Singapore is expanding mandatory cybersecurity controls across its 11 critical information infrastructure sectors: operators must support CSA led threat detection, make the full board accountable and certify supportin... The changes follow the 2025 UNC3886 campaign against Singapore’s four major telecommunications o...
Research answer

Create a landscape editorial hero image for this Studio Global article: What tougher cybersecurity requirements will Singapore impose on operators of its 11 critical information infrastructure sectors under the u. Article summary: Singapore is tightening mandatory cyber controls for critical-information-infrastructure (CII) owners to improve detection, governance, resilience and oversight beyond the designated CII system itself. The measures respo. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Singapore is widening the cybersecurity perimeter around its critical information infrastructure (CII). Under the updated Cybersecurity Code of Practice, operators in 11 essential sectors will face stronger requirements for threat detection, executive governance, interconnected systems, resilience exercises and supporting infrastructure.
The shift comes as Singapore responds to faster, more sophisticated cyber operations—including AI-enabled attacks and the state-sponsored advanced persistent threat (APT) actor UNC3886, which targeted all four of the country’s major telecommunications operators in 2025.
CII owners will work with the Cyber Security Agency of Singapore (CSA) to deploy locally developed threat-detection systems across relevant network segments. The objective is to improve visibility and identify malicious activity not only within a formally designated CII system, but also across connected parts of the operating environment.
This is important because attackers may use less-protected systems as an entry point into critical infrastructure. Singapore has said that threat actors are increasingly targeting non-CII systems for precisely that reason.
The revised approach moves cybersecurity accountability beyond the IT department or a single designated executive. The entire board and senior management will be expected to oversee cyber risk and recovery.
Boards must maintain a documented cyber-resilience framework that addresses:
The framework must be reviewed at least annually.
That requirement turns cyber resilience into a recurring governance duty rather than a one-time compliance exercise. It also gives directors a clearer role in deciding how much risk the organisation is willing to accept and how it will continue operating after a serious incident.
CII owners will need to maintain oversight of systems that connect to, communicate with or support their CII. The updated requirements also call for stronger network architecture, monitoring and detection management, along with comprehensive cybersecurity exercise plans for coordinated incident response.
The practical implication is that operators will need a more complete map of their dependencies. Systems outside the formal CII designation may still require closer scrutiny if they can provide a pathway into critical services or affect recovery after an attack.
CII owners will be required to attain Cyber Trust Mark (CTM) Level 5 by the end of 2027 for non-CII systems they control that support their business operations or services. This extends assurance requirements beyond the systems formally designated as critical infrastructure.
Level 5 is the highest tier in Singapore’s Cyber Trust framework. The broader certification programme covers areas including classical cybersecurity, cloud security, operational-technology security and AI security.
The aim is to reduce the gap between a highly protected CII system and the surrounding corporate infrastructure that may share credentials, administration tools, networks or recovery processes with it.
Singapore’s CSA says the updated code is intended to address APT and AI-enabled threats. AI can help attackers operate with greater speed, scale and sophistication, increasing pressure on organisations to detect suspicious activity earlier and respond across their environments rather than relying on narrow perimeter controls.
The policy response is therefore not limited to adding another technical safeguard. It combines detection, governance, certification and exercises so that operators can identify threats, make decisions quickly and recover critical services if prevention fails.
The 2025 UNC3886 campaign targeted Singapore’s four major telecommunications operators. Singapore described the activity as a deliberate, targeted and well-planned campaign by an actor with advanced capabilities.
CSA has also identified UNC3886 as a state-sponsored APT group that uses sophisticated techniques, including living-off-the-land methods and zero-day exploits, while targeting high-value strategic assets such as critical infrastructure.
Singapore responded with Operation CYBER GUARDIAN, a coordinated effort involving government agencies and telecommunications companies. Authorities said the operation contained the incident without disruption to telecommunications services and found no evidence that customer data had been compromised.
The absence of a reported service disruption does not make the incident irrelevant to other sectors. It demonstrates why telecommunications, energy, healthcare, finance, transport and other essential services are treated as strategic targets—and why Singapore is extending controls to the systems and suppliers surrounding CII.
Singapore plans to introduce a separate, legally binding Cybersecurity Code of Practice for Cloud Services later in 2026. The code is expected to address the secure deployment, operation and management of CII systems hosted in cloud environments.
CSA has worked with AWS, Google Cloud and Microsoft Azure on provider-specific implementation guidance covering appropriate configurations and the use of cloud-native security capabilities.
The certification deadlines also reach into the cybersecurity supply chain:
These measures reflect a broader principle: a critical operator’s security depends not only on its own controls, but also on the organisations that audit, monitor, test and host its systems.
The updated CII requirements are now listed by CSA, but the detailed obligations under the separate cloud code are still developing. Public material identifies the planned timing and broad focus of the cloud rules, while precise requirements for cloud providers, subcontractors and shared-responsibility arrangements have not yet been fully specified.
For CII operators, the immediate priority is therefore to assess the entire dependency chain: designated CII, connected systems, cloud workloads, recovery environments, suppliers and outsourced security services. The direction of Singapore’s policy is clear even where implementation details remain to be published—the protected boundary is becoming the whole operating ecosystem, not just the system carrying the CII label.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Singapore is expanding mandatory cybersecurity controls across its 11 critical information infrastructure sectors: operators must support CSA led threat detection, make the full board accountable and certify supportin...
Singapore is expanding mandatory cybersecurity controls across its 11 critical information infrastructure sectors: operators must support CSA led threat detection, make the full board accountable and certify supportin... The changes follow the 2025 UNC3886 campaign against Singapore’s four major telecommunications operators and reflect concern that AI and advanced persistent threats can discover and exploit weaknesses faster.
A separate legally binding Code of Practice for Cloud Services is planned for later in 2026, but its final provider and subcontractor requirements have not yet been fully detailed.