Guidelines  ·  2026-07-25

Singapore CSA Announces Update to Cybersecurity Code of Practice for Critical Information Infrastructure to Address AI-Enabled and APT Threats

GuidelinesHigh impactSingapore
On 22 July 2026, the Cyber Security Agency of Singapore (CSA) announced that it will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) later in 2026 — the first update since 2022 — explicitly to address AI-enabled threats and Advanced Persistent Threats (APTs). The announcement (made by Minister Josephine Teo at the Operational Technology Cybersecurity Expert Panel Forum 2026) specifies new mandatory requirements taking effect this year: board-level cybersecurity accountability (all board members, not just one director) with an annually-reviewed documented cyber resilience framework; mandatory Cyber Trust Mark Level 5 certification for CII owners; mandatory oversight of interconnected systems linked to CII; CSA-led deployment of a locally-developed threat detection tool across CII network segments; new technical guidance covering adversarial attack simulation, penetration testing, and threat hunting; and comprehensive cybersecurity exercise plans. CSA also announced a companion new Code of Practice for Cloud Services (CCoP Cloud), to be launched in 2H2026, developed jointly with AWS, Google Cloud, and Microsoft Azure via CSP-specific Companion Guides. This is the first major national CII cybersecurity code explicitly revised to codify AI-threat-driven controls (e.g., faster adversary vulnerability discovery via frontier AI).
This is a legally-mandated cybersecurity code of practice (not voluntary guidance) applicable to all 11 CII sectors in Singapore (aviation, healthcare, land transport, maritime, media, security/emergency services, water, banking/finance, energy, info-communications, government). It is one of the first instances of a national regulator hard-coding AI-enabled threat response (adversarial simulation, faster patch cycles, AI-accelerated attacker vulnerability discovery) directly into a binding critical-infrastructure compliance regime, with concrete certification (Cyber Trust Mark Level 5) and board-accountability requirements. It sets a template other APAC/Five Eyes CII regulators may follow as frontier-AI-enabled attacks against OT/critical infrastructure become a live current risk (e.g., cited May 2026 Mexican water utility incident enabled by AI).
CII owners in Singapore's 11 designated sectors should begin gap-mapping current board cybersecurity governance and technical controls against the announced CCoP 2026 requirements (board resilience framework, Cyber Trust Mark L5, interconnected-system oversight) ahead of formal publication later in 2026; cloud-hosted CII operators should track the forthcoming CCoP (Cloud) and CSP Companion Guides for AWS/Google Cloud/Azure-specific configuration guidance.
Cyber Security Agency of Singapore (CSA) — Press ReleaseThe Straits Times — Singapore tightens rules governing critical services sectors to counter AI cyberthreatsSingapore Business Review — CSA strengthens cyber rules for critical infrastructure and cloud
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →