Jul 24, 2026 · 7:49 AM
Subscribe
Home Ai

Singapore tightens cybersecurity rules for critical infrastructure after China-linked hack hit all four major telcos

Singapore is mandating new cybersecurity rules for critical infrastructure operators, including a homegrown intrusion detection tool and board-level accountability, directly in response to a China-linked espionage group breaching all four of the city-state's major telcos in 2025. The updated Cybersecurity Code of Practice takes effect in stages through 2027.

Elroy Fernandes
· 5 min read · 535 reads
Singapore tightens cybersecurity rules for critical infrastructure after China-linked hack hit all four major telcos

Singapore is tightening its cyber rules because UNC3886 showed how quickly a state-linked group can get inside the country's telecom backbone. The useful part is not the rhetoric. It is the new pressure on boards to know what they own, what connects to it, and how fast they can recover.

When Singapore named the targets of Operation CYBER GUARDIAN on February 9, 2026, the list was blunt: Singtel, StarHub, M1 and Simba Telecom. That is every major telco in the country. The Cyber Security Agency of Singapore and the Infocomm Media Development Authority said the China-nexus group UNC3886 had run a deliberate campaign against the sector, using advanced tools, a zero-day exploit in one instance, and rootkits in another to keep hidden access.

That is not a routine breach notice. It is a warning shot.

The attackers did not cut off internet service. CSA and IMDA also said there was no evidence that sensitive customer data was accessed or stolen, and the most sensitive systems, including the 5G core, were not compromised. But Minister Josephine Teo said UNC3886 managed to steal a small amount of technical data, the sort of information that helps an attacker understand the terrain before trying to do something worse later. You do not need a blackout for this to matter. Quiet access is dangerous enough.

Singapore's answer is now moving into regulation. On July 22, CSA said it will release an updated Cybersecurity Code of Practice for Critical Information Infrastructure later this year, the first update since 2022. The new code will apply to owners of critical systems across sectors such as energy, water, banking and finance, healthcare, transport, infocomm, media, emergency services and government. If you operate infrastructure the country depends on, the government is done treating cyber resilience as a narrow technical function.

The clearest change sits at the top. Boards and senior management of CII owners will be held directly accountable for cyber resilience. CSA said boards must maintain a documented framework covering risk tolerance, mitigation, transfer and recovery, and review it at least once a year. That sounds dry. It should be. The point is to make directors put real names, dates and decisions against risks that too often sit inside security reports until something breaks.

The government wants better visibility

The updated code also pushes CII owners to maintain oversight of systems that connect with and communicate with their critical infrastructure. That detail matters because attackers rarely need to begin with the most heavily guarded system. In March, Senior Minister of State Tan Kiat How told Parliament that threat actors were targeting non-CII systems because they may be less secure and can become entry points into CII systems. That is exactly the route a patient state-backed actor would look for.

CSA will also work with CII owners to deploy threat detection systems across network segments. Tan said in March that the government would equip CII owners with proprietary threat detection systems to strengthen their ability to detect malicious activity, especially state-sponsored APT activity, and that these tools would complement commercial products already in use. Here is the thing: this is a quiet admission that the commercial market alone is not enough for national infrastructure. Off-the-shelf tools didn't stop UNC3886.

The code will add technical guidance on adversarial attack simulation, penetration testing and threat hunting. It will also require CII owners to attain Cyber Trust Mark Level 5 certification. CSA separately said CII auditors have until the end of 2026 to obtain Level 5 certification, while licensed providers of penetration testing and managed security operations centre monitoring services must obtain Cyber Trust Mark Promoter, or Tier 3, certification by December 31, 2026. CII owners have until the end of 2027 for Level 5 certification covering non-CII systems under their control that support business operations.

Those dates give operators time. They do not give them much excuse.

Cloud is now part of the perimeter

Singapore is also preparing a separate code of practice for cloud services in the second half of 2026. CSA said the cloud code will govern the secure deployment and operation of CII systems hosted on cloud platforms, and that Amazon Web Services, Google Cloud and Microsoft Azure are helping prepare provider-specific companion guides. That is a practical move. If critical services now run partly on hyperscaler infrastructure, a rulebook that stops at the old data centre door is already out of date.

Josephine Teo framed the broader risk plainly at the Operational Technology Cybersecurity Expert Panel Forum 2026. AI lets attackers discover vulnerabilities faster and exploit weak links within hours, she said, while many operational technology environments remain hard to see into until someone notices something wrong. Her formula was simple: lock down, find the threat first, then fix it fast. You can argue with the slogan. You cannot argue with the sequence.

There is a harder lesson for operators here. The UNC3886 campaign lasted long enough to require an 11-month response involving more than 100 defenders across six government agencies and the telcos, according to CNA and The Straits Times. That is a lot of people cleaning up an attack that most customers never saw. The absence of public disruption was not proof that the risk was small. It was proof that the defenders caught it before the public had to learn the hard way.

Singapore's new rules will not make state-backed intrusions disappear. No code can do that. But they do change where responsibility sits. If a board signs off on poor asset visibility or leaves recovery plans vague after this, it will be much harder to pretend cybersecurity was somebody else's department.

Also read: Higgsfield AI tells creators they own their videos but quietly claims a perpetual worldwide license to train on themThe world's best green fund is up 34% by betting Japan holds the answer to AI's power crisisZ.ai's GLM-5.2 is the open-weight model US export controls cannot touch

TOPICS
Elroy is a digital marketer and developer from Goa, with over a decade of experience web development and marketing. He has been associated with several startups and serves currently as an Editor to the Asia Pacific Industrial magazine. He occasionally writes on Startup Fortune about technology and automation.
Related Articles
More posts →
Loading next article…
You're all caught up