- Singapore will hold senior management of Critical Information Infrastructures (CIIs) responsible for future breaches, emphasizing the need for cybersecurity knowledge at all leadership levels.
- The updated CCoP mandates that boards of CIIs maintain a documented cyber resilience framework that includes risk tolerance, mitigation, transfer, and recovery, to be reviewed at least annually.
- Collective cyber resilience is emphasized as a shared responsibility, with Minister Teo stating that it is only as strong as the weakest link in the system.
Singapore is enhancing cybersecurity regulations for Critical Information Infrastructures (CIIs), making senior management accountable for breaches. The updated Code of Practice (CCoP) requires boards to establish a documented cyber resilience framework, covering risk tolerance, mitigation, and recovery, with annual reviews mandated.12
Minister for Digital Development and Information, Josephine Teo, emphasized the necessity for leaders at all levels to possess adequate cybersecurity knowledge to manage risks effectively. She stated, “This starts with having clear oversight of their critical assets and putting in place continuous monitoring; after all, you cannot defend assets you did not see, and you cannot recover assets you did not know you have.”
The updated CCoP mandates that CIIs maintain a documented framework for cyber resilience, which includes risk management strategies and recovery plans. Teo highlighted the importance of this initiative, noting that “Our collective cyber resilience is only as strong as our weakest link.” She warned that sophisticated threat actors are constantly searching for vulnerabilities to exploit within interconnected systems.3
Additionally, Teo announced plans for a separate CCoP for Cloud services, which will outline cybersecurity requirements for the secure deployment and management of CII systems hosted on cloud platforms, further strengthening Singapore's cybersecurity posture.
“Following the UNC-3886 campaign, the updated CCoP requires CII boards to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery, reviewed annually. Minister Josephine Teo stressed that collective resilience depends on the weakest link, urging ecosystem-wide responsibility.”
