chungking - Fotolia

Singapore to hold CII boards accountable as AI reshapes OT threat landscape

The Cyber Security Agency’s first update to its critical infrastructure code of practice since 2022 will make boards directly answerable for cyber resilience

Singapore will require the boards of critical information infrastructure (CII) owners to answer directly for cyber resilience under an updated cyber security code of practice, its first since 2022, as artificial intelligence (AI) shortens the time attackers need to exploit loopholes in operational technology (OT) systems.

Josephine Teo, Singapore’s minister for digital development and information, and minister-in-charge of cyber security, set out the changes at the sixth Operational Technology Cybersecurity Expert Panel Forum today, along with a code of practice for cloud services and a grant-funded sandbox for AI-enabled security operations.

Under the revised code of practice, boards must maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer and recovery, reviewed at least annually.

CII owners will also be required to attain level five of the Cyber Trust Mark certification, maintain oversight of interconnected systems that communicate with their CII, develop a comprehensive cyber exercise plan and put robust management measures in place for network architecture, monitoring and detection.

The updated code, said Teo, “reflects a fundamental shift from relying on perimeter defences to actively defending against the threats”.

The Cyber Security Agency of Singapore (CSA) will work with CII owners to deploy threat detection systems across their network segments, with technical guidance on adversarial attack simulation, penetration testing and threat hunting to follow later this year.

With more CII systems being hosted on public cloud, a separate cyber security code of practice for cloud will also be published in the second half of 2026, along with companion guides produced with Amazon Web Services, Google Cloud and Microsoft Azure on implementing the controls in each hyperscaler’s environment.

Lock down, find first, fix fast

Teo framed Singapore’s approach towards OT security around three priorities — lock down, find first and fix fast — amid a threat landscape that has changed since advanced persistent threat actor UNC3886 targeted all four of Singapore’s major telcos.

Although that campaign was contained by the country’s largest coordinated cyber response before any service disruption or theft of customer data, it reinforced the principle that “our collective cyber resilience is only as strong as our weakest link”, she said.

AI has also challenged the assumption that the complexity of OT systems keeps them out of reach, said Teo, citing an attempted breach of a municipal water utility in Monterrey, Mexico, documented by OT security firm Dragos.

In that incident, the attacker had no prior OT knowledge, but tapped commercial AI tools to move through the utility’s IT network, identify a server connected to the supervisory control and data acquisition (Scada) environment, research vendor documentation and generate credentials for an automated attack. It failed, but showed how far an amateur could get.

Still, few private operators can match adversaries with state-level backing, but “AI-assisted security operations have been shown to compress months of security testing into days”, said Teo. To that end, CSA has launched an experimentation sandbox, open to non-government organisations registered in Singapore, covering the use of AI in cyber defence activities such as penetration testing and code scanning, with grants of up to 70% of project costs.

The sandbox runs to the end of February 2027, with projects expected to be completed within three months of award. CSA will publish consolidated findings, including inconclusive ones, which help clarify what works, what does not, and what limitations or risks need to be addressed.

The visibility problem

At the event, Robert M Lee, CEO and co-founder of Dragos, painted a gloomy picture of the global OT security landscape based on his firm’s annual review of OT threats.

Dragos now tracks 26 OT threat groups worldwide, 11 of them active during 2025. Three were identified last year, among them Sylvanite, an access broker that weaponised disclosed Ivanti virtual private network (VPN) vulnerabilities within 48 hours and handed footholds to Voltzite, the group associated with the China-linked Volt Typhoon campaigns.

The others were Azurite, which compromised small-office routers to build proxy infrastructure, and stole OT network diagrams, alarm data and programmable logic controller (PLC) configurations from engineer workstations; and Pyroxene, which used fake social media profiles and bogus aerospace recruitment firms to reach OT networks through the supply chain.

Defenders are struggling to keep up, said Lee. Some 26% of vulnerability advisories carried no patch or mitigation when announced, and Dragos itself had to supply alternative mitigations in 52% of cases. Ransomware groups with reach into OT networks grew 49% year on year, with 119 of them affecting some 3,300 industrial organisations.

“About 95% of the world is not looking into their OT networks, and they’re feeling very confident about the lack of things they see,” he said, adding that incidents are routinely misclassified as IT-only because the compromised machine runs Windows, even when it is a Scada server or engineer workstation.

Lee also pointed to states supplying capability to proxies, claiming that at least two governments have armed non-state actors with OT attack tools and knowledge. These actors went from defacing internet-exposed human-machine interfaces to deploying PLC implants and firmware modifications within about a month.

The threat is likely to be exacerbated when experienced adversaries, armed with frontier AI models trained on years of accumulated data, gain the ability to run thousands of operations at a time, much more than they did before.

That said, Teo pointed out that AI has also put detection and response capabilities within the reach of defenders who previously lacked it: “The question is, who moves faster? Singapore intends to be on the right side of that race.”

Read more about cyber security in APAC

Read more on Hackers and cybercrime prevention