municipal water utility in Monterrey, Mexico, where an attacker with no OT expertise used commercially available AI tools to identify SCADA-connected systems and generate login credentials. With AI lowering the barrier for OT attacks globally, Singapore's framework represents one of the most structured national responses to date, combining regulatory mandates, board-level accountability, AI-enabled defence, and international intelligence sharing into a single coordinated posture.


