SINGAPORE — Critical information infrastructure (CII) operators in Singapore will soon face stricter cybersecurity obligations under an updated regulatory framework designed to counter rapid advances in artificial intelligence and Advanced Persistent Threats (APTs).
The Cyber Security Agency of Singapore (CSA) announced on Wednesday that it will release an updated Cybersecurity Code of Practice (CCoP) for CII, along with a dedicated CCoP for Cloud Services, in the second half of 2026.
Speaking at the Operational Technology Cybersecurity Expert Panel Forum 2026, Mrs. Josephine Teo—Minister for Digital Development and Information and Minister-in-charge of Cybersecurity and Smart Nation Group—highlighted how the threat landscape has shifted since the last CCoP revision in 2022.
“With the emergence of Frontier AI, threat actors can now discover vulnerabilities faster, thus shortening the window period for exploitation,” the agency noted, warning that AI-enabled tools allow attackers to deploy threats at greater scale and velocity.
Enhanced Accountability & Operational Controls
To help critical infrastructure owners keep pace with AI-driven exploits, the revised CCoP introduces technical guidance focused on three proactive defense pillars: adversarial attack simulation, penetration testing, and threat hunting.
The regulatory updates align with recent amendments to Singapore’s Cybersecurity Act, expanding risk oversight to interconnected enterprise networks that communicate with critical systems.
Key Governance Mandates
Dedicated Code Introduced for Cloud Infrastructure
As critical operators rely more heavily on cloud architectures, the agency will launch the CCoP (Cloud) later this year to govern the deployment, operation, and management of cloud-hosted CII systems.
Following closed-door consultations with operators and auditors, the CSA co-developed provider-specific Companion Guides alongside market leaders Amazon Web Services, Google Cloud, and Microsoft Azure. These guides will publish concurrently with the cloud code to give operators tailored blueprints for leveraging native security capabilities within each environment.





Leave a Reply