S’pore tightens rules governing critical services sectors

S’pore tightens rules governing critical services sectors


SINGAPORE – Operators of Singapore’s critical infrastructure will need to use a homegrown intrusion detection tool and ensure board-level involvement in cyber security matters to counter growing threats posed by artificial intelligence.

These are among a host of tougher mandatory cybersecurity requirements under the Cybersecurity Code of Practice that will take effect by end July.

The locally-developed threat detection tool has come on the heels of state-sponsored cyber-espionage group UNC3886’s attack on Singapore’s four major telcos Singtel, StarHub, M1 and Simba Telecom detected in July 2025.

The tool, developed by the Ministry of Defence’s Centre for Strategic Infocomm Technologies, has already been deployed in selected critical CII systems. A wider rollout across all 11 CII sectors is being planned to strengthen Singapore’s defence against such advanced persistent threats.

The 11 CII sectors are aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government.

Announcing the new rules on July 22, the Minister of Digital Development and Information Josephine Teo said: “Sophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go in deep into interconnected systems.”

Teo also pointed out that UNC3886 is not the first to target Singapore’s CII systems, nor will it be the last.

“AI has challenged the long-standing assumption that the complexity of operational technology systems keeps them safe from attack,” said Teo, who was referring to systems that operate heavy industrial machinery like those in power plants or transport networks.

She was speaking at the sixth edition of the Operational Technology Cybersecurity Expert Panel Forum.

Advances in AI are making cyberattacks increasingly sophisticated, enabling threat actors to discover vulnerabilities faster, and launch attacks at a greater scale.

For example, Anthropic’s latest Claude Mythos Preview model is said to be able to autonomously uncover unknown software vulnerabilities and engineer exploits.




Read Full Article At Source

Share. Save. Don't Miss The Buzz: XFacebookRedditLINETelegramWhatsAppGmail