Singapore will hold senior management of CIIs responsible for future breaches as part of tightened cybersecurity rules for critical services
Josephine TeoCyber Security Agency of Singapore

Singapore will hold senior management of CIIs responsible for future breaches as part of tightened cybersecurity rules for critical services

Singapore is tightening cybersecurity regulations for Critical Information Infrastructures (CIIs), holding senior management accountable for breaches. The updated Code of Practice mandates boards to ensure cyber resilience, with a focus on risk management and continuous monitoring, as emphasized by Minister Josephine Teo at a recent forum.

GovInsider GovInsider23 July 2026 · 05:29 UTC
CuriousCats Full Story

Singapore is enhancing cybersecurity regulations for Critical Information Infrastructures (CIIs), making senior management accountable for breaches. The updated Code of Practice (CCoP) requires boards to establish a documented cyber resilience framework, covering risk tolerance, mitigation, and recovery, with annual reviews mandated.12

Minister for Digital Development and Information, Josephine Teo, emphasized the necessity for leaders at all levels to possess adequate cybersecurity knowledge to manage risks effectively. She stated, “This starts with having clear oversight of their critical assets and putting in place continuous monitoring; after all, you cannot defend assets you did not see, and you cannot recover assets you did not know you have.”

The updated CCoP mandates that CIIs maintain a documented framework for cyber resilience, which includes risk management strategies and recovery plans. Teo highlighted the importance of this initiative, noting that “Our collective cyber resilience is only as strong as our weakest link.” She warned that sophisticated threat actors are constantly searching for vulnerabilities to exploit within interconnected systems.3

Additionally, Teo announced plans for a separate CCoP for Cloud services, which will outline cybersecurity requirements for the secure deployment and management of CII systems hosted on cloud platforms, further strengthening Singapore's cybersecurity posture.

Key Insight
“Following the UNC-3886 campaign, the updated CCoP requires CII boards to maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery, reviewed annually. Minister Josephine Teo stressed that collective resilience depends on the weakest link, urging ecosystem-wide responsibility.”
CuriousCats studied:
1
GovInsiderGovInsider
“Under the updated CCoP for CIIs, owners were expected to detect, respond, and recover from attacks. Boards and senior management would be held directly accountable for cyber resilience.”
GovInsider →
Ask CuriousCats
What are Singapore's new cybersecurity rules?
Who is affected by the updated CCoP?
Why is senior management held accountable?
How do these rules compare to previous regulations?
Are other countries adopting similar accountability measures?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
One story brought you here.
CuriousCats brings you everything else worth knowing.
Get CuriousCats