What Changed and Why It Matters
The Cyber Security Agency of Singapore (CSA) announced these changes on July 22. Boards of 11 critical sectors including telcos, banks, and aviation are now directly accountable for cyber resilience. This goes beyond funding security teams, it’s about documented recovery frameworks reviewed annually.
The CSA also introduced a mandatory security code for critical systems hosted on public cloud, developed in partnership with Amazon Web Services, Google Cloud, and Microsoft Azure, as detailed in the CSA’s July 22 announcement.
The Singapore Telecom Breaches Forced This
Minister for Digital Development and Information Josephine Teo unveiled these measures at the Operational Technology Cybersecurity Expert Panel Forum 2026. The timing wasn’t accidental. Nine months earlier, in February 2026, investigators confirmed that a China-linked threat actor called UNC3886 had silently breached all four of Singapore’s major telecommunications operators.
The breach was surgical. No services were disrupted. No customer data was stolen. But the attackers did exfiltrate technical and network-related data. That reconnaissance material is the blueprint for future, more disruptive attacks.
AI Changed the Attack Calculus
Singapore’s regulatory response directly addresses what investigators learned. The threat landscape has shifted fundamentally. Sophisticated threat actors no longer need deep operational technology expertise to reach industrial control systems. AI now accelerates every phase of an attack.
Most critical infrastructure remains largely blind to internal network activity. A real-world example illustrates how close we are to catastrophic failure. The Monterrey incident in Mexico, documented by Dragos, showed an attacker using commercial AI tools to access a municipal water utility’s network. They then used AI to research vendor documentation and generate login credentials for the SCADA environment. The attack failed, but the path was clear.
Singapore’s New Framework: Three Core Obligations
Singapore’s revised Cybersecurity Code of Practice for Critical Information Infrastructure (CCoP) will be published in . The framework rests on three obligations:
- Lock down: Secure access to critical systems and networks
- Find first: Detect intrusions before they cause damage
- Fix fast: Respond and recover without business disruption
These now extend from the IT team to the boardroom and the cloud. Boards must maintain a documented cyber resilience framework, reviewed annually. This covers risk tolerance, mitigation strategies, transfer mechanisms, and recovery procedures.
The distinction matters. Cybersecurity asks how do we keep attackers out?
Cyber resilience asks what happens when they get in, and how do we survive?
Singapore’s new standard requires boards to answer the second question in writing.
Certification Deadlines Are Aggressive
| Requirement | Deadline | Who |
|---|---|---|
| Cyber Trust Mark Level 5 certification required | CII auditors and licensed security providers | |
| Full compliance for CII owners | Critical infrastructure operators |
Level 5 certification demands preparedness across 22 cybersecurity domains, now including cloud security, operational technology, and AI security.
The Reality Check
Robert M. Lee’s keynote at OTCEP 2026 delivered a sobering reality check. As reported by Computer Weekly, he noted: About 95 percent of the world is not looking into their OT networks, and they’re feeling very confident about the lack of things they see.
Singapore is betting that board accountability and mandatory resilience frameworks will change that calculation. Whether other nations follow remains to be seen.
Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates



