Skip to content
Singapore Makes Critical Infrastructure Boards Own Cyber Recovery, Launches Cloud Code

Singapore Makes Critical Infrastructure Boards Own Cyber Recovery, Launches Cloud Code

Techtimes July 23, 2026

Singapore's government on July 22 issued its most sweeping overhaul of national critical infrastructure cybersecurity standards since 2022, requiring the boards of power companies, hospitals, banks, telcos, and seven other essential-service sectors to formally own their organizations' cyber recovery posture — not just fund a team to handle it. At the same moment, the Cyber Security Agency of Singapore (CSA) announced a first-of-its-kind mandatory security code specifically for critical systems hosted on public cloud, developed in partnership with Amazon Web Services, Google Cloud, and Microsoft Azure, as described in CSA's July 22 announcement .

The twin announcements, made by Minister for Digital Development and Information Josephine Teo at the Operational Technology Cybersecurity Expert Panel (OTCEP) Forum 2026, came nine months after a China-linked threat actor designated UNC3886 had silently penetrated all four of Singapore's major telecommunications operators — M1, SIMBA Telecom, Singtel, and StarHub. Investigators confirmed in February 2026 that while the attackers failed to disrupt services or steal customer data, they did exfiltrate a small amount of technical and network-related data — exactly the kind of reconnaissance material needed to execute a future, more disruptive operation.

The regulatory response is explicitly shaped by what investigators found: that sophisticated threat actors no longer need OT expertise to reach industrial control systems, that AI is accelerating every phase of an attack, and that most critical infrastructure remains effectively blind to what is happening inside its own networks. Singapore's answer is a framework built around three obligations: lock down, find first, and fix fast — and for the first time, it extends those obligations to the boardroom and to the cloud.

The incident that most clearly illustrates the threat Singapore is now regulating against did not happen in Singapore. Earlier this year, Dragos documented the Monterrey incident — an attempted breach of a municipal water utility in Monterrey, Mexico. The attacker had no prior operational technology knowledge. Using commercially available AI tools — not sophisticated, purpose-built exploit frameworks — the intruder gained access to the utility's IT network, identified a server connected to the SCADA environment, researched vendor documentation online, and generated login credentials for an automated attack. The attack failed. But the trajectory it demonstrated did not.

That trajectory — IT network compromise leading quickly to OT targeting via SCADA-connected infrastructure — describes a structural vulnerability that exists across virtually every modernized industrial facility. Legacy operational technology was designed without internet connectivity in mind. When Industry 4.0 and the Industrial Internet of Things dissolved the air gap between IT and OT networks, it exposed industrial systems to the full IT threat landscape without giving them the patching cycles, EDR coverage, or behavioral detection tools that IT environments rely on, as IBM X-Force 2026 threat data on the manufacturing sector demonstrates.

At the OTCEP Forum, Robert M. Lee's keynote at OTCEP 2026 presented data on the global OT threat landscape that framed Singapore's policy decisions in specific numbers. His firm tracks 26 OT threat groups worldwide; 11 were active in 2025 alone. Three new groups emerged last year: Sylvanite, which weaponized disclosed Ivanti VPN vulnerabilities within 48 hours and handed footholds directly to Voltzite, the group associated with China-linked Volt Typhoon campaigns; Azurite, which compromised small-office routers to build proxy infrastructure and stole OT network diagrams, alarm data, and PLC configurations from engineer workstations; and Pyroxene, which used fake social media profiles and bogus aerospace recruitment firms to reach OT networks through supply chain entry points. Ransomware groups with reach into OT networks grew 49% year on year, with 119 of them affecting approximately 3,300 industrial organizations.

Lee offered one summary figure that captures why Singapore's regulators acted when they did, as Computer Weekly reported from the keynote: " 95% of the world is not looking into their OT networks, and they're feeling very confident the lack of things they see." Incidents are routinely misclassified as IT-only because the compromised machine runs Windows, even when it is a SCADA server or engineer workstation.

In late December 2025, a coordinated Poland energy grid attack struck more than 30 wind and solar farms, a combined heat-and-power plant, and a manufacturing company simultaneously. The Polish grid remained stable — but the incident demonstrated that a single attacker can now orchestrate simultaneous disruption across many physical sites, including OT environments, at a scale previously requiring nation-state coordination.

Singapore's revised Cybersecurity Code of Practice for Critical Information Infrastructure (CCoP) is scheduled for H2 2026 publication alongside technical guidance on adversarial attack simulation, penetration testing, and threat hunting. Several of its headline requirements shift the nature of cyber accountability in ways that go beyond technical compliance.

On board and senior management accountability, the revised code will require boards to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery, reviewed at least annually. This distinction matters: cybersecurity and cyber resilience are not synonyms. Cybersecurity asks "how do we keep attackers out?" Cyber resilience, as defined in NIST's definition of cyber resilience , asks "what happens when they get in, and how do we survive?" Singapore's new standard requires boards to answer the second question in writing, with a review cadence that matches the pace of the threat landscape rather than the pace of annual strategic planning cycles.

Research from WEF's 2026 Cybersecurity Outlook found that 99% of organizations classified as "highly resilient" actively engage their boards in cybersecurity decisions. Yet Gartner's 2025 board survey found that 67% of non-executive directors believed current board practices were inadequate to oversee cyber risk. Singapore's new code is designed to close that gap through regulatory mandate.

On Cyber Trust Mark Level 5 certification, critical information infrastructure owners will be required to attain the highest tier of Singapore's national cybersecurity certification scheme, known as the Cyber Trust Mark Level 5 certification . Published as Singapore Standards 712 under the Singapore Standardisation Programme, Level 5 certification requires demonstrated preparedness across 22 cybersecurity domains — including governance, asset protection, and secure access — and has been updated to specifically incorporate cloud security, OT security, and AI security domains. The compliance timeline has teeth: CII auditors and licensed cybersecurity service providers must achieve certification by December 31, 2026, while CII owners themselves have until December 31, 2027, per the compliance deadlines .

On visibility into interconnected systems, CII owners must now maintain oversight of systems that communicate with their designated CII — not just the CII systems themselves. This requirement responds directly to the UNC3886 attack pattern, in which the threat actor moved through interconnected enterprise systems rather than targeting the highest-security CII systems directly.

On continuous threat detection, the CSA will work with CII owners to deploy threat detection systems across their network segments to identify malicious activity in real time. This represents a structural shift away from perimeter-based defense — a model that treats the boundary of a network as its primary defensive surface — toward interior detection that assumes adversaries may already be present and looks for behavioral indicators inside the network. The Monterrey water utility incident demonstrated why perimeter defense alone is insufficient: once an attacker has IT access, the path to OT can be traveled with commercially available AI tools.

On mandatory exercise planning, CII owners will be required to develop a comprehensive cybersecurity exercise plan to ensure a coordinated, rehearsed response to incidents. Operation Cyber Guardian succeeded in part because years of cross-agency exercises had built the trust and coordination needed for multiple independent organizations to work together under real-world attack conditions. That success is now being codified as a permanent compliance obligation rather than left as a best practice.

The framework applies across all 11 critical sectors regulated under Singapore's Cybersecurity Act: energy, info-communications, water, healthcare, banking and finance, security and emergency services, aviation, land transport, maritime, government, and media.

The board accountability mandate carries a legal dimension that CII operators' directors should engage counsel to assess. Singapore's legal framework — as analyzed in the ICLG Cybersecurity 2026 report for Singapore — establishes that "if a company fails to prevent, mitigate, manage or respond to an incident due to a lack of honesty, or a lack of the requisite skill, care and diligence on the part of its directors, this may constitute a breach of directors' duties."

The CCoP's annual board review requirement creates a paper trail of board-level cybersecurity decisions. When an incident occurs, that trail becomes a record of what the board knew, when they reviewed it, and what risk tolerance they documented. This structural feature aligns Singapore's board accountability approach with the SEC's 2023 cybersecurity governance rules and the EU's Cyber Resilience Act (which entered into force December 10, 2024), both of which created enforceable board-level accountability for cyber risk. Singapore-based multinational CII operators may now face parallel board accountability obligations across multiple jurisdictions simultaneously.

The planned CCoP for Cloud Services — scheduled for publication in the second half of 2026 — is the first time Singapore has codified mandatory cybersecurity standards specifically for critical infrastructure deployed on public cloud platforms.

The development of this code reflects a broader architectural tension in critical infrastructure regulation. When Singapore's Cybersecurity Act was first enacted in 2018 and updated to its CCoP 2.0 published in 2022 , cloud-hosted CII was the exception rather than the rule. The 2024 amendment to Singapore's Cybersecurity Act — whose key provisions took effect on October 31, 2025 — already updated the law to establish that accountability stays with the CII owner even when systems are hosted offshore or by third-party vendors. The new cloud code translates that legal principle into a technical compliance framework.

CSA conducted a series of closed-door consultations with CII owners, cloud service providers, and auditors before finalizing the cloud code, specifically to ensure that the proposed controls are implementable in real cloud environments rather than written for on-premises assumptions. The result is an architecture in which the cloud code sets baseline cybersecurity requirements, and each of the three major hyperscalers — Amazon Web Services, Google Cloud, and Microsoft Azure — will publish CSP-specific Companion Guides explaining how to implement those requirements using native services, configurations, and security capabilities in their respective environments. The Companion Guides will be published simultaneously with the cloud code.

This approach mirrors the NIST Cybersecurity Framework's "Profile" model, in which a common framework is interpreted through organization- and environment-specific implementation guidance, but applies it as a mandatory regulatory instrument rather than a voluntary best practice. For CII owners migrating workloads to cloud, the Companion Guides will define what "compliant" means in their specific hyperscaler environment — removing a significant ambiguity that has slowed cloud adoption in regulated industries globally.

The reforms extend accountability beyond CII owners to the manufacturers, vendors, and technology partners who supply the systems on which critical infrastructure runs.

Minister Teo stated at the OTCEP Forum that leading original equipment manufacturers and technology providers of operational technology have committed to obtaining Cyber Trust Mark certification — meaning their own organizations, and the products and services they sell, will meet a recognized national cybersecurity standard. This is a meaningful extension: a compromised vendor or technology partner represents the same entry-point risk as a misconfigured CII system, and the supply chain has been a documented attack vector in multiple major OT intrusions. Pyroxene, one of the three new threat groups identified by Dragos in 2025, operates specifically through supply chain targeting.

The supply chain security push also builds on a March 2026 announcement from the Ministry of Digital Development and Information that required not only CII owners but also the auditors who conduct CII cybersecurity assessments and the licensed service providers who offer penetration testing and managed security operations center monitoring to meet Cyber Trust Mark requirements. Service providers have until December 31, 2026, to comply.

The same AI capabilities that have lowered the barrier to OT attacks have also, in principle, made detection and response capabilities accessible to defenders who previously lacked the resources to deploy them.

Minister Teo cited research showing that AI-assisted security operations can compress months of security testing into days. As part of Singapore's "find first" strategy, CSA's AI cybersecurity sandbox is open to non-government organizations registered in Singapore. The program provides grants covering up to 70% of project costs for work on AI applications in cyber defense activities including penetration testing and code scanning. Projects must be completed within three months of award, and the sandbox runs to the end of February 2027. Crucially, the CSA intends to publish all findings from the program — including inconclusive results — so that lessons from what did not work are available to the wider ecosystem, not just to the best-funded operators.

On the intelligence side, the CSA renewed its Memorandum of Understanding with Dragos for deeper exchange of threat intelligence and joint capability development. Robert M. Lee's OTCEP keynote data illustrated what that intelligence relationship can produce: three new named threat groups identified, specific TTPs documented, and vendor advisory gaps (26% of advisories had no patch when released; Dragos supplied alternative mitigations in 52% of cases) flagged to the broader defender community.

Both the updated CCoP and the CCoP (Cloud) are scheduled for formal publication in the second half of 2026. When they take effect, the regulatory landscape for Singapore's 11 critical sectors will have changed on every major dimension: governance (board accountability mandate), detection (continuous monitoring across network segments), certification (Cyber Trust Mark Level 5), cloud (first-ever cloud-specific obligations), and supply chain (vendor certification requirements).

For boards of directors in Singapore's regulated sectors, the most time-sensitive obligation is the Cyber Trust Mark compliance deadline. CII auditors and licensed cybersecurity service providers face a December 31, 2026, deadline — meaning compliance work must begin immediately. CII owners themselves have until December 31, 2027, for their non-CII supporting systems.

The overarching question Minister Teo posed at the OTCEP Forum is one that every board in Singapore's regulated sectors will now be legally obligated to answer: "The question is, who moves faster?" AI has reduced the preparation time attackers need to reach operational technology from months to hours. It has equally put capabilities within reach of defenders. Singapore has decided that regulatory mandate, not market incentive, is the mechanism that will ensure defenders actually use them.

Under the updated Cybersecurity Code of Practice, boards and senior management at critical information infrastructure owners must maintain a documented cyber resilience framework that covers risk tolerance, mitigation, transfer, and recovery — and must review it at least annually. This differs from simply funding a security team: the framework must exist as a board-level record that can be audited, and it places personal accountability on directors for failures that arise from a lack of "skill, care and diligence" in cyber risk oversight. Boards should also ensure their organizations are on a compliance path toward Cyber Trust Mark Level 5 certification by end-2027.

The CCoP for Cloud Services will set baseline cybersecurity requirements for CII systems hosted on public cloud platforms. The CSA is co-developing CSP-specific Companion Guides with Amazon Web Services, Google Cloud, and Microsoft Azure; these guides translate the cloud code's controls into implementation instructions for each hyperscaler's native security services and configurations. When both the cloud code and the Companion Guides are published in H2 2026, CII owners will have a clear, hyperscaler-specific roadmap for compliance — removing the ambiguity that has historically made cloud adoption difficult in highly regulated sectors.

Cyber Trust Mark Level 5 is the highest tier of Singapore's national cybersecurity certification scheme, now published as Singapore Standards 712:2025. It requires demonstrated preparedness across 22 cybersecurity domains, including governance, asset protection, secure access, cloud security, OT security, and AI security. The mandatory deadlines differ by category: CII auditors and licensed cybersecurity service providers providing penetration testing or managed SOC monitoring must comply by December 31, 2026; CII owners (for non-CII systems supporting their operations) must comply by December 31, 2027.

The UNC3886 campaign against M1, SIMBA Telecom, Singtel, and StarHub has been contained — no services were disrupted and no customer data was stolen. However, the attackers did exfiltrate a small amount of technical and network-related data. Threat intelligence specialists assess that data of this type is used to prepare future, more targeted intrusions: the stolen network diagrams and configuration data provide the attacker a map of what to target . The CSA's new CCoP requirements — particularly continuous network monitoring and mandatory incident exercise plans — are directly designed to accelerate detection of the kind of long-dwell, low-signature activity that UNC3886 used to remain undetected.