Singapore sets three priorities against AI-enabled OT attacks
A major coordinated response contained a cyberattack on all four of Singapore’s telcos.
Singapore has outlined three priorities for protecting operational technology from increasingly capable AI-assisted cyberattacks.
Minister for Digital Development and Information Josephine Teo said the country’s approach would focus on ‘lock down, find first and fix fast’.
Speaking at the Operational Technology Cybersecurity Expert Panel Forum, Teo warned that AI is lowering the technical barriers for attackers targeting critical infrastructure.
She cited an attempted breach of a municipal water utility in Monterrey, Mexico, in which an attacker without prior operational technology expertise reportedly used commercial AI tools to access the organisation’s IT network and identify systems connected to its industrial environment.
Teo also referred to a December 2025 campaign targeting more than 30 wind and solar farms and other industrial facilities in Poland. Electricity generation was not disrupted, but the incident demonstrated the potential for coordinated attacks across multiple operational technology sites.
Under the ‘lockdown’ priority, the Cyber Security Agency of Singapore is releasing an updated Cybersecurity Code of Practice for owners of critical information infrastructure.
The code will place greater emphasis on continuous monitoring, incident detection, response and recovery, with boards and senior management directly accountable for cyber resilience.
CSA also plans to introduce a separate code later in 2026 for critical systems hosted in cloud environments.
To ‘find first’, the agency has launched a sandbox to pilot AI-enabled security operations across critical infrastructure and to share lessons with the wider cybersecurity community.
The ‘fix fast’ priority will focus on faster vulnerability prioritisation, automation and practical mitigation where systems cannot be immediately patched.
CSA is also renewing its agreement with the industrial cybersecurity company Dragos to deepen threat intelligence sharing and jointly develop defensive capabilities.
Why does it matter?
AI could make attacks on operational technology faster and more accessible to people without specialist industrial knowledge, increasing risks to telecommunications, energy, water and other essential services. Singapore’s response combines regulatory expectations, board-level accountability, AI-assisted security testing and intelligence sharing, reflecting the need to strengthen the entire critical infrastructure ecosystem rather than relying only on individual operators.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
