Singapore Strengthens Cyber Defenses as AI Reshapes the Threat Landscape
Overview
Artificial Intelligence is rapidly transforming cybersecurity—not only by empowering defenders with faster detection and automation, but also by giving cybercriminals new tools to launch increasingly sophisticated attacks. Recognising this shift, the Cyber Security Agency of Singapore (CSA) released its latest Singapore Cyber Landscape 2025/2026 report on 30 June 2026, outlining how the nation intends to strengthen its cyber resilience amid an AI-driven threat environment.
The report provides more than a snapshot of Singapore’s cybersecurity status. It offers valuable insight into the government’s regulatory direction, highlighting the policies, certification schemes, and national initiatives that organisations should prepare for over the coming years. Whether operating critical infrastructure, developing connected devices, or providing digital services, businesses can expect cybersecurity requirements to become increasingly rigorous.
AI Is Changing Both Attackers and Defenders
One of the report’s central themes is the emergence of agentic AI, where autonomous AI systems are capable of performing complex cybersecurity tasks with minimal human intervention. According to CSA, these technologies have significantly lowered the technical barrier for attackers by automating many stages of the cyber kill chain, enabling faster vulnerability discovery, exploit development, and large-scale attacks.
At the same time, AI is becoming an essential tool for defenders. Security teams are increasingly using AI-powered detection, automated vulnerability assessments, and intelligent incident response capabilities to reduce response times and improve operational efficiency. However, CSA also warns that AI systems themselves are becoming attractive attack targets. As organisations integrate AI into critical business processes, securing AI applications is now considered a dedicated cybersecurity discipline rather than simply another IT control.
Cyber Threats Continue to Evolve
Although Singapore experienced encouraging progress in some areas during 2025, the overall threat landscape remains challenging.
Reported phishing incidents declined by approximately 21%, suggesting that public awareness campaigns and defensive technologies are beginning to produce measurable results. Nevertheless, AI-generated phishing emails, deepfake voice scams, and synthetic identities continue to make social engineering attacks increasingly convincing.
Meanwhile, the number of infected devices across Singapore surged dramatically, rising by more than 140% year over year. CSA attributes this increase to the widespread compromise of consumer IoT devices through botnet malware, combined with improved national detection capabilities.
Ransomware also remains a persistent concern. Although reported cases increased only slightly, small and medium-sized enterprises (SMEs) continue to be disproportionately affected due to limited cybersecurity resources and lower security maturity.
Perhaps most notably, Singapore faced a significant Advanced Persistent Threat (APT) campaign targeting all four of its major telecommunications operators. The coordinated national response, known as Operation CYBER GUARDIAN, successfully contained the incident without causing service disruption or confirmed data compromise, demonstrating the country’s growing cyber incident response capabilities.
National Cyber Resilience Becomes a Strategic Priority
Beyond responding to attacks, CSA is investing heavily in building long-term national resilience.
Several new initiatives were introduced during the past year. These include a National Simulated Scams Exercise designed to test public resilience against AI-enabled scam calls, the establishment of a Cyber Resilience Centre to provide cybersecurity support for SMEs, and the launch of a subsidised Chief Information Security Officer as a Service (CISOaaS) programme to improve cybersecurity governance among smaller organisations.
Singapore has also continued expanding its Cyber Essentials and Cyber Trust certification programmes. These schemes now incorporate cloud security and AI security requirements, reflecting the country’s recognition that cybersecurity must evolve alongside modern digital technologies.
Higher Security Expectations for Connected Products
For manufacturers of connected devices, CSA’s report carries particular significance.
By the end of 2027, all residential routers sold in Singapore must comply with Cybersecurity Labelling Scheme (CLS) Level 2 requirements. This represents a notable increase in baseline security expectations, including stronger authentication mechanisms and more secure protection of sensitive information.
In parallel, all Critical Information Infrastructure (CII) operators must achieve Cyber Trust certification by the same deadline. This requirement extends cybersecurity governance beyond traditionally regulated operational technology into broader enterprise environments supporting critical services.
Singapore is also actively contributing to international cybersecurity standardisation through ISO/IEC 27404, helping align national IoT security labelling programmes with global frameworks. This harmonisation may ultimately reduce compliance complexity for manufacturers selling products across multiple regulated markets.
Preparing for the Next Phase of Cybersecurity Regulation
CSA makes it clear that its current initiatives are only the beginning.
The agency plans to continue developing guidance for securing agentic AI systems, expand technical training for cybersecurity professionals responsible for protecting critical infrastructure, and accelerate research into quantum-safe cryptography as future computing technologies mature.
Rather than viewing today’s guidance as a final destination, organisations should expect cybersecurity requirements to continue evolving in response to technological advances and increasingly sophisticated cyber threats.
Looking Ahead
The Singapore Cyber Landscape 2025/2026 report reinforces a broader global trend: cybersecurity is shifting from reactive protection toward continuous resilience. Artificial intelligence, secure product development, supply chain security, and regulatory compliance are becoming increasingly interconnected.
For organisations operating in Singapore—or planning to enter its market—the message is clear. Cybersecurity is no longer simply an IT responsibility. It has become a strategic business capability that influences product design, operational resilience, regulatory compliance, and customer trust.
As governments around the world continue strengthening cybersecurity regulations, businesses that invest early in secure development practices and compliance readiness will be better positioned to navigate the evolving digital landscape and maintain a competitive advantage.
References
CSA’s Initiatives to Strengthen Singapore’s Cyber Defences Amid an AI-Driven Threat Landscape | Cyber Security Agency of Singapore
https://www.csa.gov.sg/news-events/press-releases/csa-s-initiatives-to-strengthen-singapore-s-cyber-defences-amid-an-ai-driven-threat-landscape/
Not Sure Where to Start?
Request a free initial consultation or product assessment.
Our experts are here to help.
