Singapore to Hold Boards Accountable for Cyber Resilience

Singapore’s Cyber Security Agency (CSA) will update its Cybersecurity Code of Practice for Critical Information Infrastructure (CII) later this year, holding boards and senior management directly accountable for cyber resilience as artificial intelligence reshapes the threat landscape.

The update, announced by Mrs Josephine Teo, Minister for Digital Development and Information and Minister-in-charge of Cybersecurity and Smart Nation Group, at the Operational Technology Cybersecurity Expert Panel Forum 2026, is the first revision to the code since 2022. CII owners will be required to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer and recovery, reviewed at least annually, and to attain Cyber Trust Mark Level 5 certification. A separate code of practice for cloud services is also due in the second half of 2026.

Identity as the common control layer

Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan at Keeper Security, said the reforms elevate cyber risk to the same level as financial and operational risk, where it has always belonged. He noted that cybersecurity failures rarely stem from a lack of policy, but from responsibility for identity, operational technology, cloud infrastructure, third-party access and regulatory compliance sitting across separate teams with limited shared visibility.

‘As critical infrastructure becomes more interconnected, human users, service accounts, APIs and AI-driven agents are all interacting across IT, OT and cloud environments, making identity the common control layer across the organisation,’ Nishiyama said, citing Keeper’s 2026 research that found only 38 per cent of APAC organisations have Privileged Access Management (PAM) fully deployed, despite machine identities already outnumbering human ones.

A regional benchmark

For APAC entities more broadly, the update sets a benchmark regulatory standard and supply-chain baseline across interconnected regional networks. CSA will also work with CII owners to deploy threat detection systems across their network segments, with technical guidance on adversarial attack simulation, penetration testing and threat hunting to follow later this year.

Nishiyama said the practical starting point for boards facing the mandate is establishing who and what has privileged access, enforcing least-privilege access by default, and making privileged sessions continuously auditable across both IT and OT environments.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading