SINGAPORE — Critical information infrastructure (CII) operators in Singapore will soon face stricter cybersecurity obligations under an updated regulatory framework designed to counter rapid advances in artificial intelligence and Advanced Persistent Threats (APTs).

The Cyber Security Agency of Singapore (CSA) announced on Wednesday that it will release an updated Cybersecurity Code of Practice (CCoP) for CII, along with a dedicated CCoP for Cloud Services, in the second half of 2026.

Speaking at the Operational Technology Cybersecurity Expert Panel Forum 2026, Mrs. Josephine Teo—Minister for Digital Development and Information and Minister-in-charge of Cybersecurity and Smart Nation Group—highlighted how the threat landscape has shifted since the last CCoP revision in 2022.

“With the emergence of Frontier AI, threat actors can now discover vulnerabilities faster, thus shortening the window period for exploitation,” the agency noted, warning that AI-enabled tools allow attackers to deploy threats at greater scale and velocity.

Enhanced Accountability & Operational Controls

To help critical infrastructure owners keep pace with AI-driven exploits, the revised CCoP introduces technical guidance focused on three proactive defense pillars: adversarial attack simulation, penetration testing, and threat hunting.

The regulatory updates align with recent amendments to Singapore’s Cybersecurity Act, expanding risk oversight to interconnected enterprise networks that communicate with critical systems.

Key Governance Mandates

Requirement Area Summary of New Expectations
Executive Governance Boards and senior leadership face direct accountability for cyber resilience. They must maintain and annually review a framework spanning risk tolerance, mitigation, transfer, and recovery.
Mandatory Certification CII owners must attain Cyber Trust Mark Level 5 certification to establish high baseline security standards.
Network & Detection CSA and operators will jointly deploy threat detection systems across network segments. Operators must maintain oversight of interconnected third-party systems.
Incident Preparedness CII organizations are required to develop comprehensive exercise plans to ensure swift, coordinated incident response.

Dedicated Code Introduced for Cloud Infrastructure

As critical operators rely more heavily on cloud architectures, the agency will launch the CCoP (Cloud) later this year to govern the deployment, operation, and management of cloud-hosted CII systems.

Following closed-door consultations with operators and auditors, the CSA co-developed provider-specific Companion Guides alongside market leaders Amazon Web Services, Google Cloud, and Microsoft Azure. These guides will publish concurrently with the cloud code to give operators tailored blueprints for leveraging native security capabilities within each environment.

Leave a Reply

Designed with WordPress

Discover more from Press KL: Your Voice, Your Vision

Subscribe now to keep reading and get access to the full archive.

Continue reading