SINGAPORE, — Singapore is stepping up efforts to strengthen the cybersecurity of operational technology (OT) systems that underpin its critical infrastructure, as artificial intelligence (AI) enables increasingly sophisticated cyberattacks against industrial control environments.

Speaking at the Operational Technology Cybersecurity Expert Panel (OTCEP) Forum 2026, Minister for Digital Development and Information Josephine Teo said AI is rapidly reshaping the threat landscape for OT defenders, making it easier for attackers with little or no OT expertise to target critical infrastructure.

She cited an attempted cyberattack on a municipal water utility in Monterrey, Mexico, where an attacker used commercially available AI tools to identify a pathway from an information technology (IT) network into the supervisory control and data acquisition (SCADA) environment.

Although the attack failed, Teo said it demonstrated how AI can significantly reduce the expertise and preparation needed to target OT systems.

She also referred to cyberattacks in Poland in late 2025 targeting more than 30 wind and solar farms, a combined heat and power plant, and a manufacturing company, saying the incidents showed attackers’ growing ability to coordinate operations across multiple OT environments.

Teo warned that modern OT systems are increasingly interconnected with IT networks, allowing attackers to move more easily between the two. She added that many OT environments remain difficult to monitor, enabling threat actors to remain undetected for extended periods.

To address these risks, Singapore will adopt a three-pronged strategy of “lock down, find first and fix fast” to strengthen cyber resilience across critical infrastructure.

As part of the initiative, the Cyber Security Agency of Singapore (CSA) will introduce an updated Cybersecurity Code of Practice requiring owners of Critical Information Infrastructure (CII) to improve their ability to detect, respond to and recover from cyberattacks, while placing greater accountability on boards and senior management.

CSA will also launch a separate Cybersecurity Code of Practice for cloud environments later this year to establish security requirements for CII systems hosted on cloud platforms.

Teo also called on original equipment manufacturers (OEMs), technology vendors and suppliers of OT systems to strengthen their cybersecurity practices, welcoming commitments by several companies to obtain certification under Singapore’s Cyber Trust Mark.

To help organisations identify vulnerabilities before attackers can exploit them, CSA has launched an AI cybersecurity sandbox that will pilot AI-enabled security operations across critical infrastructure.

The agency will also renew its memorandum of understanding with industrial cybersecurity firm Dragos to expand threat intelligence sharing and joint capability development.

Teo said safeguarding OT systems requires collaboration across governments, infrastructure operators and technology providers, adding that AI has become both a challenge and an opportunity for cyber defenders.

“The answer is not to wait and respond only when hit. It is to be proactive — lock down, find first and fix fast,” she said.

Leave a Reply

Designed with WordPress

Discover more from Press KL: Your Voice, Your Vision

Subscribe now to keep reading and get access to the full archive.

Continue reading