Singapore to hold senior management of CIIs responsible for future breaches

The Republic will update its code of practice for critical information infrastructure owners and introduce new one for cloud services to counter malicious threat actors who are increasingly using AI to mount attacks.

Singapore’s Minister for Digital Development and Information, Josephine Teo, addressing the Operational Technology Cybersecurity Expert Panel (OTCEP) forum 2026, on Wednesday. Image: MDDI.

Later this year, the Cyber Security Agency of Singapore (CSA) will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) owners and a new CCoP for cloud services.

 

This was in response to new threats emerging due to increasing use of artificial intelligence (AI) by threat actors.

 

Under the updated CCoP for CIIs, owners were expected to detect, respond, and recover from attacks. Boards and senior management would be held directly accountable for cyber resilience.

 

Speaking at the Operational Technology Cybersecurity Expert Panel (OTCEP) forum 2026, on Wednesday, Singapore’s Minister for Digital Development and Information, Josephine Teo, noted that leaders at every level of CIIs must have the cybersecurity knowledge needed to govern and manage cyber risks effectively.

 

“This starts with having clear oversight of their critical assets and putting in place continuous monitoring; after all, you cannot defend assets you did not see, and you cannot recover assets you did not know you have,” she said.

 

The Minister noted that many of the vulnerabilities in Operational Technology (OT) environments arose from poor cyber hygiene, such as weak passwords and outdated software.

 

“Threat actors can use AI to exploit these weak links within hours. They often find hundreds or thousands of vulnerabilities.

 

“Stronger cyber hygiene is essential to reduce the entry points that attackers can exploit.

 

"But we must still assume that some attacks will still succeed. That is why continuous monitoring, proactive detection, swift response, and recovery are equally important,” she said.

 

The updates reflected a fundamental shift from relying on perimeter defences to actively defending against threats.

Cyber resilience framework a must

 

Under the updated CCoP, boards of CIIs were required to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery – reviewing it at least annually.

 

The CII owners were also required to attain Cyber Trust Mark Level 5 certification to elevate their organisation’s cybersecurity posture and maintain oversight of interconnected systems that interacted with and communicated with the CIIs.

 

This was intended to strengthen visibility of the broader network architecture and improve cybersecurity risk management.

 

While CSA would work with owners to deploy threat detection systems across CII network segments to detect malicious activities, the owners were expected to develop a comprehensive cybersecurity exercise plan to ensure coordinated and effective response to cyber incidents.

 

They were required to have robust management measures to maintain network architecture, for example, in the areas of network management, monitoring, and detection management.

Need to extend cloud security baseline

 

The Minister noted that with CII owners increasingly adopting cloud technologies, “locking down” had to also extend to cloud environments while raising their security baseline.

 

“That is why CSA will be launching a separate CCoP for Cloud later this year.

 

“It will lay out cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on cloud,” she said.

 

According to the CSA, the CCoP (Cloud) aimed at establishing cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud.

 

CSA earlier conducted a series of closed-door consultations with key stakeholders, including auditors as well as CII owners that had or were exploring the adoption of cloud services.

 

It has incorporated feedback gathered through these engagements to refine both the controls and the accompanying guidance statements, resulting in a more robust, practical, and operationally applicable set of requirements, the agency said.

 

The aency has also partnered with leading Cloud Service Providers (CSPs) like Amazon Web Services (AWS), Google Cloud and Microsoft Azure to jointly develop CSP-specific Companion Guides.

 

These Companion Guides would provide practical guidance on how the CCoP (Cloud) controls could be implemented within their respective cloud environments through appropriate configurations and the effective use of cloud-native services and security capabilities.

 

CSA would publish the Companion Guides alongside the CCoP (Cloud) later this year.

How UNC-3886 was a wake-up call

 

Sharing a bit of background, the Minister noted that Singapore’s telecommunications sector had been the target of cyberattacks by UNC-3886, an Advanced Persistent Threat (APT) actor.

 

The campaign was methodical, and all four of the major telcos were hit, she noted.

 

Teo added that following the detection, CSA, relevant government agencies, and the telcos mounted a coordinated cyber response.

 

“We called it ‘Operation Cyber Guardian’, and it was the largest of its kind in Singapore,” she said.

 

Noting that while the attack was contained before the threat actor caused a service disruption or stole sensitive customer data, Operation Cyber Guardian “reinforced a fundamental reality”.

 

“Our collective cyber resilience is only as strong as our weakest link. Sophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go deep into interconnected systems.

 

“This makes cybersecurity a shared responsibility for everyone across the entire ecosystem. The UNC-3886 campaign is not the first to target Singapore’s CII, nor will it be the last.

 

“AI has also challenged a longstanding assumption that the complexity of OT systems keeps them safe from attack,” she said.

OEMs also need to step up

 

Teo noted that in today’s interconnected world, the risk to CII does not stop at the organisation’s boundary.

 

“A compromised vendor or partner can be just as vulnerable an entry point as a misconfigured internal system,” she said.

 

The Minister highlighted the need to strengthen the cybersecurity posture of the manufacturers, vendors and technology partners that develop and supply the technologies underpinning our critical infrastructure.

 

“I am encouraged that leading original equipment manufacturers (OEMs) and technology providers of OT have committed to be certified under Singapore's Cyber Trust Mark.

 

“This will demonstrate that they have implemented robust cybersecurity practices within their own organisations, and that the products and services they deliver meet a recognised standard,” the Minister said.