
New Cybersecurity Rules in Singapore: Are Your People Ready?
Singapore announced major updates to its Cybersecurity Code of Practice for Critical Information Infrastructure (CII) sectors. The reason? AI-enabled threats are rewriting the rules of cyber defence. Minister Josephine Teo said AI has challenged a longstanding assumption “that the complexity of OT systems keeps them safe from attack.”
For Singapore organisations, especially those in critical information infrastructure sectors, it is not just a policy update. It is a signal that cybersecurity awareness across every level of the organisation, from the board to the frontline, is now part of the compliance baseline.
Why Singapore’s Cybersecurity Rules Are Changing in 2026
OT means operational technology also known as the gear that runs physical things. Pumps, valves, power switching, production lines. The old comfort was that this equipment is so specialised, and its manuals so obscure, that an outsider wouldn’t know where to begin.
That’s the assumption that just broke.
Earlier this year Dragos looked into an attempted break-in at a water utility in Monterrey, Mexico. The attacker knew nothing about OT. Using ordinary off-the-shelf AI tools, they got into the utility’s office network, found a server linked to the control system running the plant, worked their way through the vendor’s own manuals, and generated login details for an automated attack.
It didn’t work. That isn’t really the point. Making sense of unfamiliar industrial documentation used to be the hard part of an OT attack. Now it’s the easy part.
For OT security teams, this changes the threat model entirely. Cyber threat detection can no longer rely on the assumption that obscurity provides protection. Attackers equipped with AI can now learn your systems faster than your teams can patch them.
Cybersecurity Compliance for CII Sectors Explained
For organisations in Singapore’s CII sectors (including energy, water, banking, healthcare and transport), they need to comply with cybersecurity requirements under the updated Code that involves six specific obligations.
- Boards must keep a documented cyber resilience framework covering risk tolerance, mitigation, transfer and recovery, reviewed at least annually
- Cyber Trust Mark Level 5 certification for the CII itself, with non-CII systems under their control to follow by end-2027
- Oversight of interconnected systems that communicate with the CII
- Threat detection deployed across network segments, with CSA
- A proper cybersecurity exercise plan, so response is rehearsed
- Robust network architecture management
Technical guidance on attack simulation, penetration testing and threat hunting comes with it, giving CII owners a clearer playbook for testing whether their defences actually hold.
But here’s what keeps security professionals up at night: AI doesn’t just make attacks faster but smarter and more personalised.
Why Security Awareness Training Is Now a Compliance Requirement, Not Just Good Practice
Today’s scams are far more sophisticated than “you’ve won a million dollars” emails. During the National Day period, scammers impersonate NDP organisers seeking cash payments or personal information while during year-end bonus season, cybercriminals craft emails that look exactly like HR communications about bonus payouts. (…based on true client stories!) The pattern is always the same: timely, relevant, and convincing.
No firewall, no intrusion detection system, and no board-level mandate can protect an organisation if its employees are not trained to recognise these threats. This is where security awareness training and phishing simulation programmes do what technology alone cannot. Security awareness training is no longer optional so by training your people properly, they become the layer that catches what the tools miss.
