Singapore has introduced stricter cybersecurity regulations for operators of its critical information infrastructure (CII) to better address the increasing risks posed by cyber threats, particularly those involving artificial intelligence (AI). The updated requirements, set to take effect by the end of July, mandate the use of a domestically developed intrusion detection tool and require organizations to ensure board-level engagement in cybersecurity governance.

The new measures follow a significant cyber-espionage incident in July 2025, when UNC3886, a state-sponsored hacking group, targeted Singapore’s four major telecommunications companies—Singtel, StarHub, M1, and Simba Telecom. In response, the Ministry of Defence’s Centre for Strategic Infocomm Technologies developed the detection tool now being deployed across select CII systems. Plans are underway for its broader implementation across all critical sectors.

Singapore’s CII sectors encompass aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government agencies. These sectors are considered vital to national security and economic stability, and the tightened regulations reflect growing concerns about sophisticated cyberattacks.

Minister for Digital Development and Information Josephine Teo outlined the rationale behind the updated code of practice during the announcement on July 22. She emphasized that there is a persistent and evolving threat landscape where adversaries actively seek vulnerabilities in interconnected systems. “Sophisticated threat actors will be relentless in their search for vulnerabilities and will not hesitate to exploit every opening to go in deep into interconnected systems,” Teo said.

Highlighting the broader implications of AI on cybersecurity, Teo noted that previous assumptions about the resilience of operational technology systems—such as those controlling power plants or transportation networks—are being challenged. The enhanced complexity introduced by AI has increased the risk of attacks penetrating these traditionally secure environments.

Teo also acknowledged that while UNC3886’s attack was notable, it is not an isolated incident and that Singapore must remain vigilant against future threats targeting its critical infrastructure. The government’s move to enforce stricter cybersecurity practices, including mandatory adoption of advanced threat detection tools and elevated corporate accountability, aims to bolster resilience across key sectors and safeguard national interests in an increasingly digital landscape.