Singapore Tightens Cyber Rules for Critical Infrastructure
The update forces full board accountability to speed organisational response to faster AI-enabled attacks.
Overview
- Ministers announced an updated Cybersecurity Code of Practice on Wednesday that takes effect by the end of July and imposes new mandatory requirements on operators of Singapore’s 11 critical information infrastructure sectors.
- Boards and senior management must be directly accountable for cyber resilience and must keep a documented cyber resilience framework that is reviewed at least once a year.
- The code mandates use of a locally developed intrusion-detection tool from the Ministry of Defence’s Centre for Strategic Infocomm Technologies that is already in selected systems and will be rolled out more widely across CII network segments.
- Owners must obtain Cyber Trust Mark Level 5 for non-CII systems that support their operations by the end of 2027 to meet a higher baseline across 22 security domains.
- A legally binding Cloud Code will be published later in 2026 with companion guides from major cloud providers and the Cyber Security Agency will run an AI-for-cyber sandbox to pilot detection and response tools, a move driven by past telco intrusions and industry findings that AI can speed vulnerability discovery and exploit development.