Singapore Tightens Critical Infrastructure Cybersecurity Against AI Threats
- tech360.tv

- 8 hours ago
- 3 min read
Singapore is implementing stricter cybersecurity regulations for its critical information infrastructure operators, known as CII. These new rules, taking effect by the end of the current month, mandate a locally developed intrusion detection tool and require heightened board-level oversight of cybersecurity. These measures directly address growing digital threats, including those enabled by artificial intelligence.

According to the The Straits Times, the new home-grown threat detection tool emerged after a cyber-espionage incident involving the UNC3886 group. This group targeted Singtel, StarHub, M1, and Simba Telecom in July of the previous year. The Ministry of Defence's Centre for Strategic Infocomm Technologies developed the tool. It currently operates within selected CII systems, with a wider rollout planned across all eleven sectors, which span aviation to government.
And Minister for Digital Development and Information Josephine Teo announced these new rules. She stated that advanced threat actors will relentlessly seek vulnerabilities, exploiting every opening to infiltrate interconnected systems. Teo noted that UNC3886 was not the first group to target Singapore's CII systems. She highlighted that artificial intelligence challenges the assumption that operational technology systems are inherently safe from attack due to their complexity.
AI advancements render cyberattacks increasingly sophisticated. Threat actors can now discover vulnerabilities faster and launch attacks at greater scale. Anthropic's Claude Mythos Preview model reportedly uncovers unknown software vulnerabilities autonomously. Check Point Research also found AI automated most cyberattacks. Many industrial systems remain opaque, making early detection difficult.
Minister Teo clarified that AI has lowered the entry barrier for cyberattackers to target industrial systems. Singapore must respond by securing its systems and strengthening baseline defences to deny attackers an easy win. The updated Cybersecurity Code of Practice ensures this posture. CII owners must now ensure their entire boards are accountable for cybersecurity, moving beyond the previous requirement of only one board member possessing cybersecurity risk knowledge.
So, the Cyber Security Agency of Singapore, CSA, attributed the increased importance of board-level oversight to the accelerated speed and scale of AI-enabled threats. Boards will also now maintain a documented cyber resilience framework outlining the organisation's risk tolerance, mitigation measures, and recovery strategies, requiring annual review. The updated code mandates that CII owners obtain the highest-tier cybersecurity certification, Cyber Trust Mark Level 5, for non-CII systems supporting their operations. Level 5 certification requires preparedness across twenty-two domains. CII owners have until the end of 2027 to achieve this certification.
Securing systems also extends to cloud environments, as CII owners increasingly adopt them, Teo confirmed. She emphasised that a compromised vendor or partner can serve as a vulnerable entry point. A new legally binding code will be introduced later in the current year to compel CII owners using cloud services to ensure their providers implement adequate safeguards. This Cybersecurity Code of Practice (Cloud), under the Cybersecurity Act, will require CII owners to work collaboratively with vendors, establishing security controls and operational arrangements for secure cloud environments. Specific details will be shared subsequently.
And CII owners retain ultimate responsibility for meeting these cloud requirements. CSA conducted consultations with auditors and CII owners to ensure requirements are robust and practical. The new code will be complemented by guides developed jointly by CSA and cloud providers.
All board members of critical infrastructure owners are now accountable for cybersecurity.
A new legally binding cybersecurity code for cloud services will be introduced later in the current year.
The Cyber Security Agency of Singapore will deploy local threat detection tools and collaborate with cloud providers.


