Photo from Freepik

CSA strengthens cyber rules for critical infrastructure and cloud

New cloud security code will launch in 2H2026.

The Cyber Security Agency of Singapore (CSA) will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and a new CCoP for Cloud Services later this year.

The announcement was made by Minister for Digital Development and Information Josephine Teo at the Operational Technology Cybersecurity Expert Panel Forum 2026.

The revised CII code is the first update since 2022 and comes amid the rise of AI-enabled cyber threats. According to CSA, frontier AI is enabling threat actors to identify vulnerabilities and launch attacks more quickly, shortening the window for organisations to respond.

To address these risks, the updated code will include new technical guidance on adversarial attack simulation, penetration testing and threat hunting.

“The updates to CCoP focus on strengthening CII governance, visibility, detection and readiness, and broader enterprise networks that are interconnected with the CIIs to align with the amendments made to the Cybersecurity Act,” the agency said.

Under the updated code, organisations will be required to strengthen board and senior management accountability by maintaining an annually reviewed cyber resilience framework covering risk tolerance, mitigation, transfer and recovery.

CII owners must also obtain Cyber Trust Mark Level 5 certification, maintain oversight of interconnected systems linked to critical infrastructure, participate in CSA-led deployment of threat detection systems across network segments, develop comprehensive cybersecurity exercise plans, and implement stronger network management, monitoring and detection measures.

Alongside the revised CII code, CSA will launch a new CCoP for Cloud Services in the second half of 2026 to establish cybersecurity requirements for the secure deployment, operation and management of CII systems hosted on cloud platforms.

The agency said the new code reflects the increasing adoption of cloud technologies by critical infrastructure operators and aims to ensure cloud environments remain protected against evolving cyber threats.

CSA developed the framework following consultations with auditors and CII owners that are using or considering cloud services. Feedback from these engagements was incorporated into the final controls and implementation guidance.

To support adoption, CSA has partnered with Amazon Web Services, Google Cloud and Microsoft Azure to develop cloud provider-specific Companion Guides.
 

Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

If you've been wondering whether SBR could work for your company — yes, probably.

A lot of the companies we partner with started as readers. They'd been following our coverage for a while, saw their own customers and competitors in it, and eventually asked the obvious question: could we do something with you? The answer is usually yes. The shape of it depends on what you're trying to do.


The options are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. Some partners use one channel; most use a mix. We figure out the right combination by starting with your brief, not with our rate card.


So if the question has been on your mind, here's the easy way to ask it.

We'll tell you honestly whether we can help, and how. It's a better use of everyone's time.