Blog | Insicon Cyber

Singapore Just Told Critical Infrastructure Boards What's Coming. Australia and New Zealand Should Be Reading Closely.

Written by Greg Bunt | 14/9/26, 3:38 am

On 22 July 2026, the Cyber Security Agency of Singapore (CSA) announced it will update the Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure and launch a companion Code of Practice for Cloud Services later this year. Source: CSA press release.

Most regulatory announcements from outside Australia and New Zealand don't warrant a second look. This one does. Singapore is a close trading partner to both countries, sits inside the same Asia-Pacific threat environment, and its Cybersecurity Act does much the same job for Singapore that Australia's Security of Critical Infrastructure (SOCI) Act does here: it sets out which sectors count as critical and what their operators must do to protect them. When Singapore hardens its critical infrastructure requirements, it's a reasonable preview of where Australian and New Zealand regulators are likely headed, not just a story about someone else's compliance regime.

What's actually changing

The update, announced by Minister Josephine Teo at the Operational Technology Cybersecurity Expert Panel Forum 2026, is explicitly framed as a response to Advanced Persistent Threats (APTs) and AI-enabled attacks. CSA's stated rationale is blunt: Frontier AI is letting threat actors discover vulnerabilities faster, which shortens the window defenders have to respond before exploitation.

The practical changes for Critical Information Infrastructure (CII) owners:

  • Documented board accountability. Boards must maintain a written cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery, reviewed at least annually.
  • Cyber Trust Mark Level 5 certification becomes a requirement, not a voluntary badge.
  • Oversight extends beyond the CII itself. Owners must maintain visibility over the broader network architecture, including systems that merely interconnect with the CII.
  • Government-deployed detection. CSA will work with CII owners to deploy threat detection systems across their network segments.
  • Mandatory exercise plans, to ensure a coordinated response when an incident occurs.
  • A separate CCoP for Cloud Services, developed with AWS, Google Cloud, and Microsoft Azure as companion-guide partners, covering CII workloads hosted in the cloud.

None of this is exploratory guidance. It's a binding code of practice with a certification bar attached to it.

Why Australian and New Zealand boards should treat this as a preview, not a curiosity

We've written before about the direction Australian and New Zealand board accountability is heading. In How New Zealand's Cybersecurity Landscape is Reshaping Board Accountability, we argued that director liability is converging toward continuous, evidenced oversight rather than an annual checkbox exercise, and that this convergence is happening across borders, not within a single jurisdiction's rules. Singapore mandating an annually reviewed, board-owned resilience framework is that exact convergence, playing out in a third market with no direct regulatory link to Australia or New Zealand. That's a stronger signal than if it had come from a jurisdiction already harmonised with ours.

The AI-acceleration rationale CSA is using also isn't new territory for readers of this blog. It's Too Late to Secure AI: Why Trans-Tasman Organisations Must Focus on Governance made the same underlying argument: security controls that assume a human-speed threat actor no longer hold. What's notable is that Singapore has now put that argument into binding text, ahead of APRA or ASIC. APRA's AI letter of 30 April 2026 (covered in APRA Has Named Four AI Governance Failures) and ASIC's open letter of 8 May 2026 both raised board literacy and AI governance expectations, but neither mandated specific technical controls such as adversarial testing, penetration testing, or threat hunting cadence. CSA's update does exactly that. It's a fair bet this is the next escalation for regulated Australian and New Zealand entities, not a Singapore-specific quirk.

It's also worth reading CSA's announcement alongside the Five Eyes AI Cyber Security Statement, which we covered when it was issued on 22 June 2026, a month before Singapore's update.

That statement, "The AI shift in cyber risk: why leaders must act now," was jointly issued by the cyber security agency heads of Australia, New Zealand, the United Kingdom, Canada, and the United States, and made the identical case: Frontier AI is transforming both offensive and defensive cyber capability, and the timeline for organisations to respond has shrunk from years to months. Australia and New Zealand co-signed that warning. Singapore has now acted on the same logic independently, with no direct link to the Five Eyes grouping. That's two separate blocs converging on the same read of the threat within weeks of each other, which makes it harder to treat CSA's update as an isolated, Singapore-specific move.

Board Cyber Advisory

Is your board's cyber resilience framework documented, board-owned, and reviewed annually, or does it live in a slide deck from two years ago?

Insicon Cyber's Board Cyber Advisory service equips Australian and New Zealand directors with the frameworks and ongoing support to answer that question with evidence, not assumptions.

Explore Board Cyber Advisory Talk to our team

The requirement to maintain oversight of systems that merely connect to the CII, rather than just the CII itself, is the same blind spot we described in The Hidden Risks in Your Supply Chain: Protecting What You Can't See. Most organisations still evaluate third-party relationships on price and functionality, not security posture. Singapore has decided that's no longer acceptable for critical infrastructure. The SOCI Act's positive security obligations already point Australian critical infrastructure entities in this direction; CSA has simply been more specific about what "oversight" has to include.

And the mandatory cyber exercise plan requirement lands on ground we've already covered in Why Progressive Boards Are Rethinking Cyber Tabletop Simulations, where we argued boards should be testing AI-enabled and supply chain scenarios rather than running the same ransomware drill every year. Singapore has now made structured exercising a compliance requirement for CII owners, not a governance nicety.

The one genuinely new piece: cloud-specific codes of practice

The CCoP for Cloud Services doesn't have a direct precedent in Australian or New Zealand critical infrastructure regulation yet, and it's worth watching closely. CSA running closed-door consultations with cloud service providers and CII owners, then co-developing provider-specific companion guides with AWS, Google Cloud, and Microsoft Azure, is a more prescriptive approach than anything currently required under the SOCI Act or APRA's prudential standards. As more Australian and New Zealand critical infrastructure workloads move to the cloud, a cloud-specific code of practice becomes a logical next step for local regulators too.

What this means for boards now

You don't need to wait for an Australian or New Zealand regulator to mirror this before acting on it. The direction of travel is consistent across every jurisdiction we track: documented, board-owned resilience frameworks; mandated technical validation rather than self-assessment; and explicit oversight of the systems around your critical assets, not just the assets themselves.

If your organisation sits inside or adjacent to critical infrastructure in Australia or New Zealand, the questions to bring to your next board or risk committee are straightforward.

Is our cyber resilience framework documented, board-owned, and reviewed on a set cadence, or does it live in a slide deck from two years ago?

Do we have visibility into the systems that connect to our critical assets, not just the assets themselves?

When did we last run a structured exercise against an AI-enabled or supply chain scenario, rather than a generic ransomware playbook?

Insicon Cyber's Board Cyber Advisory service and Adaptive Security Operations Centre (aSOC) are built for exactly this shift, translating board-level accountability into monitored, evidenced operational practice across Australia and New Zealand. If Singapore's update raises questions about where your own organisation stands, that's the conversation worth having next.

Insicon Cyber

From boardroom strategy to 24/7 protection, let's discuss what Singapore's update means for your organisation.

Insicon Cyber delivers Board Cyber Advisory, CISO-as-a-Service, Managed Compliance, AI Security and Governance, and our Adaptive SOC (aSOC) across Australia and New Zealand.

Contact Insicon Cyber Visit insiconcyber.com