{"id":70738,"date":"2026-07-22T17:17:59","date_gmt":"2026-07-22T09:17:59","guid":{"rendered":"https:\/\/sgbuzz.com\/?p=70738"},"modified":"2026-07-22T17:17:59","modified_gmt":"2026-07-22T09:17:59","slug":"spore-tightens-rules-governing-critical-services-sectors","status":"publish","type":"post","link":"https:\/\/sgbuzz.com\/?p=70738","title":{"rendered":"S&#8217;pore tightens rules governing critical services sectors"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">SINGAPORE &#8211; Operators of Singapore\u2019s critical infrastructure <!-- -->will need to use a homegrown intrusion detection tool and ensure board-level involvement in cyber security matters to counter <!-- -->growing threats posed by artificial intelligence.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">These are among a host of tougher mandatory cybersecurity requirements under <!-- -->the Cybersecurity Code of Practice<!-- --> that will take effect by end July<!-- -->.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The locally-developed threat detection tool has come on the heels of <a href=\"https:\/\/www.straitstimes.com\/tech\/spores-four-major-telcos-came-under-attack-by-cyber-espionage-group-unc3886?ref=inline-article\" rel=\"noopener\" class=\"gap-x-04 items-center inline text-primary-60 select-auto\" aria-label=\"link\" target=\"_blank\" data-testid=\"custom-link\"><span class=\"inline font-tertiary-body-baseline-regular\" data-testid=\"typography-test-id\">state-sponsored cyber-espionage group UNC3886\u2019s attack<\/span><\/a> on Singapore\u2019s four major telcos Singtel, StarHub, M1 and Simba Telecom detected in July 2025.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The tool,<!-- --> developed by the Ministry of Defence\u2019s Centre for Strategic Infocomm Technologies, has already been deployed in selected critical CII systems. <!-- -->A wider rollout across all 11 CII sectors is being planned to strengthen Singapore\u2019s defence against such advanced persistent threats.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The 11 CII sectors are aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Announcing the new rules on July 22, the Minister of Digital Development and Information Josephine Teo said: <!-- -->\u201cSophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go in deep into interconnected systems.\u201d<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Teo also pointed out that UNC3886 is not the first to target Singapore\u2019s CII systems, nor will it be the last.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">\u201cAI has challenged the long-standing assumption that the complexity of operational technology systems keeps them safe from attack,\u201d said Teo, who was referring to systems that operate heavy industrial machinery like those in power plants or transport networks.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">She was speaking at the sixth edition of the Operational Technology Cybersecurity Expert Panel Forum.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Advances in AI are making cyberattacks increasingly sophisticated, enabling threat actors to discover vulnerabilities faster, and launch attacks at a greater scale.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">For example, Anthropic\u2019s latest <a href=\"https:\/\/www.straitstimes.com\/world\/why-anthropics-mythos-is-sparking-global-alarm?ref=inline-article\" rel=\"noopener\" class=\"gap-x-04 items-center inline text-primary-60 select-auto\" aria-label=\"link\" target=\"_blank\" data-testid=\"custom-link\"><span class=\"inline font-tertiary-body-baseline-regular\" data-testid=\"typography-test-id\">Claude Mythos Preview model<\/span><\/a> is said to be able to autonomously uncover unknown software vulnerabilities and engineer exploits.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">A recent intelligence report by cybersecurity company Check Point Research also found that <a href=\"https:\/\/www.straitstimes.com\/tech\/ai-now-carries-out-cyber-attacks-with-little-human-input-report?ref=inline-article\" rel=\"noopener\" class=\"gap-x-04 items-center inline text-primary-60 select-auto\" aria-label=\"link\" target=\"_blank\" data-testid=\"custom-link\"><span class=\"inline font-tertiary-body-baseline-regular\" data-testid=\"typography-test-id\">AI had helped to automate the bulk of cyber attacks<\/span><\/a> that previously required skilled human hackers.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Teo said that AI has lowered the barrier of entry for cyber attackers to target industrial systems. For example in May 2026, amateur hackers used AI to map a Mexican municipal water utility\u2019s network and generate malicious code.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">But many industrial systems remain opaque. \u201cWe are caught by surprise when something seems wrong with operations. By then, the attacker may have compromised systems for weeks,\u201d said Teo.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">As such, Singapore needs to respond by locking down systems to strengthen its baseline defence so attackers are denied an easy win, she said.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The updated measures in the Cybersecurity Code of Practice is one way of ensuring this.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">CII owners <!-- -->are also required<!-- --> to ensure their entire boards\u2014not just a single director\u2014account for cybersecurity<!-- --> under the updated code. <!-- -->Previously, CII owners only need to ensure at least one board member with knowledge of cybersecurity risks to provide guidance to senior management.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The Cyber Security Agency of Singapore (CSA) said that AI-enabled threats have accelerated the speed and scale of cyberattacks, and board-level oversight and accountability has become more important<!-- -->. <!-- -->\u201cUltimately, cybersecurity is a business risk that requires sustained leadership and oversight from the board, rather than being viewed solely as a technical or operational issue.\u201d<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Boards will now also have to maintain a documented cyber resilience framework setting out the organisation\u2019s risk tolerance, mitigation, and recovery measures, and review it at least annually.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The updated Cybersecurity Code of Practice will also mandate that CII owners obtain the highest-tier cybersecurity certification Cyber Trust mark level 5 for their non-CII systems that support their business operations and services.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Level 5 certification requires preparedness in all of 22 domains, including governance, asset protection and secure access. Lower-level certification requires preparedness in fewer domains.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\"><a href=\"https:\/\/www.straitstimes.com\/singapore\/politics\/singapore-develops-its-own-threat-detection-tool-on-the-heels-of-unc3886-attacks?ref=inline-article\" rel=\"noopener\" class=\"gap-x-04 items-center inline text-primary-60 select-auto\" aria-label=\"link\" target=\"_blank\" data-testid=\"custom-link\"><span class=\"inline font-tertiary-body-baseline-regular\" data-testid=\"typography-test-id\">The move was previously announced<\/span><\/a> at a debate on<!-- --> the Ministry of Digital Development and Information\u2019s <!-- -->budget<!-- --> in March.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">CII owners have till the end of 2027 to comply<!-- --> with the requirement to obtain the Cyber Trust mark certification.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Locking down systems also extends to cloud environments as CII owners increasingly adopt them, said<!-- --> <!-- -->Teo.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">A new legally binding code will also be introduced later in 2026 to require CII owners using cloud services to ensure their providers have adequate safeguards against cyber threats.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">\u201cA compromised vendor or partner can be just as vulnerable an entry point as misconfigured internal system,\u201d said Teo.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The upcoming Cybersecurity Code of Practice (Cloud), which will be issued under the Cybersecurity Act, will require CII owners to work with their vendors to put in place security controls and operational arrangements to ensure their environments are secure.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The new code will set out requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud. These details will be shared later.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">CII owners are responsible for ensuring the requirements are met.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">CSA has conducted a series of closed-door consultations with auditors and CII owners that have or are exploring the adoption of cloud services to ensure that the requirements are robust, practical, and can be implemented by operators.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">The new code will also be accompanied by companion guides jointly developed by CSA and cloud providers including Amazon Web Services, Google Cloud and Microsoft Azure.<\/p>\n<p class=\"text-primary font-tertiary-body-baseline-regular\" data-testid=\"article-paragraph-annotation-test-id\">Each guide sets out how the code\u2019s requirements can be implemented within that provider\u2019s cloud environment.<\/p>\n<\/div>\n<p><br \/>\n<center><br \/>\n<br \/><a href=\"https:\/\/www.straitstimes.com\/tech\/singapore-tightens-rules-governing-critical-services-sectors-to-counter-ai-cyber-threats\" target=\"_blank\" rel=\"noopener\">Read Full Article At Source <\/a><br \/>\n<center\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SINGAPORE &#8211; Operators of Singapore\u2019s critical infrastructure will need to use a homegrown intrusion detection tool and ensure board-level involvement in cyber security matters to&#8230;<\/p>\n","protected":false},"author":1,"featured_media":70739,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","footnotes":""},"categories":[2611],"tags":[],"class_list":["post-70738","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-buzz-headlines","wpcat-2611-id"],"_links":{"self":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/posts\/70738","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=70738"}],"version-history":[{"count":0,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/posts\/70738\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=\/wp\/v2\/media\/70739"}],"wp:attachment":[{"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=70738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=70738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sgbuzz.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=70738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}