Washington | 20°C (heavy intensity rain)
Singapore Tightens Cyber Rules: Senior Leaders Now Directly Responsible for Critical Infrastructure Security

CSA unveils updated Cybersecurity Code of Practice, spotlighting AI‑driven threats and senior‑management accountability

The Cyber Security Agency of Singapore (CSA) announced a revamped Code of Practice for Critical Information Infrastructure, making boardroom leaders directly answerable for cyber‑resilience and hinting at a new cloud‑security guide later this year.

On a busy Wednesday in July 2026, Minister Josephine Teo – who wears both the Digital Development and Cybersecurity hats – stepped up to the podium at the Operational Technology Cybersecurity Expert Panel (OTCEP) Forum and gave Singapore’s critical infrastructure owners a clear message: the buck stops with you.

In plain words, the senior‑management teams of organisations that run everything from power plants and water treatment works to public transport and digital banking systems will now be directly accountable for their cyber‑resilience. That’s a step up from the previous “oversee” language that many said was too vague.

The announcement came alongside the Cyber Security Agency’s (CSA) press release titled “Cybersecurity Code of Practice for Critical Information Infrastructure to be Updated to Address APT and AI‑enabled Threats”. The updated code, which was rolled out the same day, inserts a handful of new, concrete obligations.

First, board members must now sign off on a Cyber‑Trust‑Mark Level 5 certification – the highest assurance tier – before any new system goes live. Second, owners are required to map out and monitor any interconnected assets, recognising that a breach in a seemingly peripheral system can cascade into a full‑blown outage.

On the technical side, the code pushes for regular adversarial‑attack simulations, more rigorous penetration testing and an ongoing threat‑hunting programme. In other words, organisations can no longer treat cyber‑defence as a one‑off checklist; it must become a continuous, board‑level priority.

What’s perhaps most striking is the explicit nod to the rising tide of AI‑augmented attacks. The Minister warned that threat actors are now wielding generative‑AI tools to automate phishing, craft deep‑fake audio and even fine‑tune malware. “Our defenses must evolve at the same pace,” she said, before urging all CII owners to revisit their risk assessments in light of these new capabilities.

Looking ahead, CSA hinted that a separate Code of Practice for cloud services will be published “later this year”. That guide will lay down the rules for deploying and managing critical workloads in public‑cloud environments – a move that reflects the growing reliance on cloud‑native architectures across the island’s essential services.

Industry observers have welcomed the tighter stance, noting that clear accountability at the top can drive faster implementation of security controls. Some critics, however, caution that smaller players may struggle with the added compliance burden, especially the Level 5 certification requirement.

Regardless of the debate, the message is unequivocal: in Singapore’s digital age, cyber‑risk is no longer an IT issue alone. It’s a boardroom issue, a national‑security issue, and, increasingly, an AI‑driven issue. The updated Code of Practice aims to make sure that the people who make the big decisions also bear the responsibility for keeping the nation’s critical systems safe.

Comments 0
Please login to post a comment. Login
No approved comments yet.

Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.