Singapore's amended cyber code takes effect by end July 2026 with personal director liability, a state built intrusion sensor across eleven critical sectors, and a binding cloud rule coming later.
In July 2025, a state-linked group compromised Singapore's four major telecoms and stayed in their management interfaces for months. A year later, the response from the Cyber Security Agency of Singapore (CSA) puts a specific group of people on the hook: every board member of a critical-infrastructure owner, who under an amended Cybersecurity Code of Practice (CCoP) that takes effect by end-July 2026 is now personally accountable for the company's cyber posture.
The amended CCoP applies to eleven sectors: aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government. The technical mandates are concrete. Operators must install a state-built intrusion-detection tool developed by the Ministry of Defence's Centre for Strategic Infocomm Technologies (CSIT), already deployed in selected systems with wider rollout in progress, per a CSA press release. The structural change is more direct: a material cyber incident is now a director-liability event, not a CISO work order.
Boards that previously delegated cyber to a security function must now own the residual risk themselves. CSA set the standard in the Cybersecurity Code of Practice for CII, Second Edition, Revision One, with the CSA Notices page and Codes of Practice carrying the implementing amendments. Compliance is the operator's job, not the regulator's.
The trigger for the new code was a named intrusion. UNC3886, a state-linked group, hit Singtel, StarHub, M1, and Simba in mid-2025. Speaking at the OTCEP Forum on 22 July, Minister for Communications and Information Josephine Teo framed the response: "Sophisticated threat actors will be relentless… will not hesitate to exploit every opening to go in deep into interconnected systems."
Two pieces of evidence sit behind the timing. Minister Teo cited Anthropic's Claude Mythos Preview, a vendor-published research note on autonomous exploit discovery, and recent Check Point Research findings on AI-automated attack scaling. Both describe attacker-side capability. Neither independently measures the impact on Singapore. The regulator is the one drawing the line from AI capability to a faster regulatory cycle, and that causal link is the regulator's framing, not an independently measured claim.
CSA is making its Cyber Trust Mark (CTM) certification mandatory for critical-infrastructure owners, their auditors, and licensed cybersecurity service providers. Critical-infrastructure owners get a two-year grace period to reach CTM Level 5, which covers 22 domains including governance, asset protection, and secure access; auditors and licensed providers have until end-2026. The mark was enhanced in 2025 for cloud, operational technology, and AI security, per a Baker McKenzie analysis. CTM Level 5 applies to non-critical systems that support a critical-infrastructure owner's business, not the critical systems themselves.
CSA is working with cloud providers to introduce a new cybersecurity code in 2026, according to the Straits Times, raising the bar on what hyperscalers must do for Singapore workloads. The licensing framework changes took effect in February 2026 after a 22 September to 21 October 2025 public consultation that drew 17 responses. Licence validity is now five years, and notification rules are streamlined.
A material incident under the amended code is now a director-liability event, and that propagates pressure to vendors, auditors, and cloud providers through the parallel certification regime. Singapore is betting that putting a director's name on the line will do what the new sensor alone cannot: force the money and the attention to follow the threat.
The next checkpoint is the cloud code, expected later in 2026.